- kernel-uek-5.15.0-310.184.5.3.el9uek (oel9-uek7)
- 5.15.0-318.199.3.2.el9uek
- 2026-03-24 21:40:03
- 2026-03-25 08:55:57
- K20260324_08
- CVE-2024-53100
- Description:
nvme: tcp: avoid race between queue_lock lock and destroy
- CVE: https://linux.oracle.com/cve/CVE-2024-53100.html
- Patch: oel9-uek7/5.15.0-311.185.9.el9uek/CVE-2024-53100-nvme-tcp-avoid-race-between-queue-lock-lock-and-destroy.patch
- From: 5.15.0-311.185.9.el9uek
- CVE-2023-6931
- Description:
perf: Fix perf_event_validate_size()
- CVE: https://linux.oracle.com/cve/CVE-2023-6931.html
- Patch: oel9-uek7/5.15.0-311.185.9.el9uek/CVE-2023-6931-perf-fix-perf-event-validate-size.patch
- From: 5.15.0-311.185.9.el9uek
- CVE-2023-6931
- Description:
perf: Fix perf_event_validate_size() lockdep splat
- CVE: https://linux.oracle.com/cve/CVE-2023-6931.html
- Patch: oel9-uek7/5.15.0-311.185.9.el9uek/CVE-2023-6931-perf-fix-perf-event-validate-size-lockdep-splat.patch
- From: 5.15.0-311.185.9.el9uek
- CVE-2025-38061
- Description:
net: pktgen: fix access outside of user given buffer in pktgen_thread_write()
- CVE: https://linux.oracle.com/cve/CVE-2025-38061.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38061-net-pktgen-fix-access-outside-of-user-given-buffer-in-pktgen-thread-write-5.15.0-310.184.5.3.el9uek.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38051
- Description:
smb: client: Fix use-after-free in cifs_fill_dirent
- CVE: https://linux.oracle.com/cve/CVE-2025-38051.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38051-smb-client-fix-use-after-free-in-cifs-fill-dirent-5.15.0-310.184.5.3.el9uek.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38066
- Description:
dm cache: prevent BUG_ON by blocking retries on failed device resumes
- CVE: https://linux.oracle.com/cve/CVE-2025-38066.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38066-dm-cache-prevent-bug-on-by-blocking-retries-on-failed-device-resumes-5.15.0-310.184.5.3.el9uek.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38065
- Description:
orangefs: Do not truncate file size
- CVE: https://linux.oracle.com/cve/CVE-2025-38065.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38065-orangefs-do-not-truncate-file-size-5.15.0-310.184.5.3.el9uek.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38058
- Description:
__legitimize_mnt(): check for MNT_SYNC_UMOUNT should be under mount_lock
- CVE: https://linux.oracle.com/cve/CVE-2025-38058.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38058-legitimize-mnt-check-for-mnt-sync-umount-should-be-under-mount-lock-5.15.0-310.184.5.3.el9uek.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38044
- Description:
media: cx231xx: set device_caps for 417
- CVE: https://linux.oracle.com/cve/CVE-2025-38044.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38044-media-cx231xx-set-device-caps-for-417-5.15.0-310.184.5.3.el9uek.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38035
- Description:
nvmet-tcp: don't restore null sk_state_change
- CVE: https://linux.oracle.com/cve/CVE-2025-38035.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38035-nvmet-tcp-don-t-restore-null-sk-state-change-5.15.0-310.184.5.3.el9uek.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38037
- Description:
vxlan: Annotate FDB data races
- CVE: https://linux.oracle.com/cve/CVE-2025-38037.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38037-vxlan-annotate-fdb-data-races.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38075
- Description:
scsi: target: iscsi: Fix timeout on deleted connection
- CVE: https://linux.oracle.com/cve/CVE-2025-38075.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38075-scsi-target-iscsi-fix-timeout-on-deleted-connection-5.15.0-310.184.5.3.el9uek.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38043
- Description:
Patch targets ARM architecture, which this distro does not support.
- CVE:
- Patch: skipped/CVE-2025-38043.patch
- From:
- CVE-2025-38077
- Description:
platform/x86: dell-wmi-sysman: Avoid buffer overflow in current_password_store()
- CVE: https://linux.oracle.com/cve/CVE-2025-38077.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38077-platform-x86-dell-wmi-sysman-avoid-buffer-overflow-in-current-password-store-5.15.0-310.184.5.3.el9uek.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38048
- Description:
virtio_ring: Fix data race by tagging event_triggered as racy for KCSAN
- CVE: https://linux.oracle.com/cve/CVE-2025-38048.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38048-virtio-ring-fix-data-race-by-tagging-event-triggered-as-racy-for-kcsan-5.15.0-310.184.5.3.el9uek.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38079
- Description:
crypto: algif_hash - fix double free in hash_accept
- CVE: https://linux.oracle.com/cve/CVE-2025-38079.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38079-crypto-algif-hash-fix-double-free-in-hash-accept-5.15.0-310.184.5.3.el9uek.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38000
- Description:
sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()
- CVE: https://linux.oracle.com/cve/CVE-2025-38000.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38000-sch-hfsc-fix-qlen-accounting-bug-when-using-peek-in-hfsc-enqueue.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38001
- Description:
net_sched: hfsc: Address reentrant enqueue adding class to eltree twice
- CVE: https://linux.oracle.com/cve/CVE-2025-38001.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38001-net-sched-hfsc-address-reentrant-enqueue-adding-class-to-eltree-twice.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38350
- Description:
[PATCH] sch_htb: make htb_qlen_notify() idempotent
- CVE: https://linux.oracle.com/cve/CVE-2025-38350.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38350-sch_htb-make-htb_qlen_notify-idempotent.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38350
- Description:
[PATCH] sch_qfq: make qfq_qlen_notify() idempotent
- CVE: https://linux.oracle.com/cve/CVE-2025-38350.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38350-sch_qfq-make-qfq_qlen_notify-idempotent.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38350
- Description:
[PATCH] sch_htb: make htb_deactivate() idempotent
- CVE: https://linux.oracle.com/cve/CVE-2025-38350.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38350-sch_htb-make-htb_deactivate-idempotent.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38350
- Description:
[PATCH] sch_ets: make est_qlen_notify() idempotent
- CVE: https://linux.oracle.com/cve/CVE-2025-38350.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38350-sch_ets-make-est_qlen_notify-idempotent.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38350
- Description:
[PATCH] sch_drr: make drr_qlen_notify() idempotent
- CVE: https://linux.oracle.com/cve/CVE-2025-38350.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38350-sch_drr-make-drr_qlen_notify-idempotent.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38350
- Description:
[PATCH] sch_hfsc: make hfsc_qlen_notify() idempotent
- CVE: https://linux.oracle.com/cve/CVE-2025-38350.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38350-sch_hfsc-make-hfsc_qlen_notify-idempotent.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38350
- Description:
[PATCH] net/sched: fix lockdep splat in qdisc_tree_reduce_backlog()
- CVE: https://linux.oracle.com/cve/CVE-2025-38350.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38350-net-sched-fix-lockdep-splat-in-qdisc_tree_reduce_backlog.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38350
- Description:
[PATCH] net/sched: Always pass notifications when child class becomes empty
- CVE: https://linux.oracle.com/cve/CVE-2025-38350.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38350-net-sched-Always-pass-notifications-when-child-class-becomes-empty.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38293
- Description:
wifi: ath11k: fix node corruption in ar->arvifs list
- CVE: https://linux.oracle.com/cve/CVE-2025-38293.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38293-wifi-ath11k-fix-node-corruption-in-ar-arvifs-list.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38160
- Description:
CONFIG_CLK_RASPBERRYPI is not enabled on UEK7
- CVE:
- Patch: skipped/CVE-2025-38160.patch
- From:
- CVE-2025-38285
- Description:
bpf: Fix WARN() in get_bpf_raw_tp_regs
- CVE: https://linux.oracle.com/cve/CVE-2025-38285.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38285-bpf-fix-warn-in-get-bpf-raw-tp-regs.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38159
- Description:
wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds
- CVE: https://linux.oracle.com/cve/CVE-2025-38159.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38159-wifi-rtw88-fix-the-para-buffer-size-to-avoid-reading-out-of-bounds.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38157
- Description:
wifi: ath9k_htc: Abort software beacon handling if disabled
- CVE: https://linux.oracle.com/cve/CVE-2025-38157.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38157-wifi-ath9k-htc-abort-software-beacon-handling-if-disabled.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38280
- Description:
bpf: Avoid __bpf_prog_ret0_warn when jit fails
- CVE: https://linux.oracle.com/cve/CVE-2025-38280.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38280-bpf-avoid-bpf-prog-ret0-warn-when-jit-fails.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38147
- Description:
calipso: Don't call calipso functions for AF_INET sk.
- CVE: https://linux.oracle.com/cve/CVE-2025-38147.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38147-calipso-don-t-call-calipso-functions-for-af-inet-sk.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38147
- Description:
calipso: unlock rcu before returning -EAFNOSUPPORT
- CVE: https://linux.oracle.com/cve/CVE-2025-38147.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38147-calipso-unlock-rcu-before-returning-EAFNOSUPPORT.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38146
- Description:
net: openvswitch: Fix the dead loop of MPLS parse
- CVE: https://linux.oracle.com/cve/CVE-2025-38146.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38146-net-openvswitch-fix-the-dead-loop-of-mpls-parse.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38415
- Description:
Squashfs: check return result of sb_min_blocksize
- CVE: https://linux.oracle.com/cve/CVE-2025-38415.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38415-squashfs-check-return-result-of-sb-min-blocksize.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38415
- Description:
squashfs: fix memory leak in squashfs_fill_super
- CVE: https://linux.oracle.com/cve/CVE-2025-38415.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38415-squashfs-fix-memory-leak-in-squashfs_fill_super.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38313
- Description:
bus: fsl-mc: fix double-free on mc_dev
- CVE: https://linux.oracle.com/cve/CVE-2025-38313.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38313-bus-fsl-mc-fix-double-free-on-mc-dev.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38312
- Description:
fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod()
- CVE: https://linux.oracle.com/cve/CVE-2025-38312.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38312-fbdev-core-fbcvt-avoid-division-by-0-in-fb-cvt-hperiod.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38138
- Description:
dmaengine: ti: Add NULL check in udma_probe()
- CVE: https://linux.oracle.com/cve/CVE-2025-38138.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38138-dmaengine-ti-add-null-check-in-udma-probe.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38498
- Description:
do_change_type(): refuse to operate on unmounted/not ours mounts
- CVE: https://linux.oracle.com/cve/CVE-2025-38498.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38498-do-change-type-refuse-to-operate-on-unmounted-not-ours-mounts.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38498
- Description:
[PATCH] use uniform permission checks for all mount propagation
- CVE: https://linux.oracle.com/cve/CVE-2025-38498.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38498-use-uniform-permission-checks-for-all-mount-propagation-changes.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38119
- Description:
scsi: core: ufs: Fix a hang in the error handler
- CVE: https://linux.oracle.com/cve/CVE-2025-38119.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38119-scsi-core-ufs-fix-a-hang-in-the-error-handler.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38305
- Description:
ptp: remove ptp->n_vclocks check logic in ptp_vclock_in_use()
- CVE: https://linux.oracle.com/cve/CVE-2025-38305.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38305-ptp-remove-ptp-n-vclocks-check-logic-in-ptp-vclock-in-use.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38305
- Description:
ptp: fix breakage after ptp_vclock_in_use() rework
- CVE: https://linux.oracle.com/cve/CVE-2025-38305.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38305-ptp-fix-breakage-after-ptp_vclock_in_use-rework.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38083
- Description:
net_sched: prio: fix a race in prio_tune()
- CVE: https://linux.oracle.com/cve/CVE-2025-38083.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38083-net-sched-prio-fix-a-race-in-prio-tune.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38108
- Description:
net_sched: red: fix a race in __red_change()
- CVE: https://linux.oracle.com/cve/CVE-2025-38108.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38108-net-sched-red-fix-a-race-in-red-change.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38352
- Description:
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
- CVE: https://linux.oracle.com/cve/CVE-2025-38352.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38352-posix-cpu-timers-fix-race-between-handle-posix-cpu-timers-and-posix-cpu-timer-del.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38100
- Description:
x86/iopl: Cure TIF_IO_BITMAP inconsistencies
- CVE: https://linux.oracle.com/cve/CVE-2025-38100.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38100-x86-iopl-cure-tif-io-bitmap-inconsistencies.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38430
- Description:
nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request
- CVE: https://linux.oracle.com/cve/CVE-2025-38430.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38430-nfsd-nfsd4-spo-must-allow-must-check-this-is-a-v4-compound-request.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38229
- Description:
media: cxusb: no longer judge rbuf when the write fails
- CVE: https://linux.oracle.com/cve/CVE-2025-38229.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38229-media-cxusb-no-longer-judge-rbuf-when-the-write-fails.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38336
- Description:
ata: pata_via: Force PIO for ATAPI devices on VT6415/VT6330
- CVE: https://linux.oracle.com/cve/CVE-2025-38336.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38336-ata-pata-via-force-pio-for-atapi-devices-on-vt6415-vt6330.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38214
- Description:
fbdev: Fix fb_set_var to prevent null-ptr-deref in fb_videomode_to_var
- CVE: https://linux.oracle.com/cve/CVE-2025-38214.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38214-fbdev-fix-fb-set-var-to-prevent-null-ptr-deref-in-fb-videomode-to-var.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38212
- Description:
ipc: fix to protect IPCS lookups using RCU
- CVE: https://linux.oracle.com/cve/CVE-2025-38212.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38212-ipc-fix-to-protect-ipcs-lookups-using-rcu.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38211
- Description:
RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction
- CVE: https://linux.oracle.com/cve/CVE-2025-38211.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38211-rdma-iwcm-fix-use-after-free-of-work-objects-after-cm-id-destruction.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38086
- Description:
net: ch9200: fix uninitialised access during mii_nway_restart
- CVE: https://linux.oracle.com/cve/CVE-2025-38086.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38086-net-ch9200-fix-uninitialised-access-during-mii-nway-restart.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38206
- Description:
exfat: fix double free in delayed_free
- CVE: https://linux.oracle.com/cve/CVE-2025-38206.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38206-exfat-fix-double-free-in-delayed-free.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38204
- Description:
jfs: fix array-index-out-of-bounds read in add_missing_indices
- CVE: https://linux.oracle.com/cve/CVE-2025-38204.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38204-jfs-fix-array-index-out-of-bounds-read-in-add-missing-indices.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38342
- Description:
software node: Correct a OOB check in software_node_get_reference_args()
- CVE: https://linux.oracle.com/cve/CVE-2025-38342.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38342-software-node-correct-a-oob-check-in-software-node-get-reference-args.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38332
- Description:
scsi: lpfc: Use memcpy() for BIOS version
- CVE: https://linux.oracle.com/cve/CVE-2025-38332.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38332-scsi-lpfc-use-memcpy-for-bios-version.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38200
- Description:
i40e: fix MMIO write access to an invalid page in i40e_clear_hw
- CVE: https://linux.oracle.com/cve/CVE-2025-38200.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38200-i40e-fix-mmio-write-access-to-an-invalid-page-in-i40e-clear-hw.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38197
- Description:
platform/x86: dell_rbu: Fix list usage
- CVE: https://linux.oracle.com/cve/CVE-2025-38197.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38197-platform-x86-dell-rbu-fix-list-usage.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38090
- Description:
drivers/rapidio/rio_cm.c: prevent possible heap overwrite
- CVE: https://linux.oracle.com/cve/CVE-2025-38090.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38090-drivers-rapidio-rio-cm-c-prevent-possible-heap-overwrite.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38194
- Description:
jffs2: check that raw node were preallocated before writing summary
- CVE: https://linux.oracle.com/cve/CVE-2025-38194.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38194-jffs2-check-that-raw-node-were-preallocated-before-writing-summary.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38328
- Description:
jffs2: check jffs2_prealloc_raw_node_refs() result in few other places
- CVE: https://linux.oracle.com/cve/CVE-2025-38328.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38328-jffs2-check-jffs2-prealloc-raw-node-refs-result-in-few-other-places.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38084
- Description:
mm/hugetlb: unshare page tables during VMA split, not before
- CVE: https://linux.oracle.com/cve/CVE-2025-38084.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38084-mm-hugetlb-unshare-page-tables-during-vma-split-not-before.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38085
- Description:
Complex adaptation required. High risk of regression.
- CVE:
- Patch: skipped/CVE-2025-38085.patch
- From:
- CVE-2025-38420
- Description:
wifi: carl9170: do not ping device which has failed to load firmware
- CVE: https://linux.oracle.com/cve/CVE-2025-38420.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38420-wifi-carl9170-do-not-ping-device-which-has-failed-to-load-firmware.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38324
- Description:
mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu().
- CVE: https://linux.oracle.com/cve/CVE-2025-38324.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38324-mpls-use-rcu-dereference-rtnl-in-mpls-route-input-rcu.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38184
- Description:
tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer
- CVE: https://linux.oracle.com/cve/CVE-2025-38184.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38184-tipc-fix-null-ptr-deref-when-acquiring-remote-ip-of-ethernet-bearer.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38181
- Description:
calipso: Fix null-ptr-deref in calipso_req_{set,del}attr().
- CVE: https://linux.oracle.com/cve/CVE-2025-38181.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38181-calipso-fix-null-ptr-deref-in-calipso-req-set-del-attr.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38320
- Description:
arm64/ptrace: Fix stack-out-of-bounds read in regs_get_kernel_stack_nth()
- CVE: https://linux.oracle.com/cve/CVE-2025-38320.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38320-arm64-ptrace-fix-stack-out-of-bounds-read-in-regs-get-kernel-stack-nth.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38363
- Description:
drm/tegra: Fix a possible null pointer dereference
- CVE: https://linux.oracle.com/cve/CVE-2025-38363.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38363-drm-tegra-fix-a-possible-null-pointer-dereference.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38403
- Description:
vsock/vmci: Clear the vmci transport packet properly when initializing it
- CVE: https://linux.oracle.com/cve/CVE-2025-38403.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38403-vsock-vmci-clear-the-vmci-transport-packet-properly-when-initializing-it.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38412
- Description:
platform/x86: dell-wmi-sysman: Fix WMI data block retrieval in sysfs callbacks
- CVE: https://linux.oracle.com/cve/CVE-2025-38412.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38412-platform-x86-dell-wmi-sysman-fix-wmi-data-block-retrieval-in-sysfs-callbacks.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38399
- Description:
scsi: target: Fix NULL pointer dereference in core_scsi3_decode_spec_i_port()
- CVE: https://linux.oracle.com/cve/CVE-2025-38399.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38399-scsi-target-fix-null-pointer-dereference-in-core-scsi3-decode-spec-i-port.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38386
- Description:
ACPICA: Refuse to evaluate a method if arguments are missing
- CVE: https://linux.oracle.com/cve/CVE-2025-38386.html
- Patch: oel9-uek7/5.15.0-312.187.5.el9uek/CVE-2025-38386-acpica-refuse-to-evaluate-a-method-if-arguments-are-missing.patch
- From: 5.15.0-312.187.5.el9uek
- CVE-2025-38264
- Description:
nvme-tcp: sanitize request list handling
- CVE: https://linux.oracle.com/cve/CVE-2025-38264.html
- Patch: oel9-uek7/5.15.0-312.187.5.3.el9uek/CVE-2025-38264-nvme-tcp-sanitize-request-list-handling.patch
- From: 5.15.0-312.187.5.3.el9uek
- CVE-2025-38264
- Description:
nvme-tcp: sanitize request list handling
- CVE: https://linux.oracle.com/cve/CVE-2025-38264.html
- Patch: oel9-uek7/5.15.0-312.187.5.3.el9uek/CVE-2025-38264-nvme-tcp-sanitize-request-list-handling-kpatch.patch
- From: 5.15.0-312.187.5.3.el9uek
- CVE-2025-38499
- Description:
clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns
- CVE: https://linux.oracle.com/cve/CVE-2025-38499.html
- Patch: oel9-uek7/5.15.0-312.187.5.3.el9uek/CVE-2025-38499-clone-private-mnt-make-sure-that-caller-has-cap-sys-admin-in-the-right-userns.patch
- From: 5.15.0-312.187.5.3.el9uek
- CVE-2025-38495
- Description:
HID: core: ensure the allocated report buffer can contain the reserved report ID
- CVE: https://linux.oracle.com/cve/CVE-2025-38495.html
- Patch: oel9-uek7/5.15.0-312.187.5.3.el9uek/CVE-2025-38495-hid-core-ensure-the-allocated-report-buffer-can-contain-the-reserved-report-id.patch
- From: 5.15.0-312.187.5.3.el9uek
- CVE-2025-38494
- Description:
HID: core: do not bypass hid_hw_raw_request
- CVE: https://linux.oracle.com/cve/CVE-2025-38494.html
- Patch: oel9-uek7/5.15.0-312.187.5.3.el9uek/CVE-2025-38494-hid-core-do-not-bypass-hid-hw-raw-request.patch
- From: 5.15.0-312.187.5.3.el9uek
- CVE-2025-38618
- Description:
vsock: Do not allow binding to VMADDR_PORT_ANY
- CVE: https://linux.oracle.com/cve/CVE-2025-38618.html
- Patch: oel9-uek7/5.15.0-312.187.5.3.el9uek/CVE-2025-38618-vsock-do-not-allow-binding-to-vmaddr-port-any.patch
- From: 5.15.0-312.187.5.3.el9uek
- CVE-2025-38466
- Description:
perf: Revert to requiring CAP_SYS_ADMIN for uprobes
- CVE: https://linux.oracle.com/cve/CVE-2025-38466.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38466-perf-revert-to-requiring-cap-sys-admin-for-uprobes.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38441
- Description:
netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto()
- CVE: https://linux.oracle.com/cve/CVE-2025-38441.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38441-netfilter-flowtable-account-for-ethernet-header-in-nf-flow-pppoe-proto.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38443
- Description:
nbd: fix uaf in nbd_genl_connect() error path
- CVE: https://linux.oracle.com/cve/CVE-2025-38443.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38443-nbd-fix-uaf-in-nbd-genl-connect-error-path.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38444
- Description:
raid10: cleanup memleak at raid10_make_request
- CVE: https://linux.oracle.com/cve/CVE-2025-38444.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38444-raid10-cleanup-memleak-at-raid10-make-request.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2024-26775
- Description:
aoe: avoid potential deadlock at set_capacity
- CVE: https://linux.oracle.com/cve/CVE-2024-26775.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2024-26775-aoe-avoid-potential-deadlock-at-set-capacity.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38467
- Description:
drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling
- CVE: https://linux.oracle.com/cve/CVE-2025-38467.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38467-drm-exynos-exynos7-drm-decon-add-vblank-check-in-irq-handling.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38464
- Description:
tipc: Fix use-after-free in tipc_conn_close().
- CVE: https://linux.oracle.com/cve/CVE-2025-38464.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38464-tipc-fix-use-after-free-in-tipc-conn-close.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38457
- Description:
net/sched: Abort __tc_modify_qdisc if parent class does not exist
- CVE: https://linux.oracle.com/cve/CVE-2025-38457.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38457-net-sched-abort-tc-modify-qdisc-if-parent-class-does-not-exist.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38445
- Description:
md/raid1: Fix stack memory use after return in raid1_reshape
- CVE: https://linux.oracle.com/cve/CVE-2025-38445.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38445-md-raid1-fix-stack-memory-use-after-return-in-raid1-reshape.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38569
- Description:
benet: fix BUG when creating VFs
- CVE: https://linux.oracle.com/cve/CVE-2025-38569.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38569-benet-fix-bug-when-creating-vfs.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38236
- Description:
Complex adaptation required. Livepatching of this vulnerability can harm the network subsystem..
- CVE:
- Patch: skipped/CVE-2025-38236.patch
- From:
- CVE-2025-38462
- Description:
vsock: Fix transport_{g2h,h2g} TOCTOU
- CVE: https://linux.oracle.com/cve/CVE-2025-38462.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38462-vsock-fix-transport-g2h-h2g-toctou.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38461
- Description:
vsock: Fix transport_* TOCTOU
- CVE: https://linux.oracle.com/cve/CVE-2025-38461.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38461-vsock-fix-transport-toctou.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38375
- Description:
virtio-net: ensure the received length does not exceed allocated size
- CVE: https://linux.oracle.com/cve/CVE-2025-38375.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38375-virtio-net-ensure-the-received-length-does-not-exceed-allocated-size.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-39866
- Description:
fs: writeback: fix use-after-free in __mark_inode_dirty()
- CVE: https://linux.oracle.com/cve/CVE-2025-39866.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-39866-fs-writeback-fix-use-after-free-in-mark-inode-dirty.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38067
- Description:
rseq: Fix segfault on registration when rseq_cs is non-zero
- CVE: https://linux.oracle.com/cve/CVE-2025-38067.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38067-rseq-fix-segfault-on-registration-when-rseq-cs-is-non-zero.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38465
- Description:
netlink: Fix wraparounds of sk->sk_rmem_alloc.
- CVE: https://linux.oracle.com/cve/CVE-2025-38465.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38465-netlink-fix-wraparounds-of-sk-sk-rmem-alloc.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38448
- Description:
usb: gadget: u_serial: Fix race condition in TTY wakeup
- CVE: https://linux.oracle.com/cve/CVE-2025-38448.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38448-usb-gadget-u-serial-fix-race-condition-in-tty-wakeup.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38439
- Description:
bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT
- CVE: https://linux.oracle.com/cve/CVE-2025-38439.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38439-bnxt-en-set-dma-unmap-len-correctly-for-xdp-redirect.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38727
- Description:
netlink: avoid infinite retry looping in netlink_unicast()
- CVE: https://linux.oracle.com/cve/CVE-2025-38727.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38727-netlink-avoid-infinite-retry-looping-in-netlink-unicast.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38513
- Description:
wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev()
- CVE: https://linux.oracle.com/cve/CVE-2025-38513.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38513-wifi-zd1211rw-fix-potential-null-pointer-dereference-in-zd-mac-tx-to-dev.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38458
- Description:
atm: clip: Fix NULL pointer dereference in vcc_sendmsg()
- CVE: https://linux.oracle.com/cve/CVE-2025-38458.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38458-atm-Revert-atm_account_tx-if-copy_from_iter_full-fails.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38458
- Description:
atm: clip: Fix NULL pointer dereference in vcc_sendmsg()
- CVE: https://linux.oracle.com/cve/CVE-2025-38458.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38458-atm-clip-Fix-NULL-pointer-dereference-in-vcc_sendmsg.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38458
- Description:
atm: clip: Fix NULL pointer dereference in vcc_sendmsg()
- CVE: https://linux.oracle.com/cve/CVE-2025-38458.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38458-atm-clip-Fix-NULL-pointer-dereference-in-vcc_sendmsg-kpatch.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38459
- Description:
atm: clip: Fix infinite recursive call of clip_push().
- CVE: https://linux.oracle.com/cve/CVE-2025-38459.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38459-atm-clip-Fix-infinite-recursive-call-of-clip_push.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38460
- Description:
atm: clip: Fix potential null-ptr-deref in to_atmarpd().
- CVE: https://linux.oracle.com/cve/CVE-2025-38460.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38460-atm-clip-Fix-potential-null-ptr-deref-in-to_atmarpd.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38546
- Description:
atm: clip: Fix memory leak of struct clip_vcc.
- CVE: https://linux.oracle.com/cve/CVE-2025-38546.html
- Patch: oel9-uek7/5.15.0-313.189.5.1.el9uek/CVE-2025-38546-atm-clip-Fix-memory-leak-of-struct-clip_vcc.patch
- From: 5.15.0-313.189.5.1.el9uek
- CVE-2025-38724
- Description:
nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()
- CVE: https://linux.oracle.com/cve/CVE-2025-38724.html
- Patch: oel9-uek7/5.15.0-313.189.5.2.el9uek/CVE-2025-38724-nfsd-handle-get-client-locked-failure-in-nfsd4-setclientid-confirm.patch
- From: 5.15.0-313.189.5.2.el9uek
- CVE-2025-39964
- Description:
crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
- CVE: https://linux.oracle.com/cve/CVE-2025-39964.html
- Patch: oel9-uek7/5.15.0-313.189.5.2.el9uek/CVE-2025-39964-crypto-af_alg-disallow-concurrent-writes-in-af_alg_sendmsg.patch
- From: 5.15.0-313.189.5.2.el9uek
- CVE-2025-39964
- Description:
crypto: af_alg - Fix incorrect boolean values in af_alg_ctx
- CVE: https://linux.oracle.com/cve/CVE-2025-39964.html
- Patch: oel9-uek7/5.15.0-313.189.5.2.el9uek/CVE-2025-39964-crypto-af_alg-fix-incorrect-boolean-values-in-af_alg_ctx.patch
- From: 5.15.0-313.189.5.2.el9uek
- CVE-2025-39964
- Description:
crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg kpatch
- CVE: https://linux.oracle.com/cve/CVE-2025-39964.html
- Patch: oel9-uek7/5.15.0-313.189.5.2.el9uek/CVE-2025-39964-crypto-af_alg-disallow-concurrent-writes-in-af_alg_sendmsg-kpatch.patch
- From: 5.15.0-313.189.5.2.el9uek
- CVE-2025-39973
- Description:
i40e: add validation for ring_len param
- CVE: https://linux.oracle.com/cve/CVE-2025-39973.html
- Patch: oel9-uek7/5.15.0-313.189.5.3.el9uek/CVE-2025-39973-i40e-add-validation-for-ring-len-param.patch
- From: 5.15.0-313.189.5.3.el9uek
- CVE-2025-39973
- Description:
i40e: validate ring_len parameter against hardware-specific values
- CVE: https://linux.oracle.com/cve/CVE-2025-39973.html
- Patch: oel9-uek7/5.15.0-313.189.5.3.el9uek/CVE-2025-39973-i40e-validate-ring-len-against-hw-specific-values.patch
- From: 5.15.0-313.189.5.3.el9uek
- CVE-2025-38535
- Description:
phy: tegra: xusb: Fix unbalanced regulator disable in UTMI PHY mode
- CVE: https://linux.oracle.com/cve/CVE-2025-38535.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38535-phy-tegra-xusb-fix-unbalanced-regulator-disable-in-utmi-phy-mode.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38497
- Description:
usb: gadget: configfs: Fix OOB read on empty string write
- CVE: https://linux.oracle.com/cve/CVE-2025-38497.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38497-usb-gadget-configfs-fix-oob-read-on-empty-string-write.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38474
- Description:
usb: net: sierra: check for no status endpoint
- CVE: https://linux.oracle.com/cve/CVE-2025-38474.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38474-usb-net-sierra-check-for-no-status-endpoint.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38550
- Description:
ipv6: mcast: Delay put pmc->idev in mld_del_delrec()
- CVE: https://linux.oracle.com/cve/CVE-2025-38550.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38550-ipv6-mcast-delay-put-pmc-idev-in-mld-del-delrec.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38335
- Description:
PEEMPT_RT config isn't enabled
- CVE:
- Patch: skipped/CVE-2025-38335.patch
- From:
- CVE-2025-38668
- Description:
regulator: core: fix NULL dereference on unbind due to stale coupling data
- CVE: https://linux.oracle.com/cve/CVE-2025-38668.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38668-regulator-core-fix-null-dereference-on-unbind-due-to-stale-coupling-data.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38668
- Description:
regulator: core: fix NULL dereference on unbind due to stale coupling data
- CVE: https://linux.oracle.com/cve/CVE-2025-38668.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38668-regulator-core-fix-null-dereference-on-unbind-due-to-stale-coupling-data-kpatch.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38604
- Description:
wifi: rtl818x: Kill URBs before clearing tx status queue
- CVE: https://linux.oracle.com/cve/CVE-2025-38604.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38604-wifi-rtl818x-kill-urbs-before-clearing-tx-status-queue.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39730
- Description:
NFS: Fix filehandle bounds checking in nfs_fh_to_dentry()
- CVE: https://linux.oracle.com/cve/CVE-2025-39730.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39730-nfs-fix-filehandle-bounds-checking-in-nfs-fh-to-dentry.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38572
- Description:
ipv6: reject malicious packets in ipv6_gso_segment()
- CVE: https://linux.oracle.com/cve/CVE-2025-38572.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38572-ipv6-reject-malicious-packets-in-ipv6-gso-segment.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39757
- Description:
ALSA: usb-audio: Validate UAC3 cluster segment descriptors
- CVE: https://linux.oracle.com/cve/CVE-2025-39757.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39757-alsa-usb-audio-validate-uac3-cluster-segment-descriptors.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39757
- Description:
ALSA: usb-audio: Fix size validation in convert_chmap_v3()
- CVE: https://linux.oracle.com/cve/CVE-2025-39757.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39757-ALSA-usb-audio-fix-size-validation-in-convert_chmap_v3.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39835
- Description:
xfs: do not propagate ENODATA disk errors into xattr code
- CVE: https://linux.oracle.com/cve/CVE-2025-39835.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39835-xfs-do-not-propagate-enodata-disk-errors-into-xattr-code.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39845
- Description:
Out of scope: boot time issue
- CVE:
- Patch: skipped/CVE-2025-39845.patch
- From:
- CVE-2025-39844
- Description:
Out of scope: boot time issue
- CVE:
- Patch: skipped/CVE-2025-39844.patch
- From:
- CVE-2024-50022
- Description:
device-dax: correct pgoff align in dax_set_mapping()
- CVE: https://linux.oracle.com/cve/CVE-2024-50022.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2024-50022-device-dax-correct-pgoff-align-in-dax-set-mapping.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39891
- Description:
wifi: mwifiex: Initialize the chan_stats array to zero
- CVE: https://linux.oracle.com/cve/CVE-2025-39891.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39891-wifi-mwifiex-initialize-the-chan-stats-array-to-zero.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39891
- Description:
wifi: mwifiex: Initialize the chan_stats array to zero
- CVE: https://linux.oracle.com/cve/CVE-2025-39891.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39891-wifi-mwifiex-initialize-the-chan-stats-array-to-zero-kpatch.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2024-26652
- Description:
net: pds_core: Fix possible double free in error handling path
- CVE: https://linux.oracle.com/cve/CVE-2024-26652.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2024-26652-net-pds-core-fix-possible-double-free-in-error-handling-path.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-37916
- Description:
pds_core: remove write-after-free of client_id
- CVE: https://linux.oracle.com/cve/CVE-2025-37916.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-37916-pds-core-remove-write-after-free-of-client-id.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38473
- Description:
Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb()
- CVE: https://linux.oracle.com/cve/CVE-2025-38473.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38473-bluetooth-fix-null-ptr-deref-in-l2cap-sock-resume-cb.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38718
- Description:
sctp: linearize cloned gso packets in sctp_rcv
- CVE: https://linux.oracle.com/cve/CVE-2025-38718.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38718-sctp-linearize-cloned-gso-packets-in-sctp-rcv.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39773
- Description:
net: bridge: fix soft lockup in br_multicast_query_expired()
- CVE: https://linux.oracle.com/cve/CVE-2025-39773.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39773-net-bridge-fix-soft-lockup-in-br-multicast-query-expired.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39773
- Description:
net: bridge: fix soft lockup in br_multicast_query_expired()
- CVE: https://linux.oracle.com/cve/CVE-2025-39773.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39773-net-bridge-fix-soft-lockup-in-br-multicast-query-expired-kpatch.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39860
- Description:
Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen()
- CVE: https://linux.oracle.com/cve/CVE-2025-39860.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39860-bluetooth-fix-use-after-free-in-l2cap-sock-cleanup-listen.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39898
- Description:
e1000e: fix heap overflow in e1000_set_eeprom
- CVE: https://linux.oracle.com/cve/CVE-2025-39898.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39898-e1000e-fix-heap-overflow-in-e1000-set-eeprom.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38602
- Description:
iwlwifi: Add missing check for alloc_ordered_workqueue
- CVE: https://linux.oracle.com/cve/CVE-2025-38602.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38602-iwlwifi-add-missing-check-for-alloc-ordered-workqueue.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38601
- Description:
wifi: ath11k: clear initialized flag for deinit-ed srng lists
- CVE: https://linux.oracle.com/cve/CVE-2025-38601.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38601-wifi-ath11k-clear-initialized-flag-for-deinit-ed-srng-lists.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38574
- Description:
pptp: ensure minimal skb length in pptp_xmit()
- CVE: https://linux.oracle.com/cve/CVE-2025-38574.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38574-pptp-ensure-minimal-skb-length-in-pptp-xmit.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38574
- Description:
pptp: fix pptp_xmit() error path
- CVE: https://linux.oracle.com/cve/CVE-2025-38574.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38574-pptp-fix-pptp_xmit-error-path.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38617
- Description:
net/packet: fix a race in packet_set_ring() and packet_notifier()
- CVE: https://linux.oracle.com/cve/CVE-2025-38617.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38617-net-packet-fix-a-race-in-packet-set-ring-and-packet-notifier.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38555
- Description:
usb: gadget : fix use-after-free in composite_dev_cleanup()
- CVE: https://linux.oracle.com/cve/CVE-2025-38555.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38555-usb-gadget-fix-use-after-free-in-composite-dev-cleanup.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38706
- Description:
ASoC: core: Check for rtd == NULL in snd_soc_remove_pcm_runtime()
- CVE: https://linux.oracle.com/cve/CVE-2025-38706.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38706-asoc-core-check-for-rtd-null-in-snd-soc-remove-pcm-runtime.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38701
- Description:
ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr
- CVE: https://linux.oracle.com/cve/CVE-2025-38701.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38701-ext4-do-not-bug-when-inline-data-fl-lacks-system-data-xattr.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38700
- Description:
scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated
- CVE: https://linux.oracle.com/cve/CVE-2025-38700.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38700-scsi-libiscsi-initialize-iscsi-conn-dd-data-only-if-memory-is-allocated.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38699
- Description:
scsi: bfa: Double-free fix
- CVE: https://linux.oracle.com/cve/CVE-2025-38699.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38699-scsi-bfa-double-free-fix.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38699
- Description:
scsi: bfa: Double-free fix
- CVE: https://linux.oracle.com/cve/CVE-2025-38699.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38699-scsi-bfa-double-free-fix-kpatch.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39742
- Description:
RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask()
- CVE: https://linux.oracle.com/cve/CVE-2025-39742.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39742-rdma-hfi1-fix-possible-divide-by-zero-in-find-hw-thread-mask.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39766
- Description:
net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit
- CVE: https://linux.oracle.com/cve/CVE-2025-39766.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39766-net-sched-make-cake-enqueue-return-net-xmit-cn-when-past-buffer-limit.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38732
- Description:
netfilter: nf_reject: don't leak dst refcount for loopback packets
- CVE: https://linux.oracle.com/cve/CVE-2025-38732.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38732-netfilter-nf-reject-don-t-leak-dst-refcount-for-loopback-packets.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39817
- Description:
efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare
- CVE: https://linux.oracle.com/cve/CVE-2025-39817.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39817-efivarfs-fix-slab-out-of-bounds-in-efivarfs-d-compare.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39824
- Description:
HID: asus: fix UAF via HID_CLAIMED_INPUT validation
- CVE: https://linux.oracle.com/cve/CVE-2025-39824.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39824-hid-asus-fix-uaf-via-hid-claimed-input-validation.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39864
- Description:
wifi: cfg80211: fix use-after-free in cmp_bss()
- CVE: https://linux.oracle.com/cve/CVE-2025-39864.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39864-wifi-cfg80211-fix-use-after-free-in-cmp-bss.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39853
- Description:
i40e: Fix potential invalid access when MAC list is empty
- CVE: https://linux.oracle.com/cve/CVE-2025-39853.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39853-i40e-fix-potential-invalid-access-when-mac-list-is-empty.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39841
- Description:
scsi: lpfc: Fix buffer free/clear order in deferred receive path
- CVE: https://linux.oracle.com/cve/CVE-2025-39841.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39841-scsi-lpfc-fix-buffer-free-clear-order-in-deferred-receive-path.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-38095
- Description:
dma-buf: insert memory barrier before updating num_fences
- CVE: https://linux.oracle.com/cve/CVE-2025-38095.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-38095-dma-buf-insert-memory-barrier-before-updating-num-fences.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-39902
- Description:
mm/slub: avoid accessing metadata when pointer is invalid in object_err()
- CVE: https://linux.oracle.com/cve/CVE-2025-39902.html
- Patch: oel9-uek7/5.15.0-314.193.5.3.el9uek/CVE-2025-39902-mm-slub-avoid-accessing-metadata-when-pointer-is-invalid-in-object-err.patch
- From: 5.15.0-314.193.5.3.el9uek
- CVE-2025-40019
- Description:
crypto: essiv - Check ssize for decryption and in-place encryption
- CVE: https://linux.oracle.com/cve/CVE-2025-40019.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40019-crypto-essiv-check-ssize-for-decryption-and-in-place-encryption.patch
- From: 5.15.0-315.196.5.1.el9uek
- N/A
- Description:
kpatch add alt asm definitions
- CVE: https://www.kernel.org
- Patch: 5.15.0/kpatch-add-alt-asm-definitions.patch
- From: N/A
- N/A
- Description:
kpatch add paravirt asm definitions
- CVE: N/A
- Patch: 5.15.0/kpatch-add-paravirt-asm-definitions.patch
- From: N/A
- CVE-2025-39885
- Description:
ocfs2: fix recursive semaphore deadlock in fiemap call
- CVE: https://linux.oracle.com/cve/CVE-2025-39885.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39885-ocfs2-fix-recursive-semaphore-deadlock-in-fiemap-call.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39967
- Description:
fbcon: fix integer overflow in fbcon_do_set_font
- CVE: https://linux.oracle.com/cve/CVE-2025-39967.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39967-fbcon-fix-integer-overflow-in-fbcon-do-set-font.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39967
- Description:
fbcon: fix integer overflow in fbcon_do_set_font
- CVE: https://linux.oracle.com/cve/CVE-2025-39967.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39967-fbcon-fix-OOB-access-in-font-allocation.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40027
- Description:
net/9p: fix double req put in p9_fd_cancelled
- CVE: https://linux.oracle.com/cve/CVE-2025-40027.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40027-net-9p-fix-double-req-put-in-p9-fd-cancelled.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40173
- Description:
net/ip6_tunnel: Prevent perpetual tunnel growth
- CVE: https://linux.oracle.com/cve/CVE-2025-40173.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40173-net-ip6-tunnel-prevent-perpetual-tunnel-growth.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40085
- Description:
ALSA: usb-audio: Fix NULL pointer deference in try_to_register_card
- CVE: https://linux.oracle.com/cve/CVE-2025-40085.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40085-alsa-usb-audio-fix-null-pointer-deference-in-try-to-register-card.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40115
- Description:
scsi: mpt3sas: Fix crash in transport port remove by using ioc_info()
- CVE: https://linux.oracle.com/cve/CVE-2025-40115.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40115-scsi-mpt3sas-fix-crash-in-transport-port-remove-by-using-ioc_info.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39923
- Description:
dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees
- CVE: https://linux.oracle.com/cve/CVE-2025-39923.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39923-dmaengine-qcom-bam-dma-fix-dt-error-handling-for-num-channels-ees.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39945
- Description:
cnic: Fix use-after-free bugs in cnic_delete_task
- CVE: https://linux.oracle.com/cve/CVE-2025-39945.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39945-cnic-fix-use-after-free-bugs-in-cnic-delete-task.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39980
- Description:
nexthop: Forbid FDB status change while nexthop is in a group
- CVE: https://linux.oracle.com/cve/CVE-2025-39980.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39980-nexthop-forbid-fdb-status-change-while-nexthop-is-in-a-group.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40011
- Description:
drm/gma500: Fix null dereference in hdmi teardown
- CVE: https://linux.oracle.com/cve/CVE-2025-40011.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40011-drm-gma500-fix-null-dereference-in-hdmi-teardown.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39998
- Description:
scsi: target: target_core_configfs: Add length check to avoid buffer overflow
- CVE: https://linux.oracle.com/cve/CVE-2025-39998.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39998-scsi-target-target-core-configfs-add-length-check-to-avoid-buffer-overflow.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40081
- Description:
perf: arm_spe: Prevent overflow in PERF_IDX2OFF()
- CVE: https://linux.oracle.com/cve/CVE-2025-40081.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40081-perf-arm-spe-prevent-overflow-in-perf-idx2off.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40154
- Description:
ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping
- CVE: https://linux.oracle.com/cve/CVE-2025-40154.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40154-asoc-intel-bytcr-rt5640-fix-invalid-quirk-input-mapping.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40140
- Description:
net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast
- CVE: https://linux.oracle.com/cve/CVE-2025-40140.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40140-net-usb-remove-disruptive-netif-wake-queue-in-rtl8150-set-multicast.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40048
- Description:
uio_hv_generic: Let userspace take care of interrupt mask
- CVE: https://linux.oracle.com/cve/CVE-2025-40048.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40048-uio-hv-generic-let-userspace-take-care-of-interrupt-mask.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40153
- Description:
mm: hugetlb: avoid soft lockup when mprotect to large memory area
- CVE: https://linux.oracle.com/cve/CVE-2025-40153.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40153-mm-hugetlb-avoid-soft-lockup-when-mprotect-to-large-memory-area.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40030
- Description:
pinctrl: check the return value of pinmux_ops::get_function_name()
- CVE: https://linux.oracle.com/cve/CVE-2025-40030.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40030-pinctrl-check-the-return-value-of-pinmux-ops-get-function-name.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40111
- Description:
drm/vmwgfx: Fix Use-after-free in validation
- CVE: https://linux.oracle.com/cve/CVE-2025-40111.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40111-drm-vmwgfx-fix-use-after-free-in-validation.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40187
- Description:
net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce()
- CVE: https://linux.oracle.com/cve/CVE-2025-40187.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40187-net-sctp-fix-a-null-dereference-in-sctp-disposition-sctp-sf-do-5-1d-ce.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40186
- Description:
tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request().
- CVE: https://linux.oracle.com/cve/CVE-2025-40186.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40186-tcp-don-t-call-reqsk-fastopen-remove-in-tcp-conn-request.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40194
- Description:
cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request()
- CVE: https://linux.oracle.com/cve/CVE-2025-40194.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40194-cpufreq-intel-pstate-fix-object-lifecycle-issue-in-update-qos-request.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40204
- Description:
sctp: Fix MAC comparison to be constant-time
- CVE: https://linux.oracle.com/cve/CVE-2025-40204.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40204-sctp-fix-mac-comparison-to-be-constant-time.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40026
- Description:
KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O
- CVE: https://linux.oracle.com/cve/CVE-2025-40026.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40026-kvm-x86-don-t-re-check-l1-intercepts-when-completing-userspace-i-o.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40197
- Description:
media: mc: Clear minor number before put device
- CVE: https://linux.oracle.com/cve/CVE-2025-40197.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40197-media-mc-clear-minor-number-before-put-device.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40134
- Description:
dm: fix NULL pointer dereference in __dm_suspend()
- CVE: https://linux.oracle.com/cve/CVE-2025-40134.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40134-dm-fix-null-pointer-dereference-in-dm-suspend.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40178
- Description:
pid: Add a judgment for ns null in pid_nr_ns
- CVE: https://linux.oracle.com/cve/CVE-2025-40178.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40178-pid-add-a-judgment-for-ns-null-in-pid-nr-ns.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39913
- Description:
tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock->cork.
- CVE: https://linux.oracle.com/cve/CVE-2025-39913.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39913-tcp-bpf-call-sk-msg-free-when-tcp-bpf-send-verdict-fails-to-allocate-psock-cork.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40021
- Description:
tracing: dynevent: Add a missing lockdown check on dynevent
- CVE: https://linux.oracle.com/cve/CVE-2025-40021.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40021-tracing-dynevent-add-a-missing-lockdown-check-on-dynevent.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39996
- Description:
media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove
- CVE: https://linux.oracle.com/cve/CVE-2025-39996.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39996-media-b2c2-fix-use-after-free-causing-by-irq-check-work-in-flexcop-pci-remove.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40109
- Description:
crypto: rng - Ensure set_ent is always present
- CVE: https://linux.oracle.com/cve/CVE-2025-40109.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40109-crypto-rng-ensure-set-ent-is-always-present.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40109
- Description:
crypto: rng - Ensure set_ent is always present (kpatch adaptation)
- CVE: https://linux.oracle.com/cve/CVE-2025-40109.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40109-crypto-rng-ensure-set-ent-is-always-present-kpatch.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40125
- Description:
blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx
- CVE: https://linux.oracle.com/cve/CVE-2025-40125.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40125-blk-mq-check-kobject-state-in-sysfs-before-deleting-in-blk-mq-unregister-hctx.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40078
- Description:
bpf: Explicitly check accesses to bpf_sock_addr
- CVE: https://linux.oracle.com/cve/CVE-2025-40078.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40078-bpf-explicitly-check-accesses-to-bpf-sock-addr.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40055
- Description:
ocfs2: fix double free in user_cluster_connect()
- CVE: https://linux.oracle.com/cve/CVE-2025-40055.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40055-ocfs2-fix-double-free-in-user-cluster-connect.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40183
- Description:
bpf: Fix metadata_dst leak __bpf_redirect_neigh_v{4,6}
- CVE: https://linux.oracle.com/cve/CVE-2025-40183.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40183-bpf-fix-metadata-dst-leak-bpf-redirect-neigh-v-46.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40167
- Description:
ext4: detect invalid INLINE_DATA + EXTENTS flag combination
- CVE: https://linux.oracle.com/cve/CVE-2025-40167.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40167-ext4-detect-invalid-inline-data-extents-flag-combination.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-38678
- Description:
netfilter: nf_tables: reject duplicate device on updates
- CVE: https://linux.oracle.com/cve/CVE-2025-38678.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-38678-netfilter-nf-tables-reject-duplicate-device-on-updates.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40035
- Description:
Input: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak
- CVE: https://linux.oracle.com/cve/CVE-2025-40035.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40035-input-uinput-zero-initialize-uinput-ff-upload-compat-to-avoid-info-leak.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40105
- Description:
vfs: Don't leak disconnected dentries on umount
- CVE: https://linux.oracle.com/cve/CVE-2025-40105.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40105-vfs-don-t-leak-disconnected-dentries-on-umount.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40094
- Description:
usb: gadget: f_acm: Refactor bind path to use __free()
- CVE: https://linux.oracle.com/cve/CVE-2025-40094.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40094-usb-gadget-f-acm-refactor-bind-path-to-use-free.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2024-43876
- Description:
PCI: rcar: Demote WARN() to dev_warn_ratelimited() in rcar_pcie_wakeup()
- CVE: https://linux.oracle.com/cve/CVE-2024-43876.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2024-43876-pci-rcar-demote-warn-to-dev-warn-ratelimited-in-rcar-pcie-wakeup.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39880
- Description:
libceph: fix invalid accesses to ceph_connection_v1_info
- CVE: https://linux.oracle.com/cve/CVE-2025-39880.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39880-libceph-fix-invalid-accesses-to-ceph-connection-v1-info.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39911
- Description:
i40e: fix IRQ freeing in i40e_vsi_request_irq_msix error path
- CVE: https://linux.oracle.com/cve/CVE-2025-39911.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39911-i40e-fix-irq-freeing-in-i40e-vsi-request-irq-msix-error-path-5.15.0-314.193.5.5.el9uek.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39883
- Description:
mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory
- CVE: https://linux.oracle.com/cve/CVE-2025-39883.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39883-mm-memory-failure-fix-vm-bug-on-page-pagepoisoned-page-when-unpoison-memory.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39949
- Description:
qed: Don't collect too many protection override GRC elements
- CVE: https://linux.oracle.com/cve/CVE-2025-39949.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39949-qed-don-t-collect-too-many-protection-override-grc-elements.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39955
- Description:
tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect().
- CVE: https://linux.oracle.com/cve/CVE-2025-39955.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39955-tcp-clear-tcp-sk-sk-fastopen-rsk-in-tcp-disconnect.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-22058
- Description:
udp: Fix memory accounting leak.
- CVE: https://linux.oracle.com/cve/CVE-2025-22058.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-22058-udp-fix-memory-accounting-leak.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2024-43877
- Description:
Introduced and fixed in v5.15.0-315.196.3, no live patching needed.
- CVE:
- Patch: skipped/CVE-2024-43877.patch
- From:
- CVE-2025-40020
- Description:
can: peak_usb: fix shift-out-of-bounds issue
- CVE: https://linux.oracle.com/cve/CVE-2025-40020.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40020-can-peak-usb-fix-shift-out-of-bounds-issue.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39993
- Description:
media: rc: fix races with imon_disconnect()
- CVE: https://linux.oracle.com/cve/CVE-2025-39993.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39993-media-rc-fix-races-with-imon-disconnect.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-39994
- Description:
media: tuner: xc5000: Fix use-after-free in xc5000_release
- CVE: https://linux.oracle.com/cve/CVE-2025-39994.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-39994-media-tuner-xc5000-fix-use-after-free-in-xc5000-release-5.15.0-314.193.5.5.el9uek.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40118
- Description:
scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod
- CVE: https://linux.oracle.com/cve/CVE-2025-40118.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40118-scsi-pm80xx-fix-array-index-out-of-of-bounds-on-rmmod.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40070
- Description:
pps: fix warning in pps_register_cdev when register device fail
- CVE: https://linux.oracle.com/cve/CVE-2025-40070.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40070-pps-fix-warning-in-pps-register-cdev-when-register-device-fail.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40121
- Description:
ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping
- CVE: https://linux.oracle.com/cve/CVE-2025-40121.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40121-asoc-intel-bytcr-rt5651-fix-invalid-quirk-input-mapping.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40053
- Description:
net: dlink: handle copy_thresh allocation failure
- CVE: https://linux.oracle.com/cve/CVE-2025-40053.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40053-net-dlink-handle-copy-thresh-allocation-failure.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40044
- Description:
fs: udf: fix OOB read in lengthAllocDescs handling
- CVE: https://linux.oracle.com/cve/CVE-2025-40044.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40044-fs-udf-fix-oob-read-in-lengthallocdescs-handling.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40179
- Description:
ext4: verify orphan file size is not too big
- CVE: https://linux.oracle.com/cve/CVE-2025-40179.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40179-ext4-verify-orphan-file-size-is-not-too-big-5.15.0-313.189.5.3.el9uek.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40179
- Description:
ext4: verify orphan file size is not too big (kpatch adaptation)
- CVE: https://linux.oracle.com/cve/CVE-2025-40179.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40179-ext4-verify-orphan-file-size-is-not-too-big-5.15.0-313.189.5.3.el9uek-kpatch.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40190
- Description:
ext4: guard against EA inode refcount underflow in xattr update
- CVE: https://linux.oracle.com/cve/CVE-2025-40190.html
- Patch: oel9-uek7/5.15.0-315.196.5.1.el9uek/CVE-2025-40190-ext4-guard-against-ea-inode-refcount-underflow-in-xattr-update.patch
- From: 5.15.0-315.196.5.1.el9uek
- CVE-2025-40271
- Description:
fs/proc: fix uaf in proc_readdir_de()
- CVE: https://linux.oracle.com/cve/CVE-2025-40271.html
- Patch: oel9-uek7/5.15.0-316.196.4.1.el9uek/CVE-2025-40271-fs-proc-fix-uaf-in-proc-readdir-de.patch
- From: 5.15.0-316.196.4.1.el9uek
- CVE-2025-40280
- Description:
tipc: Fix use-after-free in tipc_mon_reinit_self().
- CVE: https://linux.oracle.com/cve/CVE-2025-40280.html
- Patch: oel9-uek7/5.15.0-316.196.4.1.el9uek/CVE-2025-40280-tipc-fix-use-after-free-in-tipc-mon-reinit-self.patch
- From: 5.15.0-316.196.4.1.el9uek
- CVE-2025-40248
- Description:
vsock: Ignore signal/timeout on connect() if already established
- CVE: https://linux.oracle.com/cve/CVE-2025-40248.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40248-vsock-Ignore-signal-timeout-on-connect-if-already-established.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40250
- Description:
net/mlx5: Clean up only new IRQ glue on request_irq() failure
- CVE: https://linux.oracle.com/cve/CVE-2025-40250.html
- Patch: oel9-uek7/5.15.0-316.196.4.1.el9uek/CVE-2025-40250-net-mlx5-clean-up-only-new-irq-glue-on-request-irq-failure.patch
- From: 5.15.0-316.196.4.1.el9uek
- CVE-2025-38571
- Description:
sunrpc: fix client side handling of tls alerts
- CVE: https://access.redhat.com/security/cve/CVE-2025-38571
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-38571-sunrpc-fix-client-side-handling-of-tls-alerts.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-38571
- Description:
SUNRPC: call xs_sock_process_cmsg for all cmsg
- CVE: https://access.redhat.com/security/cve/CVE-2025-38571
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-38571-sunrpc-call-xs_sock_process_cmsg-for-all-cmsg.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40258
- Description:
mptcp: fix race condition in mptcp_schedule_work()
- CVE: https://linux.oracle.com/cve/CVE-2025-40258.html
- Patch: oel9-uek7/5.15.0-316.196.4.2.el9uek/CVE-2025-40258-mptcp-fix-race-condition-in-mptcp-schedule-work.patch
- From: 5.15.0-316.196.4.2.el9uek
- CVE-2025-40319
- Description:
bpf: Sync pending IRQ work before freeing ring buffer
- CVE: https://linux.oracle.com/cve/CVE-2025-40319.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40319-bpf-sync-pending-irq-work-before-freeing-ring-buffer.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68192
- Description:
net: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup
- CVE: https://linux.oracle.com/cve/CVE-2025-68192.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68192-net-usb-qmi-wwan-initialize-mac-header-offset-in-qmimux-rx-fixup.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68244
- Description:
drm/i915: Avoid lock inversion when pinning to GGTT on CHV/BXT+VTD
- CVE: https://linux.oracle.com/cve/CVE-2025-68244.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68244-drm-i915-avoid-lock-inversion-when-pinning-to-ggtt-on-chv-bxt-vtd.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40283
- Description:
Bluetooth: btusb: reorder cleanup in btusb_disconnect to avoid UAF
- CVE: https://linux.oracle.com/cve/CVE-2025-40283.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40283-bluetooth-btusb-reorder-cleanup-in-btusb-disconnect-to-avoid-uaf.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40281
- Description:
sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto
- CVE: https://linux.oracle.com/cve/CVE-2025-40281.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40281-sctp-prevent-possible-shift-out-of-bounds-in-sctp-transport-update-rto.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40275
- Description:
ALSA: usb-audio: Fix NULL pointer dereference in snd_usb_mixer_controls_badd
- CVE: https://linux.oracle.com/cve/CVE-2025-40275.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40275-alsa-usb-audio-fix-null-pointer-dereference-in-snd-usb-mixer-controls-badd.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40040
- Description:
mm/ksm: fix flag-dropping behavior in ksm_madvise
- CVE: https://linux.oracle.com/cve/CVE-2025-40040.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40040-mm-ksm-fix-flag-dropping-behavior-in-ksm-madvise.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68241
- Description:
ipv4: route: Prevent rt_bind_exception() from rebinding stale fnhe
- CVE: https://linux.oracle.com/cve/CVE-2025-68241.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68241-ipv4-route-prevent-rt-bind-exception-from-rebinding-stale-fnhe.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40264
- Description:
be2net: pass wrb_params in case of OS2BMC
- CVE: https://linux.oracle.com/cve/CVE-2025-40264.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40264-be2net-pass-wrb-params-in-case-of-os2bmc.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40259
- Description:
scsi: sg: Do not sleep in atomic context
- CVE: https://linux.oracle.com/cve/CVE-2025-40259.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40259-scsi-sg-do-not-sleep-in-atomic-context.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40324
- Description:
NFSD: Fix crash in nfsd4_read_release()
- CVE: https://linux.oracle.com/cve/CVE-2025-40324.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40324-nfsd-fix-crash-in-nfsd4-read-release.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40211
- Description:
ACPI: video: Fix use-after-free in acpi_video_switch_brightness()
- CVE: https://linux.oracle.com/cve/CVE-2025-40211.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40211-acpi-video-fix-use-after-free-in-acpi-video-switch-brightness.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40342
- Description:
nvme-fc: use lock accessing port_state and rport state
- CVE: https://linux.oracle.com/cve/CVE-2025-40342.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40342-nvme-fc-use-lock-accessing-port-state-and-rport-state.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40363
- Description:
net: ipv6: fix field-spanning memcpy warning in AH output
- CVE: https://linux.oracle.com/cve/CVE-2025-40363.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40363-net-ipv6-fix-field-spanning-memcpy-warning-in-ah-output.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68185
- Description:
nfs4_setup_readdir(): insufficient locking for ->d_parent->d_inode dereferencing
- CVE: https://linux.oracle.com/cve/CVE-2025-68185.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68185-nfs4-setup-readdir-insufficient-locking-for-d-parent-d-inode-dereferencing.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40309
- Description:
Bluetooth: SCO: Fix UAF on sco_conn_free
- CVE: https://linux.oracle.com/cve/CVE-2025-40309.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40309-bluetooth-sco-fix-uaf-on-sco-conn-free.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40308
- Description:
Bluetooth: bcsp: receive data only if registered
- CVE: https://linux.oracle.com/cve/CVE-2025-40308.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40308-bluetooth-bcsp-receive-data-only-if-registered.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40261
- Description:
nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()
- CVE: https://linux.oracle.com/cve/CVE-2025-40261.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40261-nvme-nvme-fc-ensure-ioerr-work-is-cancelled-in-nvme-fc-delete-ctrl.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68284
- Description:
libceph: prevent potential out-of-bounds writes in handle_auth_session_key()
- CVE: https://linux.oracle.com/cve/CVE-2025-68284.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68284-libceph-prevent-potential-out-of-bounds-writes-in-handle-auth-session-key.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40322
- Description:
fbdev: bitblit: bound-check glyph index in bit_putcs*
- CVE: https://linux.oracle.com/cve/CVE-2025-40322.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40322-fbdev-bitblit-bound-check-glyph-index-in-bit-putcs.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40304
- Description:
fbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds
- CVE: https://linux.oracle.com/cve/CVE-2025-40304.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40304-fbdev-add-bounds-checking-in-bit-putcs-to-fix-vmalloc-out-of-bounds.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40277
- Description:
drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE
- CVE: https://linux.oracle.com/cve/CVE-2025-40277.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40277-drm-vmwgfx-validate-command-header-size-against-svga-cmd-max-datasize.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40269
- Description:
ALSA: usb-audio: Fix potential overflow of PCM transfer buffer
- CVE: https://linux.oracle.com/cve/CVE-2025-40269.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40269-alsa-usb-audio-fix-potential-overflow-of-pcm-transfer-buffer.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40269
- Description:
ALSA: usb-audio: Fix potential overflow of PCM transfer buffer
- CVE: https://linux.oracle.com/cve/CVE-2025-40269.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40269-ALSA-usb-audio-Fix-missing-unlock-at-error-path-of-maxpacksize-check.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40272
- Description:
mm/secretmem: fix use-after-free race in fault handler
- CVE: https://linux.oracle.com/cve/CVE-2025-40272.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40272-mm-secretmem-fix-use-after-free-race-in-fault-handler.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68301
- Description:
net: atlantic: fix fragment overflow handling in RX path
- CVE: https://linux.oracle.com/cve/CVE-2025-68301.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68301-net-atlantic-fix-fragment-overflow-handling-in-rx-path.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40345
- Description:
usb: storage: sddr55: Reject out-of-bound new_pba
- CVE: https://linux.oracle.com/cve/CVE-2025-40345.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40345-usb-storage-sddr55-reject-out-of-bound-new-pba.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68287
- Description:
usb: dwc3: Fix race condition between concurrent dwc3_remove_requests() call paths
- CVE: https://linux.oracle.com/cve/CVE-2025-68287.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68287-usb-dwc3-fix-race-condition-between-concurrent-dwc3-remove-requests-call-paths.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68285
- Description:
libceph: fix potential use-after-free in have_mon_and_osd_map()
- CVE: https://linux.oracle.com/cve/CVE-2025-68285.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68285-libceph-fix-potential-use-after-free-in-have-mon-and-osd-map.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68285
- Description:
libceph: fix potential use-after-free in have_mon_and_osd_map()
- CVE: https://linux.oracle.com/cve/CVE-2025-68285.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68285-libceph-fix-potential-use-after-free-in-have-mon-and-osd-map-kpatch.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-38239
- Description:
scsi: megaraid_sas: Fix invalid node index
- CVE: https://linux.oracle.com/cve/CVE-2025-38239.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-38239-scsi-megaraid-sas-fix-invalid-node-index.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40252
- Description:
net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end()
- CVE: https://linux.oracle.com/cve/CVE-2025-40252.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40252-net-qlogic-qede-fix-potential-out-of-bounds-read-in-qede-tpa-cont-and-qede-tpa-end.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40252
- Description:
net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end()
- CVE: https://linux.oracle.com/cve/CVE-2025-40252.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40252-net-qlogic-qede-fix-potential-out-of-bounds-read-in-qede-tpa-cont-and-qede-tpa-end-kpatch.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40279
- Description:
net: sched: act_connmark: initialize struct tc_ife to fix kernel leak
- CVE: https://linux.oracle.com/cve/CVE-2025-40279.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40279-net-sched-act-connmark-initialize-struct-tc-ife-to-fix-kernel-leak-5.15.0-316.196.4.2.el9uek.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40321
- Description:
wifi: brcmfmac: fix crash while sending Action Frames in standalone AP Mode
- CVE: https://linux.oracle.com/cve/CVE-2025-40321.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40321-wifi-brcmfmac-fix-crash-while-sending-action-frames-in-standalone-ap-mode.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68229
- Description:
scsi: target: tcm_loop: Fix segfault in tcm_loop_tpg_address_show()
- CVE: https://linux.oracle.com/cve/CVE-2025-68229.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68229-scsi-target-tcm-loop-fix-segfault-in-tcm-loop-tpg-address-show.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68312
- Description:
usbnet: Prevents free active kevent
- CVE: https://linux.oracle.com/cve/CVE-2025-68312.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68312-usbnet-prevents-free-active-kevent.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-40331
- Description:
sctp: Prevent TOCTOU out-of-bounds write
- CVE: https://linux.oracle.com/cve/CVE-2025-40331.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-40331-sctp-prevent-toctou-out-of-bounds-write-5.15.0-316.196.4.2.el9uek.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68331
- Description:
usb: uas: fix urb unmapping issue when the uas device is remove during ongoing data transfer
- CVE: https://linux.oracle.com/cve/CVE-2025-68331.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68331-usb-uas-fix-urb-unmapping-issue-when-the-uas-device-is-remove-during-ongoing-data-transfer.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68227
- Description:
mptcp: Fix proto fallback detection with BPF
- CVE: https://linux.oracle.com/cve/CVE-2025-68227.html
- Patch: oel9-uek7/5.15.0-317.197.5.1.el9uek/CVE-2025-68227-mptcp-fix-proto-fallback-detection-with-bpf.patch
- From: 5.15.0-317.197.5.1.el9uek
- CVE-2025-68337
- Description:
jbd2: avoid bug_on in jbd2_journal_get_create_access() when file system corrupted
- CVE: https://linux.oracle.com/cve/CVE-2025-68337.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-68337-jbd2-avoid-bug-on-in-jbd2-journal-get-create-access-when-file-system-corrupted.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-68264
- Description:
ext4: refresh inline data size before write operations
- CVE: https://linux.oracle.com/cve/CVE-2025-68264.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-68264-ext4-refresh-inline-data-size-before-write-operations.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-68261
- Description:
ext4: add i_data_sem protection in ext4_destroy_inline_data_nolock()
- CVE: https://linux.oracle.com/cve/CVE-2025-68261.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-68261-ext4-add-i-data-sem-protection-in-ext4-destroy-inline-data-nolock.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-68732
- Description:
gpu: host1x: Fix race in syncpt alloc/free
- CVE: https://linux.oracle.com/cve/CVE-2025-68732.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-68732-gpu-host1x-fix-race-in-syncpt-alloc-free.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-68757
- Description:
drm/vgem-fence: Fix potential deadlock on release
- CVE: https://linux.oracle.com/cve/CVE-2025-68757.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-68757-drm-vgem-fence-fix-potential-deadlock-on-release.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-68724
- Description:
crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id
- CVE: https://linux.oracle.com/cve/CVE-2025-68724.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-68724-crypto-asymmetric-keys-prevent-overflow-in-asymmetric-key-generate-id.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-68367
- Description:
macintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse
- CVE: https://linux.oracle.com/cve/CVE-2025-68367.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-68367-macintosh-mac-hid-fix-race-condition-in-mac-hid-toggle-emumouse.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-68759
- Description:
wifi: rtl818x: Fix potential memory leaks in rtl8180_init_rx_ring()
- CVE: https://linux.oracle.com/cve/CVE-2025-68759.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-68759-wifi-rtl818x-fix-potential-memory-leaks-in-rtl8180-init-rx-ring.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-68362
- Description:
wifi: rtl818x: rtl8187: Fix potential buffer underflow in rtl8187_rx_cb()
- CVE: https://linux.oracle.com/cve/CVE-2025-68362.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-68362-wifi-rtl818x-rtl8187-fix-potential-buffer-underflow-in-rtl8187-rx-cb.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-68349
- Description:
NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid
- CVE: https://linux.oracle.com/cve/CVE-2025-68349.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-68349-nfsv4-pnfs-clear-nfs-ino-layoutcommit-in-pnfs-mark-layout-stateid-invalid.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-68764
- Description:
NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags
- CVE: https://linux.oracle.com/cve/CVE-2025-68764.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-68764-nfs-automounted-filesystems-should-inherit-ro-noexec-nodev-sync-flags-5.15.0-317.197.5.2.el9uek.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-68346
- Description:
ALSA: dice: fix buffer overflow in detect_stream_formats()
- CVE: https://linux.oracle.com/cve/CVE-2025-68346.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-68346-alsa-dice-fix-buffer-overflow-in-detect-stream-formats.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-71146
- Description:
Out of scope: not affected
- CVE:
- Patch: skipped/CVE-2025-71146.patch
- From:
- CVE-2025-68776
- Description:
net/hsr: fix NULL pointer dereference in prp_get_untagged_frame()
- CVE: https://linux.oracle.com/cve/CVE-2025-68776.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-68776-net-hsr-fix-null-pointer-dereference-in-prp-get-untagged-frame.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-68819
- Description:
media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg()
- CVE: https://linux.oracle.com/cve/CVE-2025-68819.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-68819-media-dvb-usb-dtv5100-fix-out-of-bounds-in-dtv5100-i2c-msg.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-68771
- Description:
ocfs2: fix kernel BUG in ocfs2_find_victim_chain
- CVE: https://linux.oracle.com/cve/CVE-2025-68771.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-68771-ocfs2-fix-kernel-bug-in-ocfs2-find-victim-chain.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-71116
- Description:
libceph: make decode_pool() more resilient against corrupted osdmaps
- CVE: https://linux.oracle.com/cve/CVE-2025-71116.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-71116-libceph-make-decode-pool-more-resilient-against-corrupted-osdmaps.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-71087
- Description:
iavf: fix off-by-one issues in iavf_config_rss_reg()
- CVE: https://linux.oracle.com/cve/CVE-2025-71087.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-71087-iavf-fix-off-by-one-issues-in-iavf-config-rss-reg.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-71098
- Description:
ip6_gre: make ip6gre_header() robust
- CVE: https://linux.oracle.com/cve/CVE-2025-71098.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-71098-ip6-gre-make-ip6gre-header-robust.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-71098
- Description:
arp: do not assume dev_hard_header() does not change skb->head
- CVE: https://linux.oracle.com/cve/CVE-2025-71098.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-71098-arp-do-not-assume-dev-hard-header-does-not-change-skb-head.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-71091
- Description:
team: fix check for port enabled in team_queue_override_port_prio_changed()
- CVE: https://linux.oracle.com/cve/CVE-2025-71091.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-71091-team-fix-check-for-port-enabled-in-team-queue-override-port-prio-changed.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-71132
- Description:
smc91x: fix broken irq-context in PREEMPT_RT
- CVE: https://linux.oracle.com/cve/CVE-2025-71132.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-71132-smc91x-fix-broken-irq-context-in-preempt-rt.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-71094
- Description:
net: usb: asix: validate PHY address before use
- CVE: https://linux.oracle.com/cve/CVE-2025-71094.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-71094-net-usb-asix-validate-phy-address-before-use.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-71085
- Description:
ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr()
- CVE: https://linux.oracle.com/cve/CVE-2025-71085.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-71085-ipv6-bug-in-pskb-expand-head-as-part-of-calipso-skbuff-setattr.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-71097
- Description:
ipv4: Fix reference count leak when using error routes with nexthop objects
- CVE: https://linux.oracle.com/cve/CVE-2025-71097.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-71097-ipv4-fix-reference-count-leak-when-using-error-routes-with-nexthop-objects.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-71093
- Description:
e1000: fix OOB in e1000_tbi_should_accept()
- CVE: https://linux.oracle.com/cve/CVE-2025-71093.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-71093-e1000-fix-oob-in-e1000-tbi-should-accept.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-38022
- Description:
RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem
- CVE: https://linux.oracle.com/cve/CVE-2025-38022.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-38022-rdma-core-fix-kasan-slab-use-after-free-read-in-ib-register-device-problem.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-40110
- Description:
drm/vmwgfx: Fix a null-ptr access in the cursor snooper
- CVE: https://linux.oracle.com/cve/CVE-2025-40110.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-40110-drm-vmwgfx-fix-a-null-ptr-access-in-the-cursor-snooper.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-22022
- Description:
usb: xhci: move link chain bit quirk checks into one helper function.
- CVE: https://linux.oracle.com/cve/CVE-2025-22022.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-22022-usb-xhci-move-link-chain-bit-quirk-checks-into-one-helper-function.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-22022
- Description:
usb: xhci: Apply the link chain quirk on NEC isoc endpoints
- CVE: https://linux.oracle.com/cve/CVE-2025-22022.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-22022-usb-xhci-apply-the-link-chain-quirk-on-nec-isoc-endpoints.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-71127
- Description:
wifi: mac80211: Discard Beacon frames to non-broadcast address
- CVE: https://linux.oracle.com/cve/CVE-2025-71127.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-71127-wifi-mac80211-discard-beacon-frames-to-non-broadcast-address.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-38129
- Description:
page_pool: Fix use-after-free in page_pool_recycle_in_ring
- CVE: https://linux.oracle.com/cve/CVE-2025-38129.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-38129-page-pool-fix-use-after-free-in-page-pool-recycle-in-ring.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2024-46830
- Description:
KVM: x86: Acquire kvm->srcu when handling KVM_SET_VCPU_EVENTS
- CVE: https://linux.oracle.com/cve/CVE-2024-46830.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2024-46830-kvm-x86-acquire-kvm-srcu-when-handling-kvm-set-vcpu-events.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-38556
- Description:
HID: core: Harden s32ton() against conversion to 0 bits
- CVE: https://linux.oracle.com/cve/CVE-2025-38556.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-38556-hid-core-harden-s32ton-against-conversion-to-0-bits.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23020
- Description:
net: 3com: 3c59x: fix possible null dereference in vortex_probe1()
- CVE: https://linux.oracle.com/cve/CVE-2026-23020.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23020-net-3com-3c59x-fix-possible-null-dereference-in-vortex-probe1.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-22990
- Description:
libceph: replace overzealous BUG_ON in osdmap_apply_incremental()
- CVE: https://linux.oracle.com/cve/CVE-2026-22990.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-22990-libceph-replace-overzealous-bug-on-in-osdmap-apply-incremental.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-22991
- Description:
libceph: make free_choose_arg_map() resilient to partial allocation
- CVE: https://linux.oracle.com/cve/CVE-2026-22991.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-22991-libceph-make-free-choose-arg-map-resilient-to-partial-allocation.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23047
- Description:
libceph: make calc_target() set t->paused, not just clear it
- CVE: https://linux.oracle.com/cve/CVE-2026-23047.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23047-libceph-make-calc-target-set-t-paused-not-just-clear-it.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23139
- Description:
Out of scope: not affected
- CVE:
- Patch: skipped/CVE-2026-23139.patch
- From:
- CVE-2026-23003
- Description:
ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv()
- CVE: https://nvd.nist.gov/vuln/detail/CVE-2026-23003
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23003-ip6-tunnel-use-skb-vlan-inet-prepare-in-ip6-tnl-rcv-kpatch.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-71190
- Description:
dmaengine: bcm-sba-raid: fix device leak on probe
- CVE: https://linux.oracle.com/cve/CVE-2025-71190.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-71190-dmaengine-bcm-sba-raid-fix-device-leak-on-probe.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23120
- Description:
l2tp: avoid one data-race in l2tp_tunnel_del_work()
- CVE: https://linux.oracle.com/cve/CVE-2026-23120.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23120-l2tp-avoid-one-data-race-in-l2tp-tunnel-del-work.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23074
- Description:
net/sched: Enforce that teql can only be used as root qdisc
- CVE: https://linux.oracle.com/cve/CVE-2026-23074.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23074-net-sched-enforce-that-teql-can-only-be-used-as-root-qdisc.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23060
- Description:
crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec
- CVE: https://linux.oracle.com/cve/CVE-2026-23060.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23060-crypto-authencesn-reject-too-short-aad-assoclen-8-to-match-esp-esn-spec.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23071
- Description:
regmap: Fix race condition in hwspinlock irqsave routine
- CVE: https://linux.oracle.com/cve/CVE-2026-23071.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23071-regmap-fix-race-condition-in-hwspinlock-irqsave-routine.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23121
- Description:
mISDN: annotate data-race around dev->work
- CVE: https://linux.oracle.com/cve/CVE-2026-23121.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23121-misdn-annotate-data-race-around-dev-work.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23124
- Description:
ipv6: annotate data-race in ndisc_router_discovery()
- CVE: https://linux.oracle.com/cve/CVE-2026-23124.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23124-ipv6-annotate-data-race-in-ndisc-router-discovery.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23084
- Description:
be2net: Fix NULL pointer dereference in be_cmd_get_mac_from_list
- CVE: https://linux.oracle.com/cve/CVE-2026-23084.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23084-be2net-fix-null-pointer-dereference-in-be-cmd-get-mac-from-list.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23101
- Description:
leds: led-class: Only Add LED to leds_list when it is fully ready
- CVE: https://linux.oracle.com/cve/CVE-2026-23101.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23101-leds-led-class-only-add-led-to-leds-list-when-it-is-fully-ready.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23076
- Description:
ALSA: ctxfi: Fix potential OOB access in audio mixer handling
- CVE: https://linux.oracle.com/cve/CVE-2026-23076.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23076-alsa-ctxfi-fix-potential-oob-access-in-audio-mixer-handling.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23089
- Description:
ALSA: usb-audio: Fix use-after-free in snd_usb_mixer_free()
- CVE: https://linux.oracle.com/cve/CVE-2026-23089.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23089-alsa-usb-audio-fix-use-after-free-in-snd-usb-mixer-free.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23133
- Description:
wifi: ath10k: fix dma_free_coherent() pointer
- CVE: https://linux.oracle.com/cve/CVE-2026-23133.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23133-wifi-ath10k-fix-dma-free-coherent-pointer.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23058
- Description:
can: ems_usb: ems_usb_read_bulk_callback(): fix URB memory leak
- CVE: https://linux.oracle.com/cve/CVE-2026-23058.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23058-can-ems-usb-ems-usb-read-bulk-callback-fix-urb-memory-leak.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23061
- Description:
can: kvaser_usb: kvaser_usb_read_bulk_callback(): fix URB memory leak
- CVE: https://linux.oracle.com/cve/CVE-2026-23061.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23061-can-kvaser-usb-kvaser-usb-read-bulk-callback-fix-urb-memory-leak.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23108
- Description:
can: usb_8dev: usb_8dev_read_bulk_callback(): fix URB memory leak
- CVE: https://linux.oracle.com/cve/CVE-2026-23108.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23108-can-usb-8dev-usb-8dev-read-bulk-callback-fix-urb-memory-leak.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23097
- Description:
migrate: correct lock ordering for hugetlb file folios
- CVE: https://linux.oracle.com/cve/CVE-2026-23097.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23097-migrate-correct-lock-ordering-for-hugetlb-file-folios.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-68725
- Description:
bpf: Do not let BPF test infra emit invalid GSO types to stack
- CVE: https://linux.oracle.com/cve/CVE-2025-68725.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-68725-bpf-do-not-let-bpf-test-infra-emit-invalid-gso-types-to-stack.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-38591
- Description:
bpf: Reject narrower access to pointer ctx fields
- CVE: https://linux.oracle.com/cve/CVE-2025-38591.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-38591-bpf-reject-narrower-access-to-pointer-ctx-fields.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23146
- Description:
Bluetooth: hci_uart: fix null-ptr-deref in hci_uart_write_work
- CVE: https://linux.oracle.com/cve/CVE-2026-23146.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23146-bluetooth-hci-uart-fix-null-ptr-deref-in-hci-uart-write-work.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23164
- Description:
rocker: fix memory leak in rocker_world_port_post_fini()
- CVE: https://linux.oracle.com/cve/CVE-2026-23164.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23164-rocker-fix-memory-leak-in-rocker-world-port-post-fini.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2026-23087
- Description:
scsi: xen: scsiback: Fix potential memory leak in scsiback_remove()
- CVE: https://linux.oracle.com/cve/CVE-2026-23087.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2026-23087-scsi-xen-scsiback-fix-potential-memory-leak-in-scsiback-remove.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-40164
- Description:
usbnet: Fix using smp_processor_id() in preemptible code warnings
- CVE: https://linux.oracle.com/cve/CVE-2025-40164.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-40164-usbnet-fix-using-smp-processor-id-in-preemptible-code-warnings.patch
- From: 5.15.0-318.199.3.2.el9uek
- CVE-2025-21979
- Description:
Out of scope: not affected
- CVE:
- Patch: skipped/CVE-2025-21979.patch
- From:
- CVE-2025-22119
- Description:
Out of scope: not affected
- CVE:
- Patch: skipped/CVE-2025-22119.patch
- From:
- CVE-2025-37860
- Description:
sfc: fix NULL dereferences in ef100_process_design_param()
- CVE: https://linux.oracle.com/cve/CVE-2025-37860.html
- Patch: oel9-uek7/5.15.0-318.199.3.2.el9uek/CVE-2025-37860-sfc-fix-null-dereferences-in-ef100-process-design-param.patch
- From: 5.15.0-318.199.3.2.el9uek