- kernel-5.14.0-503.11.1.el9_5 (almalinux9)
- 5.14.0-503.35.1.el9_5
- 2025-04-16 23:09:10
- 2025-04-18 09:09:16
- K20250417_03
- CVE-2024-46824, CVSSv2 Score: 5.5
- Description:
iommufd: Require drivers to supply the cache_invalidate_user ops
- CVE: https://access.redhat.com/security/cve/CVE-2024-46824
- Patch: rhel9/5.14.0-503.14.1.el9_5/CVE-2024-46824-iommufd-require-drivers-to-supply-the-cache-invalidate-user-ops.patch
- From: 5.14.0-503.14.1.el9_5
- CVE-2024-42283, CVSSv2 Score: 5.5
- Description:
net: nexthop: Initialize all fields in dumped nexthops
- CVE: https://access.redhat.com/security/cve/CVE-2024-42283
- Patch: rhel9/5.14.0-503.14.1.el9_5/CVE-2024-42283-net-nexthop-initialize-all-fields-in-dumped-nexthops.patch
- From: 5.14.0-503.14.1.el9_5
- CVE-2024-46858, CVSSv2 Score: 7.0
- Description:
mptcp: pm: Fix uaf in __timer_delete_sync
- CVE: https://access.redhat.com/security/cve/CVE-2024-46858
- Patch: rhel9/5.14.0-503.14.1.el9_5/CVE-2024-46858-mptcp-pm-fix-uaf-in-timer-delete-sync.patch
- From: 5.14.0-503.14.1.el9_5
- CVE-2024-41009, CVSSv2 Score: 5.5
- Description:
bpf: Fix overrunning reservations in ringbuf
- CVE: https://access.redhat.com/security/cve/CVE-2024-41009
- Patch: rhel9/5.14.0-503.15.1.el9_5/CVE-2024-41009-bpf-fix-overrunning-reservations-in-ringbuf.patch
- From: 5.14.0-503.15.1.el9_5
- CVE-2024-41009, CVSSv2 Score: 5.5
- Description:
bpf: Fix overrunning reservations in ringbuf
- CVE: https://access.redhat.com/security/cve/CVE-2024-41009
- Patch: rhel9/5.14.0-503.15.1.el9_5/CVE-2024-41009-bpf-fix-overrunning-reservations-in-ringbuf-kpatch.patch
- From: 5.14.0-503.15.1.el9_5
- CVE-2024-42244, CVSSv2 Score: 5.5
- Description:
USB: serial: mos7840: fix crash on resume
- CVE: https://access.redhat.com/security/cve/CVE-2024-42244
- Patch: rhel9/5.14.0-503.15.1.el9_5/CVE-2024-42244-USB-serial-mos7840-fix-crash-on-resume.patch
- From: 5.14.0-503.15.1.el9_5
- CVE-2024-42244, CVSSv2 Score: 5.5
- Description:
USB: serial: mos7840: fix crash on resume
- CVE: https://access.redhat.com/security/cve/CVE-2024-42244
- Patch: rhel9/5.14.0-503.15.1.el9_5/CVE-2024-42244-USB-serial-mos7840-fix-crash-on-resume-kpatch.patch
- From: 5.14.0-503.15.1.el9_5
- CVE-2024-50226, CVSSv2 Score: 7.8
- Description:
cxl/port: Fix use-after-free, permit out-of-order decoder shutdown
- CVE: https://access.redhat.com/security/cve/CVE-2024-50226
- Patch: rhel9/5.14.0-503.15.1.el9_5/CVE-2024-50226-cxl-port-fix-use-after-free-permit-out-of-order-decoder-shutdown.patch
- From: 5.14.0-503.15.1.el9_5
- CVE-2024-50251, CVSSv2 Score: 6.2
- Description:
netfilter: nft_payload: sanitize offset and length before calling skb_checksum()
- CVE: https://access.redhat.com/security/cve/CVE-2024-50251
- Patch: rhel9/5.14.0-503.16.1.el9_5/CVE-2024-50251-netfilter-nft_payload-sanitize-offset-and-length-before-calling-skb_checksum.patch
- From: 5.14.0-503.16.1.el9_5
- CVE-2024-26615, CVSSv2 Score: 5.5
- Description:
net/smc: fix illegal rmb_desc access in SMC-D connection dump
- CVE: https://access.redhat.com/security/cve/CVE-2024-26615
- Patch: rhel9/5.14.0-503.16.1.el9_5/CVE-2024-26615-net-smc-fix-illegal-rmb-desc-access-in-smc-d-connection-dump.patch
- From: 5.14.0-503.16.1.el9_5
- CVE-2024-43854, CVSSv2 Score: 5.5
- Description:
block: initialize integrity buffer to zero before writing it to media
- CVE: https://access.redhat.com/security/cve/CVE-2024-43854
- Patch: rhel9/5.14.0-503.16.1.el9_5/CVE-2024-43854-block-initialize-integrity-buffer-to-zero-before-writing-it-to-media.patch
- From: 5.14.0-503.16.1.el9_5
- CVE-2024-44994, CVSSv2 Score: 5.5
- Description:
iommu: Restore lost return in iommu_report_device_fault()
- CVE: https://access.redhat.com/security/cve/CVE-2024-44994
- Patch: rhel9/5.14.0-503.16.1.el9_5/CVE-2024-44994-iommu-restore-lost-return-in-iommu-report-device-fault.patch
- From: 5.14.0-503.16.1.el9_5
- CVE-2024-46695, CVSSv2 Score: 5.5
- Description:
selinux,smack: don't bypass permissions check in inode_setsecctx hook
- CVE: https://access.redhat.com/security/cve/CVE-2024-46695
- Patch: rhel9/5.14.0-503.16.1.el9_5/CVE-2024-46695-selinux-smack-don-t-bypass-permissions-check-in-inode-setsecctx-hook.patch
- From: 5.14.0-503.16.1.el9_5
- CVE-2024-49949, CVSSv2 Score: 5.5
- Description:
net: avoid potential underflow in qdisc_pkt_len_init() with UFO
- CVE: https://access.redhat.com/security/cve/CVE-2024-49949
- Patch: rhel9/5.14.0-503.16.1.el9_5/CVE-2024-49949-net-avoid-potential-underflow-in-qdisc_pkt_len_init-with-UFO.patch
- From: 5.14.0-503.16.1.el9_5
- CVE-2024-27399, CVSSv2 Score: 5.5
- Description:
Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout
- CVE: https://access.redhat.com/security/cve/CVE-2024-27399
- Patch: rhel9/5.14.0-503.19.1.el9_5/CVE-2024-27399-bluetooth-l2cap-fix-null-ptr-deref-in-l2cap-chan-timeout.patch
- From: 5.14.0-503.19.1.el9_5
- CVE-2024-38564, CVSSv2 Score: 5.5
- Description:
bpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE
- CVE: https://access.redhat.com/security/cve/CVE-2024-38564
- Patch: rhel9/5.14.0-503.19.1.el9_5/CVE-2024-38564-bpf-add-bpf-prog-type-cgroup-skb-attach-type-enforcement-in-bpf-link-create.patch
- From: 5.14.0-503.19.1.el9_5
- CVE-2024-45020, CVSSv2 Score: 5.5
- Description:
bpf: Fix a kernel verifier crash in stacksafe()
- CVE: https://access.redhat.com/security/cve/CVE-2024-45020
- Patch: rhel9/5.14.0-503.19.1.el9_5/CVE-2024-45020-bpf-fix-a-kernel-verifier-crash-in-stacksafe.patch
- From: 5.14.0-503.19.1.el9_5
- CVE-2024-47675, CVSSv2 Score: 7.8
- Description:
bpf: Fix use-after-free in bpf_uprobe_multi_link_attach()
- CVE: https://access.redhat.com/security/cve/CVE-2024-47675
- Patch: rhel9/5.14.0-503.19.1.el9_5/CVE-2024-47675-bpf-fix-use-after-free-in-bpf-uprobe-multi-link-attach.patch
- From: 5.14.0-503.19.1.el9_5
- CVE-2024-50099, CVSSv2 Score: 5.5
- Description:
arm64: probes: Remove broken LDR (literal) uprobe support
- CVE: https://access.redhat.com/security/cve/CVE-2024-50099
- Patch: rhel9/5.14.0-503.19.1.el9_5/CVE-2024-50099-arm64-probes-remove-broken-ldr-literal-uprobe-support.patch
- From: 5.14.0-503.19.1.el9_5
- CVE-2024-50262, CVSSv2 Score: 7.8
- Description:
bpf: Fix out-of-bounds write in trie_get_next_key()
- CVE: https://access.redhat.com/security/cve/CVE-2024-50262
- Patch: rhel9/5.14.0-503.19.1.el9_5/CVE-2024-50262-bpf-fix-out-of-bounds-write-in-trie-get-next-key.patch
- From: 5.14.0-503.19.1.el9_5
- CVE-2024-50115, CVSSv2 Score: 7.1
- Description:
KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory
- CVE: https://access.redhat.com/security/cve/CVE-2024-50115
- Patch: rhel9/5.14.0-503.19.1.el9_5/CVE-2024-50115-KVM-nSVM-Ignore-nCR3-4-0-when-loading-PDPTEs-from-memory.patch
- From: 5.14.0-503.19.1.el9_5
- CVE-2024-46697, CVSSv2 Score: 5.5
- Description:
nfsd: ensure that nfsd4_fattr_args.context is zeroed out
- CVE: https://access.redhat.com/security/cve/CVE-2024-46697
- Patch: rhel9/5.14.0-503.19.1.el9_5/CVE-2024-46697-nfsd-ensure-that-nfsd4_fattr_args-context-is-zeroed-out.patch
- From: 5.14.0-503.19.1.el9_5
- CVE-2024-50110, CVSSv2 Score: 5.5
- Description:
xfrm: fix one more kernel-infoleak in algo dumping
- CVE: https://access.redhat.com/security/cve/CVE-2024-50110
- Patch: rhel9/5.14.0-503.19.1.el9_5/CVE-2024-50110-xfrm-fix-one-more-kernel-infoleak-in-algo-dumping.patch
- From: 5.14.0-503.19.1.el9_5
- CVE-2024-50142, CVSSv2 Score: 5.5
- Description:
xfrm: validate new SA's prefixlen using SA family when sel.family is unset
- CVE: https://access.redhat.com/security/cve/CVE-2024-50142
- Patch: rhel9/5.14.0-503.19.1.el9_5/CVE-2024-50142-xfrm-validate-new-sa-s-prefixlen-using-sa-family-when-sel-family-is-unset.patch
- From: 5.14.0-503.19.1.el9_5
- CVE-2024-50148, CVSSv2 Score: 5.5
- Description:
Bluetooth: bnep: fix wild-memory-access in proto_unregister
- CVE: https://access.redhat.com/security/cve/CVE-2024-50148
- Patch: rhel9/5.14.0-503.19.1.el9_5/CVE-2024-50148-Bluetooth-bnep-fix-wild-memory-access-in-proto_unregister.patch
- From: 5.14.0-503.19.1.el9_5
- CVE-2024-50255, CVSSv2 Score:
- Description:
Bluetooth subsystem. Patched function may wait for a while, which may prevent patching/unpatching.
- CVE:
- Patch: skipped/CVE-2024-50255.patch
- From:
- CVE-2024-50223, CVSSv2 Score: 5.5
- Description:
sched/numa: Fix the potential null pointer dereference in task_numa_work()
- CVE: https://access.redhat.com/security/cve/CVE-2024-50223
- Patch: rhel9/5.14.0-503.19.1.el9_5/CVE-2024-50223-sched-numa-Fix-the-potential-null-pointer-dereference-in-task_numa_work.patch
- From: 5.14.0-503.19.1.el9_5
- CVE-2024-50125, CVSSv2 Score: 7.8
- Description:
Bluetooth: SCO: Fix UAF on sco_sock_timeout
- CVE: https://access.redhat.com/security/cve/CVE-2024-50125
- Patch: rhel9/5.14.0-503.19.1.el9_5/CVE-2024-50125-Bluetooth-SCO-Fix-UAF-on-sco_sock_timeout.patch
- From: 5.14.0-503.19.1.el9_5
- CVE-2024-50124, CVSSv2 Score: 7.8
- Description:
Bluetooth: ISO: Fix UAF on iso_sock_timeout
- CVE: https://access.redhat.com/security/cve/CVE-2024-50124
- Patch: rhel9/5.14.0-503.19.1.el9_5/CVE-2024-50124-Bluetooth-ISO-Fix-UAF-on-iso_sock_timeout.patch
- From: 5.14.0-503.19.1.el9_5
- CVE-2024-49888, CVSSv2 Score: 5.5
- Description:
bpf: Fix a sdiv overflow issue
- CVE: https://access.redhat.com/security/cve/CVE-2024-49888
- Patch: rhel9/5.14.0-503.19.1.el9_5/CVE-2024-49888-bpf-fix-a-sdiv-overflow-issue.patch
- From: 5.14.0-503.19.1.el9_5
- CVE-2024-50192, CVSSv2 Score:
- Description:
arm64: Low-score CVE requiring adaptation that is hard to implement; targets very rare hardware
- CVE:
- Patch: skipped/CVE-2024-50192.patch
- From:
- CVE-2024-50208, CVSSv2 Score: 5.5
- Description:
RDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pages
- CVE: https://access.redhat.com/security/cve/CVE-2024-50208
- Patch: rhel9/5.14.0-503.21.1.el9_5/CVE-2024-50208-rdma-bnxt-re-fix-a-bug-while-setting-up-level-2-pbl-pages.patch
- From: 5.14.0-503.21.1.el9_5
- CVE-2024-53122, CVSSv2 Score: 5.5
- Description:
mptcp: cope racing subflow creation in mptcp_rcv_space_adjust
- CVE: https://access.redhat.com/security/cve/CVE-2024-53122
- Patch: rhel9/5.14.0-503.21.1.el9_5/CVE-2024-53122-mptcp-cope-racing-subflow-creation-in-mptcp-rcv-space-adjust.patch
- From: 5.14.0-503.21.1.el9_5
- CVE-2024-50252, CVSSv2 Score: 5.5
- Description:
mlxsw: spectrum_ipip: Fix memory leak when changing remote IPv6 address
- CVE: https://access.redhat.com/security/cve/CVE-2024-50252
- Patch: rhel9/5.14.0-503.21.1.el9_5/CVE-2024-50252-mlxsw-spectrum_ipip-Fix-memory-leak-when-changing-remote-IPv6-address.patch
- From: 5.14.0-503.21.1.el9_5
- CVE-2024-46713, CVSSv2 Score: 5.5
- Description:
perf/aux: Fix AUX buffer serialization
- CVE: https://access.redhat.com/security/cve/CVE-2024-46713
- Patch: rhel9/5.14.0-503.21.1.el9_5/CVE-2024-46713-perf-aux-Fix-AUX-buffer-serialization.patch
- From: 5.14.0-503.21.1.el9_5
- CVE-2024-46713, CVSSv2 Score: 5.5
- Description:
perf/aux: Fix AUX buffer serialization (Adaptation)
- CVE: https://access.redhat.com/security/cve/CVE-2024-46713
- Patch: rhel9/5.14.0-503.21.1.el9_5/CVE-2024-46713-perf-aux-Fix-AUX-buffer-serialization-kpatch.patch
- From: 5.14.0-503.21.1.el9_5
- CVE-2024-50154, CVSSv2 Score: 7.8
- Description:
tcp/dccp: Don't use timer_pending() in reqsk_queue_unlink()
- CVE: https://access.redhat.com/security/cve/CVE-2024-50154
- Patch: rhel9/5.14.0-503.22.1.el9_5/CVE-2024-50154-tcp-dccp-Don-t-use-timer_pending-in-reqsk_queue_unlink.patch
- From: 5.14.0-503.22.1.el9_5
- CVE-2024-50275, CVSSv2 Score: 7.0
- Description:
Discard stale CPU state when handling SVE traps
- CVE: https://access.redhat.com/security/cve/CVE-2024-50275
- Patch: rhel9/5.14.0-503.22.1.el9_5/CVE-2024-50275-arm64-sve-Discard-stale-CPU-state-when-handling-SVE.patch
- From: 5.14.0-503.22.1.el9_5
- CVE-2024-53088, CVSSv2 Score: 5.5
- Description:
fix race condition by adding filter's intermediate sync state
- CVE: https://access.redhat.com/security/cve/CVE-2024-53088
- Patch: rhel9/5.14.0-503.22.1.el9_5/CVE-2024-53088-0002-i40e-fix-race-condition-by-adding-filter-s-intermediate-sync-state.patch
- From: 5.14.0-503.22.1.el9_5
- CVE-2024-53104, CVSSv2 Score: 7.3
- Description:
media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format
- CVE: https://access.redhat.com/security/cve/CVE-2024-53104
- Patch: rhel9/5.14.0-503.23.2.el9_5/CVE-2024-53104-media-uvcvideo-Skip-parsing-frames-of-type-UVC_VS_UNDEFINED.patch
- From: 5.14.0-503.23.2.el9_5
- CVE-2023-52490, CVSSv2 Score: 5.5
- Description:
mm: migrate: fix getting incorrect page mapping during page migration
- CVE: https://access.redhat.com/security/cve/CVE-2023-52490
- Patch: rhel9/5.14.0-503.26.1.el9_5/CVE-2023-52490-mm-migrate-fix-getting-incorrect-page-mapping-during-page-migration.patch
- From: 5.14.0-503.23.2.el9_5
- CVE-2024-53113, CVSSv2 Score: 5.5
- Description:
mm: fix NULL pointer dereference in alloc_pages_bulk_noprof
- CVE: https://access.redhat.com/security/cve/CVE-2024-53113
- Patch: rhel9/5.14.0-503.31.1.el9_5/CVE-2024-53113-mm-fix-null-pointer-dereference-in-alloc-pages-bulk-noprof.patch
- From: 5.14.0-503.31.1.el9_5
- CVE-2024-53197, CVSSv2 Score: 5.5
- Description:
ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices
- CVE: https://access.redhat.com/security/cve/CVE-2024-53197
- Patch: rhel9/5.14.0-503.31.1.el9_5/CVE-2024-53197-ALSA-usb-audio-Fix-potential-out-of-bound-accesses-for-Extigy-and-Mbox-devices.patch
- From: 5.14.0-503.31.1.el9_5
- CVE-2023-52922, CVSSv2 Score: 7.8
- Description:
can: bcm: Fix UAF in bcm_proc_show()
- CVE: https://access.redhat.com/security/cve/CVE-2023-52922
- Patch: rhel9/5.14.0-503.31.1.el9_5/CVE-2023-52922-can-bcm-fix-uaf-in-bcm-proc-show.patch
- From: 5.14.0-503.31.1.el9_5
- CVE-2023-52605, CVSSv2 Score:
- Description:
CVE Rejected
- CVE:
- Patch: skipped/CVE-2023-52605.patch
- From:
- CVE-2024-50264, CVSSv2 Score: 7.8
- Description:
vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans
- CVE: https://access.redhat.com/security/cve/CVE-2024-50264
- Patch: rhel9/5.14.0-503.31.1.el9_5/CVE-2024-50264-vsock-virtio-initialization-of-the-dangling-pointer-occurring-in-vsk-trans.patch
- From: 5.14.0-503.31.1.el9_5
- CVE-2024-50302, CVSSv2 Score: 7.8
- Description:
HID: core: zero-initialize the report buffer
- CVE: https://access.redhat.com/security/cve/CVE-2024-50302
- Patch: rhel9/5.14.0-503.31.1.el9_5/CVE-2024-50302-hid-core-zero-initialize-the-report-buffer.patch
- From: 5.14.0-503.31.1.el9_5
- CVE-2025-21785, CVSSv2 Score:
- Description:
Out of scope: ARM64 architecture isn't supported for current kernel
- CVE:
- Patch: skipped/CVE-2025-21785.patch
- From:
- CVE-2024-43855, CVSSv2 Score: 5.5
- Description:
md: fix deadlock between mddev_suspend and flush bio
- CVE: https://access.redhat.com/security/cve/CVE-2024-43855
- Patch: rhel9/5.14.0-503.35.1.el9_5/CVE-2024-43855-md-fix-deadlock-between-mddev-suspend-and-flush-bio.patch
- From: 5.14.0-503.35.1.el9_5