- kernel-uek-5.4.17-2136.347.6.2.el8uek (oel8-uek6)
- 5.4.17-2136.348.3.el8uek
- 2025-11-05 13:11:36
- 2025-11-06 16:39:56
- K20251105_22
- CVE-2025-38724
- Description:
nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()
- CVE: https://linux.oracle.com/cve/CVE-2025-38724.html
- Patch: oel8-uek6/5.4.17-2136.347.6.4.el8uek/CVE-2025-38724-nfsd-handle-get-client-locked-failure-in-nfsd4-setclientid-confirm.patch
- From: 5.4.17-2136.347.6.4.el8uek
- CVE-2025-39742
- Description:
RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask()
- CVE: https://linux.oracle.com/cve/CVE-2025-39742.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39742-rdma-hfi1-fix-possible-divide-by-zero-in-find-hw-thread-mask.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38695
- Description:
scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure
- CVE: https://linux.oracle.com/cve/CVE-2025-38695.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38695-scsi-lpfc-check-for-hdwq-null-ptr-when-cleaning-up-lpfc-vport-structure.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38694
- Description:
media: dvb-frontends: dib7090p: fix null-ptr-deref in dib7090p_rw_on_apb()
- CVE: https://linux.oracle.com/cve/CVE-2025-38694.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38694-media-dvb-frontends-dib7090p-fix-null-ptr-deref-in-dib7090p-rw-on-apb.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38693
- Description:
media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar
- CVE: https://linux.oracle.com/cve/CVE-2025-38693.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38693-media-dvb-frontends-w7090p-fix-null-ptr-deref-in-w7090p-tuner-write-serpar-and-w7090p-tuner-read-serpar.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38680
- Description:
media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format()
- CVE: https://linux.oracle.com/cve/CVE-2025-38680.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38680-media-uvcvideo-fix-1-byte-out-of-bounds-read-in-uvc-parse-format.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39783
- Description:
PCI: endpoint: Fix configfs group list head handling
- CVE: https://linux.oracle.com/cve/CVE-2025-39783.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39783-pci-endpoint-fix-configfs-group-list-head-handling.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39691
- Description:
fs/buffer: fix use-after-free when call bh_read() helper
- CVE: https://linux.oracle.com/cve/CVE-2025-39691.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39691-fs-buffer-fix-use-after-free-when-call-bh-read-helper.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39689
- Description:
ftrace: Also allocate and copy hash for reading of filter files
- CVE: https://linux.oracle.com/cve/CVE-2025-39689.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39689-ftrace-also-allocate-and-copy-hash-for-reading-of-filter-files.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38664
- Description:
ice: Fix a null pointer dereference in ice_copy_and_init_pkg()
- CVE: https://linux.oracle.com/cve/CVE-2025-38664.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38664-ice-fix-a-null-pointer-dereference-in-ice-copy-and-init-pkg.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39798
- Description:
NFS: Fix the setting of capabilities when automounting a new filesystem
- CVE: https://linux.oracle.com/cve/CVE-2025-39798.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39798-nfs-fix-the-setting-of-capabilities-when-automounting-a-new-filesystem.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39798
- Description:
NFS: Fix the setting of capabilities when automounting a new filesystem
- CVE: https://linux.oracle.com/cve/CVE-2025-39798.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39798-nfs-fix-the-setting-of-capabilities-when-automounting-a-new-filesystem-kpatch.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38403
- Description:
vsock/vmci: Clear the vmci transport packet properly when initializing it
- CVE: https://linux.oracle.com/cve/CVE-2025-38403.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38403-vsock-vmci-clear-the-vmci-transport-packet-properly-when-initializing-it.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38464
- Description:
tipc: Fix use-after-free in tipc_conn_close().
- CVE: https://linux.oracle.com/cve/CVE-2025-38464.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38464-tipc-fix-use-after-free-in-tipc-conn-close.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38457
- Description:
net/sched: Abort __tc_modify_qdisc if parent class does not exist
- CVE: https://linux.oracle.com/cve/CVE-2025-38457.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38457-net-sched-abort-tc-modify-qdisc-if-parent-class-does-not-exist.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38445
- Description:
md/raid1: Fix stack memory use after return in raid1_reshape
- CVE: https://linux.oracle.com/cve/CVE-2025-38445.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38445-md-raid1-fix-stack-memory-use-after-return-in-raid1-reshape.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38439
- Description:
bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT
- CVE: https://linux.oracle.com/cve/CVE-2025-38439.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38439-bnxt-en-set-dma-unmap-len-correctly-for-xdp-redirect.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38497
- Description:
usb: gadget: configfs: Fix OOB read on empty string write
- CVE: https://linux.oracle.com/cve/CVE-2025-38497.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38497-usb-gadget-configfs-fix-oob-read-on-empty-string-write.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38477
- Description:
net/sched: sch_qfq: Fix race condition on qfq_aggregate
- CVE: https://linux.oracle.com/cve/CVE-2025-38477.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38477-net-sched-sch-qfq-fix-race-condition-on-qfq-aggregate.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38477
- Description:
net/sched: sch_qfq: Avoid triggering might_sleep in atomic context in qfq_delete_class
- CVE: https://linux.oracle.com/cve/CVE-2025-38477.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38477-net-sched-sch_qfq-Avoid-triggering-might_sleep-in-atomic-context-in-qfq_delete_class.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38474
- Description:
usb: net: sierra: check for no status endpoint
- CVE: https://linux.oracle.com/cve/CVE-2025-38474.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38474-usb-net-sierra-check-for-no-status-endpoint.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39730
- Description:
NFS: Fix filehandle bounds checking in nfs_fh_to_dentry()
- CVE: https://linux.oracle.com/cve/CVE-2025-39730.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39730-nfs-fix-filehandle-bounds-checking-in-nfs-fh-to-dentry.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38718
- Description:
sctp: linearize cloned gso packets in sctp_rcv
- CVE: https://linux.oracle.com/cve/CVE-2025-38718.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38718-sctp-linearize-cloned-gso-packets-in-sctp-rcv.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38245
- Description:
atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister().
- CVE: https://linux.oracle.com/cve/CVE-2025-38245.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38245-atm-release-atm-dev-mutex-after-removing-procfs-in-atm-dev-deregister.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2024-26644
- Description:
btrfs: don't abort filesystem when attempting to snapshot deleted subvolume
- CVE: https://linux.oracle.com/cve/CVE-2024-26644.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2024-26644-btrfs-don-t-abort-filesystem-when-attempting-to-snapshot-deleted-subvolume.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38406
- Description:
wifi: ath6kl: remove WARN on bad firmware input
- CVE: https://linux.oracle.com/cve/CVE-2025-38406.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38406-wifi-ath6kl-remove-warn-on-bad-firmware-input.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38514
- Description:
rxrpc: Fix oops due to non-existence of prealloc backlog struct
- CVE: https://linux.oracle.com/cve/CVE-2025-38514.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38514-rxrpc-fix-oops-due-to-non-existence-of-prealloc-backlog-struct.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38691
- Description:
pNFS: Fix uninited ptr deref in block/scsi layout
- CVE: https://linux.oracle.com/cve/CVE-2025-38691.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38691-pnfs-fix-uninited-ptr-deref-in-block-scsi-layout.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39713
- Description:
media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt()
- CVE: https://linux.oracle.com/cve/CVE-2025-39713.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39713-media-rainshadow-cec-fix-toctou-race-condition-in-rain-interrupt.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38177
- Description:
sch_hfsc: make hfsc_qlen_notify() idempotent
- CVE: https://linux.oracle.com/cve/CVE-2025-38177.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38177-sch-hfsc-make-hfsc-qlen-notify-idempotent.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39766
- Description:
net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit
- CVE: https://linux.oracle.com/cve/CVE-2025-39766.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39766-net-sched-make-cake-enqueue-return-net-xmit-cn-when-past-buffer-limit.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39817
- Description:
efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare
- CVE: https://linux.oracle.com/cve/CVE-2025-39817.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39817-efivarfs-fix-slab-out-of-bounds-in-efivarfs-d-compare.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39824
- Description:
HID: asus: fix UAF via HID_CLAIMED_INPUT validation
- CVE: https://linux.oracle.com/cve/CVE-2025-39824.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39824-hid-asus-fix-uaf-via-hid-claimed-input-validation.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38249
- Description:
ALSA: usb-audio: Fix out-of-bounds read in snd_usb_get_audioformat_uac3()
- CVE: https://linux.oracle.com/cve/CVE-2025-38249.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38249-alsa-usb-audio-fix-out-of-bounds-read-in-snd-usb-get-audioformat-uac3.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38386
- Description:
ACPICA: Refuse to evaluate a method if arguments are missing
- CVE: https://linux.oracle.com/cve/CVE-2025-38386.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38386-acpica-refuse-to-evaluate-a-method-if-arguments-are-missing.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38473
- Description:
Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb()
- CVE: https://linux.oracle.com/cve/CVE-2025-38473.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38473-bluetooth-fix-null-ptr-deref-in-l2cap-sock-resume-cb.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38668
- Description:
regulator: core: fix NULL dereference on unbind due to stale coupling data
- CVE: https://linux.oracle.com/cve/CVE-2025-38668.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38668-regulator-core-fix-null-dereference-on-unbind-due-to-stale-coupling-data.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38581
- Description:
crypto: ccp - Fix crash when rebind ccp device for ccp.ko
- CVE: https://linux.oracle.com/cve/CVE-2025-38581.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38581-crypto-ccp-fix-crash-when-rebind-ccp-device-for-ccp-ko.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38569
- Description:
benet: fix BUG when creating VFs
- CVE: https://linux.oracle.com/cve/CVE-2025-38569.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38569-benet-fix-bug-when-creating-vfs.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39757
- Description:
ALSA: usb-audio: Validate UAC3 cluster segment descriptors
- CVE: https://linux.oracle.com/cve/CVE-2025-39757.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39757-alsa-usb-audio-validate-uac3-cluster-segment-descriptors.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39757
- Description:
ALSA: usb-audio: Validate UAC3 cluster segment descriptors
- CVE: https://linux.oracle.com/cve/CVE-2025-39757.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-39757-ALSA-usb-audio-fix-size-validation-in-convert_chmap_v3.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38699
- Description:
scsi: bfa: Double-free fix
- CVE: https://linux.oracle.com/cve/CVE-2025-38699.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38699-scsi-bfa-double-free-fix.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38698
- Description:
jfs: Regular file corruption check
- CVE: https://linux.oracle.com/cve/CVE-2025-38698.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38698-jfs-regular-file-corruption-check.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2024-53237
- Description:
Bluetooth: fix use-after-free in device_for_each_child()
- CVE: https://linux.oracle.com/cve/CVE-2024-53237.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2024-53237-bluetooth-fix-use-after-free-in-device-for-each-child.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38468
- Description:
net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree
- CVE: https://linux.oracle.com/cve/CVE-2025-38468.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38468-net-sched-return-null-when-htb-lookup-leaf-encounters-an-empty-rbtree.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38650
- Description:
hfsplus: remove mutex_lock check in hfsplus_free_extents
- CVE: https://linux.oracle.com/cve/CVE-2025-38650.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38650-hfsplus-remove-mutex-lock-check-in-hfsplus-free-extents.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38604
- Description:
wifi: rtl818x: Kill URBs before clearing tx status queue
- CVE: https://linux.oracle.com/cve/CVE-2025-38604.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38604-wifi-rtl818x-kill-urbs-before-clearing-tx-status-queue.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38602
- Description:
iwlwifi: Add missing check for alloc_ordered_workqueue
- CVE: https://linux.oracle.com/cve/CVE-2025-38602.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38602-iwlwifi-add-missing-check-for-alloc-ordered-workqueue.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38574
- Description:
pptp: ensure minimal skb length in pptp_xmit()
- CVE: https://linux.oracle.com/cve/CVE-2025-38574.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38574-pptp-ensure-minimal-skb-length-in-pptp-xmit.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38574
- Description:
pptp: fix pptp_xmit() error path
- CVE: https://linux.oracle.com/cve/CVE-2025-38574.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38574-pptp-fix-pptp_xmit-error-path.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38555
- Description:
usb: gadget : fix use-after-free in composite_dev_cleanup()
- CVE: https://linux.oracle.com/cve/CVE-2025-38555.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38555-usb-gadget-fix-use-after-free-in-composite-dev-cleanup.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38714
- Description:
hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read()
- CVE: https://linux.oracle.com/cve/CVE-2025-38714.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38714-hfsplus-fix-slab-out-of-bounds-in-hfsplus-bnode-read.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38713
- Description:
hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
- CVE: https://linux.oracle.com/cve/CVE-2025-38713.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38713-hfsplus-fix-slab-out-of-bounds-read-in-hfsplus-uni2asc.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-38713
- Description:
hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
- CVE: https://linux.oracle.com/cve/CVE-2025-38713.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38713-hfsplus-fix-slab-out-of-bounds-read-in-hfsplus_uni2asc.patch
- From: 5.4.17-2136.348.3.el8uek
- CVE-2025-39751
- Description:
This CVE has been rejected or withdrawn by its CVE Numbering Authority as per NVD website
- CVE:
- Patch: skipped/CVE-2025-39751.patch
- From:
- CVE-2025-38700
- Description:
scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated
- CVE: https://linux.oracle.com/cve/CVE-2025-38700.html
- Patch: oel8-uek6/5.4.17-2136.348.3.el8uek/CVE-2025-38700-scsi-libiscsi-initialize-iscsi-conn-dd-data-only-if-memory-is-allocated.patch
- From: 5.4.17-2136.348.3.el8uek
- n/a
- Description:
x86/xen: Add xenpv_restore_regs_and_return_to_usermode()
- CVE: n/a
- Patch: 5.4.17/x86-xen-Add-xenpv_restore_regs_and_return_to_usermode.patch
- From: v5.16
- N/A
- Description:
kpatch add alt asm definitions
- CVE: N/A
- Patch: 5.11.0/kpatch-add-alt-asm-definitions.patch
- From: N/A
- N/A
- Description:
kpatch add paravirt asm definitions
- CVE: N/A
- Patch: 5.11.0/kpatch-add-paravirt-asm-definitions.patch
- From: N/A
- N/A
- Description:
Restrict access to pagemap/kpageflags/kpagecount
- CVE: http://googleprojectzero.blogspot.ru/2015/03/exploiting-dram-rowhammer-bug-to-gain.html
- Patch: 4.15.0/proc-restrict-pagemap-access.patch
- From: N/A