- kernel-plus-3.10.0-1160.59.1.el7.centos.plus (centos7-plus)
- 3.10.0-1160.108.1.el7.centos.plus
- 2026-04-29 06:06:56
- 2026-04-29 12:36:26
- K20260429_03
- CVE-2021-4028
- Description:
RDMA/cma: Do not change route.addr.src_addr.ss_family
- CVE: https://security-tracker.debian.org/tracker/CVE-2021-4028
- Patch: 3.10.0/CVE-2021-4028-RDMA-cma-Do-not-change-route.addr.src_addr.ss_family.patch
- From: 3.10.0-1160.62.1
- CVE-2022-1016
- Description:
Initialize registers to avoid stack leak into userspace.
- CVE: https://access.redhat.com/security/cve/cve-2022-1016
- Patch: 3.10.0/CVE-2022-1016-ge-1062.patch
- From: >kernel-3.10.0-1160.62.1.el7
- CVE-2022-1015
- Description:
Bail out in case userspace uses unsupported registers.
- CVE: https://access.redhat.com/security/cve/cve-2022-1015
- Patch: 3.10.0/CVE-2022-1015.patch
- From: >kernel-3.10.0-1160.62.1.el7
- CVE-2022-0492
- Description:
cgroup-v1: Require capabilities to set release_agent
- CVE: https://access.redhat.com/security/cve/CVE-2022-0492
- Patch: 3.10.0/CVE-2022-0492-cgroup-v1-Require-capabilities-to-set-release_agent.patch
- From: 3.10.0-1160.66.1.el7
- CVE-2022-1729
- Description:
perf: Fix sys_perf_event_open() race against self
- CVE: https://access.redhat.com/security/cve/CVE-2022-1729
- Patch: 3.10.0/CVE-2022-1729-perf-Fix-sys-perf-event-open-race-against-itself.patch
- From: 5.4.17-2136.307.3.2.el8uek
- CVE-2022-32250
- Description:
netfilter: nf_tables: disallow non-stateful expression in
- CVE: https://access.redhat.com/security/cve/CVE-2022-32250
- Patch: 3.10.0/CVE-2022-32250-nf_tables-disallow-non-stateful-expression-in-sets-earlier.patch
- From: 3.10.0-1160.71.1
- CVE-2022-21499
- Description:
Not affected without certain conditions - Secure Boot, configured kgdb/kdb. Complex adaptation
- CVE:
- Patch: skipped/CVE-2022-21499.patch
- From:
- CVE-2022-21123 CVE-2022-21125 CVE-2022-21166 CVE-2022-21127
- Description:
x86/speculation/mmio: Add mitigation for Processor MMIO Stale Data
- CVE: https://access.redhat.com/security/cve/cve-2022-21127
- Patch: mmio-enable.patch
- From: 5.18
- CVE-2022-2588
- Description:
net_sched: cls_route: remove from list when handle is 0
- CVE: https://access.redhat.com/security/cve/cve-2022-2588
- Patch: 3.10.0/CVE-2022-2588.patch
- From: 3.10.0-1160.80.1.el7
- CVE-2022-23816
- Description:
Livepatching Retbleed may decrease kernel stability and performance. This vulnerability has medium security impact and applies to certain hardware environments only.
- CVE:
- Patch: skipped/CVE-2022-23816.patch
- From:
- CVE-2022-23825
- Description:
Livepatching Retbleed may decrease kernel stability and performance. This vulnerability has medium security impact and applies to certain hardware environments only.
- CVE:
- Patch: skipped/CVE-2022-23825.patch
- From:
- CVE-2022-26373
- Description:
Livepatching Retbleed may decrease the stability and performance of the kernel, while vulnerability has a medium security impact and only for a certain hardware environment.
- CVE:
- Patch: skipped/CVE-2022-26373.patch
- From:
- CVE-2022-29900
- Description:
Livepatching Retbleed may decrease kernel stability and performance. This vulnerability has medium security impact and applies to certain hardware environments only.
- CVE:
- Patch: skipped/CVE-2022-29900.patch
- From:
- CVE-2022-29901
- Description:
Livepatching Retbleed may decrease the stability and performance of the kernel, while vulnerability has a medium security impact and only for a certain hardware environment.
- CVE:
- Patch: skipped/CVE-2022-29901.patch
- From:
- CVE-2022-2964
- Description:
net: usb: ax88179_178a: fix packet alignment padding
- CVE: https://access.redhat.com/security/cve/CVE-2022-2964
- Patch: 3.10.0/CVE-2022-2964-1510-net-usb-ax88179_178a-fix-packet-alignment-padding.patch
- From: kernel-3.10.0-1160.83.1.el7
- CVE-2022-2964
- Description:
ax88179_178a: Merge memcpy + le32_to_cpus to get_unaligned_le32
- CVE: https://access.redhat.com/security/cve/CVE-2022-2964
- Patch: 3.10.0/CVE-2022-2964-1511-ax88179_178a-Merge-memcpy-le32_to_cpus-to-get_unalig.patch
- From: kernel-3.10.0-1160.83.1.el7
- CVE-2022-2964
- Description:
net: usb: Merge cpu_to_le32s + memcpy to put_unaligned_le32
- CVE: https://access.redhat.com/security/cve/CVE-2022-2964
- Patch: 3.10.0/CVE-2022-2964-1512-net-usb-Merge-cpu_to_le32s-memcpy-to-put_unaligned_l.patch
- From: kernel-3.10.0-1160.83.1.el7
- CVE-2022-2964
- Description:
net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup
- CVE: https://access.redhat.com/security/cve/CVE-2022-2964
- Patch: 3.10.0/CVE-2022-2964-1518-net-usb-ax88179_178a-Fix-out-of-bounds-accesses-in-R.patch
- From: kernel-3.10.0-1160.83.1.el7
- CVE-2022-2964
- Description:
net: usb: ax88179_178a: Fix packet receiving
- CVE: https://access.redhat.com/security/cve/CVE-2022-2964
- Patch: 3.10.0/CVE-2022-2964-1519-net-usb-ax88179_178a-Fix-packet-receiving.patch
- From: kernel-3.10.0-1160.83.1.el7
- CVE-2021-26401
- Description:
An introduction of required changes through KernelCare could cause unavoidable problems to applications which use unprivileged eBPF.
- CVE:
- Patch: skipped/CVE-2021-26401.patch
- From:
- CVE-2022-4378
- Description:
proc: avoid integer type confusion in get_proc_long
- CVE: https://access.redhat.com/security/cve/CVE-2022-4378
- Patch: 3.10.0/CVE-2022-4378-1-proc-avoid-integer-type-confusion-in-get_proc_long.patch
- From: 3.10.0-1160.88.1.el7
- CVE-2022-4378
- Description:
proc: proc_skip_spaces() shouldn't think it is working on C strings
- CVE: https://access.redhat.com/security/cve/CVE-2022-4378
- Patch: 3.10.0/CVE-2022-4378-2-proc-sysctl-fix-return-error-for-proc_doulongvec_min.patch
- From: 3.10.0-1160.88.1.el7
- CVE-2022-43750
- Description:
usb: mon: make mmapped memory read only
- CVE: https://access.redhat.com/security/cve/CVE-2022-43750
- Patch: 3.10.0/CVE-2022-43750-usb-mon-make-mmapped-memory-read-only.patch
- From: 3.10.0-1160.90.1
- CVE-2022-3564
- Description:
Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu
- CVE: https://access.redhat.com/security/cve/CVE-2022-3564
- Patch: 3.10.0/CVE-2022-3564-Bluetooth-L2CAP-Fix-use-after-free-caused-by-l2cap_reassemble_sdu.patch
- From: 3.10.0-1160.95.1.el7
- CVE-2023-35788
- Description:
net/sched: flower: fix possible OOB write in fl_set_geneve_opt()
- CVE: https://access.redhat.com/security/cve/CVE-2023-35788
- Patch: rhel7/3.10.0-1160.99.1.el7/CVE-2023-35788-net-sched-flower-fix-possible-oob-write-in-fl-set-geneve-opt.patch
- From: 3.10.0-1160.99.1.el7
- CVE-2023-20593
- Description:
hw: amd: Cross-Process Information Leak
- CVE: https://access.redhat.com/security/cve/cve-2023-20593
- Patch: rhel7/3.10.0-1160.99.1.el7/CVE-2023-20593-zenbleed.patch
- From: 3.10.0-1160.99.1.el7
- CVE-2023-32233
- Description:
netfilter: nf_tables: deactivate anonymous set from preparation phase
- CVE: https://access.redhat.com/security/cve/CVE-2023-32233
- Patch: rhel7/3.10.0-1160.102.1.el7/CVE-2023-32233-1.patch
- From: 3.10.0-1160.102.1.el7
- CVE-2023-32233
- Description:
netfilter: nf_tables: deactivate anonymous set from preparation phase (adaptation)
- CVE: https://access.redhat.com/security/cve/CVE-2023-32233
- Patch: rhel7/3.10.0-1160.102.1.el7/CVE-2023-32233-1-kpatch.patch
- From: 3.10.0-1160.102.1.el7
- CVE-2023-32233
- Description:
netfilter: nf_tables: do not allow SET_ID to refer to another table
- CVE: https://access.redhat.com/security/cve/CVE-2023-32233
- Patch: rhel7/3.10.0-1160.102.1.el7/CVE-2023-32233-2.patch
- From: 3.10.0-1160.102.1.el7
- CVE-2023-32233
- Description:
netfilter: nf_tables: skip deactivated anonymous sets during lookups
- CVE: https://access.redhat.com/security/cve/CVE-2023-32233
- Patch: rhel7/3.10.0-1160.102.1.el7/CVE-2023-32233-3.patch
- From: 3.10.0-1160.102.1.el7
- CVE-2023-35001
- Description:
netfilter: nf_tables: prevent OOB access in nft_byteorder_eval
- CVE: https://access.redhat.com/security/cve/CVE-2023-35001
- Patch: rhel7/3.10.0-1160.102.1.el7/CVE-2023-35001.patch
- From: 3.10.0-1160.102.1.el7
- CVE-2023-3609
- Description:
Smart Patch for net/sched: cls_u32: Fix reference counter leak leading to overflow
- CVE: https://access.redhat.com/security/cve/CVE-2023-3609
- Patch: rhel7/3.10.0-1160.102.1.el7/CVE-2023-3609-smart-backport-for-net-sched-cls-u32-c.patch
- From: 3.10.0-1160.102.1.el7
- CVE-2023-4208 CVE-2023-4128
- Description:
Smart Patch for net/sched/cls_u32.c
- CVE: https://access.redhat.com/security/cve/CVE-2023-4208
- Patch: rhel7/3.10.0-1160.102.1.el7/CVE-2023-4208-smart-patch-for-net-sched-cls-u32-c.patch
- From: kernel-3.10.0-1160.105.1.el7
- CVE-2023-4207 CVE-2023-4128
- Description:
net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free
- CVE: https://access.redhat.com/security/cve/CVE-2023-4207
- Patch: rhel7/3.10.0-1160.105.1.el7/CVE-2023-4207-net-sched-cls-fw-no-longer-copy-tcf-result-on-update-to-avoid.patch
- From: kernel-3.10.0-1160.105.1.el7
- CVE-2023-4206 CVE-2023-4128
- Description:
net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free
- CVE: https://access.redhat.com/security/cve/CVE-2023-4206
- Patch: rhel7/3.10.0-1160.105.1.el7/CVE-2023-4206-net-sched-cls-route-no-longer-copy-tcf-result-on-update-to-avoid.patch
- From: kernel-3.10.0-1160.105.1.el7
- CVE-2023-3776
- Description:
net/sched: cls_fw: Fix improper refcount update leads to use-after-free
- CVE: https://access.redhat.com/security/cve/CVE-2023-3776
- Patch: rhel7/3.10.0-1160.105.1.el7/CVE-2023-3776-net-sched-cls-fw-fix-improper-refcount-update-leads-to.patch
- From: kernel-3.10.0-1160.105.1.el7
- CVE-2023-3611
- Description:
net/sched: sch_qfq: account for stab overhead in qfq_enqueue
- CVE: https://access.redhat.com/security/cve/CVE-2023-3611
- Patch: rhel7/3.10.0-1160.105.1.el7/CVE-2023-3611-net-sched-sch-qfq-account-for-stab-overhead-in-qfq-enqueue.patch
- From: kernel-3.10.0-1160.105.1.el7
- CVE-2022-40982
- Description:
Complex adaptation required.
- CVE:
- Patch: skipped/CVE-2022-40982.patch
- From:
- CVE-2023-31436
- Description:
net/sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg
- CVE: https://access.redhat.com/security/cve/CVE-2023-31436
- Patch: rhel7/3.10.0-1160.105.1.el7/CVE-2023-31436-net-sched-sch_qfq-prevent-slab-out-of-bounds-in-qfq_.patch
- From: kernel-3.10.0-1160.105.1.el7
- CVE-2023-42753
- Description:
revert of: netfilter: ipset: actually allow allowable CIDR 0 in hash:net, port, net
- CVE: https://access.redhat.com/security/cve/CVE-2023-42753
- Patch: rhel7/3.10.0-1160.108.1.el7/CVE-2023-42753-REVERT-net-netfilter-ipset-actually-allow-allowable-CIDR-0-.patch
- From: 3.10.0-1160.108.1.el7
- CVE-2022-42896
- Description:
Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM
- CVE: https://access.redhat.com/security/cve/CVE-2022-42896
- Patch: rhel7/3.10.0-1160.114.2.el7/CVE-2022-42896-Bluetooth-L2CAP-Fix-accepting-connection-request-for-invalid-SPSM.patch
- From: 3.10.0-1160.114.2.el7
- CVE-2022-42896
- Description:
Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm
- CVE: https://access.redhat.com/security/cve/CVE-2022-42896
- Patch: rhel7/3.10.0-1160.114.2.el7/CVE-2022-42896-Bluetooth-L2CAP-Fix-l2cap_global_chan_by_psm.patch
- From: 3.10.0-1160.114.2.el7
- CVE-2023-4921
- Description:
net: sched: sch_qfq: Fix UAF in qfq_dequeue()
- CVE: https://access.redhat.com/security/cve/CVE-2023-4921
- Patch: rhel7/3.10.0-1160.114.2.el7/CVE-2023-4921-net-sched-sch-qfq-fix-uaf-in-qfq-dequeue.patch
- From: 3.10.0-1160.114.2.el7
- CVE-2023-4921
- Description:
net: sched: sch_qfq: Fix UAF in qfq_dequeue() (adaptation)
- CVE: https://access.redhat.com/security/cve/CVE-2023-4921
- Patch: rhel7/3.10.0-1160.114.2.el7/CVE-2023-4921-net-sched-sch-qfq-fix-uaf-in-qfq-dequeue-kpatch.patch
- From: 3.10.0-1160.114.2.el7
- CVE-2023-38409
- Description:
fbcon driver was updated and patched in the same kernel 3.10.0-1160.111.1.el7. Older versions don't contain vulnerabilities b07db3958485 and d443d9386472
- CVE:
- Patch: skipped/CVE-2023-38409.patch
- From:
- CVE-2023-45871
- Description:
igb: set max size RX buffer when store bad packet is enabled
- CVE: https://access.redhat.com/security/cve/CVE-2023-45871
- Patch: rhel7/3.10.0-1160.114.2.el7/CVE-2023-45871-igb-set-max-size-rx-buffer-when-store-bad-packet-is-enabled.patch
- From: 3.10.0-1160.114.2.el7
- CVE-2023-45871
- Description:
igb: set max size RX buffer when store bad packet is enabled (adaptation)
- CVE: https://access.redhat.com/security/cve/CVE-2023-45871
- Patch: rhel7/3.10.0-1160.114.2.el7/CVE-2023-45871-igb-set-max-size-rx-buffer-when-store-bad-packet-is-enabled-kpatch.patch
- From: 3.10.0-1160.114.2.el7
- CVE-2024-1086
- Description:
netfilter: nf_tables: reject QUEUE/DROP verdict parameters
- CVE: https://access.redhat.com/security/cve/CVE-2024-1086
- Patch: rhel7/3.10.0-1160.114.2.el7/CVE-2024-1086-netfilter-nf-tables-reject-queue-drop-verdict-parameters.patch
- From: 3.10.0-1160.114.2.el7
- CVE-2024-26602
- Description:
sched/membarrier: reduce the ability to hammer on sys_membarrier
- CVE: https://access.redhat.com/security/cve/CVE-2024-26602
- Patch: rhel7/3.10.0-1160.114.2.el7/CVE-2024-26602-sched-membarrier-reduce-the-ability-to-hammer-on-sys_membarrier.patch
- From: 3.10.0-1160.114.2.el7
- CVE-2023-4622
- Description:
[PATCH 1681/1699] af_unix: Fix null-ptr-deref in
- CVE: https://access.redhat.com/security/cve/CVE-2023-4622
- Patch: rhel7/3.10.0-1160.118.1.el7/CVE-2023-4622-patch-1681-1699-af-unix-fix-null-ptr-deref-in.patch
- From: 3.10.0-1160.118.1.el7
- CVE-2023-4623
- Description:
[PATCH 1658/1699] net/sched: sch_hfsc: Ensure inner classes have fsc
- CVE: https://access.redhat.com/security/cve/CVE-2023-4623
- Patch: rhel7/3.10.0-1160.118.1.el7/CVE-2023-4623-patch-1658-1699-net-sched-sch-hfsc-ensure-inner-classes-have-fsc.patch
- From: 3.10.0-1160.118.1.el7
- CVE-2023-4623
- Description:
[PATCH 1659/1699] net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it
- CVE: https://access.redhat.com/security/cve/CVE-2023-4623
- Patch: rhel7/3.10.0-1160.118.1.el7/CVE-2023-4623-patch-1659-1699-net-sched-sch-hfsc-upgrade-rt-to-sc-when-it.patch
- From: 3.10.0-1160.118.1.el7
- CVE-2023-2002
- Description:
[PATCH 1686/1699] bluetooth: Perform careful capability checks in
- CVE: https://access.redhat.com/security/cve/CVE-2023-2002
- Patch: rhel7/3.10.0-1160.118.1.el7/CVE-2023-2002-patch-1686-1699-bluetooth-perform-careful-capability-checks-in.patch
- From: 3.10.0-1160.118.1.el7
- CVE-2023-2002
- Description:
[PATCH 1689/1699] bluetooth: Add cmd validity checks at the start of
- CVE: https://access.redhat.com/security/cve/CVE-2023-2002
- Patch: rhel7/3.10.0-1160.118.1.el7/CVE-2023-2002-patch-1689-1699-bluetooth-add-cmd-validity-checks-at-the-start-of.patch
- From: 3.10.0-1160.118.1.el7
- CVE-2020-36558
- Description:
[PATCH 1696/1699] vt: vt_ioctl: fix race in VT_RESIZEX
- CVE: https://access.redhat.com/security/cve/CVE-2020-36558
- Patch: rhel7/3.10.0-1160.118.1.el7/CVE-2020-36558-patch-1696-1699-vt-vt-ioctl-fix-race-in-vt-resizex.patch
- From: 3.10.0-1160.118.1.el7
- CVE-2023-25775
- Description:
[PATCH 1643/1699] RDMA/i40iw: Prevent zero-length STAG registration
- CVE: https://access.redhat.com/security/cve/CVE-2023-25775
- Patch: rhel7/3.10.0-1160.118.1.el7/CVE-2023-25775-patch-1643-1699-rdma-i40iw-prevent-zero-length-stag-registration.patch
- From: 3.10.0-1160.118.1.el7
- CVE-2023-25775
- Description:
RDMA/irdma: Prevent zero-length STAG registration (adaptation)
- CVE: https://ubuntu.com/security/CVE-2023-25775
- Patch: rhel7/3.10.0-1160.118.1.el7/CVE-2023-25775-patch-1643-1699-rdma-i40iw-prevent-zero-length-stag-registration-kpatch.patch
- From: 5.15.0-89.99
- CVE-2024-36971
- Description:
net: fix __dst_negative_advice() race
- CVE: https://access.redhat.com/security/cve/CVE-2024-36971
- Patch: rhel7/3.10.0-1160.123.1.el7/CVE-2024-36971-ELSCVE-27162-net-fix-__dst_negative_advice-race.patch
- From: 3.10.0-1160.123.1.el7
- CVE-2022-1011
- Description:
fuse: fix pipe buffer lifetime for direct_io
- CVE: https://access.redhat.com/security/cve/CVE-2022-1011
- Patch: rhel7/3.10.0-1160.123.1.el7/CVE-2022-1011-ELSCVE-14458-fuse-fix-pipe-buffer-lifetime-for-direc.patch
- From: 3.10.0-1160.123.1.el7
- CVE-2022-1011
- Description:
fuse: fix pipe buffer lifetime for direct_io
- CVE: https://access.redhat.com/security/cve/CVE-2022-1011
- Patch: rhel7/3.10.0-1160.123.1.el7/CVE-2022-1011-ELSCVE-14458-fuse-fix-pipe-buffer-lifetime-for-direc-kpatch.patch
- From: 3.10.0-1160.123.1.el7
- CVE-2024-41071
- Description:
wifi: mac80211: Avoid address calculations via out of bounds array indexing
- CVE: https://access.redhat.com/security/cve/CVE-2024-41071
- Patch: rhel7/3.10.0-1160.125.1.el7/CVE-2024-41071-wifi-mac80211-Avoid-address-calculation.patch
- From: 3.10.0-1160.125.1.el7
- N/A
- Description:
N/A
- CVE: N/A
- Patch: 3.10.0/paravirt-asm-definition.patch
- From: N/A
- CVE-2024-2201
- Description:
x86/bhi: Add support for clearing branch history at syscall entry
- CVE: https://access.redhat.com/security/cve/CVE-2024-2201
- Patch: 3.10.0/CVE-2024-2201-native-bhi-el7-2.patch
- From: kernel-4.18.0-553.16.1.el8_10
- CVE-2024-53104
- Description:
media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format
- CVE: https://access.redhat.com/security/cve/CVE-2024-53104
- Patch: rhel7/3.10.0-1160.132.1.el7/CVE-2024-53104-media-uvcvideo-Skip-parsing-frames-of-type-UVC_VS_UNDEFINED.patch
- From: 3.10.0-1160.132.1.el7
- CVE-2023-52922
- Description:
can: bcm: Fix UAF in bcm_proc_show()
- CVE: https://access.redhat.com/security/cve/CVE-2023-52922
- Patch: rhel7/3.10.0-1160.133.1.el7/CVE-2023-52922-can-bcm-Fix-UAF-in-bcm_proc_show.patch
- From: 3.10.0-1160.133.1.el7
- CVE-2024-50302
- Description:
HID: core: zero-initialize the report buffer
- CVE: https://access.redhat.com/security/cve/CVE-2024-50302
- Patch: rhel7/3.10.0-1160.133.1.el7/CVE-2024-50302-HID-core-zero-initialize-the-report-buffer.patch
- From: 3.10.0-1160.133.1.el7
- CVE-2024-53197
- Description:
ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices
- CVE: https://access.redhat.com/security/cve/CVE-2024-53197
- Patch: rhel7/3.10.0-1160.133.1.el7/CVE-2024-53197-0001-ALSA-usb-audio-Fix-potential-out-of-bound-accesses-f.patch
- From: 3.10.0-1160.133.1.el7
- CVE-2024-53197
- Description:
ALSA: usb-audio: Fix a DMA to stack memory bug
- CVE: https://access.redhat.com/security/cve/CVE-2024-53197
- Patch: rhel7/3.10.0-1160.133.1.el7/CVE-2024-53197-0002-ALSA-usb-audio-Fix-a-DMA-to-stack-memory-bug.patch
- From: 3.10.0-1160.133.1.el7
- CVE-2024-53150
- Description:
ALSA: usb-audio: Fix out of bounds reads when finding clock sources
- CVE: https://access.redhat.com/security/cve/CVE-2024-53150
- Patch: rhel7/3.10.0-1160.133.1.el7/CVE-2024-53150-alsa-usb-audio-fix-out-of-bounds-reads-when-finding-clock-sources.patch
- From: 3.10.0-1160.133.1.el7
- CVE-2024-53141
- Description:
netfilter: ipset: add missing range check in bitmap_ip_uadt
- CVE: https://access.redhat.com/security/cve/CVE-2024-53141
- Patch: rhel7/3.10.0-1160.119.1.el7.tuxcare.els15/CVE-2024-53141-netfilter-ipset-add-missing-range-check.patch
- From: 3.10.0-1160.119.1.el7.tuxcare.els15
- CVE-2025-22004
- Description:
net: atm: fix use after free in lec_send()
- CVE: https://access.redhat.com/security/cve/CVE-2025-22004
- Patch: rhel7/3.10.0-1160.136.1.el7/CVE-2025-22004-net-atm-fix-use-after-free-in-lec_send.patch
- From: kernel-3.10.0-1160.136.1.el7
- CVE-2022-50066
- Description:
net: atlantic: fix aq_vec index out of range error
- CVE: https://access.redhat.com/security/cve/CVE-2022-50066
- Patch: rhel7/3.10.0-1160.136.1.el7/CVE-2022-50066-net-atlantic-fix-aq_vec-index-out-of-range-error.patch
- From: kernel-3.10.0-1160.136.1.el7
- CVE-2025-21928
- Description:
HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove()
- CVE: https://access.redhat.com/security/cve/CVE-2025-21928
- Patch: rhel7/3.10.0-1160.137.1.el7/CVE-2025-21928-hid-intel-ish-hid-Fix-use-after-free-issue-in-ishtp_hid_remove.patch
- From: 3.10.0-1160.137.1.el7
- CVE-2024-57980
- Description:
media: uvcvideo: Fix double free in error path
- CVE: https://access.redhat.com/security/cve/CVE-2024-57980
- Patch: rhel7/3.10.0-1160.137.1.el7/CVE-2024-57980-media-uvcvideo-Fix-double-free-in-error.patch
- From: 3.10.0-1160.137.1.el79
- CVE-2022-49788
- Description:
misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram()
- CVE: https://access.redhat.com/security/cve/cve-2022-49788
- Patch: rhel7/3.10.0-1160.137.1.el7/CVE-2022-49788-misc-vmw_vmci-fix-an-infoleak-in-vmci_host_do_receive_datagram.patch
- From: 3.10.0-1160.137.1.el7
- CVE-2025-23150
- Description:
ext4: fix off-by-one error in do_split
- CVE: https://access.redhat.com/security/cve/CVE-2025-23150
- Patch: rhel7/3.10.0-1160.137.1.el7/CVE-2025-23150-ext4-fix-off-by-one-error-in-do-split.patch
- From: 3.10.0-1160.137.1.el7
- CVE-2022-50022
- Description:
drivers:md:fix a potential use-after-free bug
- CVE: https://access.redhat.com/security/cve/CVE-2022-50022
- Patch: rhel7/3.10.0-1160.137.1.el7/CVE-2022-50022-drivers-md-fix-a-potential-use-after-free-bug.patch
- From: 3.10.0-1160.137.1.el7
- CVE-2025-38177
- Description:
sch_hfsc: make hfsc_qlen_notify() idempotent
- CVE: https://access.redhat.com/security/cve/CVE-2025-38177
- Patch: rhel7/3.10.0-1160.137.1.el7/CVE-2025-38177-sch_hfsc-make-hfsc_qlen_notify-idempotent.patch
- From: 3.10.0-1160.137.1.el7
- CVE-2022-50020
- Description:
ext4: avoid resizing to a partial cluster size
- CVE: https://access.redhat.com/security/cve/CVE-2022-50020
- Patch: rhel7/3.10.0-1160.137.1.el7/CVE-2022-50020-ext4-avoid-resizing-to-a-partial-cluster-size.patch
- From: 3.10.0-1160.137.1.el7
- CVE-2025-38350
- Description:
Change signature of qdisc_tree_reduce_backlog() to use ints
- CVE: https://access.redhat.com/security/cve/CVE-2025-38350
- Patch: rhel7/3.10.0-1160.137.1.el7/CVE-2025-38350-sch_api-Change-signature-of-qdisc_tree_reduce_backlo.patch
- From: 3.10.0-1160.137.1.el7
- CVE-2025-38350
- Description:
net/sched: Always pass notifications when child class becomes empty
- CVE: https://access.redhat.com/security/cve/CVE-2025-38350
- Patch: rhel7/3.10.0-1160.137.1.el7/CVE-2025-38350-net-sched-Always-pass-notifications-when-child-class.patch
- From: 3.10.0-1160.137.1.el7
- CVE-2025-38350
- Description:
sch_cbq: make cbq_qlen_notify() idempotent
- CVE: https://access.redhat.com/security/cve/CVE-2025-38350
- Patch: rhel7/3.10.0-1160.137.1.el7/CVE-2025-38350-sch_cbq-make-cbq_qlen_notify-idempotent.patch
- From: 3.10.0-1160.137.1.el7
- CVE-2025-38350
- Description:
sch_htb: make htb_deactivate() idempotent
- CVE: https://access.redhat.com/security/cve/CVE-2025-38350
- Patch: rhel7/3.10.0-1160.137.1.el7/CVE-2025-38350-sch_htb-make-htb_deactivate-idempotent.patch
- From: 3.10.0-1160.137.1.el7
- CVE-2025-38350
- Description:
codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog()
- CVE: https://access.redhat.com/security/cve/CVE-2025-38350
- Patch: rhel7/3.10.0-1160.137.1.el7/CVE-2025-38350-codel-remove-sch-qqlen-check-before-qdisc_tree_reduce_backlog.patch
- From: 3.10.0-1160.137.1.el7
- CVE-2025-38350
- Description:
sch_qfq: make qfq_qlen_notify() idempotent
- CVE: https://access.redhat.com/security/cve/CVE-2025-38350
- Patch: rhel7/3.10.0-1160.137.1.el7/CVE-2025-38350-sch_qfq-make-qfq_qlen_notify-idempotent.patch
- From: 3.10.0-1160.137.1.el7
- CVE-2025-38350
- Description:
sch_drr: make drr_qlen_notify() idempotent
- CVE: https://access.redhat.com/security/cve/CVE-2025-38350
- Patch: rhel7/3.10.0-1160.137.1.el7/CVE-2025-38350-sch_drr-make-drr_qlen_notify-idempotent.patch
- From: 3.10.0-1160.137.1.el7
- CVE-2025-38350
- Description:
sch_htb: make htb_qlen_notify() idempotent
- CVE: https://access.redhat.com/security/cve/CVE-2025-38350
- Patch: rhel7/3.10.0-1160.137.1.el7/CVE-2025-38350-sch_htb-make-htb_qlen_notify-idempotent.patch
- From: 3.10.0-1160.137.1.el7
- CVE-2025-38000
- Description:
sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()
- CVE: https://access.redhat.com/security/cve/CVE-2025-38000
- Patch: rhel7/3.10.0-1160.137.1.el7/CVE-2025-38000-sch_hfsc-Fix-qlen-accounting-bug-when-using-peek-in-hfsc-enqueue.patch
- From: 3.10.0-1160.137.1.el7
- CVE-2025-38079
- Description:
crypto: algif_hash - fix double free in hash_accept
- CVE: https://access.redhat.com/security/cve/CVE-2025-38079
- Patch: rhel7/3.10.0-1160.138.1.el7/CVE-2025-38079-crypto-algif_hash-fix-double-free-in-hash_accept.patch
- From: kernel-3.10.0-1160.138.1.el7
- CVE-2025-38332
- Description:
scsi: lpfc: Use memcpy() for BIOS version
- CVE: https://access.redhat.com/security/cve/CVE-2025-38332
- Patch: rhel7/kernel-3.10.0-1160.139.1.el7/CVE-2025-38332-scsi-lpfc-Use-memcpy-for-BIOS-version.patch
- From: 3.10.0-1160.139.1.el7
- CVE-2025-38352
- Description:
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
- CVE: https://access.redhat.com/security/cve/CVE-2025-38352
- Patch: rhel7/kernel-3.10.0-1160.139.1.el7/CVE-2025-38352-posix-cpu-timers-fix-race-between-handle_posix_cpu_timers-and-posix_cpu_timer_del.patch
- From: 3.10.0-1160.139.1.el7
- CVE-2023-53125
- Description:
net: usb: smsc75xx: Limit packet length to skb->len
- CVE: https://access.redhat.com/security/cve/CVE-2023-53125
- Patch: rhel7/3.10.0-1160.141.1.el7/CVE-2023-53125-net-usb-smsc75xx-Limit-packet-length-to-skb-len.patch
- From: kernel-3.10.0-1160.141.1.el7
- CVE-2023-53125
- Description:
net: usb: smsc75xx: Move packet length check to prevent kernel panic in skb_pull
- CVE: https://access.redhat.com/security/cve/CVE-2023-53125
- Patch: rhel7/3.10.0-1160.141.1.el7/CVE-2023-53125-net-usb-smsc75xx-Move-packet-length-check-to-prevent.patch
- From: kernel-3.10.0-1160.141.1.el7
- CVE-2025-38477
- Description:
net/sched: sch_qfq: Fix race condition on qfq_aggregate
- CVE: https://access.redhat.com/security/cve/CVE-2025-38477
- Patch: rhel7/3.10.0-1160.141.1.el7/CVE-2025-38477-net-sched-sch_qfq-Fix-race-condition-on-qfq_aggregate.patch
- From: kernel-3.10.0-1160.141.1.el7
- CVE-2022-48701
- Description:
nALSA: usb-audio: Fix an out-of-bounds bug in __snd_usb_parse_audio_interface()
- CVE: https://access.redhat.com/security/cve/CVE-2022-48701
- Patch: rhel7/3.10.0-1160.141.1.el7/CVE-2022-48701-ALSA-usb-audio-Fix-an-out-of-bounds-bug-in-__snd_usb.patch
- From: kernel-3.10.0-1160.141.1.el7
- CVE-2025-38200
- Description:
i40e: fix MMIO write access to an invalid page in i40e_clear_hw
- CVE: https://access.redhat.com/security/cve/CVE-2025-38200
- Patch: rhel7/3.10.0-1160.141.1.el7/CVE-2025-38200-i40e-fix-MMIO-write-access-to-an-invalid-page-in-i40e_clear_hw.patch
- From: kernel-3.10.0-1160.141.1.el7
- CVE-2022-50229
- Description:
ALSA: bcd2000: Fix a UAF bug on the error path of probing
- CVE: https://access.redhat.com/security/cve/CVE-2022-50229
- Patch: rhel7/3.10.0-1160.141.1.el7/CVE-2022-50229-ALSA-bcd2000-Fix-a-UAF-bug-on-the-error-path-of-probing.patch
- From: kernel-3.10.0-1160.141.1.el7
- CVE-2022-50211
- Description:
md-raid10: fix KASAN warning
- CVE: https://access.redhat.com/security/cve/CVE-2022-50211
- Patch: rhel7/3.10.0-1160.141.1.el7/CVE-2022-50211-md-raid10-fix-KASAN-warning.patch
- From: kernel-3.10.0-1160.141.1.el7
- CVE-2025-37797
- Description:
net_sched: hfsc: Fix a UAF vulnerability in class handling
- CVE: https://access.redhat.com/security/cve/CVE-2025-37797
- Patch: rhel7/3.10.0-1160.142.1.el7/CVE-2025-37797-net_sched-hfsc-Fix-a-UAF-vulnerability-in-class-handling.patch
- From: kernel-3.10.0-1160.142.1.el7
- CVE-2025-38556
- Description:
HID: core: Harden s32ton() against conversion to 0 bits
- CVE: https://access.redhat.com/security/cve/CVE-2025-38556
- Patch: rhel7/3.10.0-1160.142.1.el7/CVE-2025-38556-core-Harden-s32ton-against-conversion-to-0-bits.patch
- From: kernel-3.10.0-1160.142.1.el7
- CVE-2023-53373
- Description:
crypto: seqiv - Handle EBUSY correctly
- CVE: https://access.redhat.com/security/cve/CVE-2023-53373
- Patch: rhel7/3.10.0-1160.142.1.el7/CVE-2023-53373-crypto-seqiv-handle-ebusy-correctly.patch
- From: kernel-3.10.0-1160.142.1.el7
- CVE-2025-22026
- Description:
Out of scope: not affected
- CVE:
- Patch: skipped/CVE-2025-22026.patch
- From:
- CVE-2025-39751
- Description:
This CVE has been rejected or withdrawn by its CVE Numbering Authority as per NVD website
- CVE:
- Patch: skipped/CVE-2025-39751.patch
- From:
- CVE-2022-48978
- Description:
HID: core: detect and skip invalid inputs to snto32()
- CVE: https://access.redhat.com/security/cve/CVE-2022-48978
- Patch: rhel7/3.10.0-1160.142.1.el7/CVE-2022-48978-HID-core-detect-and-skip-invalid-inputs-to-snto32.patch
- From: kernel-3.10.0-1160.142.1.el7
- CVE-2022-48978
- Description:
HID: core: fix shift-out-of-bounds in hid_report_raw_event
- CVE: https://access.redhat.com/security/cve/CVE-2022-48978
- Patch: rhel7/3.10.0-1160.142.1.el7/CVE-2022-48978-HID-core-fix-shift-out-of-bounds-in-hid_report_raw_event.patch
- From: kernel-3.10.0-1160.142.1.el7
- CVE-2022-3640
- Description:
Out of scope: not affected
- CVE:
- Patch: skipped/CVE-2022-3640.patch
- From:
- CVE-2023-53305 CVE-2022-50386
- Description:
Bluetooth: L2CAP: Fix use-after-free
- CVE: https://access.redhat.com/security/cve/CVE-2022-50386
- Patch: rhel7/3.10.0-1160.143.1.el7/CVE-2023-53305-bluetooth-l2cap-fix-use-after-free.patch
- From: kernel-3.10.0-1160.143.1.el7
- CVE-2022-50408
- Description:
wifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit()
- CVE: https://access.redhat.com/security/cve/CVE-2022-50408
- Patch: rhel7/3.10.0-1160.143.1.el7/CVE-2022-50408-wifi-brcmfmac-fix-use-after-free-bug-in-brcmf_netdev_start_xmit.patch
- From: kernel-3.10.0-1160.143.1.el7
- CVE-2025-38718
- Description:
sctp: linearize cloned gso packets in sctp_rcv
- CVE: https://access.redhat.com/security/cve/CVE-2025-38718
- Patch: rhel7/3.10.0-1160.143.1.el7/CVE-2025-38718-sctp-linearize-cloned-gso-packets-in-sctp_rcv.patch
- From: kernel-3.10.0-1160.143.1.el7
- CVE-2023-53365
- Description:
ip6mr: Fix skb_under_panic in ip6mr_cache_report()
- CVE: https://access.redhat.com/security/cve/CVE-2023-53365
- Patch: rhel7/3.10.0-1160.143.1.el7/CVE-2023-53365-ip6mr-Fix-skb_under_panic-in-ip6mr_cache_report.patch
- From: kernel-3.10.0-1160.143.1.el7
- CVE-2022-50341
- Description:
cifs: fix oops during encryption
- CVE: https://access.redhat.com/security/cve/CVE-2022-50341
- Patch: rhel7/3.10.0-1160.143.1.el7/CVE-2022-50341-cifs-fix-oops-during-encryption.patch
- From: kernel-3.10.0-1160.143.1.el7
- CVE-2022-50367
- Description:
fs: fix UAF/GPF bug in nilfs_mdt_destroy
- CVE: https://access.redhat.com/security/cve/CVE-2022-50367
- Patch: rhel7/3.10.0-1160.144.1.el7/CVE-2022-50367-fs-fix-uaf-gpf-bug-in-nilfs_mdt_destroy.patch
- From: kernel-3.10.0-1160.144.1.el7
- CVE-2022-50410
- Description:
NFSD: Protect against send buffer overflow in NFSv2 READ
- CVE: https://access.redhat.com/security/cve/CVE-2022-50410
- Patch: rhel7/3.10.0-1160.144.1.el7/CVE-2022-50410-nfsd-protect-against-send-buffer-overflow-in-nfsv2-read.patch
- From: kernel-3.10.0-1160.144.1.el7
- CVE-2022-50406
- Description:
Bug isn't present in RHEL7 kernel.
- CVE:
- Patch: skipped/CVE-2022-50406.patch
- From:
- CVE-2023-53322
- Description:
scsi: qla2xxx: Wait for io return on terminate rport
- CVE: https://access.redhat.com/security/cve/CVE-2023-53322
- Patch: rhel7/3.10.0-1160.144.1.el7/CVE-2023-53322-scsi-qla2xxx-wait-for-io-return-on-terminate-rport.patch
- From: kernel-3.10.0-1160.144.1.el7
- CVE-2025-39955
- Description:
tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect()
- CVE: https://access.redhat.com/security/cve/CVE-2025-39955
- Patch: rhel7/3.10.0-1160.144.1.el7/CVE-2025-39955-tcp-clear-tcp_sk-sk-fastopen_rsk-in-tcp_disconnect.patch
- From: kernel-3.10.0-1160.144.1.el7
- CVE-2023-53178
- Description:
mm: fix zswap writeback race condition
- CVE: https://access.redhat.com/security/cve/CVE-2023-53178
- Patch: rhel7/3.10.0-1160.144.1.el7/CVE-2023-53178-mm-fix-zswap-writeback-race-condition.patch
- From: kernel-3.10.0-1160.144.1.el7
- CVE-2025-38729
- Description:
ALSA: usb-audio: Validate UAC3 power domain descriptors, too
- CVE: https://access.redhat.com/security/cve/CVE-2025-38729
- Patch: rhel7/3.10.0-1160.144.1.el7/CVE-2025-38729-alsa-usb-audio-validate-uac3-power-domain-descriptors-too.patch
- From: kernel-3.10.0-1160.144.1.el7
- CVE-2025-38729
- Description:
ALSA: usb-audio: Validate UAC3 power domain descriptors, too
- CVE: https://access.redhat.com/security/cve/CVE-2025-38729
- Patch: rhel7/3.10.0-1160.144.1.el7/CVE-2025-38729-alsa-usb-audio-validate-uac3-power-domain-descriptors-too-kpatch.patch
- From: kernel-3.10.0-1160.144.1.el7
- CVE-2025-39757
- Description:
ALSA: usb-audio: Validate UAC3 cluster segment descriptors
- CVE: https://access.redhat.com/security/cve/CVE-2025-39757
- Patch: rhel7/3.10.0-1160.144.1.el7/CVE-2025-39757-alsa-usb-audio-validate-uac3-cluster-segment-descriptors.patch
- From: kernel-3.10.0-1160.144.1.el7
- CVE-2023-53297
- Description:
Bluetooth: L2CAP: fix bad unlock balance in l2cap_disconnect_rsp
- CVE: https://access.redhat.com/security/cve/CVE-2023-53297
- Patch: rhel7/3.10.0-1160.144.1.el7/CVE-2023-53297-bluetooth-l2cap-fix-bad-unlock-balance-in-l2cap_disconnect_rsp-21.patch
- From: kernel-3.10.0-1160.144.1.el7
- CVE-2022-50356
- Description:
net: sched: sfb: fix null pointer access issue when sfb_init() fails
- CVE: https://access.redhat.com/security/cve/CVE-2022-50356
- Patch: rhel7/3.10.0-1160.144.1.el7/CVE-2022-50356-net-sched-sfb-fix-null-pointer-access-issue-when-sfb_init-fails.patch
- From: kernel-3.10.0-1160.144.1.el7
- CVE-2022-50403
- Description:
ext4: fix undefined behavior in bit shift for ext4_check_flag_values
- CVE: https://access.redhat.com/security/cve/CVE-2022-50403
- Patch: rhel7/3.10.0-1160.144.1.el7/CVE-2022-50403-ext4-fix-undefined-behavior-in-bit-shift-for-ext4_check_flag_values.patch
- From: kernel-3.10.0-1160.144.1.el7
- CVE-2025-37823
- Description:
net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too
- CVE: https://access.redhat.com/security/cve/CVE-2025-37823
- Patch: rhel7/3.10.0-1160.145.1.el7/CVE-2025-37823-net_sched-hfsc-Fix-a-potential-UAF-in-hfsc_dequeue-too.patch
- From: 3.10.0-1160.145.1.el7
- CVE-2023-53705
- Description:
ipv6: Fix out-of-bounds access in ipv6_find_tlv()
- CVE: https://access.redhat.com/security/cve/CVE-2023-53705
- Patch: rhel7/3.10.0-1160.145.1.el7/CVE-2023-53705-ipv6-Fix-out-of-bounds-access-in-ipv6_find_tlv.patch
- From: 3.10.0-1160.145.1.el7
- CVE-2025-68285
- Description:
libceph: fix potential use-after-free in have_mon_and_osd_map()
- CVE: https://access.redhat.com/security/cve/CVE-2025-68285
- Patch: rhel7/3.10.0-1160.145.1.el7/CVE-2025-68285-libceph-fix-potential-use-after-free-in-have_mon_and_osd_map.patch
- From: 3.10.0-1160.145.1.el7
- CVE-2023-53675
- Description:
scsi: ses: Fix possible desc_ptr out-of-bounds accesses
- CVE: https://access.redhat.com/security/cve/CVE-2023-53675
- Patch: rhel7/3.10.0-1160.145.1.el7/CVE-2023-53675-scsi-ses-Fix-possible-desc_ptr-out-of-bounds-accesses.patch
- From: 3.10.0-1160.145.1.el7
- CVE-2025-39971
- Description:
i40e: fix idx validation in config queues msg
- CVE: https://access.redhat.com/security/cve/CVE-2025-39971
- Patch: rhel7/3.10.0-1160.146.1.el7/CVE-2025-39971-i40e-fix-idx-validation-in-config-queues-msg.patch
- From: 3.10.0-1160.146.1.el7
- CVE-2025-39898
- Description:
CVE rejected
- CVE:
- Patch: skipped/CVE-2025-39898.patch
- From:
- CVE-2025-40248
- Description:
vsock: Ignore signal/timeout on connect() if already established
- CVE: https://access.redhat.com/security/cve/CVE-2025-40248
- Patch: rhel7/3.10.0-1160.146.1.el7/CVE-2025-40248-vsock-ignore-signal-timeout-on-connect-if-already-established.patch
- From: 3.10.0-1160.146.1.el7
- N/A
- Description:
Restrict access to pagemap/kpageflags/kpagecount
- CVE: http://googleprojectzero.blogspot.ru/2015/03/exploiting-dram-rowhammer-bug-to-gain.html
- Patch: 3.10.0/proc-restrict-pagemap-access-1062.patch
- From: N/A
- CVE-2025-38459
- Description:
atm: clip: Fix infinite recursive call of clip_push().
- CVE: https://access.redhat.com/security/cve/CVE-2025-38459
- Patch: rhel7/3.10.0-1160.147.1.el7/CVE-2025-38459-atm-clip-Fix-infinite-recursive-call-of-clip_push.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2025-38415
- Description:
Squashfs: check return result of sb_min_blocksize
- CVE: https://access.redhat.com/security/cve/CVE-2025-38415
- Patch: rhel7/3.10.0-1160.147.1.el7/CVE-2025-38415-squashfs-check-return-result-of-sb_min_blocksize.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2025-38415
- Description:
squashfs: fix memory leak in squashfs_fill_super
- CVE: https://access.redhat.com/security/cve/CVE-2025-38415
- Patch: rhel7/3.10.0-1160.147.1.el7/CVE-2025-38415-squashfs-fix-memory-leak-in-squashfs_fill_super.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2025-38415
- Description:
Squashfs: check return result of sb_min_blocksize
- CVE: https://access.redhat.com/security/cve/CVE-2025-38415
- Patch: rhel7/3.10.0-1160.147.1.el7/CVE-2025-38415-squashfs-check-return-result-of-sb_min_blocksize-kpatch.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2025-68349
- Description:
NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid
- CVE: https://access.redhat.com/security/cve/CVE-2025-68349
- Patch: rhel7/3.10.0-1160.147.1.el7/CVE-2025-68349-nfsv4-pnfs-clear-nfs-ino-layoutcommit-in-pnfs-mark-layout-stateid-invalid.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2025-39817
- Description:
efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare
- CVE: https://access.redhat.com/security/cve/CVE-2025-39817
- Patch: rhel7/3.10.0-1160.147.1.el7/CVE-2025-39817-efivarfs-Fix-slab-out-of-bounds-in-efivarfs_d_compare.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2025-39760
- Description:
usb: core: config: Prevent OOB read in SS endpoint companion parsing
- CVE: https://access.redhat.com/security/cve/CVE-2025-39760
- Patch: rhel7/3.10.0-1160.147.1.el7/CVE-2025-39760-usb-core-config-prevent-oob-read-in-ss-endpoint-companion-parsing.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2026-23074
- Description:
net/sched: Enforce that teql can only be used as root qdisc
- CVE: https://access.redhat.com/security/cve/CVE-2026-23074
- Patch: rhel7/3.10.0-1160.147.1.el7/CVE-2026-23074-net-sched-Enforce-that-teql-can-only-be-used-as-root-qdisc.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2025-40271
- Description:
fs/proc: fix uaf in proc_readdir_de()
- CVE: https://access.redhat.com/security/cve/CVE-2025-40271
- Patch: rhel7/3.10.0-1160.147.1.el7/CVE-2025-40271-fs-proc-fix-uaf-in-proc-readdir-de.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2025-39993
- Description:
media: rc: fix races with imon_disconnect()
- CVE: https://access.redhat.com/security/cve/CVE-2025-39993
- Patch: rhel7/3.10.0-1160.147.1.el7/CVE-2025-39993-media-rc-fix-races-with-imon-disconnect-kpatch.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2022-50673
- Description:
ext4: allow ext4_truncate() to return an error
- CVE: https://access.redhat.com/security/cve/CVE-2022-50673
- Patch: rhel7/3.10.0-1160.147.1.el7/CVE-2022-50673-ext4-allow-ext4_truncate-to-return-an-error.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2022-50673
- Description:
ext4: lost matching-pair of trace in ext4_truncate
- CVE: https://access.redhat.com/security/cve/CVE-2022-50673
- Patch: rhel7/3.10.0-1160.147.1.el7/CVE-2022-50673-ext4-lost-matching-pair-of-trace-in-ext4_truncate.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2022-50673
- Description:
ext4: fix use-after-free in ext4_orphan_cleanup
- CVE: https://access.redhat.com/security/cve/CVE-2022-50673
- Patch: rhel7/3.10.0-1160.147.1.el7/CVE-2022-50673-ext4-fix-use-after-free-in-ext4_orphan_cleanup.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2026-23193
- Description:
scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count()
- CVE: https://access.redhat.com/security/cve/CVE-2026-23193
- Patch: rhel7/3.10.0-1160.148.1.el7/CVE-2026-23193-scsi-target-iscsi-fix-use-after-free-in-iscsit-dec-session-usage-count.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2026-23231
- Description:
netfilter: nf_tables: fix use-after-free in nf_tables_addchain()
- CVE: https://access.redhat.com/security/cve/CVE-2026-23231
- Patch: rhel7/3.10.0-1160.148.1.el7/CVE-2026-23231-netfilter-nf-tables-fix-use-after-free-in-nf-tables-addchain.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2025-38024
- Description:
RDMA/rxe: Fix slab-use-after-free Read in rxe_queue_cleanup bug
- CVE: https://access.redhat.com/security/cve/CVE-2025-38024
- Patch: rhel7/3.10.0-1160.148.1.el7/CVE-2025-38024-rdma-rxe-fix-slab-use-after-free-read-in-rxe-queue-cleanup-bug.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2025-38180
- Description:
Rolled back due to regression.
- CVE:
- Patch: skipped/CVE-2025-38180.patch
- From:
- CVE-2026-23216
- Description:
scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count()
- CVE: https://access.redhat.com/security/cve/CVE-2026-23216
- Patch: rhel7/3.10.0-1160.148.1.el7/CVE-2026-23216-scsi-target-iscsi-fix-use-after-free-in-iscsit-dec-conn-usage-count.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2025-71238
- Description:
scsi: qla2xxx: Fix bsg_done() causing double free
- CVE: https://access.redhat.com/security/cve/CVE-2025-71238
- Patch: rhel7/3.10.0-1160.148.1.el7/CVE-2025-71238-scsi-qla2xxx-fix-bsg-done-causing-double-free.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2026-23204
- Description:
net/sched: cls_u32: use skb_header_pointer_careful()
- CVE: https://access.redhat.com/security/cve/CVE-2026-23204
- Patch: rhel7/3.10.0-1160.148.1.el7/CVE-2026-23204-net-sched-cls-u32-use-skb-header-pointer-careful.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2022-50053
- Description:
iavf: Fix reset error handling
- CVE: https://access.redhat.com/security/cve/CVE-2022-50053
- Patch: rhel7/3.10.0-1160.148.1.el7/CVE-2022-50053-iavf-fix-reset-error-handling.patch
- From: 3.10.0-1160.147.1.el7
- CVE-2023-53539
- Description:
RDMA/rxe: Fix incomplete state save in rxe_requester
- CVE: https://access.redhat.com/security/cve/CVE-2023-53539
- Patch: rhel7/3.10.0-1160.148.1.el7/CVE-2023-53539-rdma-rxe-fix-incomplete-state-save-in-rxe-requester.patch
- From: 3.10.0-1160.147.1.el7