{"id":"CLSA-2026-1778756832","summary":"kernel: Fix of 40 CVEs","details":"- fix: \"vsock: Ignore signal/timeout on connect() if already established {CVE-2025-40248}\"\n- gfs2: Fix possible data races in gfs2_show_options() {CVE-2023-53622}\n- ALSA: 6fire: fix use-after-free on disconnect {CVE-2026-31581}\n- nfnetlink_osf: validate individual option lengths in fingerprints {CVE-2026-23397}\n- netfilter: nfnetlink_osf: avoid OOB read {CVE-2026-23397}\n- Squashfs: check metadata block offset is within range {CVE-2026-23388}\n- scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() {CVE-2026-23216}\n- can: usb_8dev: usb_8dev_read_bulk_callback(): fix URB memory leak {CVE-2026-23108}\n- net/sched: qfq: Use cl_is_active to determine whether class is active in qfq_rm_from_ag {CVE-2026-23105}\n- ALSA: ctxfi: Fix potential OOB access in audio mixer handling {CVE-2026-23076}\n- net: usb: pegasus: fix memory leak in update_eth_regs_async() {CVE-2026-23021}\n- ipv4: ip_gre: make ipgre_header() robust {CVE-2026-23011}\n- libceph: make decode_pool() more resilient against corrupted osdmaps {CVE-2025-71116}\n- via_wdt: fix critical boot hang due to unnamed resource allocation {CVE-2025-71114}\n- hwmon: (w83791d) Convert macros to functions to avoid TOCTOU {CVE-2025-71111}\n- Bluetooth: btusb: revert use of devm_kzalloc in btusb {CVE-2025-71082}\n- Revert \"fbdev: bitblit: bound-check glyph index in bit_putcs* {CVE-2025-40322}\"\n- driver core: fix potential null-ptr-deref in device_add() {CVE-2023-54321}\n- btrfs: output extra debug info if we failed to find an inline backref {CVE-2023-53672}\n- ring-buffer: Fix deadloop issue on reading trace_pipe {CVE-2023-53668}\n- netfilter: conntrack: Avoid nf_ct_helper_hash uses after free {CVE-2023-53619}\n- ring-buffer: Sync IRQ works before buffer destruction {CVE-2023-53587}\n- net: usbnet: Fix WARNING in usbnet_start_xmit/usb_submit_urb {CVE-2023-53548}\n- udf: Do not bother merging very long extents {CVE-2023-53506}\n- lib: cpu_rmap: Fix potential use-after-free in irq_cpu_rmap_release(CVE-2023-53484)\n- lib: cpu_rmap: Avoid use after free on rmap-\u003eobj array entries {CVE-2023-53484}\n- ext4: remove a BUG_ON in ext4_mb_release_group_pa() {CVE-2023-53450}\n- md/raid10: fix wrong setting of max_corr_read_errors {CVE-2023-53313}\n- platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]() {CVE-2022-50521}\n- binfmt_misc: fix shift-out-of-bounds in check_special_flags {CVE-2022-50497}\n- ntb_netdev: Use dev_kfree_skb_any() in interrupt context {CVE-2022-50476}\n- i2c: ismt: use correct length when copy buffer {CVE-2022-50394}\n- misc: tifm: fix possible memory leak in tifm_7xx1_switch_media() {CVE-2022-50349}\n- ata: ahci: Match EM_MAX_SLOTS with SATA_PMP_MAX_PORTS {CVE-2022-50315}\n- ipv6: addrlabel: fix infoleak when sending struct ifaddrlblmsg to network {CVE-2022-49865}\n- KVM: x86/mmu: make apf token non-zero to fix bug {CVE-2022-48943}\n- kvm: avoid speculation-based attacks from out-of-range memslot accesses {CVE-2021-47277}\n- scsi: scsi_debug: Fix out-of-bound read in resp_report_tgtpgs() {CVE-2021-47219}\n- scsi: scsi_debug: Fix out-of-bound read in resp_readcap16() {CVE-2021-47191}\n- USB: core: Add routines for endpoint checks in old drivers\n- xen: sync some headers with xen tree\n- squashfs: fix memory leak in squashfs_fill_super {CVE-2025-38415}\n- pptp: fix pptp_xmit() error path {CVE-2025-38574}\n- Revert \"net/sched: sch_hfsc: Ensure inner classes have fsc curve\" {CVE-2023-4623}","modified":"2026-05-27T11:33:57.325675291Z","published":"2026-05-14T19:27:09Z","upstream":["CVE-2021-47191","CVE-2021-47219","CVE-2021-47277","CVE-2022-48943","CVE-2022-49865","CVE-2022-50315","CVE-2022-50349","CVE-2022-50394","CVE-2022-50476","CVE-2022-50497","CVE-2022-50521","CVE-2023-4623","CVE-2023-53313","CVE-2023-53450","CVE-2023-53484","CVE-2023-53506","CVE-2023-53548","CVE-2023-53587","CVE-2023-53619","CVE-2023-53622","CVE-2023-53668","CVE-2023-53672","CVE-2023-54321","CVE-2025-38415","CVE-2025-38574","CVE-2025-40248","CVE-2025-40322","CVE-2025-71082","CVE-2025-71111","CVE-2025-71114","CVE-2025-71116","CVE-2026-23011","CVE-2026-23021","CVE-2026-23076","CVE-2026-23105","CVE-2026-23108","CVE-2026-23216","CVE-2026-23388","CVE-2026-23397","CVE-2026-31581"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/centos7els/CLSA-2026-1778756832.html"}],"affected":[{"package":{"name":"bpftool","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/bpftool?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.0-1160.144.1.el7.tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1778756832.json"}},{"package":{"name":"kernel","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/kernel?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.0-1160.144.1.el7.tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1778756832.json"}},{"package":{"name":"kernel-debug","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/kernel-debug?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.0-1160.144.1.el7.tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1778756832.json"}},{"package":{"name":"kernel-debug-devel","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/kernel-debug-devel?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.0-1160.144.1.el7.tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1778756832.json"}},{"package":{"name":"kernel-devel","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/kernel-devel?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.0-1160.144.1.el7.tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1778756832.json"}},{"package":{"name":"kernel-headers","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/kernel-headers?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.0-1160.144.1.el7.tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1778756832.json"}},{"package":{"name":"kernel-tools","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/kernel-tools?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.0-1160.144.1.el7.tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1778756832.json"}},{"package":{"name":"kernel-tools-libs","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/kernel-tools-libs?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.0-1160.144.1.el7.tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1778756832.json"}},{"package":{"name":"kernel-tools-libs-devel","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/kernel-tools-libs-devel?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.0-1160.144.1.el7.tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1778756832.json"}},{"package":{"name":"perf","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/perf?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.0-1160.144.1.el7.tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1778756832.json"}},{"package":{"name":"python-perf","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/python-perf?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.0-1160.144.1.el7.tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1778756832.json"}}],"schema_version":"1.7.5"}