CLSA-2025-1757961506

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json
JSON Data
https://api.test.osv.dev/v1/vulns/CLSA-2025-1757961506
Upstream
Published
2025-09-15T18:38:29Z
Modified
2026-05-27T11:35:22.287841711Z
Summary
kernel: Fix of 26 CVEs
Details
  • posix-cpu-timers: fix race between handleposixcputimers() and posixcputimerdel() {CVE-2025-38352}
  • xfrm: state: fix out-of-bounds read during lookup {CVE-2024-57982}
  • nfsd: fix race between laundromat and free_stateid {CVE-2024-50106}
  • nfsd: split scstatus out of sctype {CVE-2024-50106}
  • nfsd: avoid race after unhashdelegationlocked() {CVE-2024-50106}
  • nfsd: don't call functions with side-effecting inside WARN_ON() {CVE-2024-50106}
  • can: peak_usb: fix use after free bugs {CVE-2021-47670}
  • wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds {CVE-2025-38159}
  • i2c/designware: Fix an initialization issue {CVE-2025-38380}
  • RDMA/rxe: Fix error unwind in rxecreateqp() {CVE-2022-50127}
  • i40e: fix MMIO write access to an invalid page in i40eclearhw {CVE-2025-38200}
  • udp: Fix memory accounting leak. {CVE-2025-22058}
  • Bluetooth: hcicore: Fix use-after-free in vhciflush() {CVE-2025-38250}
  • net_sched: ets: Fix double list add in class with netem as child qdisc {CVE-2025-38085}
  • mm/hugetlb: fix hugepmdunshare() vs GUP-fast race {CVE-2025-38085}
  • mm/khugepaged: fix GUP-fast interaction by sending IPI {CVE-2025-38085}
  • padata: fix UAF in padata_reorder {CVE-2025-21727}
  • net/sched: Always pass notifications when child class becomes empty {CVE-2025-38350}
  • codel: remove sch->q.qlen check before qdisctreereduce_backlog() {CVE-2025-38177}
  • schets: make estqlen_notify() idempotent {CVE-2025-38177}
  • schqfq: make qfqqlen_notify() idempotent {CVE-2025-38177}
  • schhfsc: make hfscqlen_notify() idempotent {CVE-2025-38177}
  • schdrr: make drrqlen_notify() idempotent {CVE-2025-38177}
  • schhtb: make htbqlen_notify() idempotent {CVE-2025-38177}
  • schhfsc: Fix qlen accounting bug when using peek in hfscenqueue() {CVE-2025-38000}
  • net/sched: schqfq: Fix race condition on qfqaggregate {CVE-2025-38477}
  • tipc: Fix use-after-free in tipcconnclose(). {CVE-2025-38464}
  • RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction {CVE-2025-38211}
  • scsi: lpfc: Use memcpy() for BIOS version {CVE-2025-38332}
  • netfilter: xtables: avoid NFPROTO_UNSPEC where needed {CVE-2024-50038}
  • netfilter: xtables: Add snapshot of hardidletimer target {CVE-2024-50038}
  • crypto: algifhash - fix double free in hashaccept {CVE-2025-38079}
  • ext4: avoid resizing to a partial cluster size {CVE-2022-50020}
  • net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc {CVE-2025-37890}
  • net: tipc: fix refcount warning in tipcaeadencrypt {CVE-2025-38273}
  • net/tipc: fix slab-use-after-free Read in tipcaeadencrypt_done {CVE-2025-38052}
  • memstick: rtsxusbms: Fix slab-use-after-free in rtsxusbmsdrvremove {CVE-2025-22020}
References

Affected packages

TuxCare:CentOS-Stream:8
bpftool

Package

Name
bpftool
Purl
pkg:rpm/tuxcare/bpftool?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel

Package

Name
kernel
Purl
pkg:rpm/tuxcare/kernel?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-core

Package

Name
kernel-core
Purl
pkg:rpm/tuxcare/kernel-core?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-cross-headers

Package

Name
kernel-cross-headers
Purl
pkg:rpm/tuxcare/kernel-cross-headers?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-debug

Package

Name
kernel-debug
Purl
pkg:rpm/tuxcare/kernel-debug?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-debug-core

Package

Name
kernel-debug-core
Purl
pkg:rpm/tuxcare/kernel-debug-core?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-debug-devel

Package

Name
kernel-debug-devel
Purl
pkg:rpm/tuxcare/kernel-debug-devel?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-debug-modules

Package

Name
kernel-debug-modules
Purl
pkg:rpm/tuxcare/kernel-debug-modules?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-debug-modules-extra

Package

Name
kernel-debug-modules-extra
Purl
pkg:rpm/tuxcare/kernel-debug-modules-extra?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-debug-modules-internal

Package

Name
kernel-debug-modules-internal
Purl
pkg:rpm/tuxcare/kernel-debug-modules-internal?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-devel

Package

Name
kernel-devel
Purl
pkg:rpm/tuxcare/kernel-devel?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-headers

Package

Name
kernel-headers
Purl
pkg:rpm/tuxcare/kernel-headers?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-ipaclones-internal

Package

Name
kernel-ipaclones-internal
Purl
pkg:rpm/tuxcare/kernel-ipaclones-internal?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-modules

Package

Name
kernel-modules
Purl
pkg:rpm/tuxcare/kernel-modules?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-modules-extra

Package

Name
kernel-modules-extra
Purl
pkg:rpm/tuxcare/kernel-modules-extra?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-modules-internal

Package

Name
kernel-modules-internal
Purl
pkg:rpm/tuxcare/kernel-modules-internal?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-selftests-internal

Package

Name
kernel-selftests-internal
Purl
pkg:rpm/tuxcare/kernel-selftests-internal?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-tools

Package

Name
kernel-tools
Purl
pkg:rpm/tuxcare/kernel-tools?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-tools-libs

Package

Name
kernel-tools-libs
Purl
pkg:rpm/tuxcare/kernel-tools-libs?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
kernel-tools-libs-devel

Package

Name
kernel-tools-libs-devel
Purl
pkg:rpm/tuxcare/kernel-tools-libs-devel?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
perf

Package

Name
perf
Purl
pkg:rpm/tuxcare/perf?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"
python3-perf

Package

Name
python3-perf
Purl
pkg:rpm/tuxcare/python3-perf?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-553.6.1.el8_10.tuxcare.els13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2025-1757961506.json"