­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ OS: almalinux8 kernel: kernel-4.18.0-553.8.1.el8_10 time: 2026-07-22 20:21:08 kpatch-name: skipped/CVE-2024-26921.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-26921 kpatch-skip-reason: Live-patching will introduce network performance degradation in the best case scenario, or even some more serious issues. N/A or Low cvss3 score from NVD or vendors. kpatch-cvss: kpatch-name: skipped/CVE-2023-52451.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2023-52451 kpatch-skip-reason: Out of scope as the patch is for powerpc arch only, x86_64 is not affected kpatch-cvss: kpatch-name: skipped/CVE-2023-28746.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2023-28746 kpatch-skip-reason: RFDS: Medium score vulnerability affecting only Intel Atom CPUs, mitigated via microcode update. kpatch-cvss: kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52469-drivers-amd-pm-fix-a-use-after-free-in-kv_parse_powe.patch kpatch-description: drivers/amd/pm: fix a use-after-free in kv_parse_power_table kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52469 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52469 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=28dd788382c43b330480f57cd34cde0840896743 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36971-net-fix-__dst_negative_advice-race.patch kpatch-description: net: fix __dst_negative_advice() race kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36971 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36971 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=92f1655aa2b2294d0b49925f3b875a634bd3b59e kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52530-wifi-mac80211-fix-potential-key-use-after-free.patch kpatch-description: wifi: mac80211: fix potential key use-after-free kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52530 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52530 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=31db78a4923ef5e2008f2eed321811ca79e7f71b kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26852-net-ipv6-avoid-possible-UAF-in-ip6_route_mpath_notif.patch kpatch-description: net/ipv6: avoid possible UAF in ip6_route_mpath_notify() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26852 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26852 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=685f7d531264599b3f167f1e94bbd22f120e5fab kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26925-netfilter-nf_tables-release-mutex-after-nft_gc_seq_e.patch kpatch-description: netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26925 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26925 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=0d459e2ffb541841714839e8228b845458ed3b27 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-27020-netfilter-nf_tables-Fix-potential-data-race-in-__nft.patch kpatch-description: netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-27020 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27020 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f969eb84ce482331a991079ab7a5c4dc3b7f89bf kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26586-mlxsw-spectrum_acl_tcam-Fix-stack-corruption.patch kpatch-description: mlxsw: spectrum_acl_tcam: Fix stack corruption kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26586 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26586 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=483ae90d8f976f8339cf81066312e1329f2d3706 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52756-pwm-fix-double-shift-bug.patch kpatch-description: pwm: Fix double shift bug kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52756 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52756 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=d27abbfd4888d79dd24baf50e774631046ac4732 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52679-of-fix-double-free-in-of_parse_phandle_with_args_map.patch kpatch-description: of: Fix double free in of_parse_phandle_with_args_map kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52679 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52679 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=4dde83569832f9377362e50f7748463340c5db6b kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52730-mmc-sdio-fix-possible-resource-leaks-in-some-error-paths.patch kpatch-description: mmc: sdio: fix possible resource leaks in some error paths kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52730 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52730 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=605d9fb9556f8f5fb4566f4df1480f280f308ded kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52784-bonding-stop-the-device-in-bond-setup-by-slave.patch kpatch-description: bonding: stop the device in bond_setup_by_slave() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52784 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52784 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3cffa2ddc4d3fcf70cde361236f5a614f81a09b2 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52658-revert-net-mlx5-block-entering-switchdev-mode.patch kpatch-description: Revert "net/mlx5: Block entering switchdev mode with ns inconsistency" kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52658 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52658 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=8deeefb24786ea7950b37bde4516b286c877db00 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52658-revert-net-mlx5-block-entering-switchdev-mode-kpatch.patch kpatch-description: Revert "net/mlx5: Block entering switchdev mode with ns inconsistency" kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52658 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52658 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=8deeefb24786ea7950b37bde4516b286c877db00 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52775-net-smc-avoid-data-corruption-caused-by-decline.patch kpatch-description: net/smc: avoid data corruption caused by decline kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52775 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52775 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e6d71b437abc2f249e3b6a1ae1a7228e09c6e563 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52662-drm-vmwgfx-fix-a-memleak-in-vmw-gmrid-man-get-node.patch kpatch-description: drm/vmwgfx: fix a memleak in vmw_gmrid_man_get_node kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52662 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52662 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=89709105a6091948ffb6ec2427954cbfe45358ce kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52764-media-gspca-cpia1-shift-out-of-bounds-in-set_flicker.patch kpatch-description: media: gspca: cpia1: shift-out-of-bounds in set_flicker kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52764 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52764 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=099be1822d1f095433f4b08af9cc9d6308ec1953 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52707-00-wait-add-wake_up_pollfree.patch kpatch-description: wait: add wake_up_pollfree() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52707 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52707 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=42288cb44c4b5fff7653bc392b583a2b8bd6a8c0 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52707-01-sched-psi-fix-use-after-free-in-ep_remove_wait_queue.patch kpatch-description: sched/psi: Fix use-after-free in ep_remove_wait_queue() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52707 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52707 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c2dbe32d5db5c4ead121cf86dabd5ab691fb47fe kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52762-virtio-blk-fix-implicit-overflow-on-virtio_max_dma_size.patch kpatch-description: virtio-blk: fix implicit overflow on virtio_max_dma_size kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52762 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52762 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=fafb51a67fb883eb2dde352539df939a251851be kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2021-46939-tracing-restructure-trace-clock-global-to-never.patch kpatch-description: tracing: Restructure trace_clock_global() to never kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2021-46939 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-46939 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=aafe104aa9096827a429bc1358f8260ee565b7cc kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2021-46939-tracing-do-no-increment-trace-clock-global-by.patch kpatch-description: tracing: Do no increment trace_clock_global() by kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2021-46939 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-46939 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=aafe104aa9096827a429bc1358f8260ee565b7cc kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2021-47257-net-ieee802154-fix-null-deref-in-parse-dev-addr.patch kpatch-description: net: ieee802154: fix null deref in parse dev addr kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2021-47257 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47257 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9fdd04918a452980631ecc499317881c1d120b70 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2021-47284-isdn-misdn-netjet-fix-crash-in-nj-probe.patch kpatch-description: isdn: mISDN: netjet: Fix crash in nj_probe: kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2021-47284 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47284 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9f6f852550d0e1b7735651228116ae9d300f69b3 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52777-wifi-ath11k-fix-gtk-offload-status-event-locking.patch kpatch-description: wifi: ath11k: fix gtk offload status event locking kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52777 kpatch-cvss: 5.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52777 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=1dea3c0720a146bd7193969f2847ccfed5be2221 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52847-media-bttv-fix-use-after-free-error-due-to.patch kpatch-description: media: bttv: fix use after free error due to kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52847 kpatch-cvss: 5.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52847 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=bd5b50b329e850d467e7bcc07b2b6bde3752fbda kpatch-name: skipped/CVE-2024-26843.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-26843 kpatch-skip-reason: EFI Firmware: CVE patch is for EFI firmware which runs at boot time. kpatch-cvss: kpatch-name: skipped/CVE-2024-35910.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-35910 kpatch-skip-reason: tcp_close is sleepable and called from kthread, which may prevent patching and unpatchng. kpatch-cvss: kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35937-wifi-cfg80211-check-a-msdu-format-more-carefully.patch kpatch-description: wifi: cfg80211: check A-MSDU format more carefully kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35937 kpatch-cvss: 5.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35937 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9ad7974856926129f190ffbe3beea78460b3b7cc kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2021-47373-irqchip-gic-v3-its-Fix-potential-VPE-leak-on-error.patch kpatch-description: irqchip/gic-v3-its: Fix potential VPE leak on error kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2021-47373 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47373 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=280bef512933b2dda01d681d8cbe499b98fc5bdd kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2021-47468-isdn-mISDN-Fix-sleeping-function-called-from-invalid.patch kpatch-description: isdn: mISDN: Fix sleeping function called from invalid context kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2021-47468 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47468 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=6510e80a0b81b5d814e3aea6297ba42f5e76f73c kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2021-47548-ethernet-hisilicon-hns-hns_dsaf_misc-fix-a-possible-.patch kpatch-description: ethernet: hisilicon: hns: hns_dsaf_misc: fix a possible array overflow in hns_dsaf_ge_srst_by_port() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2021-47548 kpatch-cvss: 6.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47548 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=a66998e0fbf213d47d02813b9679426129d0d114 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2021-47579-ovl-fix-warning-in-ovl_create_real.patch kpatch-description: ovl: fix warning in ovl_create_real() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2021-47579 kpatch-cvss: 4.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47579 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=1f5573cfe7a7056e80a92c7a037a3e69f3a13d1c kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2021-47304-tcp-fix-tcp_init_transfer-to-not-reset-icsk_ca_initi.patch kpatch-description: tcp: fix tcp_init_transfer() to not reset icsk_ca_initialized kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2021-47304 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47304 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=be5d1b61a2ad28c7e57fe8bfa277373e8ecffcdc kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2021-47408-netfilter-conntrack-serialize-hash-resizes-and-clean.patch kpatch-description: netfilter: conntrack: serialize hash resizes and cleanups kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2021-47408 kpatch-cvss: 4.7 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47408 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=e9edc188fc76499b0b9bd60364084037f6d03773 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2021-47461-userfaultfd-fix-a-race-between-writeprotect-and-exit.patch kpatch-description: userfaultfd: fix a race between writeprotect and exit_mmap() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2021-47461 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47461 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=cb185d5f1ebf900f4ae3bf84cee212e6dd035aca kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2021-47491-mm-khugepaged-skip-huge-page-collapse-for-special-fi.patch kpatch-description: mm: khugepaged: skip huge page collapse for special files kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2021-47491 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47491 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=a4aeaa06d45e90f9b279f0b09de84bd00006e733 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2021-47624-net-sunrpc-fix-reference-count-leaks-in-rpc_sysfs_xp.patch kpatch-description: net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2021-47624 kpatch-cvss: 6.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47624 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=776d794f28c95051bc70405a7b1fa40115658a18 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2022-48632-i2c-mlxbf-prevent-stack-overflow-in-mlxbf_i2c_smbus_.patch kpatch-description: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2022-48632 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-48632 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=de24aceb07d426b6f1c59f33889d6a964770547b kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-27011-netfilter-nf-tables-fix-memleak-in-map-from-abort.patch kpatch-description: netfilter: nf_tables: fix memleak in map from abort kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-27011 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27011 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=86a1471d7cde792941109b93b558b5dc078b9ee9 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-27019-netfilter-nf-tables-fix-potential-data-race-in.patch kpatch-description: netfilter: nf_tables: Fix potential data-race in kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-27019 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27019 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=d78d867dcea69c328db30df665be5be7d0148484 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-27025-nbd-null-check-for-nla-nest-start.patch kpatch-description: nbd: null check for nla_nest_start kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-27025 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27025 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6d kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-27065-netfilter-nf-tables-do-not-compare-internal-table.patch kpatch-description: netfilter: nf_tables: do not compare internal table kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-27065 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27065 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=4a0e7f2decbf9bd72461226f1f5f7dcc4b08f139 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-27388-sunrpc-fix-some-memleaks-in-gssx-dec-option-array.patch kpatch-description: SUNRPC: fix some memleaks in gssx_dec_option_array kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-27388 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27388 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3cfcfc102a5e57b021b786a755a38935e357797d kpatch-name: skipped/CVE-2024-27395.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-27395 kpatch-skip-reason: Fixed function is sleepy and called from a kthread, which may prevent patching/unpatching. kpatch-cvss: kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-27434-wifi-iwlwifi-mvm-fix-key-flags-for-igtk-on-ap.patch kpatch-description: wifi: iwlwifi: mvm: Fix key flags for IGTK on AP kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-27434 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27434 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e35f316bce9e5733c9826120c1838f4c447b2c4c kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-27434-wifi-iwlwifi-mvm-don-t-set-the-mfp-flag-for-the.patch kpatch-description: wifi: iwlwifi: mvm: don't set the MFP flag for the kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-27434 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27434 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e35f316bce9e5733c9826120c1838f4c447b2c4c kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-31076-genirq-cpuhotplug-x86-vector-prevent-vector-leak.patch kpatch-description: genirq/cpuhotplug, x86/vector: Prevent vector leak kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-31076 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-31076 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a6c11c0a5235fb144a65e0cb2ffd360ddc1f6c32 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-33621-ipvlan-dont-use-skb-sk-in.patch kpatch-description: ipvlan: Dont Use skb->sk in kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-33621 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-33621 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=b3dc6e8003b500861fa307e9a3400c52e78e4d3a kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35824-misc-lis3lv02d-i2c-fix-regulators-getting.patch kpatch-description: misc: lis3lv02d_i2c: Fix regulators getting kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35824 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35824 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=ac3e0384073b2408d6cb0d972fee9fcc3776053d kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35823-vt-fix-unicode-buffer-corruption-when-deleting.patch kpatch-description: vt: fix unicode buffer corruption when deleting kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35823 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35823 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=1581dafaf0d34bc9c428a794a22110d7046d186d kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35847-irqchip-gic-v3-its-prevent-double-free-on-error.patch kpatch-description: irqchip/gic-v3-its: Prevent double free on error kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35847 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35847 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c26591afd33adce296c022e3480dea4282b7ef91 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35893-net-sched-act-skbmod-prevent-kernel-infoleak.patch kpatch-description: net/sched: act_skbmod: prevent kernel-infoleak kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35893 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35893 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=d313eb8b77557a6d5855f42d2234bd592c7b50dd kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35801-x86-fpu-keep-xfd-state-in-sync-with-msr-ia32-xfd.patch kpatch-description: x86/fpu: Keep xfd_state in sync with MSR_IA32_XFD kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35801 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35801 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=10e4b5166df9ff7a2d5316138ca668b42d004422 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35807-ext4-fix-corruption-during-on-line-resize.patch kpatch-description: ext4: fix corruption during on-line resize kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35807 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35807 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a6b3bfe176e8a5b05ec4447404e412c2a3fc92cc kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35897-netfilter-nf_tables-reject-table-flag-and-netdev-bas.patch kpatch-description: netfilter: nf_tables: reject table flag and netdev basechain updates kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35897 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35897 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=1e1fb6f00f52812277963365d9bd835b9b0ea4e0 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35897-netfilter-nf-tables-discard-table-flag-update.patch kpatch-description: netfilter: nf_tables: discard table flag update kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35897 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35897 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=1bc83a019bbe268be3526406245ec28c2458a518 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35896-netfilter-validate-user-input-for-expected-length.patch kpatch-description: netfilter: validate user input for expected length kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35896 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35896 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=0c83842df40f86e529db6842231154772c20edcc kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35810-drm-vmwgfx-fix-the-lifetime-of-the-bo-cursor.patch kpatch-description: drm/vmwgfx: Fix the lifetime of the bo cursor kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35810 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35810 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9a9e8a7159ca09af9b1a300a6c8e8b6ff7501c76 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35925-block-prevent-division-by-zero-in.patch kpatch-description: block: prevent division by zero in blk_rq_stat_sum() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35925 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35925 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=93f52fbeaf4b676b21acfe42a5152620e6770d02 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35930-scsi-lpfc-fix-possible-memory-leak-in.patch kpatch-description: scsi: lpfc: Fix possible memory leak in lpfc_rcv_padisc() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35930 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35930 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2ae917d4bcab80ab304b774d492e2fcd6c52c06b kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35947-dyndbg-fix-old-bug-on-in-control-parser.patch kpatch-description: dyndbg: fix old BUG_ON in >control parser kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35947 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35947 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=00e7d3bea2ce7dac7bee1cf501fb071fd0ea8f6c kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35952-drm-ast-fix-soft-lockup.patch kpatch-description: drm/ast: Fix soft lockup kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35952 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35952 kpatch-patch-url: https://github.com/torvalds/linux/commit/bc004f5038220b1891ef4107134ccae44be55109 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35924-usb-typec-ucsi-limit-read-size-on-v1-2.patch kpatch-description: usb: typec: ucsi: Limit read size on v1.2 kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35924 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35924 kpatch-patch-url: https://github.com/torvalds/linux/commit/b3db266fb031fba88c423d4bb8983a73a3db6527 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35912-wifi-iwlwifi-mvm-rfi-fix-potential-response.patch kpatch-description: wifi: iwlwifi: mvm: rfi: fix potential response leaks kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35912 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35912 kpatch-patch-url: https://github.com/torvalds/linux/commit/06a093807eb7b5c5b29b6cff49f8174a4e702341 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35946-wifi-rtw89-fix-null-pointer-access-when-abort.patch kpatch-description: wifi: rtw89: fix null pointer access when abort scan kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35946 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35946 kpatch-patch-url: https://github.com/torvalds/linux/commit/7e11a2966f51695c0af0b1f976a32d64dee243b2 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35899-netfilter-nf-tables-flush-pending-destroy-work.patch kpatch-description: netfilter: nf_tables: flush pending destroy work before exit_net release kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35899 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35899 kpatch-patch-url: https://github.com/torvalds/linux/commit/24cea9677025e0de419989ecb692acd4bb34cac2 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35900-netfilter-nf-tables-reject-new-basechain-after.patch kpatch-description: netfilter: nf_tables: reject new basechain after table flag update kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35900 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35900 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=994209ddf4f430946f6247616b2e33d179243769 kpatch-name: skipped/CVE-2024-35938.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-35938 kpatch-skip-reason: wifi:ath11k, low score CVE that needs complex adaptation but decreasing MHI Bus' buf-len isn't a typical security fix. kpatch-cvss: kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52653-sunrpc-fix-a-memleak-in-gss-import-v2-context.patch kpatch-description: SUNRPC: fix a memleak in gss_import_v2_context kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52653 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52653 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e67b652d8e8591d3b1e569dbcdfcee15993e91fa kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2022-48743-net-amd-xgbe-fix-skb-data-length-underflow.patch kpatch-description: net: amd-xgbe: Fix skb data length underflow kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2022-48743 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-48743 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5aac9108a180fc06e28d4e7fb00247ce603b72ee kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2022-48747-block-fix-wrong-offset-in-bio-truncate.patch kpatch-description: block: Fix wrong offset in bio_truncate() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2022-48747 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-48747 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3ee859e384d453d6ac68bfd5971f630d9fa46ad3 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2022-48757-net-fix-information-leakage-in-proc-net-ptype.patch kpatch-description: net: fix information leakage in /proc/net/ptype kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2022-48757 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-48757 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=47934e06b65637c88a762d9c98329ae6e3238888 kpatch-name: skipped/CVE-2023-52463.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2023-52463 kpatch-skip-reason: Complex adaptation required. Issue can be reproduced with special UEFI implementation only. kpatch-cvss: kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52471-ice-fix-some-null-pointer-dereference-issues-in.patch kpatch-description: ice: Fix some null pointer dereference issues in kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52471 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52471 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3027e7b15b02d2d37e3f82d6b8404f6d37e3b8cf kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52619-pstore-ram-fix-crash-when-setting-number-of-cpus.patch kpatch-description: pstore/ram: Fix crash when setting number of cpus kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52619 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52619 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=d49270a04623ce3c0afddbf3e984cb245aa48e9c kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52623-sunrpc-fix-a-suspicious-rcu-usage-warning.patch kpatch-description: SUNRPC: Fix a suspicious RCU usage warning kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52623 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52623 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=31b62908693c90d4d07db597e685d9f25a120073 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52648-drm-vmwgfx-unmap-the-surface-before-resetting-it.patch kpatch-description: drm/vmwgfx: Unmap the surface before resetting it kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52648 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52648 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=27571c64f1855881753e6f33c3186573afbab7ba kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35814-swiotlb-Fix-double-allocation-of-slots-due-to-broken.patch kpatch-description: swiotlb: Fix double-allocation of slots due to broken alignment handling kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35814 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35814 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=04867a7a33324c9c562ee7949dbcaab7aaad1fb4 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26837-net-bridge-switchdev-skip-mdb-replays-of.patch kpatch-description: net: bridge: switchdev: Skip MDB replays of kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26837 kpatch-cvss: 5.5 kpatch-cve-url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-26837 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=dc489f86257cab5056e747344f17a164f63bff4b kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26840-cachefiles-fix-memory-leak-in-cachefiles_add_cache.patch kpatch-description: cachefiles: fix memory leak in kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26840 kpatch-cvss: 5.5 kpatch-cve-url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-26840 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e21a2f17566cbd64926fb8f16323972f7a064444 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26870-nfsv4-2-fix-nfs4-listxattr-kernel-bug-at.patch kpatch-description: NFSv4.2: fix nfs4_listxattr kernel BUG at kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26870 kpatch-cvss: 5.5 kpatch-cve-url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-26870 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=251a658bbfceafb4d58c76b77682c8bf7bcfad65 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26878-quota-fix-potential-null-pointer-dereference.patch kpatch-description: quota: Fix potential NULL pointer dereference kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26878 kpatch-cvss: 5.5 kpatch-cve-url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-26878 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=d0aa72604fbd80c8aabb46eda00535ed35570f1f kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26940-drm-vmwgfx-create-debugfs-ttm-resource-manager.patch kpatch-description: drm/vmwgfx: Create debugfs ttm_resource_manager kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26940 kpatch-cvss: 5.5 kpatch-cve-url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-26940 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=4be9075fec0a639384ed19975634b662bfab938f kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26958-nfs-fix-uaf-in-direct-writes.patch kpatch-description: nfs: fix UAF in direct writes kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26958 kpatch-cvss: 5.5 kpatch-cve-url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-26958 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=17f46b803d4f23c66cacce81db35fef3adb8f2af kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36000-mm-hugetlb-fix-missing-hugetlb-lock-for-resv.patch kpatch-description: mm/hugetlb: fix missing hugetlb_lock for resv kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36000 kpatch-cvss: 5.5 kpatch-cve-url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-36000 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=b76b46902c2d0395488c8412e1116c2486cdfcb2 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36005-netfilter-nf-tables-honor-table-dormant-flag-from.patch kpatch-description: netfilter: nf_tables: honor table dormant flag from kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36005 kpatch-cvss: 5.5 kpatch-cve-url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-36005 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=8e30abc9ace4f0add4cd761dfdbfaebae5632dd2 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36006-mlxsw-spectrum-acl-tcam-fix-incorrect-list-api.patch kpatch-description: mlxsw: spectrum_acl_tcam: Fix incorrect list API kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36006 kpatch-cvss: 5.5 kpatch-cve-url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-36006 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=b377add0f0117409c418ddd6504bd682ebe0bf79 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36017-rtnetlink-correct-nested-ifla-vf-vlan-list.patch kpatch-description: rtnetlink: Correct nested IFLA_VF_VLAN_LIST kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36017 kpatch-cvss: 5.5 kpatch-cve-url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-36017 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=1aec77b2bb2ed1db0f5efc61c4c1ca3813307489 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36020-i40e-fix-vf-may-be-used-uninitialized-in-this.patch kpatch-description: i40e: fix vf may be used uninitialized in this kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36020 kpatch-cvss: 5.5 kpatch-cve-url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-36020 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f37c4eac99c258111d414d31b740437e1925b8e8 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36025-scsi-qla2xxx-fix-off-by-one-in.patch kpatch-description: scsi: qla2xxx: Fix off by one in kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36025 kpatch-cvss: 5.5 kpatch-cve-url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-36025 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=4406e4176f47177f5e51b4cc7e6a7a2ff3dbfbbd kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36270-netfilter-tproxy-bail-out-if-ip-has-been-disabled.patch kpatch-description: netfilter: tproxy: bail out if IP has been disabled kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36270 kpatch-cvss: 5.5 kpatch-cve-url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-36270 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=21a673bddc8fd4873c370caf9ae70ffc6d47e8d3 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36286-netfilter-nfnetlink-queue-acquire-rcu-read-lock.patch kpatch-description: netfilter: nfnetlink_queue: acquire rcu_read_lock() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36286 kpatch-cvss: 5.5 kpatch-cve-url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-36286 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=dc21c6cc3d6986d938efbf95de62473982c98dec kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26660-drm-amd-display-implement-bounds-check-for-stream.patch kpatch-description: drm/amd/display: Implement bounds check for stream encoder creation in DCN301 kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26660 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26660 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=58fca355ad37dcb5f785d9095db5f748b79c5dc2 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26686-exit-use-the-correct-exit-code-in-proc-pid-stat.patch kpatch-description: exit: Use the correct exit_code in /proc//stat kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26686 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26686 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=7601df8031fd67310af891897ef6cc0df4209305 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26686-fs-proc-do-task-stat-use-for-each-thread.patch kpatch-description: fs/proc: do_task_stat: use __for_each_thread() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26686 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26686 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=7601df8031fd67310af891897ef6cc0df4209305 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26686-fs-proc-do-task-stat-move.patch kpatch-description: fs/proc: do_task_stat: move kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26686 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26686 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=7601df8031fd67310af891897ef6cc0df4209305 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26686-fs-proc-do-task-stat-use-sig-stats-lock-to.patch kpatch-description: fs/proc: do_task_stat: use sig->stats_lock to kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26686 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26686 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=7601df8031fd67310af891897ef6cc0df4209305 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26698-hv_netvsc-Fix-race-condition-between-netvsc_probe-an.patch kpatch-description: hv_netvsc: Fix race condition between netvsc_probe and netvsc_remove kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26698 kpatch-cvss: 4.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26698 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e0526ec5360a48ad3ab2e26e802b0532302a7e11 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26704-ext4-fix-double-free-of-blocks-due-to-wrong.patch kpatch-description: ext4: fix double-free of blocks due to wrong kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26704 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26704 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=55583e899a5357308274601364741a83e78d6ac4 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26733-arp-prevent-overflow-in-arp-req-get.patch kpatch-description: arp: Prevent overflow in arp_req_get(). kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26733 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26733 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a7d6027790acea24446ddd6632d394096c0f4667 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26740-net-sched-act-mirred-use-the-backlog-for-mirred.patch kpatch-description: net/sched: act_mirred: use the backlog for mirred ingress kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26740 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26740 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=52f671db18823089a02f07efc04efdb2272ddc17 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26772-ext4-avoid-allocating-blocks-from-corrupted-group.patch kpatch-description: ext4: avoid allocating blocks from corrupted group in ext4_mb_find_by_goal() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26772 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26772 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=832698373a25950942c04a512daa652c18a9b513 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26773-ext4-avoid-allocating-blocks-from-corrupted-group-in.patch kpatch-description: ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26773 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26773 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=4530b3660d396a646aad91a787b6ab37cf604b53 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26802-stmmac-clear-variable-when-destroying-workqueue.patch kpatch-description: stmmac: Clear variable when destroying workqueue kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26802 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26802 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=8af411bbba1f457c33734795f024d0ef26d0963f kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-21823-vfio-add-the-spr-dsa-and-spr-iax-devices-to-the.patch kpatch-description: VFIO: Add the SPR_DSA and SPR_IAX devices to the kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-21823 kpatch-cvss: 7.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-21823 kpatch-patch-url: https://github.com/torvalds/linux/commit/796aec4a5b5850967af0c42d4e84df2d748d570b.patch kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36016-tty-n-gsm-fix-possible-out-of-bounds-in.patch kpatch-description: tty: n_gsm: fix possible out-of-bounds in gsm0_receive() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36016 kpatch-cvss: 6.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36016 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=47388e807f85948eefc403a8a5fdc5b406a65d5a kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36896-usb-core-fix-access-violation-during-port-device.patch kpatch-description: USB: core: Fix access violation during port device removal kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36896 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36896 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a4b46d450c49f32e9d4247b421e58083fde304ce kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-38573-cppc-cpufreq-fix-possible-null-pointer-dereference.patch kpatch-description: cppc_cpufreq: Fix possible null pointer dereference kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-38573 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38573 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=cf7de25878a1f4508c69dc9f6819c21ba177dbfe kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36886-tipc-fix-uaf-in-error-path.patch kpatch-description: tipc: fix UAF in error path kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36886 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36886 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=080cbb890286cd794f1ee788bbc5463e2deb7c2b kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52791-i2c-core-fix-atomic-xfer-check-for-non-preempt.patch kpatch-description: i2c: core: Fix atomic xfer check for non-preempt kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52791 kpatch-cvss: 5.5 kpatch-cve-url: https://www.cve.org/CVERecord?id=CVE-2023-52791 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=aa49c90894d06e18a1ee7c095edbd2f37c232d02 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52832-wifi-mac80211-don-t-return-unset-power-in.patch kpatch-description: wifi: mac80211: don't return unset power in ieee80211_get_tx_power() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52832 kpatch-cvss: 5.5 kpatch-cve-url: https://www.cve.org/CVERecord?id=CVE-2023-52832 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e160ab85166e77347d0cbe5149045cb25e83937f kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52864-platform-x86-wmi-fix-opening-of-char-device.patch kpatch-description: platform/x86: wmi: Fix opening of char device kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52864 kpatch-cvss: 5.5 kpatch-cve-url: https://www.cve.org/CVERecord?id=CVE-2023-52864 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=eba9ac7abab91c8f6d351460239108bef5e7a0b6 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-25739-ubi-check-for-too-small-leb-size-in-vtbl-code.patch kpatch-description: ubi: Check for too small LEB size in VTBL code kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-25739 kpatch-cvss: 5.5 kpatch-cve-url: https://www.cve.org/CVERecord?id=CVE-2024-25739 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=68a24aba7c593eafa8fd00f2f76407b9b32b47a9 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26640-tcp-add-sanity-checks-to-rx-zerocopy.patch kpatch-description: tcp: add sanity checks to rx zerocopy kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26640 kpatch-cvss: 5.5 kpatch-cve-url: https://www.cve.org/CVERecord?id=CVE-CVE-2024-26640 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=577e4432f3ac810049cb7e6b71f4d96ec7c6e894 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52796-ipvlan-add-ipvlan-route-v6-outbound-helper.patch kpatch-description: ipvlan: add ipvlan_route_v6_outbound() helper kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52796 kpatch-cvss: 5.5 kpatch-cve-url: https://www.cve.org/CVERecord?id=CVE-2023-52796 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=18f039428c7df183b09c69ebf10ffd4e521035d2 kpatch-name: skipped/CVE-2023-52811.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2023-52811 kpatch-skip-reason: PowerPC: Unsupported. kpatch-cvss: kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52622-ext4-avoid-online-resizing-failures-due-to.patch kpatch-description: ext4: avoid online resizing failures due to kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52622 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52622 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5d1935ac02ca5aee364a449a35e2977ea84509b0 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52622-ext4-avoid-online-resizing-failures-due-to-kpatch.patch kpatch-description: ext4: avoid online resizing failures due to kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52622 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52622 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5d1935ac02ca5aee364a449a35e2977ea84509b0 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36904-tcp-use-refcount-inc-not-zero-in.patch kpatch-description: tcp: Use refcount_inc_not_zero() in tcp_twsk_unique() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36904 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36904 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f2db7230f73a80dbb179deab78f88a7947f0ab7e kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36917-block-fix-overflow-in-blk-ioctl-discard.patch kpatch-description: block: fix overflow in blk_ioctl_discard() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36917 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36917 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=22d24a544b0d49bbcbd61c8c0eaf77d3c9297155 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36489-tls-fix-missing-memory-barrier-in-tls-init.patch kpatch-description: tls: fix missing memory barrier in tls_init kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36489 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36489 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=91e61dd7a0af660408e87372d8330ceb218be302 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36927-ipv4-fix-uninit-value-access-in-ip-make-skb.patch kpatch-description: ipv4: Fix uninit-value access in __ip_make_skb() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36927 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36927 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=fc1092f51567277509563800a3c56732070b6aa4 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36929-net-core-reject-skb-copy-expand-for-fraglist.patch kpatch-description: net: core: reject skb_copy(_expand) for fraglist GSO skbs kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36929 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36929 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=d091e579b864fa790dd6a0cd537a22c383126681 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36889-mptcp-ensure-snd-nxt-is-properly-initialized-on.patch kpatch-description: mptcp: ensure snd_nxt is properly initialized on connect kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36889 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36889 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=fb7a0d334894206ae35f023a82cad5a290fd7386 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36921-wifi-iwlwifi-mvm-guard-against-invalid-sta-id-on.patch kpatch-description: wifi: iwlwifi: mvm: guard against invalid STA ID on removal kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36921 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36921 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=17f64517bf5c26af56b6c3566273aad6646c3c4f kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26669-net-sched-flower-fix-chain-template-offload-kpatch.patch kpatch-description: net/sched: flower: Fix chain template offload kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26669 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26669 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=32f2a0afa95fae0d1ceec2ff06e0e816939964b8 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36954-tipc-fix-a-possible-memleak-in-tipc-buf-append.patch kpatch-description: tipc: fix a possible memleak in tipc_buf_append kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36954 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36954 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=97bf6f81b29a8efaf5d0983251a7450e5794370d kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36941-wifi-nl80211-don-t-free-null-coalescing-rule.patch kpatch-description: wifi: nl80211: don't free NULL coalescing rule kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36941 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36941 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=801ea33ae82d6a9d954074fbcf8ea9d18f1543a7 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36933-net-nsh-Use-correct-mac_offset-to-unwind-gso-skb-in-.patch kpatch-description: net: nsh: Use correct mac_offset to unwind gso skb in nsh_gso_segment() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36933 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36933 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c83b49383b595be50647f0c764a48c78b5f3c4f8 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36933-nsh-restore-skb-protocol-data-mac-header-for.patch kpatch-description: nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment(). kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36933 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36933 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=4b911a9690d72641879ea6d13cce1de31d346d79 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36950-firewire-ohci-mask-bus-reset-interrupts-between.patch kpatch-description: firewire: ohci: mask bus reset interrupts between ISR and bottom half kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36950 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36950 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=752e3c53de0fa3b7d817a83050b6699b8e9c6ec9 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36940-pinctrl-core-fix-possible-memory-leak-in.patch kpatch-description: pinctrl: core: fix possible memory leak in pinctrl_enable() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36940 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36940 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c7892ae13e461ed20154321eb792e07ebe38f5b3 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36940-pinctrl-core-delete-incorrect-free-in.patch kpatch-description: pinctrl: core: delete incorrect free in pinctrl_enable() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36940 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36940 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5038a66dad0199de60e5671603ea6623eb9e5c79 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36960-drm-vmwgfx-fix-invalid-reads-in-fence-signaled.patch kpatch-description: drm/vmwgfx: Fix invalid reads in fence signaled events kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36960 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36960 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a37ef7613c00f2d72c8fc08bd83fb6cc76926c8c kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36978-net-sched-sch-multiq-fix-possible-oob-write-in.patch kpatch-description: net: sched: sch_multiq: fix possible OOB write in multiq_tune() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36978 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36978 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=affc18fdc694190ca7575b9a86632a73b9fe043d kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-38538-net-bridge-xmit-make-sure-we-have-at-least-eth.patch kpatch-description: net: bridge: xmit: make sure we have at least eth header len bytes kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-38538 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38538 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=8bd67ebb50c0145fd2ca8681ab65eb7e8cde1afc kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36945-net-smc-fix-neighbour-and-rtable-leak-in.patch kpatch-description: net/smc: fix neighbour and rtable leak in smc_ib_find_route() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36945 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36945 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2ddc0dd7fec86ee53b8928a5cca5fbddd4fc7c06 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36979-net-bridge-mst-fix-vlan-use-after-free.patch kpatch-description: net: bridge: mst: fix vlan use-after-free kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36979 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36979 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3a7c1661ae1383364cd6092d851f5e5da64d476b kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-40921-net-bridge-mst-pass-vlan-group-directly-to.patch kpatch-description: net: bridge: mst: pass vlan group directly to br_mst_vlan_set_state kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-40921 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40921 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=36c92936e868601fa1f43da6758cf55805043509 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-40920-net-bridge-mst-fix-suspicious-rcu-usage-in.patch kpatch-description: net: bridge: mst: fix suspicious rcu usage in br_mst_set_state kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-40920 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40920 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=546ceb1dfdac866648ec959cbc71d9525bd73462 kpatch-name: skipped/CVE-2021-47018.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2021-47018 kpatch-skip-reason: Out of scope as the patch is for powerpc arch only, x86_64 is not affected kpatch-cvss: kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52486-drm-don-t-unref-the-same-fb-many-times-by-mistake.patch kpatch-description: drm: Don't unref the same fb many times by mistake due to deadlock handling kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52486 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52486 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=cb4daf271302d71a6b9a7c01bd0b6d76febd8f0c kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-39502-ionic-clean-interrupt-before-enabling-queue-to.patch kpatch-description: ionic: clean interrupt before enabling queue to avoid credit race kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-39502 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-39502 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e8797a058466b60fc5a3291b92430c93ba90eaff kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-39502-ionic-fix-use-after-netif-napi-del.patch kpatch-description: ionic: fix use after netif_napi_del() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-39502 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-39502 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=79f18a41dd056115d685f3b0a419c7cd40055e13 kpatch-name: skipped/CVE-2024-40974.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-40974 kpatch-skip-reason: Out of scope as the patch is for powerpc arch only, x86_64 is not affected kpatch-cvss: kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26810-vfio-pci-lock-external-intx-masking-ops.patch kpatch-description: vfio/pci: Lock external INTx masking ops kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26810 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26810 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=810cd4bb53456d0503cc4e7934e063835152c1b7 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26853-igc-avoid-returning-frame-twice-in-xdp-redirect.patch kpatch-description: igc: avoid returning frame twice in XDP_REDIRECT kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26853 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26853 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=ef27f655b438bed4c83680e4f01e1cde2739854b kpatch-name: skipped/CVE-2024-26614.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-26614 kpatch-skip-reason: Complex adaptation required. Network services prevents update because sleeps in inet_csk_accept() function. kpatch-cvss: kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26908-x86-xen-fix-memory-leak-in.patch kpatch-description: x86/xen: Fix memory leak in kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26908 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26908 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3693bb4465e6e32a204a5b86d3ec7e6b9f7e67c2 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26908-x86-xen-add-some-null-pointer-checking-to-smp-c.patch kpatch-description: x86/xen: Add some null pointer checking to smp.c kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26908 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26908 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3693bb4465e6e32a204a5b86d3ec7e6b9f7e67c2 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35876-x86-mce-make-sure-to-grab-mce-sysfs-mutex-in.patch kpatch-description: x86/mce: Make sure to grab mce_sysfs_mutex in set_bank() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35876 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35876 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3ddf944b32f88741c303f0b21459dbb3872b8bc5 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52834-atl1c-work-around-the-dma-rx-overflow-issue.patch kpatch-description: atl1c: Work around the DMA RX overflow issue kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52834 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52834 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=86565682e9053e5deb128193ea9e88531bbae9cf kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52834-atl1c-work-around-the-dma-rx-overflow-issue-kpatch.patch kpatch-description: atl1c: Work around the DMA RX overflow issue kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52834 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52834 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=86565682e9053e5deb128193ea9e88531bbae9cf kpatch-name: 4.18.0/CVE-2024-2201-x86-bugs-Change-commas-to-semicolons-in-spectre_v2-sysfs-file.patch kpatch-description: x86/bugs: Change commas to semicolons in 'spectre_v2' sysfs file kpatch-kernel: kernel-4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-2201 kpatch-cvss: 4.7 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-2201 kpatch-patch-url: https://git.kernel.org/linus/0cd01ac5dcb1e18eb18df0f0d05b5de76522a437 kpatch-name: 4.18.0/CVE-2024-2201-x86-bhi-Add-support-for-clearing-branch-history-at-syscall-entry.patch kpatch-description: x86/bhi: Add support for clearing branch history at syscall entry kpatch-kernel: kernel-4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-2201 kpatch-cvss: 4.7 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-2201 kpatch-patch-url: https://git.kernel.org/linus/7390db8aea0d64e9deb28b8e1ce716f5020c7ee5 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-36010-igb-fix-string-truncation-warnings-in.patch kpatch-description: igb: Fix string truncation warnings in kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-36010 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36010 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c56d055893cbe97848611855d1c97d0ab171eccc kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26960-mm-swap-fix-race-between-free-swap-and-cache-553.patch kpatch-description: mm: swap: fix race between free_swap_and_cache() kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26960 kpatch-cvss: 5.5 kpatch-cve-url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-26960 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=82b1c07a0af603e3c47b906c8e991dc96f01688e kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-38555-net-mlx5-discard-command-completions-in-internal.patch kpatch-description: net/mlx5: Discard command completions in internal kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-38555 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38555 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=db9b31aa9bc56ff0d15b78f7e827d61c4a096e40 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-38575-wifi-brcmfmac-pcie-handle-randbuf-allocation.patch kpatch-description: wifi: brcmfmac: pcie: handle randbuf allocation kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-38575 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38575 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=316f790ebcf94bdf59f794b7cdea4068dc676d4c kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-38596-af-unix-fix-data-races-in.patch kpatch-description: af_unix: Fix data races in kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-38596 kpatch-cvss: 4.7 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38596 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=540bf24fba16b88c1b3b9353927204b4f1074e25 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-38596-af-unix-fix-data-races-around-sk-sk-shutdown.patch kpatch-description: af_unix: Fix data-races around sk->sk_shutdown. kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-38596 kpatch-cvss: 4.7 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38596 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3c73419c09a5 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-38598-md-fix-resync-softlockup-when-bitmap-size-is-less.patch kpatch-description: md: fix resync softlockup when bitmap size is less kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-38598 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38598 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f0e729af2eb6bee9eb58c4df1087f14ebaefe26b kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-38627-stm-class-fix-a-double-free-in.patch kpatch-description: stm class: Fix a double free in kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-38627 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38627 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3df463865ba42b8f88a590326f4c9ea17a1ce459 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-39276-ext4-fix-mb-cache-entry-s-e-refcnt-leak-in.patch kpatch-description: ext4: fix mb_cache_entry's e_refcnt leak in kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-39276 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-39276 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=0c0b4a49d3e7f49690a6827a41faeffad5df7e21 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-39472-xfs-fix-log-recovery-buffer-allocation-for-the.patch kpatch-description: xfs: fix log recovery buffer allocation for the kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-39472 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-39472 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=45cf976008ddef4a9c9a30310c9b4fb2a9a6602a kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-39476-md-raid5-fix-deadlock-that-raid5d-wait-for.patch kpatch-description: md/raid5: fix deadlock that raid5d() wait for kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-39476 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-39476 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=151f66bb618d1fd0eeb84acb61b4a9fa5d8bb0fa kpatch-name: rhel9/5.14.0-427.33.1.el9_4/CVE-2024-39476-md-raid5-fix-deadlock-that-raid5d-wait-for-kpatch.patch kpatch-description: md/raid5: remove pr_debug() in raid5d() kpatch-kernel: 5.14.0-427.33.1.el9_4 kpatch-cve: CVE-2024-39476 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-39476 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=151f66bb618d1fd0eeb84acb61b4a9fa5d8bb0fa kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-39487-bonding-fix-out-of-bounds-read-in.patch kpatch-description: bonding: Fix out-of-bounds read in kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-39487 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-39487 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e271ff53807e8f2c628758290f0e499dbe51cb3d kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-38615-cpufreq-exit-callback-is-optional.patch kpatch-description: cpufreq: exit() callback is optional kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-38615 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38615 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=b8f85833c05730d631576008daaa34096bc7f3ce kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-40927-xhci-handle-td-clearing-for-multiple-streams-case.patch kpatch-description: xhci: Handle TD clearing for multiple streams case kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-40927 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40927 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5ceac4402f5d975e5a01c806438eb4e554771577 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52845-tipc-change-nla-policy-for-bearer-related-names-to.patch kpatch-description: tipc: Change nla_policy for bearer-related names to kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52845 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52845 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=19b3f72a41a8751e26bffc093bb7e1cef29ad579 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52845-tipc-change-nla-policy-for-bearer-related-names-to-kpatch.patch kpatch-description: tipc: Change nla_policy for bearer-related names to kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52845 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52845 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=19b3f72a41a8751e26bffc093bb7e1cef29ad579 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2023-52803-sunrpc-fix-rpc-client-cleaned-up-the-freed-pipefs-kpatch.patch kpatch-description: SUNRPC: Fix RPC client cleaned up the freed pipefs kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2023-52803 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52803 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=bfca5fb4e97c46503ddfc582335917b0cc228264 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26961-mac802154-fix-llsec-key-resources-release-in_new.patch kpatch-description: mac802154: fix llsec key resources release in mac802154_llsec_key_del kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26961 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26961 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e8a1e58345cf40b7b272e08ac7b32328b2543e40 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26961-mac802154-fix-llsec-key-resources-release-in_new-kpatch.patch kpatch-description: mac802154: fix llsec key resources release in mac802154_llsec_key_del kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26961 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26961 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e8a1e58345cf40b7b272e08ac7b32328b2543e40 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-27010-net-sched-Fix-mirred-deadlock-on-device-recursion.patch kpatch-description: net/sched: Fix mirred deadlock on device recursion kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-27010 kpatch-cvss: 5.5 kpatch-cve-url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-27010 kpatch-patch-url: https://github.com/torvalds/linux/commit/0f022d32c3eca477fbf79a205243a6123ed0fe11 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-27010-net-sched-Fix-mirred-deadlock-on-device-recursion-kpatch.patch kpatch-description: net/sched: Fix mirred deadlock on device recursion (Adaptation) kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-27010 kpatch-cvss: 5.5 kpatch-cve-url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-27010 kpatch-patch-url: https://github.com/torvalds/linux/commit/0f022d32c3eca477fbf79a205243a6123ed0fe11 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35790-usb-typec-altmodes-displayport-create-sysfs-nodes-as-kpatch.patch kpatch-description: usb: typec: altmodes/displayport: create sysfs kpatch kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35790 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35790 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=165376f6b23e9a779850e750fb2eb06622e5a531 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-35910-0002-tcp-properly-terminate-timers-for-kernel-sockets-kpatch.patch kpatch-description: tcp: properly terminate timers for kernel sockets kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-35910 kpatch-cvss: 5.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35910 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=151c9c724d05d5b0dd8acd3e11cb69ef1f2dbada kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26929-scsi-qla2xxx-fix-double-free-of-fcport.patch kpatch-description: scsi: qla2xxx: Fix double free of fcport kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26929 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26929 kpatch-patch-url: https://github.com/torvalds/linux/commit/82f522ae0d97119a43da53e0f729275691b9c525 kpatch-name: rhel8/4.18.0-553.16.1.el8_10/CVE-2024-26929-scsi-qla2xxx-fix-double-free-of-fcport-kpatch.patch kpatch-description: scsi: qla2xxx: Fix double free of fcport kpatch-kernel: 4.18.0-553.16.1.el8_10 kpatch-cve: CVE-2024-26929 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26929 kpatch-patch-url: https://github.com/torvalds/linux/commit/82f522ae0d97119a43da53e0f729275691b9c525 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42084-ftruncate-pass-a-signed-offset.patch kpatch-description: ftruncate: pass a signed offset kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42084 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42084 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=4b8e88e563b5f666446d002ad0dc1e6e8e7102b0 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-38579-crypto-bcm-fix-pointer-arithmetic.patch kpatch-description: crypto: bcm - Fix pointer arithmetic kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-38579 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38579 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2b3460cbf454c6b03d7429e9ffc4fe09322eb1a9 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-38559-scsi-qedf-ensure-the-copied-buf-is-nul-terminated.patch kpatch-description: scsi: qedf: Ensure the copied buf is NUL terminated kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-38559 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38559 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=d0184a375ee797eb657d74861ba0935b6e405c62 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41097-usb-atm-cxacru-fix-endpoint-checking-in-cxacru-bind.patch kpatch-description: usb: atm: cxacru: fix endpoint checking in cxacru_bind() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41097 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41097 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2eabb655a968b862bc0c31629a09f0fbf3c80d51 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-39501-drivers-core-synchronize-really-probe-and-dev-uevent.patch kpatch-description: drivers: core: synchronize really_probe() and dev_uevent() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-39501 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-39501 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c0a40097f0bc81deafc15f9195d1fb54595cd6d0 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-26923-af-unix-fix-garbage-collector-racing-against-connect.patch kpatch-description: af_unix: Fix garbage collector racing against connect() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-26923 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26923 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=47d8ac011fe1c9251070e1bd64cb10b48193ec51 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42094-net-iucv-avoid-explicit-cpumask-var-allocation-on-stack.patch kpatch-description: net/iucv: Avoid explicit cpumask var allocation on stack kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42094 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42094 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=be4e1304419c99a164b4c0e101c7c2a756b635b9 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-38558-net-openvswitch-fix-overwriting-ct-original-tuple-for-ICMPv6.patch kpatch-description: net: openvswitch: fix overwriting ct original tuple for ICMPv6 kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-38558 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38558 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=7c988176b6c16c516474f6fceebe0f055af5eb56 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42090-pinctrl-fix-deadlock-in-create-pinctrl-when-handling-eprobe-defer.patch kpatch-description: pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42090 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42090 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=adec57ff8e66aee632f3dd1f93787c13d112b7a1 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40904-usb-class-cdc-wdm-fix-cpu-lockup-caused-by-excessive-log-messages.patch kpatch-description: USB: class: cdc-wdm: Fix CPU lockup caused by excessive log messages kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40904 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40904 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=22f00812862564b314784167a89f27b444f82a46 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-39499-vmci-prevent-speculation-leaks-by-sanitizing-event-in-event-deliver.patch kpatch-description: vmci: prevent speculation leaks by sanitizing event in event_deliver() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-39499 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-39499 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=8003f00d895310d409b2bf9ef907c56b42a4e0f4 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-39506-liquidio-adjust-a-null-pointer-handling-path-in-lio-vf-rep-copy-packet.patch kpatch-description: liquidio: Adjust a NULL pointer handling path in lio_vf_rep_copy_packet kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-39506 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-39506 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c44711b78608c98a3e6b49ce91678cd0917d5349 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42228-drm-amdgpu-using-uninitialized-value-size-when-calling-amdgpu-vce-cs-reloc.patch kpatch-description: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42228 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42228 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=88a9a467c548d0b3c7761b4fd54a68e70f9c0944 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-37356-tcp-fix-shift-out-of-bounds-in-dctcp_update_alpha.patch kpatch-description: tcp: Fix shift-out-of-bounds in dctcp_update_alpha(). kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-37356 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-37356 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3ebc46ca8675de6378e3f8f40768e180bb8afa66 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-37356-tcp-fix-shift-out-of-bounds-in-dctcp_update_alpha-kpatch.patch kpatch-description: tcp: Fix shift-out-of-bounds in dctcp_update_alpha(). (Adaptation) kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-37356 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-37356 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3ebc46ca8675de6378e3f8f40768e180bb8afa66 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42096-x86-stop-playing-stack-games-in-profile-pc.patch kpatch-description: x86: stop playing stack games in profile_pc() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42096 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42096 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=093d9603b60093a9aaae942db56107f6432a5dca kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42131-mm-avoid-overflows-in-dirty-throttling-logic.patch kpatch-description: mm: avoid overflows in dirty throttling logic kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42131 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42131 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=385d838df280eba6c8680f9777bfa0d0bfe7e8b2 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42124-scsi-qedf-make-qedf-execute-tmf-non-preemptible.patch kpatch-description: scsi: qedf: Make qedf_execute_tmf() non-preemptible kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42124 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42124 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=0d8b637c9c5eeaa1a4e3dfb336f3ff918eb64fec kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41076-nfsv4-fix-memory-leak-in-nfs4-set-security-label.patch kpatch-description: NFSv4: Fix memory leak in nfs4_set_security_label kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41076 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41076 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=aad11473f8f4be3df86461081ce35ec5b145ba68 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40901-scsi-mpt3sas-avoid-test-set-bit-operating-in-non-allocated-memory.patch kpatch-description: scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40901 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40901 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=4254dfeda82f20844299dca6c38cbffcfd499f41 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-38619-usb-storage-alauda-fix-uninit-value-in-alauda_check_media.patch kpatch-description: usb-storage: alauda: Fix uninit-value in alauda_check_media() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-38619 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38619 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=16637fea001ab3c8df528a8995b3211906165a30 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-38619-usb-storage-alauda-check-whether-the-media-is-initialized.patch kpatch-description: usb-storage: alauda: Check whether the media is initialized kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-38619 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38619 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=16637fea001ab3c8df528a8995b3211906165a30 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-38619-usb-storage-alauda-check-whether-the-media-is-initialized-kpatch.patch kpatch-description: usb-storage: alauda: Check whether the media is initialized (Adaptation) kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-38619 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38619 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=16637fea001ab3c8df528a8995b3211906165a30 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47384-02-hwmon-w83793-Fix-NULL-pointer-dereference.patch kpatch-description: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47384 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47384 kpatch-patch-url: https://github.com/torvalds/linux/commit/dd4d747ef05addab887dc8ff0d6ab9860bbcd783 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47385-02-hwmon-w83792d-Fix-NULL-pointer-dereference.patch kpatch-description: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47385 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47385 kpatch-patch-url: https://github.com/torvalds/linux/commit/0f36b88173f028e372668ae040ab1a496834d278 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47386-02-hwmon-w83791d-Fix-NULL-pointer-dereference.patch kpatch-description: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47386 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47386 kpatch-patch-url: https://github.com/torvalds/linux/commit/943c15ac1b84d378da26bba41c83c67e16499ac4 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47384-CVE-2021-47385-CVE-2021-47386-kpatch.patch kpatch-description: hwmon: Fix NULL pointer dereference by removing unnecessary structure field kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47384 CVE-2021-47385 CVE-2021-47386 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47384 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47385 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47386 kpatch-patch-url: https://github.com/torvalds/linux/commit/943c15ac1b84d378da26bba41c83c67e16499ac4 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41090-tap-add-missing-verification-for-short-frame.patch kpatch-description: tap: add missing verification for short frame kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41090 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41090 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=ed7f2afdd0e043a397677e597ced0830b83ba0b3 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41091-tun-add-missing-verification-for-short-frame.patch kpatch-description: tun: add missing verification for short frame kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41091 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41091 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=049584807f1d797fc3078b68035450a9769eb5c3 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47441-mlxsw-thermal-fix-out-of-bounds-memory-accesses.patch kpatch-description: mlxsw: thermal: Fix out-of-bounds memory accesses kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47441 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47441 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=332fdf951df8b870e3da86b122ae304e2aabe88c kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-39471-drm-amdgpu-add-error-handle-to-avoid-out-of-bounds.patch kpatch-description: drm/amdgpu: add error handle to avoid out-of-bounds kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-39471 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-39471 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=8b2faf1a4f3b6c748c0da36cda865a226534d520 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-39471-drm-amdgpu-fix-signedness-bug-in-sdma_v4_0_process_trap_irq.patch kpatch-description: drm/amdgpu: Fix signedness bug in sdma_v4_0_process_trap_irq() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-39471 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-39471 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=8b2faf1a4f3b6c748c0da36cda865a226534d520 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42152-nvmet-fix-a-possible-leak-when-destroy-a-ctrl-during-qp-establishment.patch kpatch-description: nvmet: fix a possible leak when destroy a ctrl during qp establishment kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42152 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42152 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c758b77d4a0a0ed3a1292b3fd7a2aeccd1a169a4 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-26769-0001-nvmet-fc-release-reference-on-target-port.patch kpatch-description: nvmet-fc: release reference on target port kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-26769 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26769 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=88bfbc18a3535bb9b5cb1564a55dd495c99b8073 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-26769-0002-nvmet-fc-avoid-deadlock-on-delete-association-path-kpatch.patch kpatch-description: nvmet-fc: avoid deadlock on delete association path kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-26769 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26769 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=710c69dbaccdac312e32931abcb8499c1525d397 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42114-wifi-cfg80211-restrict-nl80211-attr-txq-quantum-values.patch kpatch-description: wifi: cfg80211: restrict NL80211_ATTR_TXQ_QUANTUM values kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42114 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42114 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=d1cba2ea8121e7fdbe1328cea782876b1dd80993 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42114-wifi-cfg80211-restrict-nl80211-attr-txq-quantum-values-kpatch.patch kpatch-description: wifi: cfg80211: restrict NL80211_ATTR_TXQ_QUANTUM values (Adaptation) kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42114 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42114 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=d1cba2ea8121e7fdbe1328cea782876b1dd80993 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42225-wifi-mt76-replace-skb_put-with-skb_put_zero.patch kpatch-description: wifi: mt76: replace skb_put with skb_put_zero kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42225 kpatch-cvss: 7.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42225 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=7f819a2f4fbc510e088b49c79addcf1734503578 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41040-net-sched-fix-uaf-when-resolving-a-clash.patch kpatch-description: net/sched: Fix UAF when resolving a clash kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41040 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41040 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=26488172b0292bed837b95a006a3f3431d1898c3 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2022-48866-hid-hid-thrustmaster-fix-oob-read-in-thrustmaster-interrupts.patch kpatch-description: HID: hid-thrustmaster: fix OOB read in thrustmaster_interrupts kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2022-48866 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-48866 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=fc3ef2e3297b3c0e2006b5d7b3d66965e3392036 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2023-52800-wifi-ath11k-fix-htt-pktlog-locking.patch kpatch-description: wifi: ath11k: fix htt pktlog locking kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2023-52800 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52800 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3f77c7d605b29df277d77e9ee75d96e7ad145d2d kpatch-name: skipped/CVE-2023-52683.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2023-52683 kpatch-skip-reason: Out of scope: boot time issue kpatch-cvss: kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2023-52522-net-fix-possible-store-tearing-in-neigh-periodic-work.patch kpatch-description: net: fix possible store tearing in neigh_periodic_work() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2023-52522 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52522 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=25563b581ba3a1f263a00e8c9a97f5e7363be6fd kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2023-52476-perf-x86-lbr-filter-vsyscall-addresses.patch kpatch-description: perf/x86/lbr: Filter vsyscall addresses kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2023-52476 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52476 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e53899771a02f798d436655efbd9d4b46c0f9265 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-26600-phy-ti-phy-omap-usb2-fix-null-pointer-dereference-for-srp.patch kpatch-description: phy: ti: phy-omap-usb2: Fix NULL pointer dereference for SRP kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-26600 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26600 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=7104ba0f1958adb250319e68a15eff89ec4fd36d kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2023-52798-wifi-ath11k-fix-dfs-radar-event-locking.patch kpatch-description: wifi: ath11k: fix dfs radar event locking kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2023-52798 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52798 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3b6c14833165f689cc5928574ebafe52bbce5f1e kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2023-52809-scsi-libfc-fix-potential-null-pointer-dereference-in-fc-lport-ptp-setup.patch kpatch-description: scsi: libfc: Fix potential NULL pointer dereference in fc_lport_ptp_setup() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2023-52809 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52809 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=4df105f0ce9f6f30cda4e99f577150d23f0c9c5f kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2023-52840-input-synaptics-rmi4-fix-use-after-free-in-rmi-unregister-function.patch kpatch-description: Input: synaptics-rmi4 - fix use after free in rmi_unregister_function() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2023-52840 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52840 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=eb988e46da2e4eae89f5337e047ce372fe33d5b1 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-26595-mlxsw-spectrum-acl-tcam-move-devlink-param-to-tcam-code.patch kpatch-description: mlxsw: spectrum_acl_tcam: Move devlink param to TCAM code kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-26595 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26595 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=efeb7dfea8ee10cdec11b6b6ba4e405edbe75809 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-26595-mlxsw-spectrum-acl-tcam-fix-null-pointer-dereference-in-error-path.patch kpatch-description: mlxsw: spectrum_acl_tcam: Fix NULL pointer dereference in error path kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-26595 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26595 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=efeb7dfea8ee10cdec11b6b6ba4e405edbe75809 kpatch-name: skipped/CVE-2023-52605.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2023-52605 kpatch-skip-reason: CVE Rejected kpatch-cvss: kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47466-slub-don-t-panic-for-memcg-kmem-cache-creation-failure.patch kpatch-description: slub: don't panic for memcg kmem cache creation failure kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47466 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47466 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9037c57681d25e4dcc442d940d6dbe24dd31f461 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47466-mm-slub-fix-potential-memoryleak-in-kmem-cache-open.patch kpatch-description: mm, slub: fix potential memoryleak in kmem_cache_open() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47466 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47466 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9037c57681d25e4dcc442d940d6dbe24dd31f461 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47497-nvmem-fix-shift-out-of-bound-ubsan-with-byte-size-cells.patch kpatch-description: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47497 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47497 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5d388fa01fa6eb310ac023a363a6cb216d9d8fe9 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47527-serial-core-fix-transmit-buffer-reset-and-memleak.patch kpatch-description: serial: core: fix transmit-buffer reset and memleak kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47527 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47527 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=00de977f9e0aa9760d9a79d1e41ff780f74e3424 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2022-48760-usb-core-fix-hang-in-usb-kill-urb-by-adding-memory-barriers.patch kpatch-description: USB: core: Fix hang in usb_kill_urb by adding memory barriers kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2022-48760 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-48760 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=26fbe9772b8c459687930511444ce443011f86bf kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47609-firmware-arm-scpi-fix-string-overflow-in-scpi-genpd-driver.patch kpatch-description: firmware: arm_scpi: Fix string overflow in SCPI genpd driver kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47609 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47609 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=865ed67ab955428b9aa771d8b4f1e4fb7fd08945 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47609-firmware-arm-scpi-fix-string-overflow-in-scpi-genpd-driver-kpatch.patch kpatch-description: firmware: arm_scpi: Fix string overflow in SCPI genpd driver kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47609 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47609 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=865ed67ab955428b9aa771d8b4f1e4fb7fd08945 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2023-52470-drm-radeon-check-the-alloc-workqueue-return-value-in-radeon-crtc-init.patch kpatch-description: drm/radeon: check the alloc_workqueue return value in radeon_crtc_init() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2023-52470 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52470 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=7a2464fac80d42f6f8819fed97a553e9c2f43310 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2022-48804-vt-ioctl-fix-array-index-nospec-in-vt-setactivate.patch kpatch-description: vt_ioctl: fix array_index_nospec in vt_setactivate kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2022-48804 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-48804 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=61cc70d9e8ef5b042d4ed87994d20100ec8896d9 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2022-48836-input-aiptek-use-descriptors-of-current-altsetting.patch kpatch-description: Input: aiptek - use descriptors of current altsetting kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2022-48836 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-48836 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5600f6986628dde8881734090588474f54a540a8 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2022-48836-input-aiptek-fix-endpoint-sanity-check.patch kpatch-description: Input: aiptek - fix endpoint sanity check kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2022-48836 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-48836 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5600f6986628dde8881734090588474f54a540a8 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2022-48836-input-aiptek-properly-check-endpoint-type.patch kpatch-description: Input: aiptek - properly check endpoint type kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2022-48836 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-48836 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5600f6986628dde8881734090588474f54a540a8 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47582-usb-core-make-do-proc-control-and-do-proc-bulk-killable.patch kpatch-description: USB: core: Make do_proc_control() and do_proc_bulk() killable kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47582 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47582 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=ae8709b296d80c7f45aa1f35c0e7659ad69edce1 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47582-usb-core-don-t-hold-the-device-lock-while-sleeping-in-do-proc-control.patch kpatch-description: usb: core: Don't hold the device lock while sleeping in do_proc_control() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47582 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47582 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=ae8709b296d80c7f45aa1f35c0e7659ad69edce1 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42154-tcp-metrics-validate-source-addr-length.patch kpatch-description: tcp_metrics: validate source addr length kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42154 kpatch-cvss: 9.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42154 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=66be40e622e177316ae81717aa30057ba9e61dff kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42154-tcp-metrics-validate-source-addr-length-kpatch.patch kpatch-description: tcp_metrics: validate source addr length kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42154 kpatch-cvss: 9.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42154 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=66be40e622e177316ae81717aa30057ba9e61dff kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2022-48754-phylib-fix-potential-use-after-free.patch kpatch-description: phylib: fix potential use-after-free kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2022-48754 kpatch-cvss: 8.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-48754 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=cbda1b16687580d5beee38273f6241ae3725960c kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2023-52817-drm-amdgpu-fix-a-null-pointer-access-when-the-smc-rreg-pointer-is-null.patch kpatch-description: drm/amdgpu: Fix a null pointer access when the smc_rreg pointer is NULL kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2023-52817 kpatch-cvss: 8.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52817 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5104fdf50d326db2c1a994f8b35dcd46e63ae4ad kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2023-52817-drm-amdgpu-debugfs-fix-error-code-when-smc-register-accessors-are-null.patch kpatch-description: drm/amdgpu/debugfs: fix error code when smc register accessors are NULL kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2023-52817 kpatch-cvss: 8.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52817 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5104fdf50d326db2c1a994f8b35dcd46e63ae4ad kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2023-6040-netfilter-nf-tables-reject-tables-of-unsupported-family.patch kpatch-description: netfilter: nf_tables: Reject tables of unsupported family kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2023-6040 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-6040 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f1082dd31fe461d482d69da2a8eccfeb7bf07ac2 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-38581-drm-amdgpu-mes-fix-use-after-free-issue.patch kpatch-description: drm/amdgpu/mes: fix use-after-free issue kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-38581 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38581 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=948255282074d9367e01908b3f5dcf8c10fc9c3d kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40954-net-do-not-leave-a-dangling-sk-pointer-when-socket-creation-fails.patch kpatch-description: net: do not leave a dangling sk pointer, when socket creation fails kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40954 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40954 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=6cd4a78d962bebbaf8beb7d2ead3f34120e3f7b2 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40958-netns-make-get-net-ns-handle-zero-refcount-net.patch kpatch-description: netns: Make get_net_ns() handle zero refcount net kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40958 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40958 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=ff960f9d3edbe08a736b5a224d91a305ccc946b0 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41039-firmware-cs-dsp-fix-overflow-checking-of-wmfw-header.patch kpatch-description: firmware: cs_dsp: Fix overflow checking of wmfw header kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41039 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41039 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3019b86bce16fbb5bc1964f3544d0ce7d0137278 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41039-firmware-cs-dsp-fix-overflow-checking-of-wmfw-header-kpatch.patch kpatch-description: firmware: cs_dsp: Fix overflow checking of wmfw header (adaptation) kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41039 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41039 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3019b86bce16fbb5bc1964f3544d0ce7d0137278 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41071-wifi-mac80211-avoid-address-calculations-via-out-of-bounds-array-indexing.patch kpatch-description: wifi: mac80211: Avoid address calculations via out of bounds array indexing kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41071 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41071 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2663d0462eb32ae7c9b035300ab6b1523886c718 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41041-udp-set-sock-rcu-free-earlier-in-udp-lib-get-port.patch kpatch-description: udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port(). kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41041 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41041 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5c0b485a8c6116516f33925b9ce5b6104a6eadfd kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41056-firmware-cs-dsp-use-strnlen-on-name-fields-in-v1-wmfw-files.patch kpatch-description: firmware: cs_dsp: Use strnlen() on name fields in V1 wmfw files kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41056 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41056 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=680e126ec0400f6daecf0510c5bb97a55779ff03 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41038-firmware-cs-dsp-prevent-buffer-overrun-when-processing-v2-alg-headers.patch kpatch-description: firmware: cs_dsp: Prevent buffer overrun when processing V2 alg headers kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41038 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41038 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2163aff6bebbb752edf73f79700f5e2095f3559e kpatch-name: skipped/CVE-2024-41064.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-41064 kpatch-skip-reason: CVE patch is for powerpc arch only kpatch-cvss: kpatch-name: skipped/CVE-2024-41065.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-41065 kpatch-skip-reason: CVE patch is for powerpc arch only kpatch-cvss: kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41023-sched-deadline-fix-task-struct-reference-leak.patch kpatch-description: sched/deadline: Fix task_struct reference leak kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41023 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41023 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=b58652db66c910c2245f5bee7deca41c12d707b9 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41035-usb-core-fix-duplicate-endpoint-bug-by-clearing-reserved-bits-in-the-descriptor.patch kpatch-description: USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41035 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41035 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a368ecde8a5055b627749b09c6218ef793043e47 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41044-ppp-reject-claimed-as-lcp-but-actually-malformed-packets.patch kpatch-description: ppp: reject claimed-as-LCP but actually malformed packets kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41044 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41044 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f2aeb7306a898e1cbd03963d376f4b6656ca2b55 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41060-drm-radeon-check-bo-va-bo-is-non-null-before-using-it.patch kpatch-description: drm/radeon: check bo_va->bo is non-NULL before using it kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41060 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41060 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=6fb15dcbcf4f212930350eaee174bb60ed40a536 kpatch-name: skipped/CVE-2024-41055.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-41055 kpatch-skip-reason: The patch affects too much kernel code. Low impact CVE. kpatch-cvss: kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-35944-vmci-use-struct-size-in-kmalloc.patch kpatch-description: VMCI: Use struct_size() in kmalloc() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-35944 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35944 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e03d4910e6e45cb49f630258e870b08f2ee34e7a kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-35944-vmci-fix-memcpy-run-time-warning-in-dg-dispatch-as-host.patch kpatch-description: VMCI: Fix memcpy() run-time warning in dg_dispatch_as_host() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-35944 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35944 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=19b070fefd0d024af3daa7329cbc0d00de5302ec kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-35944-vmci-fix-possible-memcpy-run-time-warning-in-vmci-datagram-invoke-guest-handler.patch kpatch-description: VMCI: Fix possible memcpy() run-time warning in vmci_datagram_invoke_guest_handler() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-35944 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35944 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e606e4b71798cc1df20e987dde2468e9527bd376 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-35989-dmaengine-idxd-fix-oops-during-rmmod-on-single-cpu-platforms.patch kpatch-description: dmaengine: idxd: Fix oops during rmmod on single-CPU platforms kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-35989 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35989 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f221033f5c24659dc6ad7e5cf18fb1b075f4a8be kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-36920-scsi-mpi3mr-avoid-memcpy-field-spanning-write-warning.patch kpatch-description: scsi: mpi3mr: Avoid memcpy field-spanning write WARNING kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-36920 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36920 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=429846b4b6ce9853e0d803a2357bb2e55083adf0 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-36883-net-fix-out-of-bounds-access-in-ops-init.patch kpatch-description: net: fix out-of-bounds access in ops_init kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-36883 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36883 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a26ff37e624d12e28077e5b24d2b264f62764ad6 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-36901-ipv6-prevent-null-dereference-in-ip6-output.patch kpatch-description: ipv6: prevent NULL dereference in ip6_output() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-36901 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36901 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=4db783d68b9b39a411a96096c10828ff5dfada7a kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-36902-ipv6-fib6-rules-avoid-possible-null-dereference-in-fib6-rule-action.patch kpatch-description: ipv6: fib6_rules: avoid possible NULL dereference in fib6_rule_action() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-36902 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36902 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=d101291b2681e5ab938554e3e323f7a7ee33e3aa kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-36919-scsi-bnx2fc-remove-spin-lock-bh-while-releasing-resources-after-upload.patch kpatch-description: scsi: bnx2fc: Remove spin_lock_bh while releasing resources after upload kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-36919 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36919 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c214ed2a4dda35b308b0b28eed804d7ae66401f9 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-36922-wifi-iwlwifi-read-txq-read-ptr-under-lock.patch kpatch-description: wifi: iwlwifi: read txq->read_ptr under lock kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-36922 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36922 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c2ace6300600c634553657785dfe5ea0ed688ac2 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-36939-nfs-handle-error-of-rpc_proc_register-in-init_nfs_fs.patch kpatch-description: nfs: handle error of rpc_proc_register() in init_nfs_fs() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-36939 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-36939 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=24457f1be29f1e7042e50a7749f5c2dde8c433c8 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40912-wifi-mac80211-fix-deadlock-in-ieee80211-sta-ps-deliver-wakeup.patch kpatch-description: wifi: mac80211: Fix deadlock in ieee80211_sta_ps_deliver_wakeup() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40912 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40912 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=44c06bbde6443de206b30f513100b5670b23fc5e kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40929-wifi-iwlwifi-mvm-check-n-ssids-before-accessing-the-ssids.patch kpatch-description: wifi: iwlwifi: mvm: check n_ssids before accessing the ssids kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40929 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40929 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=60d62757df30b74bf397a2847a6db7385c6ee281 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40931-mptcp-ensure-snd-una-is-properly-initialized-on-connect.patch kpatch-description: mptcp: ensure snd_una is properly initialized on connect kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40931 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40931 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=8031b58c3a9b1db3ef68b3bd749fbee2e1e1aaa3 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40941-wifi-iwlwifi-mvm-don-t-read-past-the-mfuart-notifcation.patch kpatch-description: wifi: iwlwifi: mvm: don't read past the mfuart notifcation kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40941 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40941 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=4bb95f4535489ed830cf9b34b0a891e384d1aee4 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40959-xfrm6-check-ip6-dst-idev-return-value-in-xfrm6-get-saddr.patch kpatch-description: xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40959 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40959 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=d46401052c2d5614da8efea5788532f0401cb164 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40960-ipv6-prevent-possible-null-dereference-in-rt6-probe.patch kpatch-description: ipv6: prevent possible NULL dereference in rt6_probe() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40960 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40960 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=b86762dbe19a62e785c189f313cda5b989931f37 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40978-scsi-qedi-fix-crash-while-reading-debugfs-attribute.patch kpatch-description: scsi: qedi: Fix crash while reading debugfs attribute kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40978 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40978 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=28027ec8e32ecbadcd67623edb290dad61e735b5 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40977-wifi-mt76-mt7921s-fix-potential-hung-tasks-during-chip-recovery.patch kpatch-description: wifi: mt76: mt7921s: fix potential hung tasks during chip recovery kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40977 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40977 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=ecf0b2b8a37c8464186620bef37812a117ff6366 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42237-firmware-cs-dsp-validate-payload-length-before-processing-block.patch kpatch-description: firmware: cs_dsp: Validate payload length before processing block kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42237 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42237 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=6598afa9320b6ab13041616950ca5f8f938c0cf1 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42238-firmware-cs-dsp-return-error-if-block-header-overflows-file.patch kpatch-description: firmware: cs_dsp: Return error if block header overflows file kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42238 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42238 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=959fe01e85b7241e3ec305d657febbe82da16a02 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42265-protect-the-fetch-of-fd-fd-in-do-dup2-from-mispredictions.patch kpatch-description: protect the fetch of ->fd[fd] in do_dup2() from mispredictions kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42265 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42265 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=8aa37bde1a7b645816cda8b80df4753ecf172bf1 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42322-ipvs-properly-dereference-pe-in-ip-vs-add-service.patch kpatch-description: ipvs: properly dereference pe in ip_vs_add_service kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42322 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42322 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=cbd070a4ae62f119058973f6d2c984e325bce6e7 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-43830-leds-trigger-unregister-sysfs-attributes-before-calling-deactivate.patch kpatch-description: leds: trigger: Unregister sysfs attributes before calling deactivate() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-43830 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-43830 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c0dc9adf9474ecb7106e60e5472577375aedaed3 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-43871-devres-fix-memory-leakage-caused-by-driver-api-devm-free-percpu.patch kpatch-description: devres: Fix memory leakage caused by driver API devm_free_percpu() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-43871 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-43871 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=bd50a974097bb82d52a458bd3ee39fb723129a0c kpatch-name: skipped/CVE-2024-42226.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-42226 kpatch-skip-reason: Patch introduced regression and was reverted later. kpatch-cvss: kpatch-name: skipped/CVE-2024-26638.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-26638 kpatch-skip-reason: nbd: Low-score CVE. Patched function is called from a kthread and sleeps, which may prevent patching/unpatching. kpatch-cvss: kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-26645-tracing-ensure-visibility-when-inserting-an-element-into-tracing-map.patch kpatch-description: tracing: Ensure visibility when inserting an element into tracing_map kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-26645 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26645 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2b44760609e9eaafc9d234a6883d042fc21132a7 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-26649-drm-amdgpu-fix-the-null-pointer-when-load-rlc-firmware.patch kpatch-description: drm/amdgpu: Fix the null pointer when load rlc firmware kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-26649 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26649 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=bc03c02cc1991a066b23e69bbcc0f66e8f1f7453 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-26855-net-ice-fix-potential-null-pointer-dereference-in-ice-bridge-setlink.patch kpatch-description: net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-26855 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26855 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=06e456a05d669ca30b224b8ed962421770c1496c kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-26880-dm-call-the-resume-method-on-internal-suspend.patch kpatch-description: dm: call the resume method on internal suspend kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-26880 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26880 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=65e8fbde64520001abf1c8d0e573561b4746ef38 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41012-filelock-remove-locks-reliably-when-fcntl-close-race-is-detected.patch kpatch-description: filelock: Remove locks reliably when fcntl/close race is detected kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41012 kpatch-cvss: 6.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41012 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3cad1bc010416c6dd780643476bc59ed742436b9 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2022-48619-input-add-bounds-checking-to-input-set-capability.patch kpatch-description: Input: add bounds checking to input_set_capability() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2022-48619 kpatch-cvss: 6.2 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-48619 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=409353cbe9fe48f6bc196114c442b1cff05a39bc kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47097-input-elantech-fix-stack-out-of-bound-access-in-elantech-change-report-id.patch kpatch-description: Input: elantech - fix stack out of bound access in elantech_change_report_id() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47097 kpatch-cvss: 6.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47097 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=1d72d9f960ccf1052a0630a68c3d358791dbdaaa kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47101-asix-fix-uninit-value-in-asix-mdio-read.patch kpatch-description: asix: fix uninit-value in asix_mdio_read() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47101 kpatch-cvss: 6.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47101 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=8035b1a2a37a29d8c717ef84fca8fe7278bc9f03 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2023-52478-hid-logitech-hidpp-fix-kernel-crash-on-receiver-usb-disconnect.patch kpatch-description: HID: logitech-hidpp: Fix kernel crash on receiver USB disconnect kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2023-52478 kpatch-cvss: 6.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52478 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=dac501397b9d81e4782232c39f94f4307b137452 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-26894-acpi-processor-idle-fix-memory-leak-in-acpi-processor-power-exit.patch kpatch-description: ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-26894 kpatch-cvss: 6.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26894 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e18afcb7b2a12b635ac10081f943fcf84ddacc51 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47287-driver-core-auxiliary-bus-fix-memory-leak-when-driver-register-fail.patch kpatch-description: driver core: auxiliary bus: Fix memory leak when driver_register() fail kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47287 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47287 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=4afa0c22eed33cfe0c590742387f0d16f32412f3 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47289-acpi-fix-null-pointer-dereference.patch kpatch-description: ACPI: fix NULL pointer dereference kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47289 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47289 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=fc68f42aa737dc15e7665a4101d4168aadb8e4c4 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47321-watchdog-fix-possible-use-after-free-by-calling-del-timer-sync.patch kpatch-description: watchdog: Fix possible use-after-free by calling del_timer_sync() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47321 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47321 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=d0212f095ab56672f6f36aabc605bda205e1e0bf kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-27042-drm-amdgpu-fix-potential-out-of-bounds-access-in-amdgpu-discovery-reg-base-init.patch kpatch-description: drm/amdgpu: Fix potential out-of-bounds access in 'amdgpu_discovery_reg_base_init()' kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-27042 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27042 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=cdb637d339572398821204a1142d8d615668f1e9 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-26939-drm-i915-vma-fix-uaf-on-destroy-against-retire-race.patch kpatch-description: drm/i915/vma: Fix UAF on destroy against retire race kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-26939 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26939 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=0e45882ca829b26b915162e8e86dbb1095768e9e kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-35877-x86-mm-pat-fix-vm-pat-handling-in-cow-mappings.patch kpatch-description: x86/mm/pat: fix VM_PAT handling in COW mappings kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-35877 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35877 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=04c35ab3bdae7fefbd7c7a7355f29fa03a035221 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-26665-tunnels-fix-out-of-bounds-access-when-building-ipv6-pmtu-error.patch kpatch-description: tunnels: fix out of bounds access when building IPv6 PMTU error kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-26665 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26665 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=d75abeec401f8c86b470e7028a13fcdc87e5dd06 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47560-mlxsw-Verify-the-accessed-index-doesn-t-exceed-the-a.patch kpatch-description: mlxsw: Verify the accessed index doesn't exceed the array length kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47560 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47560 kpatch-patch-url: https://git.kernel.org/linus/837ec05cfea08284c575e8e834777b107da5ff9d kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47560-mlxsw-spectrum-Protect-driver-from-buggy-firmware.patch kpatch-description: mlxsw: spectrum: Protect driver from buggy firmware kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47560 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47560 kpatch-patch-url: https://git.kernel.org/linus/63b08b1f6834bbb0b4f7783bf63b80c8c8e9a047 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-38570-01-gfs2-Remove-ill-placed-consistency-check.patch kpatch-description: gfs2: Remove ill-placed consistency check kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-38570 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38570 kpatch-patch-url: https://github.com/torvalds/linux/commit/59f60005797b4018d7b46620037e0c53d690795e kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-38570-02-gfs2-simplify-gdlm_put_lock-with-out_free-label.patch kpatch-description: gfs2: simplify gdlm_put_lock with out_free label kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-38570 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38570 kpatch-patch-url: https://github.com/torvalds/linux/commit/a9b0f6f4adb1a8b4219e3e14ab6ef46c14987ac0 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-38570-03-gfs2-Fix-potential-glock-use-after-free-on-unmount.patch kpatch-description: gfs2: Fix potential glock use-after-free on unmount kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-38570 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38570 kpatch-patch-url: https://github.com/torvalds/linux/commit/d98779e687726d8f8860f1c54b5687eec5f63a73 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-38570-03-gfs2-Fix-potential-glock-use-after-free-on-unmount-kpatch.patch kpatch-description: gfs2: Fix potential glock use-after-free on unmount kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-38570 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38570 kpatch-patch-url: https://github.com/torvalds/linux/commit/d98779e687726d8f8860f1c54b5687eec5f63a73 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-23848-media-cec-cec-adap-always-cancel-work-in-cec_transmi.patch kpatch-description: media: cec: cec-adap: always cancel work in cec_transmit_msg_fh kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-23848 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-23848 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9fe2816816a3c765dff3b88af5b5c3d9bbb911ce kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-23848-media-cec-core-avoid-recursive-cec_claim_log_addrs.patch kpatch-description: media: cec: core: avoid recursive cec_claim_log_addrs kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-23848 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-23848 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=47c82aac10a6954d68f29f10d9758d016e8e5af1 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-23848-media-cec-core-avoid-recursive-cec_claim_log_addrs-kpatch.patch kpatch-description: media: cec: core: avoid recursive cec_claim_log_addrs kpatch kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-23848 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-23848 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=47c82aac10a6954d68f29f10d9758d016e8e5af1 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-23848-media-cec-cec-api-add-locking-in-cec_release.patch kpatch-description: media: cec: cec-api: add locking in cec_release() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-23848 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-23848 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=42bcaacae924bf18ae387c3f78c202df0b739292 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40911-wifi-cfg80211-Lock-wiphy-in-cfg80211_get_station.patch kpatch-description: wifi: cfg80211: Lock wiphy in cfg80211_get_station kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40911 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40911 kpatch-patch-url: https://github.com/torvalds/linux/commit/642f89daa34567d02f312d03e41523a894906dae kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-26717-hid-i2c-hid-of-fix-null-deref-on-failed-power-up.patch kpatch-description: HID: i2c-hid-of: fix NULL-deref on failed power up kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-26717 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26717 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=00aab7dcb2267f2aef59447602f34501efe1a07f kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-26717-hid-i2c-hid-of-fix-null-deref-on-failed-power-up-kpatch.patch kpatch-description: HID: i2c-hid-of: fix NULL-deref on failed power up kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-26717 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26717 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=00aab7dcb2267f2aef59447602f34501efe1a07f kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-46984-kyber-fix-out-of-bounds-access-when-preempted.patch kpatch-description: kyber: fix out of bounds access when preempted kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-46984 kpatch-cvss: 6.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-46984 kpatch-patch-url: https://github.com/torvalds/linux/commit/efed9a3337e341bd0989161b97453b52567bc59d kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40972-0001-ext4-fold-quota-accounting-into-ext4_xattr_inode.patch kpatch-description: ext4: fold quota accounting into ext4_xattr_inode_lookup_create() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40972 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40972 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=8208c41c43ad kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40972-0002-ext4-remove-duplicate-definition-of-ext4_xattr_ibody.patch kpatch-description: ext4: remove duplicate definition of ext4_xattr_ibody_inline_set() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40972 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40972 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=310c097c2b kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40972-0003-ext4-do-not-create-EA-inode-under-buffer-lock.patch kpatch-description: ext4: do not create EA inode under buffer lock kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40972 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40972 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=0a46ef234756dc kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-35884-udp-do-not-accept-non-tunnel-gso-skbs-landing-in-a-tunnel.patch kpatch-description: udp: do not accept non-tunnel GSO skbs landing in a tunnel kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-35884 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35884 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3d010c8031e39f5fa1e8b13ada77e0321091011f kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-35884-udp-do-not-accept-non-tunnel-gso-skbs-landing-in-a-tunnel-kpatch.patch kpatch-description: udp: do not accept non-tunnel GSO skbs landing in a tunnel kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-35884 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35884 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3d010c8031e39f5fa1e8b13ada77e0321091011f kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-42246-net-sunrpc-remap-eperm-in-case-of-connection-failure-in-xs-tcp-setup-socket.patch kpatch-description: net, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-42246 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42246 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=626dfed5fa3bfb41e0dffd796032b555b69f9cde kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41005-netpoll-fix-race-condition-in-netpoll-owner-active.patch kpatch-description: netpoll: Fix race condition in netpoll_owner_active kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41005 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41005 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c2e6a872bde9912f1a7579639c5ca3adf1003916 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41013-0002-xfs-don-t-walk-off-the-end-of-a-directory-data-block.patch kpatch-description: xfs: don't walk off the end of a directory data block kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41013 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41013 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=0c7fcdb6d06cdf8b19b57c17605215b06afa864a kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40988-drm-radeon-fix-ubsan-warning-in-kv-dpm-c.patch kpatch-description: drm/radeon: fix UBSAN warning in kv_dpm.c kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40988 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40988 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a498df5421fd737d11bfd152428ba6b1c8538321 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40998-ext4-fix-uninitialized-ratelimit-state-lock-access-in-ext4-fill-super.patch kpatch-description: ext4: fix uninitialized ratelimit_state->lock access in __ext4_fill_super() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40998 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40998 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=b4b4fda34e535756f9e774fb2d09c4537b7dfd1c kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40995-net-sched-act-api-fix-possible-infinite-loop-in-tcf-idr-check-alloc.patch kpatch-description: net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40995 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40995 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=d864319871b05fadd153e0aede4811ca7008f5d6 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41014-xfs-add-bounds-checking-to-xlog-recover-process-data.patch kpatch-description: xfs: add bounds checking to xlog_recover_process_data kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41014 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41014 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=fb63435b7c7dc112b1ae1baea5486e0a6e27b196 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41007-0001-tcp-refactor-tcp_retransmit_timer.patch kpatch-description: tcp: refactor tcp_retransmit_timer() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41007 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41007 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=39dc2b8d55f kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41007-0002-net-tcp-fix-unexcepted-socket-die-when-snd_wnd-is-0.patch kpatch-description: net: tcp: fix unexcepted socket die when snd_wnd is 0 kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41007 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41007 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=ebd4da36468e kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-41007-0003-tcp-avoid-too-many-retransmit-packets.patch kpatch-description: tcp: avoid too many retransmit packets kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-41007 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41007 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=97a9063518f198ec0adb2ecb89789de342bb8283 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47455-ptp-fix-possible-memory-leak-in-ptp-clock-register.patch kpatch-description: ptp: Fix possible memory leak in ptp_clock_register() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47455 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47455 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=4225fea1cb28370086e17e82c0f69bec2779dca0 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47352-virtio-net-add-validation-for-used-length.patch kpatch-description: virtio-net: Add validation for used length kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47352 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47352 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=ad993a95c508417acdeb15244109e009e50d8758 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47383-tty-fix-out-of-bound-vmalloc-access-in-imageblit.patch kpatch-description: tty: Fix out-of-bound vmalloc access in imageblit kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47383 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47383 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3b0c406124719b625b1aba431659f5cdc24a982c kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47412-block-don-t-call-rq-qos-ops-done-bio-if-the-bio-isn-t-tracked.patch kpatch-description: block: don't call rq_qos_ops->done_bio if the bio isn't tracked kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47412 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47412 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a647a524a46736786c95cdb553a070322ca096e3 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47432-lib-generic-radix-tree-c-don-t-overflow-in-peek.patch kpatch-description: lib/generic-radix-tree.c: Don't overflow in peek() kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47432 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47432 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9492261ff2460252cf2d8de89cdf854c7e2b28a0 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47393-hwmon-mlxreg-fan-return-non-zero-value-when-fan-current-state-is-enforced-from-sysfs.patch kpatch-description: hwmon: (mlxreg-fan) Return non-zero value when fan current state is enforced from sysfs kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47393 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47393 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e6fab7af6ba1bc77c78713a83876f60ca7a4a064 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2021-47338-fbmem-do-not-delete-the-mode-that-is-still-in-use.patch kpatch-description: fbmem: Do not delete the mode that is still in use kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2021-47338 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47338 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=0af778269a522c988ef0b4188556aba97fb420cc kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-27013-tun-limit-printing-rate-when-illegal-packet-received-by-tun-dev.patch kpatch-description: tun: limit printing rate when illegal packet received by tun dev kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-27013 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27013 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f8bbc07ac535593139c875ffa19af924b1084540 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-35809-pci-pm-drain-runtime-idle-callbacks-before-driver-removal.patch kpatch-description: PCI/PM: Drain runtime-idle callbacks before driver removal kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-35809 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35809 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=47d8aafcfe313511a98f165a54d0adceb34e54b1 kpatch-name: skipped/CVE-2024-26720.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-26720 kpatch-skip-reason: This CVE introduces a regression and is reverted by CVE-2024-42102 in the same errata kpatch-cvss: kpatch-name: skipped/CVE-2024-41008.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-41008 kpatch-skip-reason: Complex adaptation required, low score patch for non critical subsystem amdgpu kpatch-cvss: kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40997-cpufreq-amd-pstate-fix-memory-leak-on-cpu-epp-exit.patch kpatch-description: cpufreq: amd-pstate: fix memory leak on CPU EPP exit kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40997 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40997 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=cea04f3d9aeebda9d9c063c0dfa71e739c322c81 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-40997-cpufreq-amd-pstate-fix-memory-leak-on-cpu-epp-exit-kpatch.patch kpatch-description: cpufreq: amd-pstate: fix memory leak on CPU EPP exit kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-40997 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40997 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=cea04f3d9aeebda9d9c063c0dfa71e739c322c81 kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-26846-nvme-fc-do-not-wait-in-vain-when-unloading-module.patch kpatch-description: nvme-fc: do not wait in vain when unloading module kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-26846 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26846 kpatch-patch-url: https://gitlab.corp.cloudlinux.com/kernelcare-els/redhat-kernel/-/commit/7b475fbbddb10719d036ebbcb4f776871283b9dd kpatch-name: rhel8/4.18.0-553.22.1.el8_10/CVE-2024-26846-nvme-fc-do-not-wait-in-vain-when-unloading-module-kpatch.patch kpatch-description: nvme-fc: do not wait in vain when unloading module kpatch-kernel: 4.18.0-553.22.1.el8_10 kpatch-cve: CVE-2024-26846 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26846 kpatch-patch-url: https://gitlab.corp.cloudlinux.com/kernelcare-els/redhat-kernel/-/commit/7b475fbbddb10719d036ebbcb4f776871283b9dd kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-42301-dev-parport-fix-the-array-out-of-bounds-risk.patch kpatch-description: dev/parport: fix the array out-of-bounds risk kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-42301 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42301 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=ab11dac93d2d568d151b1918d7b84c2d02bacbd5 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-40961-ipv6-prevent-possible-NULL-deref-in-fib6_nh_init.patch kpatch-description: ipv6: prevent possible NULL deref in fib6_nh_init() kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-40961 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40961 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2eab4543a2204092c3a7af81d7d6c506e59a03a6 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-42284-tipc-return-non-zero-value-from-tipc-udp-addr2str-on-error.patch kpatch-description: tipc: Return non-zero value from tipc_udp_addr2str() on error kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-42284 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42284 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=fa96c6baef1b5385e2f0c0677b32b3839e716076 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-41092-drm-i915-gt-fix-potential-uaf-by-revoke-of-fence-registers.patch kpatch-description: drm/i915/gt: Fix potential UAF by revoke of fence registers kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-41092 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41092 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=996c3412a06578e9d779a16b9e79ace18125ab50 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-38541-of-module-add-buffer-overflow-check-in-of-modalias.patch kpatch-description: of: module: add buffer overflow check in of_modalias() kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-38541 kpatch-cvss: 9.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38541 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=cf7385cb26ac4f0ee6c7385960525ad534323252 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-27062-nouveau-lock-the-client-object-tree.patch kpatch-description: nouveau: lock the client object tree kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-27062 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27062 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=b7cc4ff787a572edf2c55caeffaa88cd801eb135 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-27062-nouveau-lock-the-client-object-tree-kpatch.patch kpatch-description: nouveau: lock the client object tree kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-27062 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27062 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=b7cc4ff787a572edf2c55caeffaa88cd801eb135 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-26976-kvm-always-flush-async-pf-workqueue-when-vcpu-is-being-destroyed.patch kpatch-description: KVM: Always flush async #PF workqueue when vCPU is being destroyed kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-26976 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26976 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3d75b8aa5c29058a512db29da7cbee8052724157 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-26976-kvm-always-flush-async-pf-workqueue-when-vcpu-is-being-destroyed-kpatch.patch kpatch-description: KVM: Always flush async #PF workqueue when vCPU is being destroyed kpatch-kernel: kernel-4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-26976 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26976 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3d75b8aa5c29058a512db29da7cbee8052724157 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-38608-net-mlx5e-Add-wrapping-for-auxiliary_driver-ops-and.patch kpatch-description: net/mlx5e: Add wrapping for auxiliary_driver op and remove unused args kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-38608 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38608 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=b1a33e65134786b9ef97f978572531c6004c8526 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-38608-net-mlx5e-Fix-netif-state-handling.patch kpatch-description: net/mlx5e: Fix netif state handling kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-38608 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38608 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3d5918477f94e4c2f064567875c475468e264644 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-38540-bnxt_re-avoid-shift-undefined-behavior-in-bnxt_qplib.patch kpatch-description: bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-38540 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38540 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=78cfd17142ef70599d6409cbd709d94b3da58659 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-38586-r8169-Fix-possible-ring-buffer-corruption-on-fragmen.patch kpatch-description: r8169: Fix possible ring buffer corruption on fragmented Tx packets. kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-38586 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38586 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c71e3a5cffd5309d7f84444df03d5b72600cc417 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-40983-tipc-force-a-dst-refcount-before-doing-decryption.patch kpatch-description: tipc: force a dst refcount before doing decryption kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-40983 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40983 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2ebe8f840c7450ecbfca9d18ac92e9ce9155e269 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-40924-drm-i915-dpt-Make-DPT-object-unshrinkable.patch kpatch-description: drm/i915/dpt: Make DPT object unshrinkable kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-40924 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40924 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=43e2b37e2ab660c3565d4cff27922bc70e79c3f1 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-40984-ACPICA-Revert-ACPICA-avoid-Info-mapping-multiple-BAR.patch kpatch-description: ACPICA: Revert "ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine." kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-40984 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40984 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a83e1385b780d41307433ddbc86e3c528db031f0 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-41042-netfilter-nf_tables-prefer-nft_chain_validate.patch kpatch-description: netfilter: nf_tables: prefer nft_chain_validate kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-41042 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41042 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=cff3bd012a9512ac5ed858d38e6ed65f6391008c kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-46826-elf-fix-kernel-randomize-va-space-double-read.patch kpatch-description: ELF: fix kernel.randomize_va_space double read kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-46826 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-46826 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2a97388a807b6ab5538aa8f8537b2463c6988bd2 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-41009-bpf-Fix-overrunning-reservations-in-ringbuf.patch kpatch-description: bpf: Fix overrunning reservations in ringbuf kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-41009 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41009 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=cfa1a2329a691ffd991fcf7248a57d752e712881 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-41009-bpf-Fix-overrunning-reservations-in-ringbuf-kpatch.patch kpatch-description: bpf: Fix overrunning reservations in ringbuf (adaptation) kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-41009 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41009 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=cfa1a2329a691ffd991fcf7248a57d752e712881 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-44935-sctp-fix-null-ptr-deref-in-reuseport-add-sock.patch kpatch-description: sctp: Fix null-ptr-deref in reuseport_add_sock(). kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-44935 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-44935 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9ab0faa7f9ffe31296dbb9bbe6f76c72c14eea18 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-45018-netfilter-flowtable-initialise-extack-before-use.patch kpatch-description: netfilter: flowtable: initialise extack before use kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-45018 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-45018 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e9767137308daf906496613fd879808a07f006a2 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2023-52492-dmaengine-fix-null-pointer-in-channel-unregistration-function.patch kpatch-description: dmaengine: fix NULL pointer in channel unregistration function kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2023-52492 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52492 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f5c24d94512f1b288262beda4d3dcb9629222fc7 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-44990-bonding-fix-null-pointer-deref-in-bond-ipsec-offload-ok.patch kpatch-description: bonding: fix null pointer deref in bond_ipsec_offload_ok kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-44990 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-44990 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=95c90e4ad89d493a7a14fa200082e466e2548f9d kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-47668-lib-generic-radix-tree-c-fix-rare-race-in-genradix-ptr-alloc.patch kpatch-description: lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc() kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-47668 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-47668 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=b2f11c6f3e1fc60742673b8675c95b78447f3dae kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-44989-bonding-fix-xfrm-real-dev-null-pointer-dereference.patch kpatch-description: bonding: fix xfrm real_dev null pointer dereference kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-44989 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-44989 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f8cde9805981c50d0c029063dc7d82821806fc44 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-41066-ibmvnic-rename-local-variable-index-to-bufidx.patch kpatch-description: ibmvnic: rename local variable index to bufidx kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-41066 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41066 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=0983d288caf984de0202c66641577b739caad561 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-41066-ibmvnic-add-tx-check-to-prevent-skb-leak.patch kpatch-description: ibmvnic: Add tx check to prevent skb leak kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-41066 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41066 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=0983d288caf984de0202c66641577b739caad561 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-41093-drm-amdgpu-avoid-using-null-object-of-framebuffer.patch kpatch-description: drm/amdgpu: avoid using null object of framebuffer kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-41093 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41093 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=bcfa48ff785bd121316592b131ff6531e3e696bb kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-42070-netfilter-nf-tables-fully-validate-nft-data-value-on-store-to-data-registers.patch kpatch-description: netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-42070 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42070 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=7931d32955e09d0a11b1fe0b6aac1bfa061c005c kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-42079-gfs2-fix-null-pointer-dereference-in-gfs2-log-flush.patch kpatch-description: gfs2: Fix NULL pointer dereference in gfs2_log_flush kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-42079 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42079 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=35264909e9d1973ab9aaa2a1b07cda70f12bb828 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-42244-usb-serial-mos7840-fix-crash-on-resume.patch kpatch-description: USB: serial: mos7840: fix crash on resume kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-42244 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42244 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c15a688e49987385baa8804bf65d570e362f8576 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-42244-usb-serial-mos7840-fix-crash-on-resume-kpatch.patch kpatch-description: USB: serial: mos7840: fix crash on resume kpatch kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-42244 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42244 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c15a688e49987385baa8804bf65d570e362f8576 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-42292-kobject-uevent-fix-oob-access-within-zap-modalias-env.patch kpatch-description: kobject_uevent: Fix OOB access within zap_modalias_env() kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-42292 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-42292 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=dd6e9894b451e7c85cceb8e9dc5432679a70e7dc kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-43854-block-initialize-integrity-buffer-to-zero-before-writing-it-to-media.patch kpatch-description: block: initialize integrity buffer to zero before writing it to media kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-43854 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-43854 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=899ee2c3829c5ac14bfc7d3c4a5846c0b709b78f kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-43880-mlxsw-spectrum-acl-erp-fix-object-nesting-warning.patch kpatch-description: mlxsw: spectrum_acl_erp: Fix object nesting warning kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-43880 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-43880 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=97d833ceb27dc19f8777d63f90be4a27b5daeedf kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-43880-mlxsw-spectrum-acl-erp-fix-object-nesting-warning-kpatch.patch kpatch-description: mlxsw: spectrum_acl_erp: Fix object nesting warning kpatch kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-43880 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-43880 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=97d833ceb27dc19f8777d63f90be4a27b5daeedf kpatch-name: skipped/CVE-2024-43889.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-43889 kpatch-skip-reason: Out of scope: This CVE modified the __init function which won't be available to patch as it is used during bootup time. kpatch-cvss: kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-26924-netfilter-nft-set-pipapo-do-not-free-live-element.patch kpatch-description: netfilter: nft_set_pipapo: do not free live element kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-26924 kpatch-cvss: 5.9 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26924 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3cfc9ec039af60dbd8965ae085b2c2ccdcfbe1cc kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-35898-netfilter-nf-tables-fix-potential-data-race-in-nft-flowtable-type-get.patch kpatch-description: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-35898 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35898 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=24225011d81b471acc0e1e315b7d9905459a6304 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2022-48773-xprtrdma-fix-pointer-derefs-in-error-cases-of-rpcrdma-ep-create.patch kpatch-description: xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2022-48773 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-48773 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a9c10b5b3b67b3750a10c8b089b2e05f5e176e33 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-35939-dma-direct-leak-pages-on-dma-set-decrypted-failure.patch kpatch-description: dma-direct: Leak pages on dma_set_decrypted() failure kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-35939 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-35939 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=b9fa16949d18e06bdf728a560f5c8af56d2bdcaf kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-43892-mm-memcg-minor-cleanup-for-mem-cgroup-id-max.patch kpatch-description: mm/memcg: minor cleanup for MEM_CGROUP_ID_MAX kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-43892 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-43892 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9972605a238339b85bd16b084eed5f18414d22db kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-43892-mm-memcontrol-fix-cannot-alloc-the-maximum-memcg-id.patch kpatch-description: mm: memcontrol: fix cannot alloc the maximum memcg ID kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-43892 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-43892 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9972605a238339b85bd16b084eed5f18414d22db kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-43892-memcontrol-ensure-memcg-acquired-by-id-is-properly-set-up.patch kpatch-description: memcontrol: ensure memcg acquired by id is properly set up kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-43892 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-43892 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9972605a238339b85bd16b084eed5f18414d22db kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-43892-memcg-protect-concurrent-access-to-mem_cgroup_idr.patch kpatch-description: memcg: protect concurrent access to mem_cgroup_idr kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-43892 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-43892 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=37a060b64ae83b76600d187d76591ce488ab836b kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-43892-memcg-protect-concurrent-access-to-mem_cgroup_idr-kpatch.patch kpatch-description: memcg: protect concurrent access to mem_cgroup_idr kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-43892 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-43892 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=37a060b64ae83b76600d187d76591ce488ab836b kpatch-name: skipped/CVE-2024-35839.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-35839 kpatch-skip-reason: Live-patching will introduce network performance degradation in the best case scenario, or even some more serious issues. N/A or Low cvss3 score from NVD or vendors. kpatch-cvss: kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-24857-bluetooth-fix-toctou-in-hci-debugfs-implementation.patch kpatch-description: Bluetooth: Fix TOCTOU in HCI debugfs implementation kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-24857 kpatch-cvss: 6.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-24857 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=7835fcfd132eb88b87e8eb901f88436f63ab60f7 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-26851-netfilter-nf_conntrack_h323-add-protection-for-bmp-length-out-of-range.patch kpatch-description: netfilter: nf_conntrack_h323: Add protection for bmp length out of kpatch-kernel: kpatch-cve: CVE-2024-26851 kpatch-cvss: 5.5 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=014a807f1cc9c9d5173c1cd935835553b00d211c kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2022-48936-gso-do-not-skip-outer-ip-header-in-case-of-ipip-and-net-failover.patch kpatch-description: gso: do not skip outer ip header in case of ipip and net_failover kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2022-48936 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-48936 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=cc20cced0598d9a5ff91ae4ab147b3b5e99ee819 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-27017-netfilter-nftables-add-helper-function-to-flush-set-elements.patch kpatch-description: netfilter: nftables: add helper function to flush set elements kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-27017 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27017 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=29b359cf6d95fd60730533f7f10464e95bd17c73 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-27017-netfilter-nft-set-pipapo-walk-over-current-view-on-netlink-dump.patch kpatch-description: netfilter: nft_set_pipapo: walk over current view on netlink dump kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-27017 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27017 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=29b359cf6d95fd60730533f7f10464e95bd17c73 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-27017-netfilter-nf-tables-missing-iterator-type-in-lookup-walk.patch kpatch-description: netfilter: nf_tables: missing iterator type in lookup walk kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-27017 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27017 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=29b359cf6d95fd60730533f7f10464e95bd17c73 kpatch-name: rhel8/4.18.0-553.27.1.el8_10/CVE-2024-27017-netfilter-nft-set-pipapo-walk-over-current-view-on-netlink-dump-kpatch.patch kpatch-description: netfilter: nft_set_pipapo: walk over current view on netlink dump kpatch-kernel: 4.18.0-553.27.1.el8_10 kpatch-cve: CVE-2024-27017 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27017 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=29b359cf6d95fd60730533f7f10464e95bd17c73 kpatch-name: rhel8/4.18.0-553.30.1.el8_10/CVE-2024-27399-bluetooth-l2cap-fix-null-ptr-deref-in-l2cap-chan-timeout.patch kpatch-description: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout kpatch-kernel: 4.18.0-553.30.1.el8_10 kpatch-cve: CVE-2024-27399 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27399 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=6466ee65e5b27161c846c73ef407f49dfa1bd1d9 kpatch-name: rhel8/4.18.0-553.30.1.el8_10/CVE-2024-38564-bpf-add-bpf-prog-type-cgroup-skb-attach-type-enforcement-in-bpf-link-create.patch kpatch-description: bpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE kpatch-kernel: 4.18.0-553.30.1.el8_10 kpatch-cve: CVE-2024-38564 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-38564 kpatch-patch-url: https://github.com/torvalds/linux/commit/543576ec15b17c0c93301ac8297333c7b6e84ac7 kpatch-name: rhel8/4.18.0-553.30.1.el8_10/CVE-2024-46858-mptcp-pm-fix-uaf-in-timer-delete-sync.patch kpatch-description: mptcp: pm: Fix uaf in __timer_delete_sync kpatch-kernel: 4.18.0-553.30.1.el8_10 kpatch-cve: CVE-2024-46858 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-46858 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=0e7814b028cd50b3ff79659d23dfa9da6a1e75e1 kpatch-name: rhel8/4.18.0-553.30.1.el8_10/CVE-2024-27043-media-edia-dvbdev-fix-a-use-after-free.patch kpatch-description: media: edia: dvbdev: fix a use-after-free kpatch-kernel: 4.18.0-553.30.1.el8_10 kpatch-cve: CVE-2024-27043 kpatch-cvss: 5.2 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-27043 kpatch-patch-url: https://github.com/torvalds/linux/commit/8c64f4cdf4e6cc5682c52523713af8c39c94e6d5 kpatch-name: rhel8/4.18.0-553.32.1.el8_10/CVE-2024-50264-vsock-virtio-initialization-of-the-dangling-pointer-occurring-in-vsk-trans.patch kpatch-description: vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans kpatch-kernel: 4.18.0-553.32.1.el8_10 kpatch-cve: CVE-2024-50264 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-50264 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=fd8ae346692a56b4437d626c5460c7104980f389 kpatch-name: rhel8/4.18.0-553.32.1.el8_10/CVE-2024-50082-blk-rq-qos-fix-crash-on-rq-qos-wait-vs-rq-qos-wake-function-race.patch kpatch-description: blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race kpatch-kernel: 4.18.0-553.32.1.el8_10 kpatch-cve: CVE-2024-50082 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-50082 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=4c5b123ab289767afe940389dbb963c5c05e594e kpatch-name: rhel8/4.18.0-553.32.1.el8_10/CVE-2024-50256-netfilter-nf-reject-ipv6-fix-potential-crash-in-nf-send-reset6-553.22.patch kpatch-description: netfilter: nf_reject_ipv6: fix potential crash in nf_send_reset6() kpatch-kernel: 4.18.0-553.32.1.el8_10 kpatch-cve: CVE-2024-50256 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-50256 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=fef63832317d9d24e1214cdd8f204d02ebdf8499 kpatch-name: rhel8/4.18.0-553.32.1.el8_10/CVE-2024-46695-selinux-smack-don-t-bypass-permissions-check-in-inode-setsecctx-hook.patch kpatch-description: selinux,smack: don't bypass permissions check in inode_setsecctx hook kpatch-kernel: 4.18.0-553.32.1.el8_10 kpatch-cve: CVE-2024-46695 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-46695 kpatch-patch-url: https://github.com/torvalds/linux/commit/76a0e79bc84f466999fa501fce5bf7a07641b8a7 kpatch-name: rhel8/4.18.0-553.32.1.el8_10/CVE-2024-49949-net-avoid-potential-underflow-in-qdisc-pkt-len-init-with-ufo.patch kpatch-description: net: avoid potential underflow in qdisc_pkt_len_init() with UFO kpatch-kernel: 4.18.0-553.32.1.el8_10 kpatch-cve: CVE-2024-49949 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-49949 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=d70ca7598943572d5e384227bd268acb5109bf72 kpatch-name: rhel8/4.18.0-553.32.1.el8_10/CVE-2024-50142-xfrm-validate-new-sa-s-prefixlen-using-sa-family-when-sel-family-is-unset.patch kpatch-description: xfrm: validate new SA's prefixlen using SA family when sel.family is unset kpatch-kernel: 4.18.0-553.32.1.el8_10 kpatch-cve: CVE-2024-50142 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-50142 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=f31398570acf0f0804c644006f7bfa9067106b0a kpatch-name: rhel8/4.18.0-553.32.1.el8_10/CVE-2024-50110-xfrm-fix-one-more-kernel-infoleak-in-algo-dumping.patch kpatch-description: xfrm: fix one more kernel-infoleak in algo dumping kpatch-kernel: 4.18.0-553.32.1.el8_10 kpatch-cve: CVE-2024-50110 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-50110 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=c73bca72b84b453c8d26a5e7673b20adb294bf54 kpatch-name: skipped/CVE-2024-50192.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-50192 kpatch-skip-reason: arm64: Low-score CVE requiring adaptation that is hard to implement; targets very rare hardware kpatch-cvss: kpatch-name: rhel8/4.18.0-553.34.1.el8_10/CVE-2024-53088-i40e-fix-i40e_count_filters-to-count-only-active-new.patch kpatch-description: i40e: fix i40e_count_filters() to count only active/new filters kpatch-kernel: 4.18.0-553.34.1.el8_10 kpatch-cve: CVE-2024-53088 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-53088 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=eb58c598ce45b7e787568fe27016260417c3d807 kpatch-name: rhel8/4.18.0-553.34.1.el8_10/CVE-2024-53088-i40e-fix-race-condition-by-adding-filter-s-intermediate-sync-state.patch kpatch-description: i40e: fix race condition by adding filter's intermediate sync state kpatch-kernel: 4.18.0-553.34.1.el8_10 kpatch-cve: CVE-2024-53088 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-53088 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=f30490e9695ef7da3d0899c6a0293cc7cd373567 kpatch-name: rhel8/4.18.0-553.34.1.el8_10/CVE-2024-53088-i40e-fix-race-condition-by-adding-filter-s-intermediate-sync-state-kpatch.patch kpatch-description: i40e: fix race condition by adding filter's intermediate sync state kpatch-kernel: 4.18.0-553.34.1.el8_10 kpatch-cve: CVE-2024-53088 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-53088 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=f30490e9695ef7da3d0899c6a0293cc7cd373567 kpatch-name: rhel8/4.18.0-553.34.1.el8_10/CVE-2024-53122-mptcp-cope-racing-subflow-creation-in-mptcp-rcv-space-adjust.patch kpatch-description: mptcp: cope racing subflow creation in mptcp_rcv_space_adjust kpatch-kernel: 4.18.0-553.34.1.el8_10 kpatch-cve: CVE-2024-53122 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-53122 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=24995851d58c4a205ad0ffa7b2f21e479a9c8527 kpatch-name: rhel8/4.18.0-553.37.1.el8_10/CVE-2024-26935-scsi-core-fix-unremoved-procfs-host-directory-regression.patch kpatch-description: scsi: core: Fix unremoved procfs host directory regression kpatch-kernel: 4.18.0-553.37.1.el8_10 kpatch-cve: CVE-2024-26935 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26935 kpatch-patch-url: https://github.com/torvalds/linux/commit/f23a4d6e07570826fe95023ca1aa96a011fa9f84 kpatch-name: rhel8/4.18.0-553.40.1.el8_10/CVE-2024-53104-media-uvcvideo-Skip-parsing-frames-of-type-UVC_VS_UNDEFINED.patch kpatch-description: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format kpatch-kernel: 4.18.0-553.40.1.el8_10 kpatch-cve: CVE-2024-53104 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-53104 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=beced2cb09b58c1243733f374c560a55382003d6 kpatch-name: 2024/CVE-2024-50302/CVE-2024-50302-hid-core-zero-initialize-the-report-buffer.patch kpatch-description: HID: core: zero-initialize the report buffer kpatch-kernel: 4.18.0-553.44.1.el8_10 kpatch-cve: CVE-2024-50302 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/cve-2024-50302 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=177f25d1292c7e16e1199b39c85480f7f8815552 kpatch-name: 2024/CVE-2024-53197/CVE-2024-53197-alsa-usb-audio-fix-potential-out-of-bound-accesses-for-extigy-and-mbox-devices.patch kpatch-description: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices kpatch-kernel: 4.18.0-553.44.1.el8_10 kpatch-cve: CVE-2024-53197 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/cve-2024-53197 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=b909df18ce2a998afef81d58bbd1a05dc0788c40 kpatch-name: 2024/CVE-2024-57807/CVE-2024-57807-scsi-megaraid-sas-fix-for-a-potential-deadlock.patch kpatch-description: scsi: megaraid_sas: Fix for a potential deadlock kpatch-kernel: 4.18.0-553.44.1.el8_10 kpatch-cve: CVE-2024-57807 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/cve-2024-57807 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f36d024bd15ed356a80dda3ddc46d0a62aa55815 kpatch-name: skipped/CVE-2024-57979.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2024-57979 kpatch-skip-reason: PPS for embedded GPS devices. Irrelevant for servers. kpatch-cvss: kpatch-name: rhel8/4.18.0-553.45.1.el8_10/CVE-2023-52922-can-bcm-Fix-UAF-in-bcm_proc_show.patch kpatch-description: can: bcm: Fix UAF in bcm_proc_show() kpatch-kernel: 4.18.0-553.45.1.el8_10 kpatch-cve: CVE-2023-52922 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-52922 kpatch-patch-url: https://github.com/torvalds/linux/commit/55c3b96074f3f9b0aee19bf93cd71af7516582bb kpatch-name: skipped/CVE-2025-21785.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2025-21785 kpatch-skip-reason: Out of scope: ARM64 architecture isn't supported for current kernel kpatch-cvss: kpatch-name: rhel8/4.18.0-553.50.1.el8_10/CVE-2024-53150-alsa-usb-audio-fix-out-of-bounds-reads-when-finding-clock-sources.patch kpatch-description: ALSA: usb-audio: Fix out of bounds reads when finding clock sources kpatch-kernel: 4.18.0-553.50.1.el8_10 kpatch-cve: CVE-2024-53150 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-53150 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=da13ade87a12dd58829278bc816a61bea06a56a9 kpatch-name: rhel8/4.18.0-553.52.1.el8_10/CVE-2024-53141-netfilter-ipset-add-missing-range-check-in-bitmap-ip-uadt.patch kpatch-description: netfilter: ipset: add missing range check in bitmap_ip_uadt kpatch-kernel: 4.18.0-553.52.1.el8_10 kpatch-cve: CVE-2024-53141 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-53141 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=35f56c554eb1b56b77b3cf197a6b00922d49033d kpatch-name: rhel8/4.18.0-553.52.1.el8_10/CVE-2022-49011-hwmon-coretemp-fix-pci-device-refcount-leak-in-nv1a_.patch kpatch-description: hwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new() kpatch-kernel: 4.18.0-553.52.1.el8_10 kpatch-cve: CVE-2022-49011 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-49011 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=6e035d5a2a6b907cfce9a80c5f442c2e459cd34e kpatch-name: rhel8/4.18.0-553.53.1.el8_10/CVE-2024-40906-net-mlx5-always-stop-health-timer-during-driver-removal.patch kpatch-description: net/mlx5: Always stop health timer during driver removal kpatch-kernel: 4.18.0-553.53.1.el8_10 kpatch-cve: CVE-2024-40906 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-40906 kpatch-patch-url: https://github.com/torvalds/linux/commit/c8b3f38d2dae0397944814d691a419c451f9906f kpatch-name: rhel8/4.18.0-553.53.1.el8_10/CVE-2024-44970-net-mlx5e-SHAMPO-Fix-invalid-WQ-linked-list-unlink.patch kpatch-description: net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink kpatch-kernel: 4.18.0-553.53.1.el8_10 kpatch-cve: CVE-2024-44970 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-44970 kpatch-patch-url: https://github.com/torvalds/linux/commit/fba8334721e266f92079632598e46e5f89082f30 kpatch-name: rhel8/4.18.0-553.53.1.el8_10/CVE-2025-21756-vsock-keep-the-binding-until-socket-destruction.patch kpatch-description: vsock: Keep the binding until socket destruction kpatch-kernel: 4.18.0-553.53.1.el8_10 kpatch-cve: CVE-2025-21756 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-21756 kpatch-patch-url: https://github.com/torvalds/linux/commit/fcdd2242c0231032fc84e1404315c245ae56322a kpatch-name: rhel8/4.18.0-553.53.1.el8_10/CVE-2025-21756-vsock-orphan-socket-after-transport-release.patch kpatch-description: vsock: Orphan socket after transport release kpatch-kernel: 4.18.0-553.53.1.el8_10 kpatch-cve: CVE-2025-21756 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-21756 kpatch-patch-url: https://github.com/torvalds/linux/commit/78dafe1cf3afa02ed71084b350713b07e72a18fb kpatch-name: rhel8/4.18.0-553.54.1.el8_10/CVE-2024-43842-wifi-rtw89-Fix-array-index-mistake-in-rtw89_sta_info_get_iter.patch kpatch-description: wifi: rtw89: Fix array index mistake in rtw89_sta_info_get_iter() kpatch-kernel: 4.18.0-553.54.1.el8_10 kpatch-cve: CVE-2024-43842 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-43842 kpatch-patch-url: https://github.com/torvalds/linux/commit/85099c7ce4f9e64c66aa397cd9a37473637ab891 kpatch-name: skipped/CVE-2022-49395.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2022-49395 kpatch-skip-reason: Out of scope: User-mode Linux isn't supported for current kernel kpatch-cvss: kpatch-name: rhel8/4.18.0-553.58.1.el8_10/CVE-2022-48919-cifs-fix-double-free-race-when-mount-fails-in-cifs_get_root.patch kpatch-description: cifs: fix double free race when mount fails in cifs_get_root() kpatch-kernel: 4.18.0-553.58.1.el8_10 kpatch-cve: CVE-2022-48919 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-48919 kpatch-patch-url: https://github.com/torvalds/linux/commit/3d6cc9898efdfb062efb74dc18cfc700e082f5d5 kpatch-name: rhel8/4.18.0-553.58.1.el8_10/CVE-2024-50301-security-keys-fix-slab-out-of-bounds-in-key_task_permission.patch kpatch-description: security/keys: fix slab-out-of-bounds in key_task_permission kpatch-kernel: 4.18.0-553.58.1.el8_10 kpatch-cve: CVE-2024-50301 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-50301 kpatch-patch-url: https://github.com/torvalds/linux/commit/4a74da044ec9ec8679e6beccc4306b936b62873f kpatch-name: rhel8/4.18.0-553.58.1.el8_10/CVE-2024-53064-idpf-fix-idpf_vc_core_init-error-path.patch kpatch-description: idpf: fix idpf_vc_core_init error path kpatch-kernel: 4.18.0-553.58.1.el8_10 kpatch-cve: CVE-2024-53064 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-53064 kpatch-patch-url: https://github.com/torvalds/linux/commit/9b58031ff96b84a38d7b73b23c7ecfb2e0557f43 kpatch-name: rhel8/4.18.0-553.58.1.el8_10/CVE-2025-21764-ndisc-use-rcu-protection-in-ndisc_alloc_skb.patch kpatch-description: ndisc: use RCU protection in ndisc_alloc_skb() kpatch-kernel: 4.18.0-553.58.1.el8_10 kpatch-cve: CVE-2025-21764 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-21764 kpatch-patch-url: https://github.com/torvalds/linux/commit/628e6d18930bbd21f2d4562228afe27694f66da9 kpatch-name: rhel8/4.18.0-553.58.1.el8_10/CVE-2025-38053-idpf-fix-null-ptr-deref-in-idpf-features-check-kpatch.patch kpatch-description: idpf: fix null-ptr-deref in idpf_features_check kpatch-kernel: 4.18.0-553.58.1.el8_10 kpatch-cve: CVE-2025-38053 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38053 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=2dabe349f7882ff1407a784d54d8541909329088 kpatch-name: rhel8/4.18.0-553.58.1.el8_10/CVE-2023-53230-smb-client-fix-warning-in-cifs_smb3_do_mount.patch kpatch-description: smb: client: fix warning in cifs_smb3_do_mount() kpatch-kernel: 4.18.0-553.58.1.el8_10 kpatch-cve: CVE-2023-53230 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53230 kpatch-patch-url: https://github.com/torvalds/linux/commit/12c30f33cc6769bf411088a2872843c4f9ea32f9 kpatch-name: rhel8/4.18.0-553.58.1.el8_10/CVE-2025-22116-idpf-check-error-for-register_netdev-on-init.patch kpatch-description: idpf: check error for register_netdev() on init kpatch-kernel: 4.18.0-553.58.1.el8_10 kpatch-cve: CVE-2025-22116 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-22116 kpatch-patch-url: https://github.com/torvalds/linux/commit/680811c67906191b237bbafe7dabbbad64649b39 kpatch-name: rhel8/4.18.0-553.60.1.el8_10/CVE-2022-49111-bluetooth-fix-use-after-free-in-hci_send_acl.patch kpatch-description: Bluetooth: Fix use after free in hci_send_acl kpatch-kernel: 4.18.0-553.60.1.el8_10 kpatch-cve: CVE-2022-49111 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-49111 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f63d24baff787e13b723d86fe036f84bdbc35045 kpatch-name: rhel8/4.18.0-553.60.1.el8_10/CVE-2022-49846-udf-fix-a-slab-out-of-bounds-write-bug-in-udf_find_entry.patch kpatch-description: udf: Fix a slab-out-of-bounds write bug in udf_find_entry() kpatch-kernel: 4.18.0-553.60.1.el8_10 kpatch-cve: CVE-2022-49846 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-49846 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=583fdd98d94acba1e7225e5cc29063aef0741030 kpatch-name: rhel8/4.18.0-553.60.1.el8_10/CVE-2022-49058-cifs-potential-buffer-overflow-in-handling-symlinks.patch kpatch-description: cifs: potential buffer overflow in handling symlinks kpatch-kernel: 4.18.0-553.62.1.el8_10 kpatch-cve: CVE-2022-49058 kpatch-cvss: 5.5 kpatch-cve-url: http://access.redhat.com/security/cve/cve-2022-49058 kpatch-patch-url: https://git.kernel.org/stable/c/1316c28569a80ab3596eeab05bf5e01991e7e739 kpatch-name: rhel8/4.18.0-553.60.1.el8_10/CVE-2024-57980-media-uvcvideo-fix-double-free-in-error-path.patch kpatch-description: media: uvcvideo: Fix double free in error path kpatch-kernel: 4.18.0-553.62.1.el8_10 kpatch-cve: CVE-2024-57980 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/cve-2024-57980 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=3ba8884a56a3eb97c22f0ce0e4dd410d4ca4c277 kpatch-name: rhel8/4.18.0-553.60.1.el8_10/CVE-2025-21991-x86-microcode-amd-fix-out-of-bounds-on-systems-with-cpu-less-numa-nodes.patch kpatch-description: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes kpatch-kernel: 4.18.0-553.62.1.el8_10 kpatch-cve: CVE-2025-21991 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/cve-2025-21991 kpatch-patch-url: https://git.kernel.org/stable/c/488ffc0cac38f203979f83634236ee53251ce593 kpatch-name: rhel8/4.18.0-553.60.1.el8_10/CVE-2025-22004-net-atm-fix-use-after-free-in-lec-send.patch kpatch-description: net: atm: fix use after free in lec_send() kpatch-kernel: 4.18.0-553.62.1.el8_10 kpatch-cve: CVE-2025-22004 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/cve-2025-22004 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=51e8be9578a2e74f9983d8fd8de8cafed191f30c kpatch-name: rhel8/4.18.0-553.60.1.el8_10/CVE-2022-49788-misc-vmw_vmci-fix-an-infoleak-in-vmci_host_do_receive_datagram.patch kpatch-description: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() kpatch-kernel: 4.18.0-553.62.1.el8_10 kpatch-cve: CVE-2022-49788 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/cve-2022-49788 kpatch-patch-url: https://git.kernel.org/stable/c/5a275528025ae4bc7e2232866856dfebf84b2fad kpatch-name: rhel8/4.18.0-553.60.1.el8_10/CVE-2025-23150-ext4-fix-off-by-one-error-in-do-split.patch kpatch-description: ext4: fix off-by-one error in do_split kpatch-kernel: 4.18.0-553.62.1.el8_10 kpatch-cve: CVE-2025-23150 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-23150 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=94824ac9a8aaf2fb3c54b4bdde842db80ffa555d kpatch-name: rhel8/4.18.0-553.60.1.el8_10/CVE-2025-37738-ext4-ignore-xattrs-past-end.patch kpatch-description: ext4: ignore xattrs past end kpatch-kernel: 4.18.0-553.62.1.el8_10 kpatch-cve: CVE-2025-37738 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-37738 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c8e008b60492cf6fd31ef127aea6d02fd3d314cd kpatch-name: rhel8/4.18.0-553.60.1.el8_10/CVE-2024-58002-media-uvcvideo-Only-save-async-fh-if-success.patch kpatch-description: media: uvcvideo: Remove dangling pointers kpatch-kernel: 4.18.0-553.62.1.el8_10 kpatch-cve: CVE-2024-58002 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-58002 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ac18d781466252cd35a3e311e0a4b264260fd927 kpatch-name: rhel8/4.18.0-553.60.1.el8_10/CVE-2024-58002-media-uvcvideo-remove-dangling-pointers.patch kpatch-description: media: uvcvideo: Remove dangling pointers kpatch-kernel: 4.18.0-553.62.1.el8_10 kpatch-cve: CVE-2024-58002 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-58002 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ac18d781466252cd35a3e311e0a4b264260fd927 kpatch-name: rhel8/4.18.0-553.60.1.el8_10/CVE-2024-58002-media-uvcvideo-remove-dangling-pointers-kpatch.patch kpatch-description: media: uvcvideo: Remove dangling pointers kpatch-kernel: 4.18.0-553.62.1.el8_10 kpatch-cve: CVE-2024-58002 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-58002 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ac18d781466252cd35a3e311e0a4b264260fd927 kpatch-name: rhel8/4.18.0-553.60.1.el8_10/CVE-2024-58002-convert-guard-mutex.patch kpatch-description: media: uvcvideo: Remove dangling pointers kpatch-kernel: 4.18.0-553.62.1.el8_10 kpatch-cve: CVE-2024-58002 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-58002 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ac18d781466252cd35a3e311e0a4b264260fd927 kpatch-name: rhel8/4.18.0-553.63.1.el8_10/CVE-2024-50154-tcp-dccp-Don-t-use-timer_pending-in-reqsk_queue_unli.patch kpatch-description: tcp/dccp: Don't use timer_pending() in reqsk_queue_unlink(). kpatch-kernel: 4.18.0-553.63.1.el8_10 kpatch-cve: CVE-2024-50154 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-50154 kpatch-patch-url: https://git.kernel.org/linus/e8c526f2bdf1845bedaf6a478816a3d06fa78b8f kpatch-name: rhel8/4.18.0-553.63.1.el8_10/CVE-2025-38086-net-ch9200-fix-uninitialised-access-during-mii_nway_restart.patch kpatch-description: net: ch9200: fix uninitialised access during mii_nway_restart kpatch-kernel: 4.18.0-553.63.1.el8_10 kpatch-cve: CVE-2025-38086 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38086 kpatch-patch-url: https://git.kernel.org/linus/9ad0452c0277b816a435433cca601304cfac7c21 kpatch-name: rhel8/4.18.0-553.64.1.el8_10/CVE-2025-21919-sched-fair-fix-potential-memory-corruption-in-child-cfs-rq-on-list.patch kpatch-description: sched/fair: Fix potential memory corruption in child_cfs_rq_on_list kpatch-kernel: kernel-4.18.0-553.63.1.el8_10 kpatch-cve: CVE-2025-21919 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-21919 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3b4035ddbfc8e4521f85569998a7569668cccf51 kpatch-name: rhel8/4.18.0-553.64.1.el8_10/CVE-2025-21905-wifi-iwlwifi-limit-printed-string-from-fw-file.patch kpatch-description: wifi: iwlwifi: limit printed string from FW file kpatch-kernel: kernel-4.18.0-553.63.1.el8_10 kpatch-cve: CVE-2025-21905 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-21905 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e0dc2c1bef722cbf16ae557690861e5f91208129 kpatch-name: rhel8/4.18.0-553.64.1.el8_10/CVE-2022-49977-ftrace-Fix-NULL-pointer-dereference-in-is_ftrace_trampoline-when-ftrace-is-dead.patch kpatch-description: ftrace: Fix NULL pointer dereference in is_ftrace_trampoline when ftrace is dead kpatch-kernel: 4.18.0-553.64.1.el8_10 kpatch-cve: CVE-2022-49977 kpatch-cvss: 7 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-49977 kpatch-patch-url: https://git.kernel.org/stable/c/8569b4ada1e0b9bfaa125bd0c0967918b6560fa2 kpatch-name: rhel8/4.18.0-553.66.1.el8_10/CVE-2025-21928-hid-intel-ish-hid-fix-use-after-free-issue-in-ishtp-hid-remove.patch kpatch-description: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() kpatch-kernel: 4.18.0-553.66.1.el8_10 kpatch-cve: CVE-2025-21928 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-21928 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=07583a0010696a17fb0942e0b499a62785c5fc9f kpatch-name: rhel8/4.18.0-553.66.1.el8_10/CVE-2025-22020-memstick-rtsx-usb-ms-fix-slab-use-after-free-in-rtsx-usb-ms-drv-remove.patch kpatch-description: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove kpatch-kernel: 4.18.0-553.66.1.el8_10 kpatch-cve: CVE-2025-22020 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-22020 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=4676741a3464b300b486e70585c3c9b692be1632 kpatch-name: rhel8/4.18.0-553.66.1.el8_10/CVE-2022-50020-ext4-avoid-resizing-to-a-partial-cluster-size.patch kpatch-description: ext4: avoid resizing to a partial cluster size kpatch-kernel: 4.18.0-553.66.1.el8_10 kpatch-cve: CVE-2022-50020 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-50020 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=69cb8e9d8cd97cdf5e293b26d70a9dee3e35e6bd kpatch-name: rhel8/4.18.0-553.66.1.el8_10/CVE-2025-38079-crypto-algif_hash-fix-double-free-in-hash_accept.patch kpatch-description: crypto: algif_hash - fix double free in hash_accept kpatch-kernel: 4.18.0-553.66.1.el8_10 kpatch-cve: CVE-2025-38079 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38079 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=bf7bba75b91539e93615f560893a599c1e1c98bf kpatch-name: rhel8/4.18.0-553.66.1.el8_10/CVE-2025-37890-net-sched-hfsc-fix-a-uaf-vulnerability-in-class-with-netem-as-child-qdisc.patch kpatch-description: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc kpatch-kernel: 4.18.0-553.66.1.el8_10 kpatch-cve: CVE-2025-37890 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-37890 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=141d34391abbb315d68556b7c67ad97885407547 kpatch-name: rhel8/4.18.0-553.66.1.el8_10/CVE-2025-37890-sch_hfsc-Fix-qlen-accounting-bug-when-using-peek-in-hfsc_enqueue.patch kpatch-description: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() kpatch-kernel: 4.18.0-553.66.1.el8_10 kpatch-cve: CVE-2025-37890 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-37890 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3f981138109f63232a5fb7165938d4c945cc1b9d kpatch-name: rhel8/4.18.0-553.66.1.el8_10/CVE-2025-37890-net-sched-hfsc-address-reentrant-enqueue-adding-class-to-eltree-twice.patch kpatch-description: net_sched: hfsc: Address reentrant enqueue adding class to eltree twice kpatch-kernel: 4.18.0-553.66.1.el8_10 kpatch-cve: CVE-2025-37890 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-37890 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=141d34391abbb315d68556b7c67ad97885407547 kpatch-name: skipped/CVE-2025-38052.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2025-38052 kpatch-skip-reason: Complex adaptation required. Low impact CVE kpatch-cvss: kpatch-name: rhel8/4.18.0-553.69.1.el8_10/CVE-2021-47670-can-peak_usb-fix-use-after-free-bugs.patch kpatch-description: can: peak_usb: fix use after free bugs kpatch-kernel: kernel-4.18.0-553.69.1.el8_10 kpatch-cve: CVE-2021-47670 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2021-47670 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=5408824636fa0dfedb9ecb0d94abd573131bfbbe kpatch-name: rhel8/4.18.0-553.69.1.el8_10/CVE-2025-21727-padata-fix-uaf-in-padata-reorder.patch kpatch-description: padata: fix UAF in padata_reorder kpatch-kernel: kernel-4.18.0-553.69.1.el8_10 kpatch-cve: CVE-2025-21727 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-21727 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e01780ea4661172734118d2a5f41bc9720765668 kpatch-name: rhel8/4.18.0-553.69.1.el8_10/CVE-2025-21759-ipv6-mcast-add-dev_net_rcu-helper.patch kpatch-description: ipv6: mcast: extend RCU protection in igmp6_send() kpatch-kernel: kernel-4.18.0-553.69.1.el8_10 kpatch-cve: CVE-2025-21759 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-21759 kpatch-patch-url: https://github.com/torvalds/linux/commit/087c1faa594fa07a66933d750c0b2610aa1a2946 kpatch-name: rhel8/4.18.0-553.69.1.el8_10/CVE-2025-21759-ipv6-mcast-extend-RCU-protection-in-igmp6_send.patch kpatch-description: ipv6: mcast: extend RCU protection in igmp6_send() kpatch-kernel: kernel-4.18.0-553.69.1.el8_10 kpatch-cve: CVE-2025-21759 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-21759 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=087c1faa594fa07a66933d750c0b2610aa1a2946 kpatch-name: rhel8/4.18.0-553.69.1.el8_10/CVE-2025-38159-wifi-rtw88-fix-the-para-buffer-size-to-avoid-reading-out-of-bounds.patch kpatch-description: wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds kpatch-kernel: kernel-4.18.0-553.69.1.el8_10 kpatch-cve: CVE-2025-38159 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38159 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=68a1037f0bac4de9a585aa9c879ef886109f3647 kpatch-name: rhel8/4.18.0-553.69.1.el8_10/CVE-2024-56644-net-ipv6-release-expired-exception-dst-cached-in-socket.patch kpatch-description: net/ipv6: release expired exception dst cached in socket kpatch-kernel: kernel-4.18.0-553.69.1.el8_10 kpatch-cve: CVE-2024-56644 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-56644 kpatch-patch-url: https://gerrit.kernelcare.com/plugins/gitiles/redhat-kernel/+/9ca54b8d0a490bc5430c279d717ee9c60b1667b8 kpatch-name: skipped/CVE-2025-38085.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2025-38085 kpatch-skip-reason: Complex adaptation required. High risk of regression. kpatch-cvss: kpatch-name: rhel8/4.18.0-553.70.1.el8_10/CVE-2025-22097-drm-vkms-fix-use-after-free-and-double-free-on-init-error.patch kpatch-description: drm/vkms: Fix use after free and double free on init error kpatch-kernel: 4.18.0-553.70.1.el8_10 kpatch-cve: CVE-2025-22097 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-22097 kpatch-patch-url: https://github.com/torvalds/linux/commit/ed15511a773df86205bda66c37193569575ae828 kpatch-name: rhel8/4.18.0-553.70.1.el8_10/CVE-2025-22097-drm-vkms-fix-use-after-free-and-double-free-on-init-error-kpatch.patch kpatch-description: drm/vkms: Fix use after free and double free on init error kpatch-kernel: 4.18.0-553.70.1.el8_10 kpatch-cve: CVE-2025-22097 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-22097 kpatch-patch-url: https://github.com/torvalds/linux/commit/ed15511a773df86205bda66c37193569575ae828 kpatch-name: rhel8/4.18.0-553.70.1.el8_10/CVE-2025-37914-net_sched-ets-fix-double-list-add-in-class-with-netem-as-child-qdisc.patch kpatch-description: net_sched: ets: Fix double list add in class with netem as child qdisc kpatch-kernel: 4.18.0-553.70.1.el8_10 kpatch-cve: CVE-2025-37914 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-37914 kpatch-patch-url: https://github.com/torvalds/linux/commit/1a6d0c00fa07972384b0c308c72db091d49988b6 kpatch-name: rhel8/4.18.0-553.70.1.el8_10/CVE-2025-38380-i2c-designware-Fix-an-initialization-issue.patch kpatch-description: i2c/designware: Fix an initialization issue kpatch-kernel: 4.18.0-553.70.1.el8_10 kpatch-cve: CVE-2025-38380 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38380 kpatch-patch-url: https://github.com/torvalds/linux/commit/3d30048958e0d43425f6d4e76565e6249fa71050 kpatch-name: rhel8/4.18.0-553.70.1.el8_10/CVE-2025-38250-bluetooth-hci-core-fix-use-after-free-in-vhci-flush-553.58.1.patch kpatch-description: Bluetooth: hci_core: Fix use-after-free in vhci_flush() kpatch-kernel: 5.14.0-570.35.1.el9_6 kpatch-cve: CVE-2025-38250 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38250 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=1d6123102e9fbedc8d25bf4731da6d513173e49e kpatch-name: rhel8/4.18.0-553.71.1.el8_10/CVE-2025-22058-udp-Fix-memory-accounting-leak.patch kpatch-description: udp: Fix memory accounting leak. kpatch-kernel: kernel-4.18.0-553.71.1.el8_10 kpatch-cve: CVE-2025-22058 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-22058 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=c4bac6c398118fba79e32b1cd01db22dbfe29fbf kpatch-name: rhel8/4.18.0-553.71.1.el8_10/CVE-2025-38200-i40e-fix-MMIO-write-access-to-an-invalid-page-in-i40e_clear_hw.patch kpatch-description: i40e: fix MMIO write access to an invalid page in i40e_clear_hw kpatch-kernel: kernel-4.18.0-553.71.1.el8_10 kpatch-cve: CVE-2025-38200 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38200 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=5e75c9082987479e647c75ec8fdf18fa68263c42 kpatch-name: rhel8/4.18.0-553.72.1.el8_10/CVE-2025-38477-net-sched-sch_qfq-Fix-race-condition-on-qfq_aggregate.patch kpatch-description: net/sched: sch_qfq: Fix race condition on qfq_aggregate kpatch-kernel: 4.18.0-553.72.1.el8_10 kpatch-cve: CVE-2025-38477 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38477 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=466e10194ab81caa2ee6a332d33ba16bcceeeba6 kpatch-name: rhel8/4.18.0-553.72.1.el8_10/CVE-2025-38477-net-sched-sch_qfq-Avoid-triggering-might_sleep-in-atomic-context-in-qfq_delete_class.patch kpatch-description: net/sched: sch_qfq: Fix race condition on qfq_aggregate kpatch-kernel: 4.18.0-553.72.1.el8_10 kpatch-cve: CVE-2025-38477 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38477 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=cf074eca0065bc5142e6004ae236bb35a2687fdf kpatch-name: rhel8/4.18.0-553.72.1.el8_10/CVE-2025-38464-tipc-fix-use-after-free-in-tipc-conn-close.patch kpatch-description: tipc: Fix use-after-free in tipc_conn_close(). kpatch-kernel: 4.18.0-553.72.1.el8_10 kpatch-cve: CVE-2025-38464 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38464 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=667eeab4999e981c96b447a4df5f20bdf5c26f13 kpatch-name: rhel8/4.18.0-553.72.1.el8_10/CVE-2025-38211-rdma-iwcm-Fix-a-use-after-free-related-to-destroying-CM-IDs.patch kpatch-description: RDMA/iwcm: Fix a use-after-free related to destroying CM IDs kpatch-kernel: 4.18.0-553.72.1.el8_10 kpatch-cve: CVE-2025-38211 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38211 kpatch-patch-url: https://github.com/torvalds/linux/commit/aee2424246f9f1dadc33faa78990c1e2eb7826e4 kpatch-name: rhel8/4.18.0-553.72.1.el8_10/CVE-2025-38211-rdma-iwcm-fix-use-after-free-of-work-objects-after-cm-id-destruction.patch kpatch-description: RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction kpatch-kernel: 4.18.0-553.72.1.el8_10 kpatch-cve: CVE-2025-38211 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38211 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=6883b680e703c6b2efddb4e7a8d891ce1803d06b kpatch-name: rhel8/4.18.0-553.72.1.el8_10/CVE-2025-38332-scsi-lpfc-use-memcpy-for-bios-version.patch kpatch-description: scsi: lpfc: Use memcpy() for BIOS version kpatch-kernel: 4.18.0-553.72.1.el8_10 kpatch-cve: CVE-2025-38332 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38332 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=ae82eaf4aeea060bb736c3e20c0568b67c701d7d kpatch-name: rhel8/4.18.0-553.74.1.el8_10/CVE-2022-49985-bpf-don-t-use-tnum_range-on-array-range-checking-for-poke-descriptors.patch kpatch-description: bpf: Don't use tnum_range on array range checking for poke descriptors kpatch-kernel: 4.18.0-553.74.1.el8_10 kpatch-cve: CVE-2022-49985 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-49985 kpatch-patch-url: https://github.com/torvalds/linux/commit/a657182a5c5150cdfacb6640aad1d2712571a409 kpatch-name: rhel8/4.18.0-553.74.1.el8_10/CVE-2025-38352-posix-cpu-timers-fix-race-between-handle_posix_cpu_timers-and-posix_cpu_timer_del.patch kpatch-description: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() kpatch-kernel: 4.18.0-553.74.1.el8_10 kpatch-cve: CVE-2025-38352 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38352 kpatch-patch-url: https://github.com/torvalds/linux/commit/f90fff1e152dedf52b932240ebbd670d83330eca kpatch-name: rhel8/4.18.0-553.75.1.el8_10/CVE-2023-53125-net-usb-smsc75xx-Limit-packet-length-to-skb-len.patch kpatch-description: net: usb: smsc75xx: Limit packet length to skb->len kpatch-kernel: kernel-4.18.0-553.75.1.el8_10 kpatch-cve: CVE-2023-53125 kpatch-cvss: 7.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53125 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=d8b228318935044dafe3a5bc07ee71a1f1424b8d kpatch-name: rhel8/4.18.0-553.75.1.el8_10/CVE-2023-53125-net-usb-smsc75xx-Move-packet-length-check-to-prevent-kernel-panic-in-skb_pull.patch kpatch-description: net: usb: smsc75xx: Move packet length check to prevent kernel panic in skb_pull kpatch-kernel: kernel-4.18.0-553.75.1.el8_10 kpatch-cve: CVE-2023-53125 kpatch-cvss: 7.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53125 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=43ffe6caccc7a1bb9d7442fbab521efbf6c1378c kpatch-name: rhel8/4.18.0-553.75.1.el8_10/CVE-2025-38350-sch_qfq-make-qfq_qlen_notify-idempotent.patch kpatch-description: sch_qfq: make qfq_qlen_notify() idempotent kpatch-kernel: kernel-4.18.0-553.75.1.el8_10 kpatch-cve: CVE-2025-38350 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38350 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=55f9eca4bfe30a15d8656f915922e8c98b7f0728 kpatch-name: rhel8/4.18.0-553.75.1.el8_10/CVE-2025-38350-sch_cbq-make-cbq_qlen_notify-idempotent.patch kpatch-description: sch_cbq: make cbq_qlen_notify() idempotent kpatch-kernel: kernel-4.18.0-553.75.1.el8_10 kpatch-cve: CVE-2025-38350 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38350 kpatch-patch-url: https://mailweb.openeuler.org/archives/list/kernel@openeuler.org/thread/LN5XC5L2CB6AWQEL2SNJOUCRBIFUO4YE/#LN5XC5L2CB6AWQEL2SNJOUCRBIFUO4YE kpatch-name: rhel8/4.18.0-553.75.1.el8_10/CVE-2025-38350-sch_htb-make-htb_qlen_notify-idempotent.patch kpatch-description: sch_htb: make htb_qlen_notify() idempotent kpatch-kernel: kernel-4.18.0-553.75.1.el8_10 kpatch-cve: CVE-2025-38350 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38350 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5ba8b837b522d7051ef81bacf3d95383ff8edce5 kpatch-name: rhel8/4.18.0-553.75.1.el8_10/CVE-2025-38350-sch_htb-make-htb_deactivate-idempotent.patch kpatch-description: sch_htb: make htb_deactivate() idempotent kpatch-kernel: kernel-4.18.0-553.75.1.el8_10 kpatch-cve: CVE-2025-38350 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38350 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3769478610135e82b262640252d90f6efb05be71 kpatch-name: rhel8/4.18.0-553.75.1.el8_10/CVE-2025-38350-sch_hfsc-make-hfsc_qlen_notify-idempotent.patch kpatch-description: sch_hfsc: make hfsc_qlen_notify() idempotent kpatch-kernel: kernel-4.18.0-553.75.1.el8_10 kpatch-cve: CVE-2025-38350 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38350 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=51eb3b65544c9efd6a1026889ee5fb5aa62da3bb kpatch-name: rhel8/4.18.0-553.75.1.el8_10/CVE-2025-38350-sch_ets-make-est_qlen_notify-idempotent.patch kpatch-description: sch_ets: make est_qlen_notify() idempotent kpatch-kernel: kernel-4.18.0-553.75.1.el8_10 kpatch-cve: CVE-2025-38350 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38350 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a7a15f39c682ac4268624da2abdb9114bdde96d5 kpatch-name: rhel8/4.18.0-553.75.1.el8_10/CVE-2025-38350-sch_drr-make-drr_qlen_notify-idempotent.patch kpatch-description: sch_drr: make drr_qlen_notify() idempotent kpatch-kernel: kernel-4.18.0-553.75.1.el8_10 kpatch-cve: CVE-2025-38350 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38350 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=df008598b3a00be02a8051fde89ca0fbc416bd55 kpatch-name: rhel8/4.18.0-553.75.1.el8_10/CVE-2025-38350-net-sched-always-pass-notifications-when-child-class-becomes-empty.patch kpatch-description: net/sched: Always pass notifications when child class becomes empty kpatch-kernel: kernel-4.18.0-553.75.1.el8_10 kpatch-cve: CVE-2025-38350 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38350 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=103406b38c600fec1fe375a77b27d87e314aea09 kpatch-name: skipped/CVE-2025-38449.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2025-38449 kpatch-skip-reason: requires a very complex adaptation kpatch-cvss: kpatch-name: rhel8/4.18.0-553.75.1.el8_10/CVE-2025-38392-idpf-convert-control-queue-mutex-to-a-spinlock.patch kpatch-description: idpf: convert control queue mutex to a spinlock kpatch-kernel: 4.18.0-553.75.1.el8_10 kpatch-cve: CVE-2025-38392 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38392 kpatch-patch-url: https://github.com/torvalds/linux/commit/b2beb5bb2cd90d7939e470ed4da468683f41baa3 kpatch-name: rhel8/4.18.0-553.76.1.el8_10/CVE-2025-38461-vsock-Fix-transport_-TOCTOU.patch kpatch-description: vsock: Fix transport_* TOCTOU kpatch-kernel: kernel-4.18.0-553.76.1.el8_10 kpatch-cve: CVE-2025-38461 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38461 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=687aa0c5581b8d4aa87fd92973e4ee576b550cdf kpatch-name: rhel8/4.18.0-553.76.1.el8_10/CVE-2025-38498-do_change_type-refuse-to-operate-on-unmounted-not-ours-mounts.patch kpatch-description: vsock: Fix transport_* TOCTOU kpatch-kernel: kernel-4.18.0-553.76.1.el8_10 kpatch-cve: CVE-2025-38498 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38498 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=12f147ddd6de7382dad54812e65f3f08d05809fc kpatch-name: rhel8/4.18.0-553.76.1.el8_10/CVE-2025-38498-use-uniform-permission-checks-for-all-mount-propagation-changes.patch kpatch-description: use uniform permission checks for all mount propagation changes kpatch-kernel: kernel-4.18.0-553.76.1.el8_10 kpatch-cve: CVE-2025-38498 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38498 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=cffd0441872e7f6b1fce5e78fb1c99187a291330 kpatch-name: rhel8/4.18.0-553.76.1.el8_10/CVE-2025-38556-core-Harden-s32ton-against-conversion-to-0-bits.patch kpatch-description: HID: core: Harden s32ton() against conversion to 0 bits kpatch-kernel: kernel-4.18.0-553.76.1.el8_10 kpatch-cve: CVE-2025-38556 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38556 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a6b87bfc2ab5bccb7ad953693c85d9062aef3fdd kpatch-name: rhel8/4.18.0-553.76.1.el8_10/CVE-2025-38556-HID-core-fix-shift-out-of-bounds-in-hid_report_raw_event.patch kpatch-description: HID: core: fix shift-out-of-bounds in hid_report_raw_event kpatch-kernel: kernel-4.18.0-553.76.1.el8_10 kpatch-cve: CVE-2025-38556 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38556 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=ec61b41918587be530398b0d1c9a0d16619397e5 kpatch-name: rhel8/4.18.0-553.77.1.el8_10/CVE-2025-38718-sctp-linearize-cloned-gso-packets-in-sctp-rcv.patch kpatch-description: sctp: linearize cloned gso packets in sctp_rcv kpatch-kernel: 4.18.0-553.77.1.el8_10 kpatch-cve: CVE-2025-38718 kpatch-cvss: 7.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38718 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=fd60d8a086191fe33c2d719732d2482052fa6805 kpatch-name: skipped/CVE-2025-22026.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2025-22026 kpatch-skip-reason: Out of scope: not affected kpatch-cvss: kpatch-name: rhel8/4.18.0-553.77.1.el8_10/CVE-2025-37797-net_sched-hfsc-Fix-a-UAF-vulnerability-in-class-handling.patch kpatch-description: net_sched: hfsc: Fix a UAF vulnerability in class handling kpatch-kernel: 4.18.0-553.77.1.el8_10 kpatch-cve: CVE-2025-37797 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-37797 kpatch-patch-url: https://github.com/torvalds/linux/commit/3df275ef0a6ae181e8428a6589ef5d5231e58b5c kpatch-name: skipped/CVE-2022-50087.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2022-50087 kpatch-skip-reason: Out of scope: not affected kpatch-cvss: kpatch-name: rhel8/4.18.0-553.78.1.el8_10/CVE-2025-39730-NFS-Fix-filehandle-bounds-checking-in-nfs_fh_to_dentry.patch kpatch-description: NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() kpatch-kernel: 4.18.0-553.78.1.el8_10 kpatch-cve: CVE-2025-39730 kpatch-cvss: 7.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39730 kpatch-patch-url: https://github.com/torvalds/linux/commit/ef93a685e01a281b5e2a25ce4e3428cf9371a205 kpatch-name: rhel8/4.18.0-553.78.1.el8_10/CVE-2025-38527-smb-client-fix-use-after-free-in-cifs_oplock_break.patch kpatch-description: smb: client: fix use-after-free in cifs_oplock_break kpatch-kernel: 4.18.0-553.78.1.el8_10 kpatch-cve: CVE-2025-38527 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38527 kpatch-patch-url: https://github.com/torvalds/linux/commit/705c79101ccf9edea5a00d761491a03ced314210 kpatch-name: rhel8/4.18.0-553.79.1.el8_10/CVE-2023-53305-bluetooth-l2cap-fix-use-after-free.patch kpatch-description: Bluetooth: L2CAP: Fix use-after-free kpatch-kernel: 4.18.0-553.79.1.el8_10 kpatch-cve: CVE-2023-53305 CVE-2022-50386 kpatch-cvss: 7.6 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53305 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-50386 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f752a0b334bb95fe9b42ecb511e0864e2768046f kpatch-name: rhel8/4.18.0-553.79.1.el8_10/CVE-2022-50228-KVM-SVM-dont-BUG-if-userspace-injects-an-interrupt.patch kpatch-description: KVM: SVM: Don't BUG if userspace injects an interrupt with GIF=0 kpatch-kernel: 4.18.0-553.79.1.el8_10 kpatch-cve: CVE-2022-50228 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-50228 kpatch-patch-url: https://github.com/torvalds/linux/commit/f17c31c48e5cde9895a491d91c424eeeada3e134 kpatch-name: rhel8/4.18.0-553.80.1.el8_10/CVE-2023-53373-crypto-seqiv-handle-ebusy-correctly.patch kpatch-description: crypto: seqiv - Handle EBUSY correctly kpatch-kernel: 4.18.0-553.80.1.el8_10 kpatch-cve: CVE-2023-53373 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53373 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=32e62025e5e52fbe4812ef044759de7010b15dbc kpatch-name: skipped/CVE-2025-39751.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2025-39751 kpatch-skip-reason: This CVE has been rejected or withdrawn by its CVE Numbering Authority as per NVD website kpatch-cvss: kpatch-name: rhel8/4.18.0-553.80.1.el8_10/CVE-2025-39757-ALSA-usb-audio-Validate-UAC3-cluster-segment-descriptors.patch kpatch-description: ALSA: usb-audio: Validate UAC3 cluster segment descriptors kpatch-kernel: 4.18.0-553.80.1.el8_10 kpatch-cve: CVE-2025-39757 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39757 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=799c06ad4c9c790c265e8b6b94947213f1fb389c kpatch-name: rhel8/4.18.0-553.80.1.el8_10/CVE-2025-39757-ALSA-usb-audio-Fix-size-validation-in-convert_chmap_v3.patch kpatch-description: ALSA: usb-audio: Validate UAC3 cluster segment descriptors kpatch-kernel: 4.18.0-553.80.1.el8_10 kpatch-cve: CVE-2025-39757 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39757 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=799c06ad4c9c790c265e8b6b94947213f1fb389c kpatch-name: rhel8/4.18.0-553.81.1.el8_10/CVE-2023-53297-Bluetooth-L2CAP-fix-bad-unlock-balance-in-l2cap_disconnect_rsp.patch kpatch-description: Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp kpatch-kernel: 4.18.0-553.81.1.el8_10 kpatch-cve: CVE-2023-53297 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53297 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2112c4c47d36bc5aba3ddeb9afedce6ae6a67e7d kpatch-name: rhel8/4.18.0-553.81.1.el8_10/CVE-2025-39817-efivarfs-fix-slab-out-of-bounds-in-efivarfs-d-compare.patch kpatch-description: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare kpatch-kernel: 4.18.0-553.81.1.el8_10 kpatch-cve: CVE-2025-39817 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39817 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a6358f8cf64850f3f27857b8ed8c1b08cfc4685c kpatch-name: rhel8/4.18.0-553.81.1.el8_10/CVE-2025-39841-scsi-lpfc-fix-buffer-free-clear-order-in-deferred-receive-path.patch kpatch-description: scsi: lpfc: Fix buffer free/clear order in deferred receive path kpatch-kernel: 4.18.0-553.81.1.el8_10 kpatch-cve: CVE-2025-39841 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39841 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9dba9a45c348e8460da97c450cddf70b2056deb3 kpatch-name: rhel8/4.18.0-553.81.1.el8_10/CVE-2025-39849-wifi-cfg80211-sme-cap-ssid-length-in-cfg80211-connect-result-553.8.patch kpatch-description: wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result() kpatch-kernel: 4.18.0-553.81.1.el8_10 kpatch-cve: CVE-2025-39849 kpatch-cvss: 7.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39849 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=62b635dcd69c4fde7ce1de4992d71420a37e51e3 kpatch-name: rhel8/4.18.0-553.81.1.el8_10/CVE-2023-53386-Bluetooth-Fix-potential-use-after-free-when-clear-keys.patch kpatch-description: Bluetooth: Fix potential use-after-free when clear keys kpatch-kernel: 4.18.0-553.81.1.el8_10 kpatch-cve: CVE-2023-53386 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53386 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3673952cf0c6cf81b06c66a0b788abeeb02ff3ae kpatch-name: rhel8/4.18.0-553.82.1.el8_10/CVE-2025-39864-wifi-cfg80211-fix-use-after-free-in-cmp-bss.patch kpatch-description: wifi: cfg80211: fix use-after-free in cmp_bss() kpatch-kernel: 4.18.0-553.82.1.el8_10 kpatch-cve: CVE-2025-39864 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39864 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=26e84445f02ce6b2fe5f3e0e28ff7add77f35e08 kpatch-name: rhel8/4.18.0-553.82.1.el8_10/CVE-2023-53226-wifi-mwifiex-Fix-OOB-and-integer-underflow-when-rx-packets.patch kpatch-description: wifi: mwifiex: Fix OOB and integer underflow when rx packets kpatch-kernel: 4.18.0-553.82.1.el8_10 kpatch-cve: CVE-2023-53226 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53226 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=29eca8b7863d1d7de6c5b746b374e3487d14f154 kpatch-name: rhel8/4.18.0-553.82.1.el8_10/CVE-2023-53226-wifi-mwifiex-Fix-missed-return-in-oob-checks-failed-path.patch kpatch-description: wifi: mwifiex: Fix missed return in oob checks failed path kpatch-kernel: 4.18.0-553.82.1.el8_10 kpatch-cve: CVE-2023-53226 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53226 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=df1753eae74bc860476ad89db64f42cea3c2668f kpatch-name: rhel8/4.18.0-553.82.1.el8_10/CVE-2023-53226-wifi-mwifiex-Fix-oob-check-condition-in-mwifiex_process_rx_packet.patch kpatch-description: wifi: mwifiex: Fix OOB and integer underflow when rx packets kpatch-kernel: 4.18.0-553.82.1.el8_10 kpatch-cve: CVE-2023-53226 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53226 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=b8e260654a29de872e7cb85387d8ab8974694e8e kpatch-name: rhel8/4.18.0-553.82.1.el8_10/CVE-2023-53257-wifi-mac80211-check-S1G-action-frame-size.patch kpatch-description: wifi: mac80211: check S1G action frame size kpatch-kernel: 4.18.0-553.82.1.el8_10 kpatch-cve: CVE-2023-53257 kpatch-cvss: 7.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53257 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=fedd9377dd9c71a950d432fbe1628eebfbed70a1 kpatch-name: skipped/CVE-2023-53751.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2023-53751 kpatch-skip-reason: The adapted patch also created safety check conflicts, so removing it. kpatch-cvss: kpatch-name: rhel8/4.18.0-553.83.1.el8_10/CVE-2022-50367-fs-fix-uaf-gpf-bug-in-nilfs-mdt-destroy.patch kpatch-description: fs: fix UAF/GPF bug in nilfs_mdt_destroy kpatch-kernel: 4.18.0-553.83.1.el8_10 kpatch-cve: CVE-2022-50367 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-50367 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2e488f13755ffbb60f307e991b27024716a33b29 kpatch-name: rhel8/4.18.0-553.83.1.el8_10/CVE-2023-53178-mm-fix-zswap-writeback-race-condition.patch kpatch-description: mm: fix zswap writeback race condition kpatch-kernel: 4.18.0-553.83.1.el8_10 kpatch-cve: CVE-2023-53178 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53178 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=04fc7816089c5a32c29a04ec94b998e219dfb946 kpatch-name: rhel8/4.18.0-553.83.1.el8_10/CVE-2023-53178-mm-zswap-fix-missing-folio-cleanup-in-writeback-race-path.patch kpatch-description: mm: zswap: fix missing folio cleanup in writeback race path kpatch-kernel: 4.18.0-553.83.1.el8_10 kpatch-cve: CVE-2023-53178 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53178 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e3b63e966cac0bf78aaa1efede1827a252815a1d kpatch-name: rhel8/4.18.0-553.84.1.el8_10/CVE-2025-39718-vsock-virtio-validate-length-in-packet-header-before-skb-put.patch kpatch-description: vsock/virtio: Validate length in packet header before skb_put() kpatch-kernel: 4.18.0-553.84.1.el8_10 kpatch-cve: CVE-2025-39718 kpatch-cvss: 7.6 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39718 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=faf332a10372390ce65d0b803888f4b25a388335 kpatch-name: rhel8/4.18.0-553.85.1.el8_10/CVE-2025-39697-nfs-fix-a-race-when-updating-an-existing-write.patch kpatch-description: NFS: Fix a race when updating an existing write kpatch-kernel: 4.18.0-553.85.1.el8_10 kpatch-cve: CVE-2025-39697 kpatch-cvss: 7.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39697 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=202a3432d21ac060629a760fff3b0a39859da3ea kpatch-name: rhel8/4.18.0-553.85.1.el8_10/CVE-2025-39971-i40e-fix-idx-validation-in-config-queues-msg.patch kpatch-description: i40e: fix idx validation in config queues msg kpatch-kernel: 4.18.0-553.85.1.el8_10 kpatch-cve: CVE-2025-39971 kpatch-cvss: 7.6 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39971 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=a6ff2af78343eceb0f77ab1a2fe802183bc21648 kpatch-name: rhel8/4.18.0-553.85.1.el8_10/CVE-2025-39973-i40e-increase-max-descriptors-for-XL710.patch kpatch-description: i40e: increase max descriptors for XL710 kpatch-kernel: 4.18.0-553.85.1.el8_10 kpatch-cve: CVE-2025-39973 kpatch-cvss: 7.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39973 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=aa6908ca3bd1 kpatch-name: rhel8/4.18.0-553.85.1.el8_10/CVE-2025-39973-i40e-add-validation-for-ring_len-param.patch kpatch-description: i40e: add validation for ring_len param kpatch-kernel: 4.18.0-553.85.1.el8_10 kpatch-cve: CVE-2025-39973 kpatch-cvss: 7.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39973 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=55d225670def06b01af2e7a5e0446fbe946289e8 kpatch-name: rhel8/4.18.0-553.87.1.el8_10/CVE-2023-53513-nbd-fix-incomplete-validation-of-ioctl-arg.patch kpatch-description: nbd: fix incomplete validation of ioctl arg kpatch-kernel: 4.18.0-553.87.1.el8_10 kpatch-cve: CVE-2023-53513 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53513 kpatch-patch-url: https://github.com/torvalds/linux/commit/55793ea54d77719a071b1ccc05a05056e3b5e009 kpatch-name: rhel8/4.18.0-553.87.1.el8_10/CVE-2025-39825-smb-client-fix-race-with-concurrent-opens-in-rename2-553.8.patch kpatch-description: smb: client: fix race with concurrent opens in rename(2) kpatch-kernel: 4.18.0-553.87.1.el8_10 kpatch-cve: CVE-2025-39825 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39825 kpatch-patch-url: https://github.com/torvalds/linux/commit/d84291fc7453df7881a970716f8256273aca5747 kpatch-name: rhel8/4.18.0-553.87.1.el8_10/CVE-2025-38724-nfsd-handle-get_client_locked-failure-in-nfsd4_setclientid_confirm.patch kpatch-description: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() kpatch-kernel: 4.18.0-553.87.1.el8_10 kpatch-cve: CVE-2025-38724 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38724 kpatch-patch-url: https://github.com/torvalds/linux/commit/908e4ead7f757504d8b345452730636e298cbf68 kpatch-name: rhel8/4.18.0-553.87.1.el8_10/CVE-2025-39898-e1000e-fix-heap-overflow-in-e1000_set_eeprom.patch kpatch-description: e1000e: fix heap overflow in e1000_set_eeprom kpatch-kernel: 4.18.0-553.87.1.el8_10 kpatch-cve: CVE-2025-39898 kpatch-cvss: 7.6 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39898 kpatch-patch-url: https://github.com/torvalds/linux/commit/90fb7db49c6dbac961c6b8ebfd741141ffbc8545 kpatch-name: rhel8/4.18.0-553.87.1.el8_10/CVE-2025-39883-mm-memory-failure-fix-VM_BUG_ON_PAGE-when-unpoison-memory.patch kpatch-description: mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory kpatch-kernel: 4.18.0-553.87.1.el8_10 kpatch-cve: CVE-2025-39883 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39883 kpatch-patch-url: https://github.com/torvalds/linux/commit/d613f53c83ec47089c4e25859d5e8e0359f6f8da kpatch-name: rhel8/4.18.0-553.87.1.el8_10/CVE-2025-39955-tcp-clear-tcp_sk-sk-fastopen_rsk-in-tcp_disconnect.patch kpatch-description: tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect(). kpatch-kernel: 4.18.0-553.87.1.el8_10 kpatch-cve: CVE-2025-39955 kpatch-cvss: 7.6 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39955 kpatch-patch-url: https://github.com/torvalds/linux/commit/45c8a6cc2bcd780e634a6ba8e46bffbdf1fc5c01 kpatch-name: rhel8/4.18.0-553.87.1.el8_10/CVE-2025-40186-tcp-don-t-call-reqsk_fastopen_remove-in-tcp_conn_request.patch kpatch-description: tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request(). kpatch-kernel: 4.18.0-553.87.1.el8_10 kpatch-cve: CVE-2025-40186 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40186 kpatch-patch-url: https://github.com/torvalds/linux/commit/2e7cbbbe3d61c63606994b7ff73c72537afe2e1c kpatch-name: rhel8/4.18.0-553.89.1.el8_10/CVE-2022-50543-rdma-rxe-fix-mr-map-double-free.patch kpatch-description: RDMA/rxe: Fix mr->map double free kpatch-kernel: 4.18.0-553.89.1.el8_10 kpatch-cve: CVE-2022-50543 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-50543 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=06f73568f553b5be6ba7f6fe274d333ea29fc46d kpatch-name: rhel8/4.18.0-553.89.1.el8_10/CVE-2023-53401-mm-kmem-fix-a-null-pointer-dereference-in-obj-stock-flush-required.patch kpatch-description: mm: kmem: fix a NULL pointer dereference in obj_stock_flush_required() kpatch-kernel: 4.18.0-553.89.1.el8_10 kpatch-cve: CVE-2023-53401 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53401 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=33391c7e1a2ad612bf3922cc168cb09a46bbe236 kpatch-name: rhel8/4.18.0-553.89.1.el8_10/CVE-2023-53539-rdma-rxe-fix-incomplete-state-save-in-rxe-requester.patch kpatch-description: RDMA/rxe: Fix incomplete state save in rxe_requester kpatch-kernel: 4.18.0-553.89.1.el8_10 kpatch-cve: CVE-2023-53539 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53539 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=255c0e60e1d16874fc151358d94bc8df661600dd kpatch-name: rhel8/4.18.0-553.92.1.el8_10/CVE-2025-40240-sctp-avoid-null-dereference-when-chunk-data-buffer-is-missing.patch kpatch-description: sctp: avoid NULL dereference when chunk data buffer is missing kpatch-kernel: 4.18.0-553.92.1.el8_10 kpatch-cve: CVE-2025-40240 kpatch-cvss: 7.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40240 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=441f0647f7673e0e64d4910ef61a5fb8f16bfb82 kpatch-name: rhel8/4.18.0-553.92.1.el8_10/CVE-2025-68285-libceph-fix-potential-use-after-free-in-have-mon-and-osd-map.patch kpatch-description: libceph: fix potential use-after-free in have_mon_and_osd_map() kpatch-kernel: 4.18.0-553.92.1.el8_10 kpatch-cve: CVE-2025-68285 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-68285 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=076381c261374c587700b3accf410bdd2dba334e kpatch-name: rhel8/4.18.0-553.92.1.el8_10/CVE-2025-68285-libceph-fix-potential-use-after-free-in-have-mon-and-osd-map-kpatch.patch kpatch-description: libceph: fix potential use-after-free in have_mon_and_osd_map() kpatch-kernel: 4.18.0-553.92.1.el8_10 kpatch-cve: CVE-2025-68285 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-68285 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=076381c261374c587700b3accf410bdd2dba334e kpatch-name: rhel8/4.18.0-553.92.1.el8_10/CVE-2025-39993-media-rc-fix-races-with-imon-disconnect-kpatch.patch kpatch-description: media: rc: fix races with imon_disconnect() kpatch-kernel: 4.18.0-553.92.1.el8_10 kpatch-cve: CVE-2025-39993 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39993 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=fa0f61cc1d828178aa921475a9b786e7fbb65ccb kpatch-name: skipped/CVE-2023-53552.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2023-53552 kpatch-skip-reason: Complex adaptation required. kpatch-cvss: kpatch-name: rhel8/4.18.0-553.94.1.el8_10/CVE-2025-40096-drm-sched-fix-potential-double-free-in-drm-sched.patch kpatch-description: drm/sched: Fix potential double free in drm_sched_job_add_resv_dependencies kpatch-kernel: 4.18.0-553.94.1.el8_10 kpatch-cve: CVE-2025-40096 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40096 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5801e65206b065b0b2af032f7f1eef222aa2fd83 kpatch-name: rhel8/4.18.0-553.94.1.el8_10/CVE-2025-68301-net-atlantic-fix-fragment-overflow-handling-in-rx-path.patch kpatch-description: net: atlantic: fix fragment overflow handling in RX path kpatch-kernel: 4.18.0-553.94.1.el8_10 kpatch-cve: CVE-2025-68301 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-68301 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5ffcb7b890f61541201461580bb6622ace405aec kpatch-name: rhel8/4.18.0-553.94.1.el8_10/CVE-2025-38051-smb-client-fix-use-after-free-in-cifs-fill-dirent.patch kpatch-description: smb: client: Fix use-after-free in cifs_fill_dirent kpatch-kernel: 4.18.0-553.94.1.el8_10 kpatch-cve: CVE-2025-38051 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38051 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=1b197931fbc821bc7e9e91bf619400db563e3338 kpatch-name: rhel8/4.18.0-553.94.1.el8_10/CVE-2025-39933-smb-client-let-recv-done-verify-data-offset.patch kpatch-description: smb: client: let recv_done verify data_offset, data_length and remaining_data_length kpatch-kernel: 4.18.0-553.94.1.el8_10 kpatch-cve: CVE-2025-39933 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39933 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=1b197931fbc821bc7e9e91bf619400db563e3338 kpatch-name: rhel8/4.18.0-553.97.1.el8_10/CVE-2025-40248-vsock-ignore-signal-timeout-on-connect-if-already-established.patch kpatch-description: vsock: Ignore signal/timeout on connect() if already established kpatch-kernel: 4.18.0-553.97.1.el8_10 kpatch-cve: CVE-2025-40248 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40248 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=002541ef650b742a198e4be363881439bb9d86b4 kpatch-name: rhel8/4.18.0-553.97.1.el8_10/CVE-2025-40277-drm-vmwgfx-validate-command-header-size-against-svga-cmd-max-datasize.patch kpatch-description: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE kpatch-kernel: 4.18.0-553.97.1.el8_10 kpatch-cve: CVE-2025-40277 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40277 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=32b415a9dc2c212e809b7ebc2b14bc3fbda2b9af kpatch-name: rhel8/4.18.0-553.97.1.el8_10/CVE-2023-53673-bluetooth-hci-event-call-disconnect-callback-before-deleting-conn.patch kpatch-description: Bluetooth: hci_event: call disconnect callback before deleting conn kpatch-kernel: 4.18.0-553.97.1.el8_10 kpatch-cve: CVE-2023-53673 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53673 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=7f7cfcb6f0825652973b780f248603e23f16ee90 kpatch-name: rhel8/4.18.0-553.97.1.el8_10/CVE-2025-40154-asoc-intel-bytcr-rt5640-fix-invalid-quirk-input-mapping.patch kpatch-description: ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping kpatch-kernel: 4.18.0-553.97.1.el8_10 kpatch-cve: CVE-2025-40154 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40154 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=fba404e4b4af4f4f747bb0e41e9fff7d03c7bcc0 kpatch-name: rhel8/4.18.0-553.100.1.el8_10/CVE-2022-50865-tcp-fix-a-signed-integer-overflow-bug-in-tcp_add_backlog.patch kpatch-description: tcp: fix a signed-integer-overflow bug in tcp_add_backlog() kpatch-kernel: 4.18.0-553.100.1.el8_10 kpatch-cve: CVE-2022-50865 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-50865 kpatch-patch-url: https://github.com/torvalds/linux/commit/ec791d8149ff60c40ad2074af3b92a39c916a03f kpatch-name: rhel8/4.18.0-553.100.1.el8_10/CVE-2025-38415-squashfs-check-return-result-of-sb_min_blocksize.patch kpatch-description: Squashfs: check return result of sb_min_blocksize kpatch-kernel: 4.18.0-553.100.1.el8_10 kpatch-cve: CVE-2025-38415 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38415 kpatch-patch-url: https://github.com/torvalds/linux/commit/734aa85390ea693bb7eaf2240623d41b03705c84 kpatch-name: rhel8/4.18.0-553.100.1.el8_10/CVE-2025-38415-squashfs-fix-memory-leak-in-squashfs_fill_super.patch kpatch-description: squashfs: fix memory leak in squashfs_fill_super kpatch-kernel: 4.18.0-553.100.1.el8_10 kpatch-cve: CVE-2025-38415 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38415 kpatch-patch-url: https://github.com/torvalds/linux/commit/b64700d41bdc4e9f82f1346c15a3678ebb91a89c kpatch-name: rhel8/4.18.0-553.100.1.el8_10/CVE-2025-38415-squashfs-check-return-result-of-sb_min_blocksize-kpatch.patch kpatch-description: Squashfs: check return result of sb_min_blocksize kpatch-kernel: 4.18.0-553.100.1.el8_10 kpatch-cve: CVE-2025-38415 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38415 kpatch-patch-url: https://github.com/torvalds/linux/commit/734aa85390ea693bb7eaf2240623d41b03705c84 kpatch-name: rhel8/4.18.0-553.100.1.el8_10/CVE-2024-26766-ib-hfi1-fix-sdma-h-tx-num-descs-off-by-one-error.patch kpatch-description: IB/hfi1: Fix sdma.h tx->num_descs off-by-one error kpatch-kernel: 4.18.0-553.100.1.el8_10 kpatch-cve: CVE-2024-26766 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26766 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e6f57c6881916df39db7d95981a8ad2b9c3458d6 kpatch-name: rhel8/4.18.0-553.100.1.el8_10/CVE-2025-38022-rdma-core-fix-kasan-slab-use-after-free-read-in-ib-register-device-problem.patch kpatch-description: RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem kpatch-kernel: 4.18.0-553.100.1.el8_10 kpatch-cve: CVE-2025-38022 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38022 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=d0706bfd3ee40923c001c6827b786a309e2a8713 kpatch-name: rhel8/4.18.0-553.100.1.el8_10/CVE-2025-38024-rdma-rxe-fix-slab-use-after-free-read-in-rxe-queue-cleanup-bug.patch kpatch-description: RDMA/rxe: Fix slab-use-after-free Read in rxe_queue_cleanup bug kpatch-kernel: 4.18.0-553.100.1.el8_10 kpatch-cve: CVE-2025-38024 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38024 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f81b33582f9339d2dc17c69b92040d3650bb4bae kpatch-name: rhel8/4.18.0-553.100.1.el8_10/CVE-2025-38459-atm-clip-fix-infinite-recursive-call-of-clip-push.patch kpatch-description: atm: clip: Fix infinite recursive call of clip_push(). kpatch-kernel: 4.18.0-553.100.1.el8_10 kpatch-cve: CVE-2025-38459 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38459 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c489f3283dbfc0f3c00c312149cae90d27552c45 kpatch-name: rhel8/4.18.0-553.100.1.el8_10/CVE-2025-39760-usb-core-config-prevent-oob-read-in-ss-endpoint-companion-parsing.patch kpatch-description: usb: core: config: Prevent OOB read in SS endpoint companion parsing kpatch-kernel: 4.18.0-553.100.1.el8_10 kpatch-cve: CVE-2025-39760 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-39760 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=cf16f408364efd8a68f39011a3b073c83a03612d kpatch-name: rhel8/4.18.0-553.100.1.el8_10/CVE-2025-40258-mptcp-fix-race-condition-in-mptcp-schedule-work.patch kpatch-description: mptcp: fix race condition in mptcp_schedule_work() kpatch-kernel: 4.18.0-553.100.1.el8_10 kpatch-cve: CVE-2025-40258 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40258 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=035bca3f017ee9dea3a5a756e77a6f7138cc6eea kpatch-name: rhel8/4.18.0-553.100.1.el8_10/CVE-2025-40271-fs-proc-fix-uaf-in-proc-readdir-de.patch kpatch-description: fs/proc: fix uaf in proc_readdir_de() kpatch-kernel: 4.18.0-553.100.1.el8_10 kpatch-cve: CVE-2025-40271 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40271 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=895b4c0c79b092d732544011c3cecaf7322c36a1 kpatch-name: rhel8/4.18.0-553.100.1.el8_10/CVE-2025-40322-fbdev-bitblit-bound-check-glyph-index-in-bit-putcs.patch kpatch-description: fbdev: bitblit: bound-check glyph index in bit_putcs* kpatch-kernel: 4.18.0-553.100.1.el8_10 kpatch-cve: CVE-2025-40322 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40322 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=18c4ef4e765a798b47980555ed665d78b71aeadf kpatch-name: rhel8/4.18.0-553.104.1.el8_10/CVE-2022-50673-ext4-fix-use-after-free-in-ext4_orphan_cleanup.patch kpatch-description: ext4: fix use-after-free in ext4_orphan_cleanup kpatch-kernel: 4.18.0-553.104.1.el8_10 kpatch-cve: CVE-2022-50673 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2022-50673 kpatch-patch-url: https://github.com/torvalds/linux/commit/a71248b1accb2b42e4980afef4fa4a27fa0e36f5 kpatch-name: rhel8/4.18.0-553.104.1.el8_10/CVE-2025-38403-vsock-vmci-clear-the-vmci-transport-packet-properly-when-initializing-it.patch kpatch-description: vsock/vmci: Clear the vmci transport packet properly when initializing it kpatch-kernel: 4.18.0-553.104.1.el8_10 kpatch-cve: CVE-2025-38403 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38403 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=223e2288f4b8c262a864e2c03964ffac91744cd5 kpatch-name: rhel8/4.18.0-553.104.1.el8_10/CVE-2025-40269-alsa-usb-audio-fix-potential-overflow-of-pcm-transfer-buffer.patch kpatch-description: ALSA: usb-audio: Fix potential overflow of PCM transfer buffer kpatch-kernel: 4.18.0-553.104.1.el8_10 kpatch-cve: CVE-2025-40269 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40269 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=05a1fc5efdd8560f34a3af39c9cf1e1526cc3ddf kpatch-name: rhel8/4.18.0-553.104.1.el8_10/CVE-2025-68349-nfsv4-pnfs-clear-nfs-ino-layoutcommit-in-pnfs-mark-layout-stateid-invalid.patch kpatch-description: NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid kpatch-kernel: 4.18.0-553.104.1.el8_10 kpatch-cve: CVE-2025-68349 kpatch-cvss: 7.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-68349 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e0f8058f2cb56de0b7572f51cd563ca5debce746 kpatch-name: rhel8/4.18.0-553.104.1.el8_10/CVE-2026-22998-nvme-tcp-fix-null-pointer-dereferences-in-nvmet-tcp-build-pdu-iovec.patch kpatch-description: nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec kpatch-kernel: 4.18.0-553.104.1.el8_10 kpatch-cve: CVE-2026-22998 kpatch-cvss: 7.6 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-22998 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=32b63acd78f577b332d976aa06b56e70d054cbba kpatch-name: rhel8/4.18.0-553.104.1.el8_10/CVE-2025-40158-01-net-dst-add-four-helpers-to-annotate-data-races-553.22.patch kpatch-description: net: dst: add four helpers to annotate data-races around dst->dev kpatch-kernel: 4.18.0-553.104.1.el8_10 kpatch-cve: CVE-2025-40158 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40158 kpatch-patch-url: https://github.com/torvalds/linux/commit/88fe14253e181878c2ddb51a298ae8c468a63010 kpatch-name: rhel8/4.18.0-553.104.1.el8_10/CVE-2025-40158-02-net-add-locking-to-protect-skb-dev-access-in-ip_output.patch kpatch-description: net: Add locking to protect skb->dev access in ip_output kpatch-kernel: 4.18.0-553.104.1.el8_10 kpatch-cve: CVE-2025-40158 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40158 kpatch-patch-url: https://github.com/torvalds/linux/commit/1dbf1d590d10a6d1978e8184f8dfe20af22d680a kpatch-name: rhel8/4.18.0-553.104.1.el8_10/CVE-2025-40158-03-net-gain-ipv4-mtu-when-mtu-is-not-locked.patch kpatch-description: net: gain ipv4 mtu when mtu is not locked kpatch-kernel: 4.18.0-553.104.1.el8_10 kpatch-cve: CVE-2025-40158 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40158 kpatch-patch-url: https://github.com/torvalds/linux/commit/8b4510d76cde3c6934d4caed2fe897bd831cdb82 kpatch-name: rhel8/4.18.0-553.104.1.el8_10/CVE-2025-40158-03-ipv4-use-RCU-protection-in-__ip_rt_update_pmtu.patch kpatch-description: ipv4: use RCU protection in __ip_rt_update_pmtu() kpatch-kernel: 4.18.0-553.104.1.el8_10 kpatch-cve: CVE-2025-40158 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40158 kpatch-patch-url: https://github.com/torvalds/linux/commit/139512191bd06f1b496117c76372b2ce372c9a41 kpatch-name: rhel8/4.18.0-553.104.1.el8_10/CVE-2025-40158-04-net-dst-introduce-dst-dev_rcu-553.22.patch kpatch-description: net: dst: introduce dst->dev_rcu kpatch-kernel: 4.18.0-553.104.1.el8_10 kpatch-cve: CVE-2025-40158 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40158 kpatch-patch-url: https://github.com/torvalds/linux/commit/caedcc5b6df1b2e2b5f39079e3369c1d4d5c5f50 kpatch-name: rhel8/4.18.0-553.104.1.el8_10/CVE-2025-40158-ipv6-use-RCU-in-ip6_output.patch kpatch-description: ipv6: use RCU in ip6_output() kpatch-kernel: 4.18.0-553.104.1.el8_10 kpatch-cve: CVE-2025-40158 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40158 kpatch-patch-url: https://github.com/torvalds/linux/commit/11709573cc4e48dc34c80fc7ab9ce5b159e29695 kpatch-name: rhel8/4.18.0-553.104.1.el8_10/CVE-2025-40135-ipv6-use-RCU-in-ip6_xmit.patch kpatch-description: ipv6: use RCU in ip6_xmit() kpatch-kernel: 4.18.0-553.104.1.el8_10 kpatch-cve: CVE-2025-40135 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40135 kpatch-patch-url: https://github.com/torvalds/linux/commit/9085e56501d93af9f2d7bd16f7fcfacdde47b99c kpatch-name: rhel8/4.18.0-553.104.1.el8_10/CVE-2025-40170-00-optimize-kpatch-553.30.patch kpatch-description: net: use dst_dev_rcu() in sk_setup_caps() kpatch-kernel: 4.18.0-553.104.1.el8_10 kpatch-cve: CVE-2025-40170 kpatch-cvss: 7.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40170 kpatch-patch-url: https://github.com/torvalds/linux/commit/99a2ace61b211b0be861b07fbaa062fca4b58879 kpatch-name: rhel8/4.18.0-553.104.1.el8_10/CVE-2025-40170-01-ipv4-add-RCU-protection-to-ip4_dst_hoplimit.patch kpatch-description: ipv4: add RCU protection to ip4_dst_hoplimit() kpatch-kernel: 4.18.0-553.104.1.el8_10 kpatch-cve: CVE-2025-40170 kpatch-cvss: 7.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40170 kpatch-patch-url: https://github.com/torvalds/linux/commit/469308552ca4560176cfc100e7ca84add1bebd7c kpatch-name: rhel8/4.18.0-553.104.1.el8_10/CVE-2025-40170-02-ipv4-use-RCU-protection-in-ip_dst_mtu_maybe_forward.patch kpatch-description: ipv4: use RCU protection in ip_dst_mtu_maybe_forward() kpatch-kernel: 4.18.0-553.104.1.el8_10 kpatch-cve: CVE-2025-40170 kpatch-cvss: 7.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40170 kpatch-patch-url: https://github.com/torvalds/linux/commit/071d8012869b6af352acca346ade13e7be90a49f kpatch-name: rhel8/4.18.0-553.104.1.el8_10/CVE-2025-40170-net-use-dst_dev_rcu-in-sk_setup_caps.patch kpatch-description: net: use dst_dev_rcu() in sk_setup_caps() kpatch-kernel: 4.18.0-553.104.1.el8_10 kpatch-cve: CVE-2025-40170 kpatch-cvss: 7.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40170 kpatch-patch-url: https://github.com/torvalds/linux/commit/99a2ace61b211b0be861b07fbaa062fca4b58879 kpatch-name: rhel8/4.18.0-553.105.1.el8_10/CVE-2025-40168-smc-use-sk-dst-get-and-dst-dev-rcu-in-smc-clc-prfx-match.patch kpatch-description: smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match(). kpatch-kernel: 4.18.0-553.105.1.el8_10 kpatch-cve: CVE-2025-40168 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40168 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=235f81045c008169cc4e1955b4a64e118eebe61b kpatch-name: rhel8/4.18.0-553.105.1.el8_10/CVE-2025-40304-fbdev-add-bounds-checking-in-bit-putcs-to-fix-vmalloc-out-of-bounds.patch kpatch-description: fbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds kpatch-kernel: 4.18.0-553.105.1.el8_10 kpatch-cve: CVE-2025-40304 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40304 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3637d34b35b287ab830e66048841ace404382b67 kpatch-name: rhel8/4.18.0-553.105.1.el8_10/CVE-2023-53762-0001-Bluetooth-hci_event-Ignore-multiple-conn-complete-ev.patch kpatch-description: Bluetooth: hci_event: Ignore multiple conn complete events kpatch-kernel: 4.18.0-553.105.1.el8_10 kpatch-cve: CVE-2023-53762 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53762 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=aa1ca580e3ffe62a2c5ea1c095b609b2943c5269 kpatch-name: rhel8/4.18.0-553.105.1.el8_10/CVE-2023-53762-0002-Bluetooth-hci_event-Fix-checking-for-invalid-handle-.patch kpatch-description: Bluetooth: hci_event: Fix checking for invalid handle on error status kpatch-kernel: 4.18.0-553.105.1.el8_10 kpatch-cve: CVE-2023-53762 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53762 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a236fa3b5a6324659cb21f249a7227088ef460d9 kpatch-name: rhel8/4.18.0-553.105.1.el8_10/CVE-2023-53762-0003-Bluetooth-hci_sync-Cleanup-hci_conn-if-it-cannot-be-.patch kpatch-description: Bluetooth: hci_sync: Cleanup hci_conn if it cannot be aborted kpatch-kernel: 4.18.0-553.105.1.el8_10 kpatch-cve: CVE-2023-53762 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53762 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=995c917d6818b39308ac6baf3f6573cb0486a238 kpatch-name: rhel8/4.18.0-553.105.1.el8_10/CVE-2023-53762-0004-Bluetooth-hci_sync-Fix-UAF-on-hci_abort_conn_sync.patch kpatch-description: Bluetooth: hci_sync: Fix UAF on hci_abort_conn_sync kpatch-kernel: 4.18.0-553.105.1.el8_10 kpatch-cve: CVE-2023-53762 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53762 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=80265dd1d944c3f33e52375b5dbe654980bd2688 kpatch-name: rhel8/4.18.0-553.105.1.el8_10/CVE-2023-53762-0005-Bluetooth-hci_sync-Fix-UAF-in-hci_disconnect_all_syn.patch kpatch-description: Bluetooth: hci_sync: Fix UAF in hci_disconnect_all_sync kpatch-kernel: 4.18.0-553.105.1.el8_10 kpatch-cve: CVE-2023-53762 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53762 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a30c074f0b5b7f909a15c978fbc96a29e2f94e42 kpatch-name: rhel8/4.18.0-553.107.1.el8_10/CVE-2025-40064-smc-fix-use-after-free-in-pnet-find-base-ndev.patch kpatch-description: smc: Fix use-after-free in __pnet_find_base_ndev(). kpatch-kernel: 4.18.0-553.107.1.el8_10 kpatch-cve: CVE-2025-40064 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40064 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3d3466878afd8d43ec0ca2facfbc7f03e40d0f79 kpatch-name: rhel8/4.18.0-553.107.1.el8_10/CVE-2025-68800-mlxsw-spectrum-mr-fix-use-after-free-when-updating-multicast-route-stats.patch kpatch-description: mlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats kpatch-kernel: 4.18.0-553.107.1.el8_10 kpatch-cve: CVE-2025-68800 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-68800 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=8ac1dacec458f55f871f7153242ed6ab60373b90 kpatch-name: rhel8/4.18.0-553.107.1.el8_10/CVE-2025-38129-page-pool-fix-use-after-free-in-page-pool-recycle-in-ring.patch kpatch-description: page_pool: Fix use-after-free in page_pool_recycle_in_ring kpatch-kernel: 4.18.0-553.107.1.el8_10 kpatch-cve: CVE-2025-38129 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38129 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=271683bb2cf32e5126c592b5d5e6a756fa374fd9 kpatch-name: rhel8/4.18.0-553.107.1.el8_10/CVE-2026-23074-net-sched-enforce-that-teql-can-only-be-used-as-root-qdisc.patch kpatch-description: net/sched: Enforce that teql can only be used as root qdisc kpatch-kernel: 4.18.0-553.107.1.el8_10 kpatch-cve: CVE-2026-23074 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-23074 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=50da4b9d07a7a463e2cfb738f3ad4cff6b2c9c3b kpatch-name: rhel8/4.18.0-553.107.1.el8_10/CVE-2025-38248-bridge-mcast-fix-use-after-free-during-router-port-configuration.patch kpatch-description: bridge: mcast: Fix use-after-free during router port configuration kpatch-kernel: 4.18.0-553.107.1.el8_10 kpatch-cve: CVE-2025-38248 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-38248 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=7544f3f5b0b58c396f374d060898b5939da31709 kpatch-name: rhel8/4.18.0-553.109.1.el8_10/CVE-2026-23097-migrate-correct-lock-ordering-for-hugetlb-file-folios.patch kpatch-description: migrate: correct lock ordering for hugetlb file folios kpatch-kernel: 4.18.0-553.109.1.el8_10 kpatch-cve: CVE-2026-23097 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-23097 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=b7880cb166ab62c2409046b2347261abf701530e kpatch-name: rhel8/4.18.0-553.111.1.el8_10/CVE-2025-71085-ipv6-bug-in-pskb-expand-head-as-part-of-calipso-skbuff-setattr.patch kpatch-description: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() kpatch-kernel: 4.18.0-553.111.1.el8_10 kpatch-cve: CVE-2025-71085 kpatch-cvss: 7.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-71085 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=58fc7342b529803d3c221101102fe913df7adb83 kpatch-name: rhel8/4.18.0-553.111.1.el8_10/CVE-2026-23001-macvlan-fix-possible-uaf-in-macvlan-forward-source.patch kpatch-description: macvlan: fix possible UAF in macvlan_forward_source() kpatch-kernel: 4.18.0-553.111.1.el8_10 kpatch-cve: CVE-2026-23001 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-23001 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=7470a7a63dc162f07c26dbf960e41ee1e248d80e kpatch-name: skipped/CVE-2025-38180.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2025-38180 kpatch-skip-reason: Complex adaptation. ATM protocol nearly dead. kpatch-cvss: kpatch-name: rhel8/4.18.0-553.115.1.el8_10/CVE-2026-23209-macvlan-fix-error-recovery-in-macvlan-common-newlink.patch kpatch-description: macvlan: fix error recovery in macvlan_common_newlink() kpatch-kernel: 4.18.0-553.115.1.el8_10 kpatch-cve: CVE-2026-23209 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-23209 kpatch-patch-url: https://git.kernel.org/linus/f8db6475a83649689c087a8f52486fcc53e627e9 kpatch-name: rhel8/4.18.0-553.115.1.el8_10/CVE-2026-23273-macvlan-observe-rcu-grace-period-in-error-path.patch kpatch-description: macvlan: observe an RCU grace period in macvlan_common_newlink() error path kpatch-kernel: 4.18.0-553.115.1.el8_10 kpatch-cve: CVE-2026-23273 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-23273 kpatch-patch-url: https://git.kernel.org/linus/e3f000f0dee1bfab52e2e61ca6a3835d9e187e35 kpatch-name: rhel8/4.18.0-553.115.1.el8_10/CVE-2026-23204-net-sched-cls-u32-use-skb-header-pointer-careful.patch kpatch-description: net/sched: cls_u32: use skb_header_pointer_careful() kpatch-kernel: 4.18.0-553.115.1.el8_10 kpatch-cve: CVE-2026-23204 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-23204 kpatch-patch-url: https://git.kernel.org/linus/cabd1a976375780dabab888784e356f574bbaed8 kpatch-name: rhel8/4.18.0-553.117.1.el8_10/CVE-2026-23231-netfilter-nf-tables-fix-use-after-free-in-nf-tables-addchain.patch kpatch-description: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() kpatch-kernel: 4.18.0-553.117.1.el8_10 kpatch-cve: CVE-2026-23231 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-23231 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=71e99ee20fc3f662555118cf1159443250647533 kpatch-name: rhel8/4.18.0-553.117.1.el8_10/CVE-2025-71238-scsi-qla2xxx-fix-bsg-done-causing-double-free.patch kpatch-description: scsi: qla2xxx: Fix bsg_done() causing double free kpatch-kernel: 4.18.0-553.117.1.el8_10 kpatch-cve: CVE-2025-71238 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-71238 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c2c68225b1456f4d0d393b5a8778d51bb0d5b1d0 kpatch-name: rhel8/4.18.0-553.117.1.el8_10/CVE-2024-26984-nouveau-fix-instmem-race-condition-around-ptr-stores.patch kpatch-description: nouveau: fix instmem race condition around ptr stores kpatch-kernel: 4.18.0-553.117.1.el8_10 kpatch-cve: CVE-2024-26984 kpatch-cvss: 5.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-26984 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=fff1386cc889d8fb4089d285f883f8cba62d82ce kpatch-name: rhel8/4.18.0-553.117.1.el8_10/CVE-2026-23193-scsi-target-iscsi-fix-use-after-free-in-iscsit-dec-session-usage-count.patch kpatch-description: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() kpatch-kernel: 4.18.0-553.117.1.el8_10 kpatch-cve: CVE-2026-23193 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-23193 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=84dc6037390b8607c5551047d3970336cb51ba9a kpatch-name: rhel8/4.18.0-553.120.1.el8_10/CVE-2025-68741-scsi-qla2xxx-Fix-improper-freeing-of-purex-item.patch kpatch-description: scsi: qla2xxx: Fix improper freeing of purex item kpatch-kernel: 4.18.0-553.120.1.el8_10 kpatch-cve: CVE-2025-68741 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-68741 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=4bccd506a1f1ab01d1f45b2a3effff6bedc73cf9 kpatch-name: rhel8/4.18.0-553.120.1.el8_10/CVE-2026-23191-ALSA-aloop-Fix-racy-access-at-PCM-trigger.patch kpatch-description: ALSA: aloop: Fix racy access at PCM trigger kpatch-kernel: 4.18.0-553.120.1.el8_10 kpatch-cve: CVE-2026-23191 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-23191 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=5727ccf9d19ca414cb76d9b647883822e2789c2e kpatch-name: rhel8/4.18.0-553.123.1.el8_10/CVE-2026-31402-nfsd-fix-heap-overflow-in-nfsv4-0-lock-replay-cache.patch kpatch-description: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache kpatch-kernel: 4.18.0-553.123.1.el8_10 kpatch-cve: CVE-2026-31402 kpatch-cvss: 9.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-31402 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5133b61aaf437e5f25b1b396b14242a6bb0508e2 kpatch-name: rhel8/4.18.0-553.123.1.el8_10/CVE-2025-40252-net-qlogic-qede-fix-potential-out-of-bounds-read-in-qede-tpa-cont-and-qede-tpa-end.patch kpatch-description: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end() kpatch-kernel: 4.18.0-553.123.1.el8_10 kpatch-cve: CVE-2025-40252 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-40252 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=896f1a2493b59beb2b5ccdf990503dbb16cb2256 kpatch-name: rhel8/4.18.0-553.123.1.el8_10/CVE-2025-68724-crypto-asymmetric-keys-prevent-overflow-in-asymmetric-key-generate-id.patch kpatch-description: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id kpatch-kernel: 4.18.0-553.123.1.el8_10 kpatch-cve: CVE-2025-68724 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-68724 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=df0845cf447ae1556c3440b8b155de0926cbaa56 kpatch-name: rhel8/4.18.0-553.123.1.el8_10/CVE-2024-41073-nvme-avoid-double-free-special-payload.patch kpatch-description: nvme: avoid double free special payload kpatch-kernel: 4.18.0-553.123.1.el8_10 kpatch-cve: CVE-2024-41073 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2024-41073 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e5d574ab37f5f2e7937405613d9b1a724811e5ad kpatch-name: rhel8/4.18.0-553.123.1.el8_10/CVE-2026-23401-kvm-x86-mmu-drop-zap-existing-present-spte-even-when-creating-an-mmio-spte.patch kpatch-description: KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE kpatch-kernel: 4.18.0-553.123.1.el8_10 kpatch-cve: CVE-2026-23401 kpatch-cvss: 8.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-23401 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=aad885e774966e97b675dfe928da164214a71605 kpatch-name: rhel8/4.18.0-553.123.1.el8_10/CVE-2026-31431-crypto-algif_aead-Revert-to-operating-out-of-place.patch kpatch-description: crypto: algif_aead - Revert to operating out-of-place kpatch-kernel: 4.18.0-553.123.1.el8_10 kpatch-cve: CVE-2026-31431 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/cve-2026-31431 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5 kpatch-name: rhel8/4.18.0-553.123.1.el8_10/CVE-2026-43033-crypto-authencesn-Do-not-place-hiseq-at-end-of-dst-for-out-of-place-decryption.patch kpatch-description: crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption kpatch-kernel: 4.18.0-553.123.1.el8_10 kpatch-cve: CVE-2026-43033 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/cve-2026-43033 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=e02494114ebf kpatch-name: rhel8/4.18.0-553.123.1.el8_10/CVE-2026-43033-crypto-authencesn-Fix-src-offset-when-decrypting-in-place.patch kpatch-description: crypto: authencesn - Fix src offset when decrypting in-place kpatch-kernel: 4.18.0-553.123.1.el8_10 kpatch-cve: CVE-2026-43033 kpatch-cvss: 4.4 kpatch-cve-url: https://access.redhat.com/security/cve/cve-2026-43033 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=1f48ad3b19a9 kpatch-name: rhel8/4.18.0-553.123.1.el8_10/CVE-2026-43077-crypto-algif_aead-fix-minimum-rx-size-check-for-decryption.patch kpatch-description: crypto: algif_aead - Fix minimum RX size check for decryption kpatch-kernel: 4.18.0-553.123.1.el8_10 kpatch-cve: CVE-2026-43077 kpatch-cvss: 5.5 kpatch-cve-url: https://nvd.nist.gov/vuln/detail/CVE-2026-43077 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3d14bd48e3a77091cbce637a12c2ae31b4a1687c kpatch-name: rhel8/4.18.0-553.123.1.el8_10/CVE-2026-23060-crypto-authencesn-reject-too-short-aad-assoclen-8-to-match-esp-esn-spec.patch kpatch-description: crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec kpatch-kernel: 4.18.0-553.123.1.el8_10 kpatch-cve: CVE-2026-23060 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-23060 kpatch-patch-url: https://git.kernel.org/linus/2397e9264676be7794f8f7f1e9763d90bd3c7335 kpatch-name: rhel8/4.18.0-553.124.1.el8_10/CVE-2026-43284-xfrm-esp-avoid-in-place-decrypt-on-shared-skb-frags.patch kpatch-description: xfrm: esp: avoid in-place decrypt on shared skb frags kpatch-kernel: v7.0 kpatch-cve: CVE-2026-43284 kpatch-cvss: 8.8 kpatch-cve-url: https://access.redhat.com/security/cve/cve-2026-43284 kpatch-patch-url: https://git.kernel.org/linus/f4c50a4034e62ab75f1d5cdd191dd5f9c77fdff4 kpatch-name: rhel8/CVE-2026-46300-fragnesia.patch kpatch-description: net: skbuff: propagate shared-frag marker through frag-transfer helpers kpatch-kernel: v7.0 kpatch-cve: CVE-2026-46300 kpatch-cvss: N/A kpatch-cve-url: https://access.redhat.com/security/cve/cve-2026-46300 kpatch-patch-url: https://lore.kernel.org/all/agW4vC0r8QOUKtRT@v4bel/ kpatch-name: rhel8/4.18.0-553.123.1.el8_10/CVE-2026-46333-ptrace-require-cap-sys-ptrace-when-mm-null.patch kpatch-description: ptrace: require CAP_SYS_PTRACE in __ptrace_may_access when task->mm is NULL kpatch-kernel: 4.18.0-553.123.1.el8_10 kpatch-cve: CVE-2026-46333 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/cve-2026-46333 kpatch-patch-url: https://github.com/torvalds/linux/commit/31e62c2ebbfdc3fe3dbdf5e02c92a9dc67087a3a kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2025-71116-libceph-make-decode-pool-more-resilient-against-corrupted-osdmaps.patch kpatch-description: libceph: make decode_pool() more resilient against corrupted osdmaps kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2025-71116 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-71116 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=8c738512714e8c0aa18f8a10c072d5b01c83db39 kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2026-23270-net-sched-only-allow-act-ct-to-bind-to-clsact-ingress-qdiscs-and-shared-blocks.patch kpatch-description: net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2026-23270 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-23270 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=11cb63b0d1a0685e0831ae3c77223e002ef18189 kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2026-23243-rdma-umad-reject-negative-data-len-in-ib-umad-write.patch kpatch-description: RDMA/umad: Reject negative data_len in ib_umad_write kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2026-23243 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-23243 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5551b02fdbfd85a325bb857f3a8f9c9f33397ed2 kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2025-68347-alsa-firewire-motu-fix-buffer-overflow-in-hwdep-read-for-dsp-events.patch kpatch-description: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2025-68347 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-68347 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=210d77cca3d0494ed30a5c628b20c1d95fa04fb1 kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2026-23455-netfilter-nf-conntrack-h323-check-for-zero-length-in-decodeq931.patch kpatch-description: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2026-23455 kpatch-cvss: 9.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-23455 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f173d0f4c0f689173f8cdac79991043a4a89bf66 kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2025-68183-ima-don-t-clear-ima-digsig-flag-when-setting-or-removing-non-ima-xattr.patch kpatch-description: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2025-68183 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-68183 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=88b4cbcf6b041ae0f2fc8a34554a5b6a83a2b7cd kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2026-31684-net-sched-act-csum-validate-nested-vlan-headers.patch kpatch-description: net: sched: act_csum: validate nested VLAN headers kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2026-31684 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-31684 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c842743d073bdd683606cb414eb0ca84465dd834 kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2026-31685-netfilter-ip6t-eui64-reject-invalid-mac-header-for-all-packets.patch kpatch-description: netfilter: ip6t_eui64: reject invalid MAC header for all packets kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2026-31685 kpatch-cvss: 9.4 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-31685 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=fdce0b3590f724540795b874b4c8850c90e6b0a8 kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2026-43027-netfilter-nf-conntrack-helper-pass-helper-to-expect-cleanup.patch kpatch-description: netfilter: nf_conntrack_helper: pass helper to expect cleanup kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2026-43027 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-43027 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a242a9ae58aa46ff7dae51ce64150a93957abe65 kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2026-43051-hid-wacom-fix-out-of-bounds-read-in-wacom-intuos-bt-irq.patch kpatch-description: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2026-43051 kpatch-cvss: 8.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-43051 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2f1763f62909ccb6386ac50350fa0abbf5bb16a9 kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2026-31532-can-raw-fix-ro-uniq-use-after-free-in-raw-rcv.patch kpatch-description: can: raw: fix ro->uniq use-after-free in raw_rcv() kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2026-31532 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-31532 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=a535a9217ca3f2fccedaafb2fddb4c48f27d36dc kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2026-43190-netfilter-xt-tcpmss-check-remaining-length-before-reading-optlen.patch kpatch-description: netfilter: xt_tcpmss: check remaining length before reading optlen kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2026-43190 kpatch-cvss: 8.2 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-43190 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=735ee8582da3d239eb0c7a53adca61b79fb228b3 kpatch-name: skipped/CVE-2025-39981.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2025-39981 kpatch-skip-reason: Complex adaptation required kpatch-cvss: kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2026-43158-xfs-delete-attr-leaf-freemap-entries-when-empty.patch kpatch-description: xfs: delete attr leaf freemap entries when empty kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2026-43158 kpatch-cvss: 8.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-43158 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=6f13c1d2a6271c2e73226864a0e83de2770b6f34 kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2026-43158-xfs-fix-freemap-adjustments-when-adding-xattrs-to-leaf-blocks-4.18.0-553.125.1.el8_10.patch kpatch-description: xfs: fix freemap adjustments when adding xattrs to leaf blocks kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2026-43158 kpatch-cvss: 8.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-43158 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=a396b3d73d51355e50acdb403ba9c4cae4c1174e kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2026-31408-bluetooth-sco-fix-use-after-free-in-sco-recv-frame-due-to-missing-sock-hold.patch kpatch-description: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2026-31408 kpatch-cvss: 8.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-31408 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=7197462e90b8ce15caa1ae15d4bc2bb8cd21b11e kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2026-43020-bluetooth-mgmt-validate-ltk-enc-size-on-load.patch kpatch-description: Bluetooth: MGMT: validate LTK enc_size on load kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2026-43020 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-43020 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=0f37d1e65c6d71ad94ccfb5c602163c525db789d kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2026-31709-smb-client-validate-the-whole-dacl-before-rewriting-it-in-cifsacl-4.18.0-513.24.1.el8_9.patch kpatch-description: smb: client: validate the whole DACL before rewriting it in cifsacl kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2026-31709 kpatch-cvss: 8.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-31709 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=0a8cf165566ba55a39fd0f4de172119dd646d39a kpatch-name: rhel8/4.18.0-553.126.1.el8_10/CVE-2026-46195-smb-client-validate-dacloffset-before-building-dacl-pointers-4.18.0-513.24.1.el8_9.patch kpatch-description: smb: client: validate dacloffset before building DACL pointers kpatch-kernel: 4.18.0-553.126.1.el8_10 kpatch-cve: CVE-2026-46195 kpatch-cvss: 9.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46195 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f98b48151cc502ada59d9778f0112d21f2586ca3 kpatch-name: rhel8/4.18.0-553.129.1.el8_10/CVE-2026-46243-smb-client-reject-userspace-cifs.spnego-descriptions.patch kpatch-description: smb: client: reject userspace cifs.spnego descriptions (cifs LPE) kpatch-kernel: 4.18.0-553.129.1.el8_10 kpatch-cve: CVE-2026-46243 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46243 kpatch-patch-url: https://git.kernel.org/linus/3da1fdf4efbc490041eb4f836bf596201203f8f2 kpatch-name: rhel8/4.18.0-553.129.1.el8_10/CVE-2026-46243-smb-client-reject-userspace-cifs.spnego-descriptions-kpatch.patch kpatch-description: smb: client: reject userspace cifs.spnego descriptions (adaptation) kpatch-kernel: 4.18.0-553.129.1.el8_10 kpatch-cve: CVE-2026-46243 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46243 kpatch-patch-url: https://git.kernel.org/linus/3da1fdf4efbc490041eb4f836bf596201203f8f2 kpatch-name: rhel8/4.18.0-553.132.1.el8_10/CVE-2026-22990-libceph-replace-overzealous-bug-on-in-osdmap-apply-incremental.patch kpatch-description: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() kpatch-kernel: 4.18.0-553.132.1.el8_10 kpatch-cve: CVE-2026-22990 kpatch-cvss: 7.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-22990 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e00c3f71b5cf75681dbd74ee3f982a99cb690c2b kpatch-name: rhel8/4.18.0-553.132.1.el8_10/CVE-2026-22984-libceph-prevent-potential-out-of-bounds-reads-in-handle-auth-done.patch kpatch-description: libceph: prevent potential out-of-bounds reads in handle_auth_done() kpatch-kernel: 4.18.0-553.132.1.el8_10 kpatch-cve: CVE-2026-22984 kpatch-cvss: 9.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-22984 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=818156caffbf55cb4d368f9c3cac64e458fb49c9 kpatch-name: rhel8/4.18.0-553.132.1.el8_10/CVE-2025-68366-nbd-defer-config-unlock-in-nbd-genl-connect.patch kpatch-description: nbd: defer config unlock in nbd_genl_connect kpatch-kernel: 4.18.0-553.132.1.el8_10 kpatch-cve: CVE-2025-68366 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-68366 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=1649714b930f9ea6233ce0810ba885999da3b5d4 kpatch-name: rhel8/4.18.0-553.132.1.el8_10/CVE-2023-53781-smc-fix-use-after-free-in-tcp-write-timer-handler.patch kpatch-description: smc: Fix use-after-free in tcp_write_timer_handler(). kpatch-kernel: 4.18.0-553.132.1.el8_10 kpatch-cve: CVE-2023-53781 kpatch-cvss: 7.3 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2023-53781 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9744d2bf19762703704ecba885b7ac282c02eacf kpatch-name: rhel8/4.18.0-553.132.1.el8_10/CVE-2026-23392-netfilter-nf-tables-release-flowtable-after-rcu-grace-period-on-error.patch kpatch-description: netfilter: nf_tables: release flowtable after rcu grace period on error kpatch-kernel: 4.18.0-553.132.1.el8_10 kpatch-cve: CVE-2026-23392 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-23392 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=d73f4b53aaaea4c95f245e491aa5eeb8a21874ce kpatch-name: rhel8/4.18.0-553.132.1.el8_10/CVE-2026-45852-rdma-rxe-fix-double-free-in-rxe-srq-from-init.patch kpatch-description: RDMA/rxe: Fix double free in rxe_srq_from_init kpatch-kernel: 4.18.0-553.132.1.el8_10 kpatch-cve: CVE-2026-45852 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-45852 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=0beefd0e15d962f497aad750b2d5e9c3570b66d1 kpatch-name: rhel8/4.18.0-553.132.1.el8_10/CVE-2026-43038-ipv6-icmp-clear-skb2-cb-in-ip6-err-gen-icmpv6-unreach.patch kpatch-description: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() kpatch-kernel: 4.18.0-553.132.1.el8_10 kpatch-cve: CVE-2026-43038 kpatch-cvss: 9.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-43038 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=86ab3e55673a7a49a841838776f1ab18d23a67b5 kpatch-name: rhel8/4.18.0-553.132.1.el8_10/CVE-2026-46181-rdma-mlx4-fix-mis-use-of-rcu-in-mlx4-srq-event.patch kpatch-description: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() kpatch-kernel: 4.18.0-553.132.1.el8_10 kpatch-cve: CVE-2026-46181 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46181 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c9341307ea16b9395c2e4c9c94d8499d91fe31d0 kpatch-name: rhel8/4.18.0-553.132.1.el8_10/CVE-2026-43125-dlm-validate-length-in-dlm-search-rsb-tree.patch kpatch-description: dlm: validate length in dlm_search_rsb_tree kpatch-kernel: 4.18.0-553.132.1.el8_10 kpatch-cve: CVE-2026-43125 kpatch-cvss: 9.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-43125 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=080e5563f878c64e697b89e7439d730d0daad882 kpatch-name: rhel8/4.18.0-553.132.1.el8_10/CVE-2026-43125-dlm-validate-length-in-dlm-search-rsb-tree-fix-lock-h.patch kpatch-description: dlm: validate length in dlm_search_rsb_tree - fix lock.h declaration kpatch-kernel: 4.18.0-553.132.1.el8_10 kpatch-cve: CVE-2026-43125 kpatch-cvss: 9.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-43125 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=080e5563f878c64e697b89e7439d730d0daad882 kpatch-name: rhel8/4.18.0-553.132.1.el8_10/CVE-2026-43037-ip6-tunnel-clear-skb2-cb-in-ip4ip6-err.patch kpatch-description: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() kpatch-kernel: 4.18.0-553.132.1.el8_10 kpatch-cve: CVE-2026-43037 kpatch-cvss: 9.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-43037 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2edfa31769a4add828a7e604b21cb82aaaa05925 kpatch-name: rhel8/4.18.0-553.132.1.el8_10/CVE-2025-21858-geneve-fix-use-after-free-in-geneve-find-dev-4.18.0-553.69.1.el8_10.patch kpatch-description: geneve: Fix use-after-free in geneve_find_dev(). kpatch-kernel: 4.18.0-553.132.1.el8_10 kpatch-cve: CVE-2025-21858 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-21858 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9593172d93b9f91c362baec4643003dc29802929 kpatch-name: rhel8/4.18.0-553.132.1.el8_10/CVE-2025-21858-geneve-Suppress-list-corruption-splat-in-geneve_destroy_tunnels-4.18.0-553.69.1.el8_10.patch kpatch-description: geneve: Suppress list corruption splat in geneve_destroy_tunnels(). kpatch-kernel: 4.18.0-553.132.1.el8_10 kpatch-cve: CVE-2025-21858 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-21858 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=62fab6eef61f245dc8797e3a6a5b890ef40e8628 kpatch-name: rhel8/4.18.0-553.132.1.el8_10/CVE-2026-31581-alsa-6fire-fix-use-after-free-on-disconnect-4.18.0-553.129.1.el8_10.patch kpatch-description: ALSA: 6fire: fix use-after-free on disconnect kpatch-kernel: 4.18.0-553.132.1.el8_10 kpatch-cve: CVE-2026-31581 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-31581 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=e719232f4552e29de8027a83918ea94434be87af kpatch-name: rhel8/4.18.0-553.134.1.el8_10/CVE-2026-31786-buffer-overflow-in-drivers-xen-sys-hypervisor-c.patch kpatch-description: Buffer overflow in drivers/xen/sys-hypervisor.c kpatch-kernel: 4.18.0-553.134.1.el8_10 kpatch-cve: CVE-2026-31786 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-31786 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=27fdbab4221b375de54bf91919798d88520c6e28 kpatch-name: rhel8/4.18.0-553.134.1.el8_10/CVE-2026-43110-wifi-brcmfmac-validate-bsscfg-indices-in-if-events.patch kpatch-description: wifi: brcmfmac: validate bsscfg indices in IF events kpatch-kernel: 4.18.0-553.134.1.el8_10 kpatch-cve: CVE-2026-43110 kpatch-cvss: 8.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-43110 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=304950a467d83678bd0b0f46331882e2ac23b12d kpatch-name: rhel8/4.18.0-553.134.1.el8_10/CVE-2026-31787-xen-privcmd-fix-double-free-via-vma-splitting.patch kpatch-description: xen/privcmd: fix double free via VMA splitting kpatch-kernel: 4.18.0-553.134.1.el8_10 kpatch-cve: CVE-2026-31787 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-31787 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=1576ff3869cbd3620717195f971c85b7d7fd62b5 kpatch-name: rhel8/4.18.0-553.134.1.el8_10/CVE-2026-31787-xen-privcmd-fix-double-free-via-vma-splitting-kpatch.patch kpatch-description: xen/privcmd: fix double free via VMA splitting (Adaptation) kpatch-kernel: 4.18.0-553.134.1.el8_10 kpatch-cve: CVE-2026-31787 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-31787 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=1576ff3869cbd3620717195f971c85b7d7fd62b5 kpatch-name: rhel8/4.18.0-553.134.1.el8_10/CVE-2026-31669-mptcp-fix-slab-use-after-free-in-inet-lookup-established.patch kpatch-description: mptcp: fix slab-use-after-free in __inet_lookup_established kpatch-kernel: 4.18.0-553.134.1.el8_10 kpatch-cve: CVE-2026-31669 kpatch-cvss: 9.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-31669 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9b55b253907e7431210483519c5ad711a37dafa1 kpatch-name: rhel8/4.18.0-553.134.1.el8_10/CVE-2026-31669-mptcp-fix-slab-use-after-free-in-inet-lookup-established-kpatch.patch kpatch-description: mptcp: fix slab-use-after-free in __inet_lookup_established kpatch-kernel: 4.18.0-553.134.1.el8_10 kpatch-cve: CVE-2026-31669 kpatch-cvss: 9.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-31669 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9b55b253907e7431210483519c5ad711a37dafa1 kpatch-name: rhel8/4.18.0-553.134.1.el8_10/CVE-2026-43329-netfilter-flowtable-strictly-check-for-maximum-number-of-actions.patch kpatch-description: netfilter: flowtable: strictly check for maximum number of actions kpatch-kernel: 4.18.0-553.134.1.el8_10 kpatch-cve: CVE-2026-43329 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-43329 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=76522fcdbc3a02b568f5d957f7e66fc194abb893 kpatch-name: rhel8/4.18.0-553.134.1.el8_10/CVE-2026-46056-bluetooth-hci-event-fix-potential-uaf-in-ssp-passkey-handlers.patch kpatch-description: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers kpatch-kernel: 4.18.0-553.134.1.el8_10 kpatch-cve: CVE-2026-46056 kpatch-cvss: 8.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46056 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=85fa3512048793076eef658f66489112dcc91993 kpatch-name: rhel8/4.18.0-553.134.1.el8_10/CVE-2026-46152-wifi-mac80211-drop-stray-static-from-fast-rx-rx-result.patch kpatch-description: wifi: mac80211: drop stray 'static' from fast-RX rx_result kpatch-kernel: 4.18.0-553.134.1.el8_10 kpatch-cve: CVE-2026-46152 kpatch-cvss: 8.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46152 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=7a5b81e0c87a075afd572f659d8eb68c9c4cd2ba kpatch-name: rhel8/4.18.0-553.134.1.el8_10/CVE-2026-46125-wifi-mac80211-remove-station-if-connection-prep-fails.patch kpatch-description: wifi: mac80211: remove station if connection prep fails kpatch-kernel: 4.18.0-553.134.1.el8_10 kpatch-cve: CVE-2026-46125 kpatch-cvss: 8.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46125 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=283fc9e44ff5b5ac967439b4951b80bd4299f4e4 kpatch-name: rhel8/4.18.0-553.136.1.el8_10/CVE-2026-31419-net-bonding-fix-use-after-free-in-bond-xmit-broadcast.patch kpatch-description: net: bonding: fix use-after-free in bond_xmit_broadcast() kpatch-kernel: 4.18.0-553.136.1.el8_10 kpatch-cve: CVE-2026-31419 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-31419 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=2884bf72fb8f03409e423397319205de48adca16 kpatch-name: rhel8/4.18.0-553.136.1.el8_10/CVE-2026-43279-alsa-usb-audio-add-sanity-check-for-oob-writes-at-silencing.patch kpatch-description: ALSA: usb-audio: Add sanity check for OOB writes at silencing kpatch-kernel: 4.18.0-553.136.1.el8_10 kpatch-cve: CVE-2026-43279 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-43279 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=fba2105a157fffcf19825e4eea498346738c9948 kpatch-name: rhel8/4.18.0-553.136.1.el8_10/CVE-2026-46090-alsa-aloop-fix-peer-runtime-uaf-during-format-change-stop-4.18.0-553.117.1.el8_10.patch kpatch-description: ALSA: aloop: Fix peer runtime UAF during format-change stop kpatch-kernel: 4.18.0-553.136.1.el8_10 kpatch-cve: CVE-2026-46090 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46090 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e5c33cdc6f402eab8abd36ecf436b22c9d3a8aff kpatch-name: rhel8/4.18.0-553.136.1.el8_10/CVE-2026-46090-alsa-aloop-fix-peer-runtime-uaf-during-format-change-stop-kpatch-4.18.0-553.117.1.el8_10.patch kpatch-description: ALSA: aloop: Fix peer runtime UAF during format-change stop kpatch kpatch-kernel: 4.18.0-553.136.1.el8_10 kpatch-cve: CVE-2026-46090 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46090 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e5c33cdc6f402eab8abd36ecf436b22c9d3a8aff kpatch-name: rhel8/4.18.0-553.136.1.el8_10/CVE-2026-43056-net-mana-fix-use-after-free-in-add-adev-error-path.patch kpatch-description: net: mana: fix use-after-free in add_adev() error path kpatch-kernel: 4.18.0-553.136.1.el8_10 kpatch-cve: CVE-2026-43056 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-43056 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=c4ea7d8907cf72b259bf70bd8c2e791e1c4ff70f kpatch-name: rhel8/4.18.0-553.136.1.el8_10/CVE-2026-46135-nvmet-tcp-fix-race-between-icreq-handling-and-queue-teardown.patch kpatch-description: nvmet-tcp: fix race between ICReq handling and queue teardown kpatch-kernel: 4.18.0-553.136.1.el8_10 kpatch-cve: CVE-2026-46135 kpatch-cvss: 9.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46135 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=5293a8882c549fab4a878bc76b0b6c951f980a61 kpatch-name: rhel8/4.18.0-553.136.1.el8_10/CVE-2026-46145-rdma-mana-validate-rx-hash-key-len-4.18.0-553.134.1.el8_10.patch kpatch-description: RDMA/mana: Validate rx_hash_key_len kpatch-kernel: 4.18.0-553.136.1.el8_10 kpatch-cve: CVE-2026-46145 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46145 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=6dd2d4ad9c8429523b1c220c5132bd551c006425 kpatch-name: rhel8/4.18.0-553.136.1.el8_10/CVE-2026-46331-net-sched-fix-pedit-partial-cow-leading-to-page-cache-corruption-4.18.0-553.134.1.el8_10.patch kpatch-description: net/sched: fix pedit partial COW leading to page cache corruption kpatch-kernel: 4.18.0-553.136.1.el8_10 kpatch-cve: CVE-2026-46331 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46331 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=2bec122b9fb91507a758ab5e3e5c4fbe7cb3f61b kpatch-name: skipped/CVE-2026-46054.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2026-46054 kpatch-skip-reason: Out of scope: boot time issue kpatch-cvss: kpatch-name: rhel8/4.18.0-553.139.1.el8_10/CVE-2026-23216-scsi-target-iscsi-fix-use-after-free-in-iscsit-dec-conn-usage-count.patch kpatch-description: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() kpatch-kernel: 4.18.0-553.139.1.el8_10 kpatch-cve: CVE-2026-23216 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-23216 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=9411a89e9e7135cc459178fa77a3f1d6191ae903 kpatch-name: rhel8/4.18.0-553.139.1.el8_10/CVE-2026-46189-rdma-vmw-pvrdma-fix-double-free-on-pvrdma-alloc-ucontext-error-path.patch kpatch-description: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path kpatch-kernel: 4.18.0-553.139.1.el8_10 kpatch-cve: CVE-2026-46189 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46189 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=e38e86995df27f1f854063dab1f0c6a513db3faf kpatch-name: rhel8/4.18.0-553.139.1.el8_10/CVE-2026-45984-gfs2-add-metapath-dibh-helper.patch kpatch-description: gfs2: Add metapath_dibh helper kpatch-kernel: 4.18.0-553.139.1.el8_10 kpatch-cve: CVE-2026-45984 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-45984 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=92099f0c9227 kpatch-name: rhel8/4.18.0-553.139.1.el8_10/CVE-2026-45984-gfs2-fix-use-after-free-in-iomap-inline-data-write-path.patch kpatch-description: gfs2: Fix use-after-free in iomap inline data write path kpatch-kernel: 4.18.0-553.139.1.el8_10 kpatch-cve: CVE-2026-45984 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-45984 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=87d4954b5c59735a99ea98cb208d47130f6dce7d kpatch-name: rhel8/4.18.0-553.140.1.el8_10/CVE-2026-43450-netfilter-nfnetlink-cthelper-fix-oob-read-in-nfnl-cthelper-dump-table.patch kpatch-description: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() kpatch-kernel: 4.18.0-553.140.1.el8_10 kpatch-cve: CVE-2026-43450 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-43450 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=6dcee8496d53165b2d8a5909b3050b62ae71fe89 kpatch-name: rhel8/4.18.0-553.140.1.el8_10/CVE-2026-46227-sctp-revalidate-list-cursor-after-sctp-sendmsg-to-asoc-in-sctp-sendall.patch kpatch-description: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL kpatch-kernel: 4.18.0-553.140.1.el8_10 kpatch-cve: CVE-2026-46227 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46227 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=abb5f36771cc4c05899b34000829a787572a8817 kpatch-name: rhel8/4.18.0-553.140.1.el8_10/CVE-2026-46209-drm-Remove-plane-hsub-vsub-alignment-requirement-for-dep.patch kpatch-description: drm: Remove plane hsub/vsub alignment requirement for core helpers kpatch-kernel: 4.18.0-553.140.1.el8_10 kpatch-cve: CVE-2026-46209 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46209 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=f2f455981a34ce8ca88a41458c09494b387d344f kpatch-name: rhel8/4.18.0-553.140.1.el8_10/CVE-2026-46209-drm-gem-fix-inconsistent-plane-dimension-calculation-in-drm-gem-fb-init-with-funcs.patch kpatch-description: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() kpatch-kernel: 4.18.0-553.140.1.el8_10 kpatch-cve: CVE-2026-46209 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46209 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=3d4c2268bd7243c3780fe32bf24ff876da272acf kpatch-name: rhel8/4.18.0-553.140.1.el8_10/CVE-2026-46259-procfs-fix-missing-rcu-protection-when-reading-real-parent-in-do-task-stat.patch kpatch-description: procfs: fix missing RCU protection when reading real_parent in do_task_stat() kpatch-kernel: 4.18.0-553.140.1.el8_10 kpatch-cve: CVE-2026-46259 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46259 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=76149d53502cf17ef3ae454ff384551236fba867 kpatch-name: skipped/CVE-2025-10263.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2025-10263 kpatch-skip-reason: Out of scope: ARM64 architecture isn't supported for current kernel kpatch-cvss: kpatch-name: rhel8/CVE-2026-43499-rtmutex-use-waiter-task-instead-of-current-in-remove-waiter.patch kpatch-description: rtmutex: Use waiter::task instead of current in remove_waiter() kpatch-kernel: 4.18.0-553.137.1.el8_10 kpatch-cve: CVE-2026-43499 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/cve-2026-43499 kpatch-patch-url: https://git.kernel.org/linus/3bfdc63936dd4773109b7b8c280c0f3b5ae7d349 kpatch-name: rhel8/CVE-2026-53163-locking-rtmutex-skip-remove-waiter-when-waiter-is-not-enqueued.patch kpatch-description: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued kpatch-kernel: 4.18.0-553.137.1.el8_10 kpatch-cve: CVE-2026-53163 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/cve-2026-53163 kpatch-patch-url: https://git.kernel.org/linus/40a25d59e85b3c8709ac2424d44f65610467871e kpatch-name: rhel8/4.18.0-553.141.1.el8_10/CVE-2026-43112-fs-smb-client-fix-out-of-bounds-read-in-cifs_sanitize_prepath.patch kpatch-description: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath kpatch-kernel: 4.18.0-553.141.1.el8_10 kpatch-cve: CVE-2026-43112 kpatch-cvss: 8.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-43112 kpatch-patch-url: https://github.com/torvalds/linux/commit/78ec5bf2f589ec7fd8f169394bfeca541b077317 kpatch-name: rhel8/4.18.0-553.143.1.el8_10/CVE-2026-53266-netfilter-bridge-make-ebt-snat-arp-rewrite-writable.patch kpatch-description: netfilter: bridge: make ebt_snat ARP rewrite writable kpatch-kernel: 4.18.0-553.143.1.el8_10 kpatch-cve: CVE-2026-53266 kpatch-cvss: 8.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-53266 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=67ba971ae02514d85818fe0c32549ab4bfa3bf49 kpatch-name: rhel8/4.18.0-553.143.1.el8_10/CVE-2025-71089-iommu-disable-sva-when-config-x86-is-set.patch kpatch-description: iommu: disable SVA when CONFIG_X86 is set kpatch-kernel: 4.18.0-553.143.1.el8_10 kpatch-cve: CVE-2025-71089 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-71089 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=72f98ef9a4be30d2a60136dd6faee376f780d06c kpatch-name: rhel8/4.18.0-553.143.1.el8_10/CVE-2025-71066-net-sched-ets-always-remove-class-from-active-list-before-deleting-in-ets-qdisc-change-4.18.0-553.74.1.el8_10.patch kpatch-description: net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change kpatch-kernel: 4.18.0-553.143.1.el8_10 kpatch-cve: CVE-2025-71066 kpatch-cvss: 7.5 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2025-71066 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/patch/?id=9987cda315c08f63a02423fa2f9a1f6602c861a0 kpatch-name: rhel8/4.18.0-553.142.1.el8_10/CVE-2026-31411-net-atm-fix-crash-due-to-unvalidated-vcc-pointer-in-sigd-send.patch kpatch-description: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() kpatch-kernel: 4.18.0-553.142.1.el8_10 kpatch-cve: CVE-2026-31411 kpatch-cvss: 7.1 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-31411 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=ae88a5d2f29b69819dc7b04086734439d074a643 kpatch-name: skipped/CVE-2026-53166.patch kpatch-description: kpatch-kernel: kpatch-cve: CVE-2026-53166 kpatch-skip-reason: Rejected by NIST kpatch-cvss: kpatch-name: rhel8/4.18.0-553.139.1.el8_10/CVE-2026-46113-kvm-x86-fix-shadow-paging-use-after-free.patch kpatch-description: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN/role kpatch-kernel: 4.18.0-553.139.1.el8_10 kpatch-cve: CVE-2026-46113 kpatch-cvss: 8.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46113 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0cb2af2ea66ad8ff195c156ea690f11216285bdf kpatch-name: rhel8/CVE-2026-52910-bpf-free-reuseport-cbpf-prog-after-rcu-grace-period.patch kpatch-description: bpf: Free reuseport cBPF prog after RCU grace period kpatch-kernel: 4.18.0-553.137.1.el8_10 kpatch-cve: CVE-2026-52910 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-52910 kpatch-patch-url: https://git.kernel.org/linus/18fc650ccd7fe3376eca89203668cfb8268f60df kpatch-name: rhel8/4.18.0-553.144.1.el8_10/CVE-2026-46086-net-bridge-use-a-stable-fdb-dst-snapshot-in-rcu-readers.patch kpatch-description: net: bridge: use a stable FDB dst snapshot in RCU readers kpatch-kernel: 4.18.0-553.144.1.el8_10 kpatch-cve: CVE-2026-46086 kpatch-cvss: 7.0 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46086 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=df4601653201de21b487c3e7fffd464790cab808 kpatch-name: rhel8/4.18.0-553.144.1.el8_10/CVE-2026-46116-xfrm-defensively-unhash-xfrm-state-lists-in-xfrm-state-delete.patch kpatch-description: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete kpatch-kernel: 4.18.0-553.144.1.el8_10 kpatch-cve: CVE-2026-46116 kpatch-cvss: 7.8 kpatch-cve-url: https://access.redhat.com/security/cve/CVE-2026-46116 kpatch-patch-url: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=14acf9652e5690de3c7486c6db5fb8dafd0a32a3 kpatch-name: xfs-resample-the-data-fork-mapping-after-cycling-ILO-5.14.0.patch kpatch-description: xfs: resample the data fork mapping after cycling ILOCK kpatch-kernel: next kpatch-cve: N/A kpatch-cvss: N/A kpatch-cve-url: https://git.kernel.org/pub/scm/fs/xfs/xfs-linux.git/commit/?h=for-next&id=2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7 kpatch-patch-url: https://git.kernel.org/pub/scm/fs/xfs/xfs-linux.git/commit/?h=for-next&id=2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7 kpatch-name: 4.18.0/x86-xen-Add-xenpv_restore_regs_and_return_to_usermode-el8-372.patch kpatch-description: x86 xen add xenpv restore regs and return to usermode kpatch-kernel: N/A kpatch-cve: N/A kpatch-cvss: N/A kpatch-cve-url: N/A kpatch-patch-url: N/A kpatch-name: 4.18.0/kpatch-add-alt-asm-definitions-el8-372.patch kpatch-description: kpatch add alt asm definitions kpatch-kernel: N/A kpatch-cve: N/A kpatch-cvss: N/A kpatch-cve-url: https://www.kernel.org kpatch-patch-url: https://www.kernel.org uname: 4.18.0-553.144.1.el8_10