Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:9079

Опубликовано: 03 окт. 2025
Источник: rocky
Оценка: Important

Описание

Important: kernel security update

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: ndisc: use RCU protection in ndisc_alloc_skb() (CVE-2025-21764)

  • kernel: ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up (CVE-2025-21887)

  • kernel: keys: Fix UAF in key_put() (CVE-2025-21893)

  • kernel: cifs: Fix integer overflow while processing closetimeo mount option (CVE-2025-21962)

  • kernel: Bluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd (CVE-2025-21969)

  • kernel: cifs: Fix integer overflow while processing acdirmax mount option (CVE-2025-21963)

  • kernel: wifi: cfg80211: cancel wiphy_work before freeing wiphy (CVE-2025-21979)

  • kernel: smb: client: fix UAF in decryption with multichannel (CVE-2025-37750)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
kernelx86_6455.17.1.el10_0kernel-6.12.0-55.17.1.el10_0.x86_64.rpm
kernel-abi-stablelistsnoarch55.17.1.el10_0kernel-abi-stablelists-6.12.0-55.17.1.el10_0.noarch.rpm
kernel-corex86_6455.17.1.el10_0kernel-core-6.12.0-55.17.1.el10_0.x86_64.rpm
kernel-debugx86_6455.17.1.el10_0kernel-debug-6.12.0-55.17.1.el10_0.x86_64.rpm
kernel-debug-corex86_6455.17.1.el10_0kernel-debug-core-6.12.0-55.17.1.el10_0.x86_64.rpm
kernel-debuginfo-common-x86_64x86_6455.17.1.el10_0kernel-debuginfo-common-x86_64-6.12.0-55.17.1.el10_0.x86_64.rpm
kernel-debug-modulesx86_6455.17.1.el10_0kernel-debug-modules-6.12.0-55.17.1.el10_0.x86_64.rpm
kernel-debug-modules-corex86_6455.17.1.el10_0kernel-debug-modules-core-6.12.0-55.17.1.el10_0.x86_64.rpm
kernel-debug-modules-extrax86_6455.17.1.el10_0kernel-debug-modules-extra-6.12.0-55.17.1.el10_0.x86_64.rpm
kernel-debug-uki-virtx86_6455.17.1.el10_0kernel-debug-uki-virt-6.12.0-55.17.1.el10_0.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
4 месяца назад

ELSA-2025-9079: kernel security update (IMPORTANT)

CVSS3: 7.8
ubuntu
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ndisc: use RCU protection in ndisc_alloc_skb() ndisc_alloc_skb() can be called without RTNL or RCU being held. Add RCU protection to avoid possible UAF.

CVSS3: 7
redhat
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ndisc: use RCU protection in ndisc_alloc_skb() ndisc_alloc_skb() can be called without RTNL or RCU being held. Add RCU protection to avoid possible UAF.

CVSS3: 7.8
nvd
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ndisc: use RCU protection in ndisc_alloc_skb() ndisc_alloc_skb() can be called without RTNL or RCU being held. Add RCU protection to avoid possible UAF.

CVSS3: 7.8
msrc
6 месяцев назад

Описание отсутствует