[ALSA-2026:6632] Moderate: kernel security update
Type:
security
Severity:
moderate
Release date:
2026-04-10
Description:
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: Linux kernel (net/mlx5): Use-after-free in ECVF vports unload leads to denial of service (CVE-2025-38109) * kernel: Linux kernel: Local denial of service and memory leak in DAMON sysfs via setup failure (CVE-2026-23144) * kernel: Linux kernel: Use-after-free in bonding module can cause system crash or arbitrary code execution (CVE-2026-23171) * kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() (CVE-2026-23193) * kernel: macvlan: fix error recovery in macvlan_common_newlink() (CVE-2026-23209) * kernel: net/sched: cls_u32: use skb_header_pointer_careful() (CVE-2026-23204) * kernel: ALSA: aloop: Fix racy access at PCM trigger (CVE-2026-23191) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
noarch kernel-doc-6.12.0-124.49.1.el10_1.noarch.rpm 0167d694f3818f92dd9f5e3b40aa44079e4d04182eabd1c0571df4161ab21427
noarch kernel-abi-stablelists-6.12.0-124.49.1.el10_1.noarch.rpm 867af4d110f57bbea440377ef3957074ff095d048b03beb99abe0146e1be2fac
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.