kernel-5.14.0-611.16.1.el9_7

エラータID: AXSA:2025-11625:100

Release date: 
Friday, December 26, 2025 - 10:55
Subject: 
kernel-5.14.0-611.16.1.el9_7
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

* kernel: clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns (CVE-2025-38499)
* kernel: iommufd: Fix race during abort for file descriptors (CVE-2025-39966)
* kernel: tls: wait for pending async decryptions if tls_strp_msg_hold fails (CVE-2025-40176)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2025-38499
In the Linux kernel, the following vulnerability has been resolved: clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns What we want is to verify there is that clone won't expose something hidden by a mount we wouldn't be able to undo. "Wouldn't be able to undo" may be a result of MNT_LOCKED on a child, but it may also come from lacking admin rights in the userns of the namespace mount belongs to. clone_private_mnt() checks the former, but not the latter. There's a number of rather confusing CAP_SYS_ADMIN checks in various userns during the mount, especially with the new mount API; they serve different purposes and in case of clone_private_mnt() they usually, but not always end up covering the missing check mentioned above.
CVE-2025-39966
In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix race during abort for file descriptors fput() doesn't actually call file_operations release() synchronously, it puts the file on a work queue and it will be released eventually. This is normally fine, except for iommufd the file and the iommufd_object are tied to gether. The file has the object as it's private_data and holds a users refcount, while the object is expected to remain alive as long as the file is. When the allocation of a new object aborts before installing the file it will fput() the file and then go on to immediately kfree() the obj. This causes a UAF once the workqueue completes the fput() and tries to decrement the users refcount. Fix this by putting the core code in charge of the file lifetime, and call __fput_sync() during abort to ensure that release() is called before kfree. __fput_sync() is a bit too tricky to open code in all the object implementations. Instead the objects tell the core code where the file pointer is and the core will take care of the life cycle. If the object is successfully allocated then the file will hold a users refcount and the iommufd_object cannot be destroyed. It is worth noting that close(); ioctl(IOMMU_DESTROY); doesn't have an issue because close() is already using a synchronous version of fput(). The UAF looks like this: BUG: KASAN: slab-use-after-free in iommufd_eventq_fops_release+0x45/0xc0 drivers/iommu/iommufd/eventq.c:376 Write of size 4 at addr ffff888059c97804 by task syz.0.46/6164 CPU: 0 UID: 0 PID: 6164 Comm: syz.0.46 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025 Call Trace: __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xcd/0x630 mm/kasan/report.c:482 kasan_report+0xe0/0x110 mm/kasan/report.c:595 check_region_inline mm/kasan/generic.c:183 [inline] kasan_check_range+0x100/0x1b0 mm/kasan/generic.c:189 instrument_atomic_read_write include/linux/instrumented.h:96 [inline] atomic_fetch_sub_release include/linux/atomic/atomic-instrumented.h:400 [inline] __refcount_dec include/linux/refcount.h:455 [inline] refcount_dec include/linux/refcount.h:476 [inline] iommufd_eventq_fops_release+0x45/0xc0 drivers/iommu/iommufd/eventq.c:376 __fput+0x402/0xb70 fs/file_table.c:468 task_work_run+0x14d/0x240 kernel/task_work.c:227 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline] exit_to_user_mode_loop+0xeb/0x110 kernel/entry/common.c:43 exit_to_user_mode_prepare include/linux/irq-entry-common.h:225 [inline] syscall_exit_to_user_mode_work include/linux/entry-common.h:175 [inline] syscall_exit_to_user_mode include/linux/entry-common.h:210 [inline] do_syscall_64+0x41c/0x4c0 arch/x86/entry/syscall_64.c:100 entry_SYSCALL_64_after_hwframe+0x77/0x7f
CVE-2025-40176
In the Linux kernel, the following vulnerability has been resolved: tls: wait for pending async decryptions if tls_strp_msg_hold fails Async decryption calls tls_strp_msg_hold to create a clone of the input skb to hold references to the memory it uses. If we fail to allocate that clone, proceeding with async decryption can lead to various issues (UAF on the skb, writing into userspace memory after the recv() call has returned). In this case, wait for all pending decryption requests.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. kernel-5.14.0-611.16.1.el9_7.src.rpm
    MD5: 08878822e7c216bc6615aa323a3a5f22
    SHA-256: 0e820d7f59530dc02ad03f39c8d78c1b7f5aabbf34895286779aa8fcdf884c8e
    Size: 143.98 MB

Asianux Server 9 for x86_64
  1. kernel-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 9ff4386beb21b750112beb1f5473ac84
    SHA-256: db29df9108f4ff00e58c3f6fbe96e23d1490c2456dbc1105a412987b32b8e23f
    Size: 1.09 MB
  2. kernel-abi-stablelists-5.14.0-611.16.1.el9_7.noarch.rpm
    MD5: b4faccadc08530c2c8f65c5a81aec9ad
    SHA-256: b2b524e3bbaa79b8db907e36b0194d829e45bc7f84203b958fdb1e4012645265
    Size: 1.12 MB
  3. kernel-core-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 850418b1370ac8782e60dc5173c3a950
    SHA-256: 04f29aa80672740f5b2f4b401e9972a468621c02c994ce77a6c3d6e1c94a860d
    Size: 17.36 MB
  4. kernel-cross-headers-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 8f46881684dddaf62dcc30b4672fa798
    SHA-256: 9d6e03468d081cda4ccb385bc0b6f4d476f13099ec420883bc7864e8b8782d33
    Size: 8.03 MB
  5. kernel-debug-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: de0aa3357b5c1ad06042d50ec5cc33e7
    SHA-256: bd6382f437659840261995fdec16e089d9638e3ad353c81b9fc6ffc11217b895
    Size: 1.09 MB
  6. kernel-debug-core-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: aa2ae1717510e44ab35573c2fea00030
    SHA-256: d436e0767f4c2e10e396f020add719c1031d33008c21c95a209d17a72a06eb70
    Size: 30.95 MB
  7. kernel-debug-devel-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 571caa1c7f77b7695b09ac266480b0c9
    SHA-256: fd28e8298446b3c3c77066ca1dc9161f9cb3f451fd51a0e4a87d2598523a6093
    Size: 21.28 MB
  8. kernel-debug-devel-matched-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 2b951079b154161facc536af66e5fa30
    SHA-256: b05a51b4cdeaa27a4c706e6bef2d1942598d4ce336e61b696fd3fef55363085b
    Size: 1.09 MB
  9. kernel-debug-modules-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: c1d678d088eec30012e09d1e3a7b06a5
    SHA-256: 55a277685205eeb28f071439a60133498833a56e0dae88198d9f7e45f27b87d0
    Size: 69.33 MB
  10. kernel-debug-modules-core-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 376c883275b75b4ce7515e2eb2276003
    SHA-256: 9f1dfa700bca33aa7dbbab4170cc607a269443aec66cec4e66f63c773665282c
    Size: 49.50 MB
  11. kernel-debug-modules-extra-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 2b5177a0a1aa6151e1dfc9c1326e81d0
    SHA-256: cc0bf823be161feb9fd3ec7134deb449d4d4d2ffc1f87def0fb485d289662dd3
    Size: 1.87 MB
  12. kernel-debug-uki-virt-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 2d25b35c82d6cf87ae837643fbfd4e78
    SHA-256: 3816c948645623bcdf634da80c612b79e0f0e54b60cd8253e3e06dab5e6cb78d
    Size: 85.81 MB
  13. kernel-devel-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: ce62a8b2197645f2dc9a963d1f2ec630
    SHA-256: 1fa306b6f5ae54256cb17144123d6cc9996fa6c1714b0e1a229f52c4ec49d47e
    Size: 21.11 MB
  14. kernel-devel-matched-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 87e5d2f5c156a57b4b333b46679c4b68
    SHA-256: 26f4b6f054b3c1d2cc3a8e2a80f917853c798f1aff6934274a13782c5828f0b6
    Size: 1.09 MB
  15. kernel-doc-5.14.0-611.16.1.el9_7.noarch.rpm
    MD5: 8d80e80f46dda13e60e5fed002580a92
    SHA-256: 7ad158a8a773147097457b8082ee0e46b1ccbbbc57cc74c64ab2459fae378416
    Size: 38.83 MB
  16. kernel-headers-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 3f87f139e4b99e1d98b541f3aa18635c
    SHA-256: 81c3aa2a2513b64036ad4e8df30095730ceca347cb5a58f744d1d283ac346191
    Size: 2.85 MB
  17. kernel-modules-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 31e577f1c3a12c6709aec47d26ca35a7
    SHA-256: 20af427602c1cb1c2d99e95f95084923eaa402ef05ddc706d314d220972b3693
    Size: 39.71 MB
  18. kernel-modules-core-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: e5fa8c283781965cc8dba2aa5324b6e8
    SHA-256: 1f156bfe9b21b836c47e7ec4cc90e572c5c43838f3f1d2e9681ffc5e8a2cb0c2
    Size: 30.97 MB
  19. kernel-modules-extra-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 57a9ebb009a0349f080d46dfb8710c6a
    SHA-256: c1fe816b73c45194d510d6cbad0d17b3160f69be77feaf8e5f89c18fa136cb8a
    Size: 1.51 MB
  20. kernel-rt-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 0cbd4c5b93f850c3a3272ce319b3293d
    SHA-256: aecc7a46b23d698b9916c97f8a09adef3774b599642c1cfb183ac9d0eed404cd
    Size: 1.09 MB
  21. kernel-rt-core-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 6918b1e176e6a2f83e326b24d6a3f295
    SHA-256: ac680f56b5c5f8d3722551b8210232ebf59297103b850ff8fa1d61f4041e4dee
    Size: 17.27 MB
  22. kernel-rt-debug-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 1c34c476b93e6c13a209ca9bc89791af
    SHA-256: a33d0ff59bc77b26496a2aa19b6a0bb4333177b27c59d0dce292b1a24606d789
    Size: 1.09 MB
  23. kernel-rt-debug-core-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 9ceaad73ac027537425d7611796f6518
    SHA-256: f9d0edf3c74e22c5b06c02f97451f1bb652a684f82da151041572a7a709684f0
    Size: 18.70 MB
  24. kernel-rt-debug-devel-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: fa21835290afc0d191d8a335a539d728
    SHA-256: 5d006a42e0098f5d9a5e23091a4754e0d81807b419d59c0d4bb522225e623867
    Size: 21.23 MB
  25. kernel-rt-debug-modules-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 8fad9eca450780d663344bd951fa2d49
    SHA-256: 9d720c07808d5b18943caa3c74649a1946a5963939025a6cd1287e9ebb936beb
    Size: 41.30 MB
  26. kernel-rt-debug-modules-core-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: e379555f41baf5f429851720bce2e5a6
    SHA-256: 8bba9193fce645e62801e2e7291a1c4d1584b7c36a5793fe855576ccbca09892
    Size: 32.12 MB
  27. kernel-rt-debug-modules-extra-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: c961bc0f48b78aeeefd00c5a42669339
    SHA-256: cd5d1aaab0bbf79ac3fb9633ac2419ce2417f4b7d4f3a512a08d0296069964ea
    Size: 1.54 MB
  28. kernel-rt-devel-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 866d1459e9c7bca3b96c16b303255076
    SHA-256: 16f0c366fce1b83466a221ae111fb1d2b864938109398616bd4ddcd8781556c9
    Size: 21.09 MB
  29. kernel-rt-modules-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 2d7043d7dcec78d58c91f9ac8b5c271a
    SHA-256: 471cd0f3c67f8a8f38f937fefa3e21e9df91f08eb52380758609d69e41264e15
    Size: 39.80 MB
  30. kernel-rt-modules-core-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 0c52b60167033c3989bd2b0c4b172300
    SHA-256: fde5652064cfc233eca624886d22cbd1834206ede258731cb70ab5fd434fc6bc
    Size: 31.03 MB
  31. kernel-rt-modules-extra-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 44f32116270432f7d1829c76e5a19bf7
    SHA-256: 2f9a2f0fa6b20916f3f5d9044470e19a667b7adb22d9378fa318669a8fce2dbc
    Size: 1.52 MB
  32. kernel-tools-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: e1d1aec478b801157a2808100a9a507c
    SHA-256: b26c7a6230f8edfbeacf4f20e6bd83f4e71e5f58e85ebc60090179fc4242ebad
    Size: 1.38 MB
  33. kernel-tools-libs-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: cf43ed11e89dcc5063ce1b983562c18b
    SHA-256: f04862e717cd5aa74dbebab0993788ef8808d0e0d1648c746eeafbe034f3b74e
    Size: 1.10 MB
  34. kernel-tools-libs-devel-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: f916b7d2a5c16cdf15d73162c5a41172
    SHA-256: 8186b07cbe443b4209e0a9822db41d9de541cf500f15fdc89a4f4ac9a52323bf
    Size: 1.09 MB
  35. kernel-uki-virt-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: c1cbeb337a04610f4c6a352338e5ee62
    SHA-256: dcb38fd989701c452fba601f05b2c967954a93338f04738daf04ce650560296e
    Size: 63.94 MB
  36. kernel-uki-virt-addons-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 2652cccdccec3b78084707458413dd6f
    SHA-256: b97012b3a50fe90a523817467d6695aa0823ed0acbe547a5b12f06d9bb72300a
    Size: 1.11 MB
  37. libperf-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 9559b14ac542ddcd11d191e9786e584f
    SHA-256: 84ba9e97842e6bc39c02d4a87ce29ab88d2718c5a1f9c2988c0423d75d0c51ad
    Size: 1.11 MB
  38. perf-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 550e64204933d1d26f3c9894a03f34ef
    SHA-256: 8181d14ea01a725895281c204083622ccd2de6fc385e4c748af687ca2881ef5d
    Size: 3.35 MB
  39. python3-perf-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: 5e02d350059c0bf1c53c3904d68152bb
    SHA-256: cce469b5af753c283b9e66a65b34af1c1479fdfada912c77e19f431bb2aeddc6
    Size: 2.52 MB
  40. rtla-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: bc1beae03de8f0ad9fa902117061761d
    SHA-256: b6f64ab9f0d53688ba23a2f37f5ec1a2d3740f04543788c161c075ee369a2438
    Size: 1.16 MB
  41. rv-5.14.0-611.16.1.el9_7.x86_64.rpm
    MD5: ac9e6ad47431d26de407e95a9bff33b1
    SHA-256: 11a0762a10dc2b73571affa40ab6a1bf51e0f87fa24e2de8fe6c50314ce02604
    Size: 1.11 MB