kernel-4.18.0-553.155.1.el8_10
エラータID: AXSA:2026-1705:70
The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
* kernel: udf: fix partition descriptor append bookkeeping (CVE-2026-45991)
* kernel: ice: fix double-free of tx_buf skb (CVE-2026-53009)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-45991
In the Linux kernel, the following vulnerability has been resolved: udf: fix partition descriptor append bookkeeping Mounting a crafted UDF image with repeated partition descriptors can trigger a heap out-of-bounds write in part_descs_loc[]. handle_partition_descriptor() deduplicates entries by partition number, but appended slots never record partnum. As a result duplicate Partition Descriptors are appended repeatedly and num_part_descs keeps growing. Once the table is full, the growth path still sizes the allocation from partnum even though inserts are indexed by num_part_descs. If partnum is already aligned to PART_DESC_ALLOC_STEP, ALIGN(partnum, step) can keep the old capacity and the next append writes past the end of the table. Store partnum in the appended slot and size growth from the next append count so deduplication and capacity tracking follow the same model.
CVE-2026-53009
In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points to it and is marked as valid (ICE_TX_BUF_SKB). 'next_to_use' remains unchanged, so the potential problem will likely fix itself when the next packet is transmitted and the tx_buf gets overwritten. But if there is no next packet and the interface is brought down instead, ice_clean_tx_ring() -> ice_unmap_and_free_tx_buf() will find the tx_buf and free the skb for the second time. The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error path, so that ice_unmap_and_free_tx_buf(). Move the initialization of 'first' up, to ensure it's already valid in case we hit the linearization error path. The bug was spotted by AI while I had it looking for something else. It also proposed an initial version of the patch. I reproduced the bug and tested the fix by adding code to inject failures, on a build with KASAN. I looked for similar bugs in related Intel drivers and did not find any.
Update packages.
In the Linux kernel, the following vulnerability has been resolved: udf: fix partition descriptor append bookkeeping Mounting a crafted UDF image with repeated partition descriptors can trigger a heap out-of-bounds write in part_descs_loc[]. handle_partition_descriptor() deduplicates entries by partition number, but appended slots never record partnum. As a result duplicate Partition Descriptors are appended repeatedly and num_part_descs keeps growing. Once the table is full, the growth path still sizes the allocation from partnum even though inserts are indexed by num_part_descs. If partnum is already aligned to PART_DESC_ALLOC_STEP, ALIGN(partnum, step) can keep the old capacity and the next append writes past the end of the table. Store partnum in the appended slot and size growth from the next append count so deduplication and capacity tracking follow the same model.
In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points to it and is marked as valid (ICE_TX_BUF_SKB). 'next_to_use' remains unchanged, so the potential problem will likely fix itself when the next packet is transmitted and the tx_buf gets overwritten. But if there is no next packet and the interface is brought down instead, ice_clean_tx_ring() -> ice_unmap_and_free_tx_buf() will find the tx_buf and free the skb for the second time. The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error path, so that ice_unmap_and_free_tx_buf(). Move the initialization of 'first' up, to ensure it's already valid in case we hit the linearization error path. The bug was spotted by AI while I had it looking for something else. It also proposed an initial version of the patch. I reproduced the bug and tested the fix by adding code to inject failures, on a build with KASAN. I looked for similar bugs in related Intel drivers and did not find any.
N/A
SRPMS
- kernel-4.18.0-553.155.1.el8_10.src.rpm
MD5: 017775fd6c6bf0f9913f09841dc8ecd4
SHA-256: 2c392923db2f568eda0c78b8b9b7f2732339c3a326022c1573ee0d78bf4c7024
Size: 132.43 MB
Asianux Server 8 for x86_64
- bpftool-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: bf58f3ad8414f34701b685335216eca3
SHA-256: 8900e3885ded582703eb457038655f686a65e88fd320f73a648379212be34894
Size: 11.33 MB - kernel-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: c9d6c6ad5c05c32e42345dfba0e2211e
SHA-256: 39ad4be2e433e595a43e75171ed3b90a1d30fcaf5a3afd8b0ff98fb73e7b4b18
Size: 10.60 MB - kernel-abi-stablelists-4.18.0-553.155.1.el8_10.noarch.rpm
MD5: 13321f9880dd00fab144a4f167df10b8
SHA-256: ca70085b247399bf6e557bc053c1f7f86adb40d0fc8407cc5673a2077f6d7f3e
Size: 10.62 MB - kernel-core-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: fe99d88f9085ed8e3d41e154f7350e60
SHA-256: 97d36859cdfc437ee8d20b22f12ed6032bad956bfb6550637cb797edb66405c9
Size: 43.65 MB - kernel-cross-headers-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: fdb8aca51e09f071cac460853dbb84f9
SHA-256: 112af34eb7d4d653b81e35d13328673df117e1411f602bba14764c6fc99d4fd7
Size: 15.95 MB - kernel-debug-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: 4c6c2f9b91dd0f8e396b3785852707a1
SHA-256: de6f0e62fe4737bf662c0a03788db507b19d621bebf9e59b9b4bf4ed359d4d11
Size: 10.60 MB - kernel-debug-core-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: e888f094b0f9b8ab77a5eea4a230bb46
SHA-256: 1992bb1c8d3d5d0d5e8a86904a64b0cf6d0a17a1d48461d78ee59abc111b52d8
Size: 72.97 MB - kernel-debug-devel-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: 912a0937573c85c7410b494423e39e09
SHA-256: 315fd52be45cbe40596cdebffb45acbfd7792da2e0d606da9d498efa6bce113b
Size: 24.46 MB - kernel-debug-modules-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: 5c27de39d7dfee04a42a624b29017846
SHA-256: 860715e1cc6b62115157ad0455ff946cf2bf910a6ab9114739ed02416127549a
Size: 66.09 MB - kernel-debug-modules-extra-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: d57e9fc21c4f9ae9e24cbf625e3dabdc
SHA-256: 988aac117f260b57cde5e3a586af3f7e34afccb3e8251ae0898c020a8aceb07e
Size: 11.98 MB - kernel-devel-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: 2126a65e92e1e4e3731086063c630eef
SHA-256: a91b15a2b1089810ca9f41bdbe1a637dedd41235900e20d8005d07d6132babad
Size: 24.25 MB - kernel-doc-4.18.0-553.155.1.el8_10.noarch.rpm
MD5: 3a76bd92fb38455fb5c5b280bab6c49c
SHA-256: 526f84d2b3cf59aa70fa24ee9f8c923bbc0371384939e23b33a48c6c4dcd079f
Size: 28.48 MB - kernel-headers-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: 9f237a0ba6d708abf0f86385d5c8e0d2
SHA-256: f1bc0a0313fe77ce1dd8adc172dbda6aabe22cc9cd88b6fe2166a16a41a2111a
Size: 11.96 MB - kernel-modules-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: 59f633bcf25770bae1fb459e5c4ad479
SHA-256: a29a1d7398e5189a1d3d43416da0910b4dd435f2596c48cac2ca27ad14add7f7
Size: 36.44 MB - kernel-modules-extra-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: e0b72da526304e2b61497930fe8fedb2
SHA-256: 8b72b80c59cb0a5b50e885c67bc825d88df7204a7d1c11b384e4baa82d8f5a22
Size: 11.29 MB - kernel-tools-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: 66c7ce9fc94668aab190ec68d80ada03
SHA-256: ecde6c350d23ac8a6d8ee030662720eeeac8c7bc663c71bbc949aae58cbf9285
Size: 10.82 MB - kernel-tools-libs-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: 4816fccbd8937df9191deb00cc11499d
SHA-256: 86ebfecb665d25af196f26d7a19ad0fefb7c4d8282f62677502a22ef182ee454
Size: 10.61 MB - kernel-tools-libs-devel-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: 97c1a411cc263fa7e7e49444aae5e494
SHA-256: a4391b6d3fd68d37b88199bb0f53d8765ea097a3d96a41a14882fdc6213be099
Size: 10.61 MB - perf-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: 1c28452cf5dbc63a7ca2025efe497ca3
SHA-256: 341f977f732178c9e434aa5850c7a8a1374d006d0609e6ebd3459547fdf5af61
Size: 12.92 MB - python3-perf-4.18.0-553.155.1.el8_10.x86_64.rpm
MD5: 14228ae92231fa6c82432cc124ff7047
SHA-256: d8b30d683e342df8eba8890188c852caa8b33e99589d109d1b9f1f36b59207c4
Size: 10.73 MB