kernel-4.18.0-553.168.1.el8_10

エラータID: AXSA:2026-1992:93

Release date: 
Thursday, October 8, 2026 - 09:29
Subject: 
kernel-4.18.0-553.168.1.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

* kernel: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CVE-2026-31566)
* kernel: netfilter: nf_queue: hold bridge skb->dev while queued (CVE-2026-52912)
* kernel: Linux kernel: PPPoE memory corruption via stale pointer (CVE-2026-68121)
* kernel: Linux kernel IPVS: Denial of Service due to stale memory references (CVE-2026-80714)
* kernel: nvme-tcp: reject a read that transferred too few bytes (CVE-2026-89480)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-31566
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib amdgpu_amdkfd_submit_ib() submits a GPU job and gets a fence from amdgpu_ib_schedule(). This fence is used to wait for job completion. Currently, the code drops the fence reference using dma_fence_put() before calling dma_fence_wait(). If dma_fence_put() releases the last reference, the fence may be freed before dma_fence_wait() is called. This can lead to a use-after-free. Fix this by waiting on the fence first and releasing the reference only after dma_fence_wait() completes. Fixes the below: drivers/gpu/drm/amd/amdgpu/amdgpu_amdkfd.c:697 amdgpu_amdkfd_submit_ib() warn: passing freed memory 'f' (line 696) (cherry picked from commit 8b9e5259adc385b61a6590a13b82ae0ac2bd3482)
CVE-2026-52912
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb->dev while queued br_pass_frame_up() rewrites skb->dev from the ingress port to the bridge master before queueing bridge LOCAL_IN packets. NFQUEUE only holds references on state.in/out and bridge physdevs, so a queued bridge packet can retain a freed bridge master in skb->dev until reinjection. When the verdict is reinjected later, br_netif_receive_skb() re-enters the receive path with skb->dev still pointing at the freed bridge master, triggering a use-after-free. Store skb->dev in the queue entry, hold a reference on it for the queue lifetime, and use the saved device when dropping queued packets during NETDEV_DOWN handling.
CVE-2026-68121
In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalidating pointers into it. This can happen when a send is blocked in copy_from_user() while the first non-Ethernet port is added to an empty team device. The team's delegated GRE header callback then expands the skb head. PPPoE subsequently writes six bytes through the stale pointer into the freed head. Reload the PPPoE header through the skb's network-header offset after device header creation. pskb_expand_head() updates that offset when it relocates the head.
CVE-2026-80714
In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced conns Synced connections can be created before their destination exists. When the destination is later added, ip_vs_bind_dest() copies connection flags from the destination into cp->flags. IP_VS_CONN_F_ONE_PACKET connections are not synced. If a synced connection inherits IP_VS_CONN_F_ONE_PACKET while it is already hashed, expiry can treat it as a one-packet connection and skip unlinking the existing conn_tab node, leaving stale hash nodes pointing at a freed struct ip_vs_conn. Drop IP_VS_CONN_F_ONE_PACKET from destination flags when binding synced connections.
CVE-2026-89480
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: reject a read that transferred too few bytes nvme_tcp_recv_data() completes a request once the current C2HData PDU has been consumed. Nothing compares the total bytes received against the length the command asked for: struct nvme_tcp_request has no receive-side counter, queue->data_remaining is per queue, and blk_mq_end_request() completes for blk_rq_bytes(rq) unconditionally with no residual concept anywhere above. A controller can therefore answer a 4096-byte read with 512 bytes and have it reported as a complete read; user space then gets 4096 bytes of which 3584 are whatever was already in the page. I reproduced that with a test target. Count the bytes received and refuse to complete a successful read whose count does not match, at the two NVME_TCP_F_DATA_SUCCESS paths and in nvme_tcp_process_nvme_cqe(). The success test shifts req->status right by one, because the driver keeps the wire value there and shifts it on completion, so the check must see what the completion path will see. Only REQ_OP_READ is checked, because there the length comes from the sectors the request covers; a passthrough command is built by its submitter, which picks both command and buffer, so the kernel has nothing to compare against.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. kernel-4.18.0-553.168.1.el8_10.src.rpm
    MD5: 01a69343fe3d6d14befc89f0be8da2d6
    SHA-256: 851df4c294857b495e85c67f5608335dc41f51773ace630b20c1f31741f0ba63
    Size: 132.46 MB

Asianux Server 8 for x86_64
  1. bpftool-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: 559fa24542435c17fc9252e021c68619
    SHA-256: f7e5831db677b9607d94d2e103402e49ddf2bc194c110202c63e30a601a9b502
    Size: 11.35 MB
  2. kernel-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: b6a86862827ca3481e67784ec68380d4
    SHA-256: 3645bf40d3c854c4d39b7bdbcf9fd27f68354a5e9ef8bd657c7c71664889de83
    Size: 10.63 MB
  3. kernel-abi-stablelists-4.18.0-553.168.1.el8_10.noarch.rpm
    MD5: 3890edf3fa0eabba243a5665141ff837
    SHA-256: 1c55e3446019ee117336ded9474da01c766cfad7de18c47443c387da59d24628
    Size: 10.64 MB
  4. kernel-core-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: bad24606c8e0b7e47081827bcf994e18
    SHA-256: a5b00829df13420f6770b0a269569768d0812e6f8f97e607eef201b08d0d5cd0
    Size: 43.68 MB
  5. kernel-cross-headers-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: 0ab5b94bd9ede783cc152b31077013c4
    SHA-256: 198e0322a6714726aade4a491aa12279132b5d4707c4f6f9719393311a2a4f5e
    Size: 15.97 MB
  6. kernel-debug-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: 234dbcd1b3b5fa3e3b1540de708da1b3
    SHA-256: ada8301955bb65696316b3ce9cac2e5f97e5fce825057411e1e1d180fb4718d0
    Size: 10.63 MB
  7. kernel-debug-core-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: 9e39b74f104f646dfd969a03ebedcf36
    SHA-256: e2796b9f597c8ac2c50a085a2dff540787e51ced45e88af18f591d0f3c6a5208
    Size: 72.99 MB
  8. kernel-debug-devel-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: 72da332830bb0882c4448041e533bd3a
    SHA-256: 77d72d866301552e701a005bab3aca06234868a0741c9d42e2a4bbd21963fe72
    Size: 24.48 MB
  9. kernel-debug-modules-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: 8ff2169a16e15434a3a3c975ceea2071
    SHA-256: 1e6f720b722a73df0446654099a1b628bd86862586bc2503c1c34408e283811a
    Size: 66.11 MB
  10. kernel-debug-modules-extra-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: bf907de60f42619bbdedea2cc436754b
    SHA-256: a10e3ad517af14bc2636bbda50f7ab7523dd1d2a6c9f3959e10799f536567db2
    Size: 12.01 MB
  11. kernel-devel-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: ef32272b23c0075cba471f02491141a0
    SHA-256: d629d1f4f04e156f09d6f6203a8024023f387a1ed7b6fb57d3a9e750377f85e4
    Size: 24.28 MB
  12. kernel-doc-4.18.0-553.168.1.el8_10.noarch.rpm
    MD5: 4642b03e6c851b79642b32c179f07fbe
    SHA-256: c3e64a01f5ef70b79980f66f999940b108b256229e55ace88e1e1c7fb7a34e3a
    Size: 28.50 MB
  13. kernel-headers-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: b41010cd136f8e15e7ed2a009694613e
    SHA-256: 2039fdca9121b6a6c550e4185c85e0b169606bd3b45ea9dc9f62841f5d78f5e7
    Size: 11.98 MB
  14. kernel-modules-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: a6a278d6039c86892d0ddd6b6d76c788
    SHA-256: 3ae965fbb018f659c2abc1153e7d2cd8e6b93d1d945b000f8b8b06645da1d6bf
    Size: 36.47 MB
  15. kernel-modules-extra-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: 97191ae2ab2746d46de647d7556d8f30
    SHA-256: 29128b0cafc493a262448c205603d5f700b07747e1d9695a1850047480365856
    Size: 11.32 MB
  16. kernel-tools-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: 2bca60a9c8696afe808dd6d74d04541e
    SHA-256: ce27632fd50f57dfce0c46af5f41b7bba10f9c822341fc22a1223fa22ca1f6f8
    Size: 10.85 MB
  17. kernel-tools-libs-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: 8cf44bd36869d8a80fc06b167bbb03a0
    SHA-256: a77bfcf1c36535e1320b51a86e50d59ddc692357f11cf8e90be9443345ad89cb
    Size: 10.63 MB
  18. kernel-tools-libs-devel-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: cf02f23bfac5e2b61e9cc8b46f500cbf
    SHA-256: a0bf35f0342fb672f0827c93d228e8bffe151c9c7ddfcdcff844ac2518f6597f
    Size: 10.63 MB
  19. perf-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: db57d793af9785e68da4fb4da2416ec5
    SHA-256: c41c7f2249f1e6e4ee23f47f2854d7c699617b70685a8acae7dd8adfb6c22564
    Size: 12.95 MB
  20. python3-perf-4.18.0-553.168.1.el8_10.x86_64.rpm
    MD5: a21335841d7657bec68de42d9ba73bbe
    SHA-256: 4078dce6d6adfe0012deb0576ab965cc0baf01832d5a6ef36bfea92341b0c7dc
    Size: 10.75 MB