kernel-5.14.0-687.45.1.el9_8

エラータID: AXSA:2026-2001:95

リリース日: 
2026/10/09 Friday - 09:40
題名: 
kernel-5.14.0-687.45.1.el9_8
影響のあるチャネル: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

* kernel: can: bcm: add locking for bcm_op runtime updates (CVE-2025-38004)
* kernel: io_uring/poll: fix signed comparison in io_poll_get_ownership() (CVE-2026-52933)
* kernel: netfilter: nat: use kfree_rcu to release ops (CVE-2026-53000)
* kernel: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (CVE-2026-64136)
* kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (CVE-2026-64320)
* kernel: nvmet-auth: validate reply message payload bounds against transfer length (CVE-2026-64319)
* kernel: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (CVE-2026-64287)
* kernel: smb: client: fix change notify replay double-free (CVE-2026-64384)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2025-38004
In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking for bcm_op runtime updates The CAN broadcast manager (CAN BCM) can send a sequence of CAN frames via hrtimer. The content and also the length of the sequence can be changed resp reduced at runtime where the 'currframe' counter is then set to zero. Although this appeared to be a safe operation the updates of 'currframe' can be triggered from user space and hrtimer context in bcm_can_tx(). Anderson Nascimento created a proof of concept that triggered a KASAN slab-out-of-bounds read access which can be prevented with a spin_lock_bh. At the rework of bcm_can_tx() the 'count' variable has been moved into the protected section as this variable can be modified from both contexts too.
CVE-2026-52933
In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix signed comparison in io_poll_get_ownership() io_poll_get_ownership() uses a signed comparison to check whether poll_refs has reached the threshold for the slowpath: if (unlikely(atomic_read(&req->poll_refs) >= IO_POLL_REF_BIAS)) atomic_read() returns int (signed). When IO_POLL_CANCEL_FLAG (BIT(31)) is set in poll_refs, the value becomes negative in signed arithmetic, so the >= 128 comparison always evaluates to false and the slowpath is never taken. Fix this by casting the atomic_read() result to unsigned int before the comparison, so that the cancel flag is treated as a large positive value and correctly triggers the slowpath.
CVE-2026-53000
In the Linux kernel, the following vulnerability has been resolved: netfilter: nat: use kfree_rcu to release ops Florian Westphal says: "Historically this is not an issue, even for normal base hooks: the data path doesn't use the original nf_hook_ops that are used to register the callbacks. However, in v5.14 I added the ability to dump the active netfilter hooks from userspace. This code will peek back into the nf_hook_ops that are available at the tail of the pointer-array blob used by the datapath. The nat hooks are special, because they are called indirectly from the central nat dispatcher hook. They are currently invisible to the nfnl hook dump subsystem though. But once that changes the nat ops structures have to be deferred too." Update nf_nat_register_fn() to deal with partial exposition of the hooks from error path which can be also an issue for nfnetlink_hook.
CVE-2026-64136
In the Linux kernel, the following vulnerability has been resolved: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() Commit 96c4af418586 ("cifs: Fix locking usage for tcon fields") refactored cifs code to change cifs_tcp_ses_lock for tc_lock around tc_count changes. There was missing lock around tc_count increment inside smb2_find_smb_sess_tcon_unlocked().
CVE-2026-64287
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU flush_hyp_vcpu() copies the host vGIC state into the hyp's private vCPU on every run. The vGIC list register save and restore use used_lrs as their loop bound and expect it to stay within the number of implemented list registers. While this is generally the case, flush_hyp_vcpu() copies vgic_v3 verbatim and does not enforce this, so a value provided by the host is used at EL2 to index vgic_lr[] and access ICH_LR_EL2 (host -> EL2). Fix by clamping used_lrs to the number of implemented list registers after the copy, as the trusted path already does in vgic_flush_lr_state(). The number of implemented list registers is constant after init, so it is replicated once from kvm_vgic_global_state.nr_lr into hyp_gicv3_nr_lr rather than read on every entry.
CVE-2026-64319
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (hash length) and dhvlen (DH value length) fields without verifying they fit within the allocated buffer of tl bytes. A malicious NVMe-oF initiator can craft a DHCHAP_REPLY message with a small transfer length but large hl/dhvlen values, causing out-of-bounds heap reads when the target processes the DH public key (rval + 2*hl) or performs the host response memcmp. With DH authentication configured, the OOB pointer is passed directly to sg_init_one() and read by crypto_kpp_compute_shared_secret(), reaching up to 526 bytes past the buffer. This is exploitable pre-authentication. Add bounds validation ensuring sizeof(*data) + 2*hl + dhvlen <= tl before any access to the variable-length fields. Discovered by Atuin - Automated Vulnerability Discovery Engine.
CVE-2026-64320
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page nvmet_execute_disc_get_log_page() validates only the dword alignment of the host-supplied Log Page Offset (lpo). The 64-bit offset is then added to a small kzalloc'd buffer that holds the discovery log page and the result is passed straight to nvmet_copy_to_sgl(), which memcpy()s data_len bytes out to the host with no source-side bound check: u64 offset = nvmet_get_log_page_offset(req->cmd); /* 64-bit host */ size_t data_len = nvmet_get_log_page_len(req->cmd); /* 32-bit host */ ... if (offset & 0x3) { ... } /* only check */ ... alloc_len = sizeof(*hdr) + entry_size * discovery_log_entries(req); buffer = kzalloc(alloc_len, GFP_KERNEL); ... status = nvmet_copy_to_sgl(req, 0, buffer + offset, data_len); The Discovery controller is unauthenticated -- nvmet_host_allowed() returns true unconditionally for the discovery subsystem -- so the call is reachable pre-authentication by any TCP/RDMA/FC peer that can reach the nvmet target. With a discovery log page of ~1 KiB, an attacker requesting up to 4 KiB starting at offset == alloc_len reads the next slab page out and gets its content returned over the fabric (an empirical run on a default nvmet-tcp loopback target leaked 81 canonical kernel pointers in one Get Log Page response). Pointing the offset at unmapped kernel memory faults the in-kernel memcpy and crashes (or panics, on panic_on_oops=1) the target host instead. The attacker-controlled source-side offset pattern "nvmet_copy_to_sgl(req, 0, buffer + ATTACKER_OFFSET, ...)" is unique to nvmet_execute_disc_get_log_page in the entire nvmet codebase: every other Get Log Page handler in admin-cmd.c either ignores lpo (and silently starts every response at offset 0) or tracks a local destination offset with a fixed source pointer. Validate the host-supplied offset against the log page size, cap the copy length to what is actually available, and zero-fill any remainder of the host transfer buffer. The zero-fill matches the existing short-response pattern in nvmet_execute_get_log_changed_ns() (admin-cmd.c) and prevents leaking transport SGL contents when the host asks for more bytes than the log page contains.
CVE-2026-64384
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_notify_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. kernel-5.14.0-687.45.1.el9_8.src.rpm
    MD5: d0baeb920ada95ce8ba6770c94b321f7
    SHA-256: 8db9757cd686fa0bf621de00cc18a54464e8dd884b11e4e3f3c6e1506b91a33f
    Size: 145.47 MB

Asianux Server 9 for x86_64
  1. kernel-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 5b3d15397bba8d233db14caddefde0e9
    SHA-256: 4cc2b9d3d015a6698c8906f0a2fe48292bb8ae234b6d9d394a7b8dfb63e01688
    Size: 0.98 MB
  2. kernel-abi-stablelists-5.14.0-687.45.1.el9_8.noarch.rpm
    MD5: 0a65393ba514ff93b8a2de2a8ad9730e
    SHA-256: 42f0b375444fe299f1935054d5174dd46d7de8e28920aefc53c3b5037e4828b3
    Size: 1.02 MB
  3. kernel-core-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 11810bb702cb22eb7f8b213ede8fc041
    SHA-256: 5d5396aeb0418a27ae2e4397fb7feb11428d6af2d9c601400dd78b4350e7f510
    Size: 17.31 MB
  4. kernel-cross-headers-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 64b28b0e0a0dd2130b2dffd8fedf0827
    SHA-256: 9c423fcf7dadac3043b3674a33597ef81f778db73e793f2a349842c48e1a03ef
    Size: 8.05 MB
  5. kernel-debug-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 6122ad894c4655fd41ceb9775b9aefdc
    SHA-256: 9811d74609c1d1d21e0c730f1f17a6b6d394c4261b3d96a780d37d661522fe41
    Size: 0.98 MB
  6. kernel-debug-core-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: aaecc7e6be5a9e10a03667114d6d1d1e
    SHA-256: 4339aece3ec01232ff44f8525fa99c5f8467a06899a5e540ceb485c5ff4d630b
    Size: 31.17 MB
  7. kernel-debug-devel-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: c35f7925fa9b72bf142fdfad6f653609
    SHA-256: 611b405e336aaefe2a5c2f91cc322cc7a413b4fcbcfa7fc0437bdbdff2bc48ff
    Size: 21.41 MB
  8. kernel-debug-devel-matched-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: d894ca0677b302a21dcc914eb92eb6b0
    SHA-256: f79de8461a03f10f3696f7d4a64fba53f39a1cdfd5ae102db70dbf81b1bc7c4a
    Size: 0.98 MB
  9. kernel-debug-modules-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: dbf4803a13c46def2e8d4bcf231f77c4
    SHA-256: 5c2414a70f119052404130aecbf7b1502b1cec01353f0e7a9929ddfb882139eb
    Size: 70.13 MB
  10. kernel-debug-modules-core-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 3d538dd05c999affa00788d7bc0ee3c5
    SHA-256: cb84c53f34662318418f97ab19319d59adadb81032ca7ba94c86d96ce80ba506
    Size: 49.88 MB
  11. kernel-debug-modules-extra-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 1414c223db2be5b636228b28b75d3a55
    SHA-256: 5a0634dd4bba0546846e51f0f4029c09f2c3df98dc012ab43c38d33bcb8c7aa7
    Size: 1.79 MB
  12. kernel-debug-uki-virt-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 0dfc98d9c9d316b8c64b3ab31437c398
    SHA-256: 73a9847e9d409bf495891cd9a7ea14366fa1ab0b0bde43f2b501b4ca04fc2d1b
    Size: 88.09 MB
  13. kernel-devel-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: c20956dbaa3bec18e1ab611e6e38d8d7
    SHA-256: de5196b80b09c745e1eaf0ea6304b91325afa18b4fbcd23059fd1f946d052069
    Size: 21.21 MB
  14. kernel-devel-matched-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 085b00b46a9645a084b62711bc6d1d7e
    SHA-256: 865c2679903d526749e75259f769a7ff1a4ad40d3bdda3dc21ab03749223c59a
    Size: 0.98 MB
  15. kernel-doc-5.14.0-687.45.1.el9_8.noarch.rpm
    MD5: 300b2dba7143c031f7d6ee603fe4c849
    SHA-256: db6d6099a3e20c293d266a3e0500c92e9454c708c2170ee30f951eddba1539e8
    Size: 38.99 MB
  16. kernel-headers-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 10ca999cac62f59e0eb3342ffd47396a
    SHA-256: 9b083b306658b329b62e4e8e1579fd78debe279a3e8e652c0e54c14b04d6437e
    Size: 2.77 MB
  17. kernel-modules-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 44daf910351df4477cc5b0bde1bd4345
    SHA-256: b08a9e5003ad0112d4028f4690a940d61db3e3dcb4e6759be2e210093c6d2105
    Size: 39.97 MB
  18. kernel-modules-core-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: d59a24d8a6a107634cdc64374e446791
    SHA-256: cee90d2c8051ef0b6189f28b4489ba76135b0b1de44ad33bb3f40abb78ecc079
    Size: 31.05 MB
  19. kernel-modules-extra-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: e3c9d5591440a903c2694d79a690a993
    SHA-256: add6ba4f3e49e48ec29480ce43c5971617311c6719fa80172a86b22e81bb70c7
    Size: 1.42 MB
  20. kernel-rt-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: abd3f18b98c10b3b1bb58445216fd518
    SHA-256: a00777e1433af2919c5e931e89a823c5a41c0db2a68c4590430e029d9a3648e8
    Size: 0.98 MB
  21. kernel-rt-core-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 2ed887dece9700e4ce69a7faa00269f3
    SHA-256: 7c439c899fc5545b644c237b9f8df9e46093570f2ee6b555c9c30b349ea40bab
    Size: 17.21 MB
  22. kernel-rt-debug-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: da06212a54ac95cc6f384df5a833a8a6
    SHA-256: d12d54e0c8786ae0c54aaa3b66ce4f92177f0764702c7253aa467fc5fe7ddeb9
    Size: 0.98 MB
  23. kernel-rt-debug-core-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 9b76dd92b834c03735e89f85af46fc38
    SHA-256: d03a83dd6dddbe5bd917332aa4a97b2b3d22ed263818f6241a7aadd7af29df03
    Size: 18.66 MB
  24. kernel-rt-debug-devel-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 5b4b405664d452e927fa3a899cd33c6c
    SHA-256: 3f4319c92fbfe9b898f6aa9771f8d093a8594e9264d312dfe232b7d9ee7d3796
    Size: 21.34 MB
  25. kernel-rt-debug-modules-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 6d9732f20bb247bb856cc037460d9da8
    SHA-256: ef7dcc59540f0a698febe86a5e1a3b0c4de25bfb3389035fb37e0aa3679939a0
    Size: 41.54 MB
  26. kernel-rt-debug-modules-core-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: a069bf42537b96df27f97cd77d497b53
    SHA-256: 37870186e569fc17819b4ba795019609618420213b818591f38558f60014c0f7
    Size: 32.21 MB
  27. kernel-rt-debug-modules-extra-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: add639087fefce018a7c0124779fe5b3
    SHA-256: cbe39bbdfc71c5728aad81957d387530c1fb17b059d6242e6cd6999a9787a6ce
    Size: 1.45 MB
  28. kernel-rt-devel-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 26e6dbf7c6aee82e732beb4fdfc3c137
    SHA-256: 257c749a9b7ba83d45c31a4199014ed68bdd0699b70c2509b70cddc1099715a1
    Size: 21.20 MB
  29. kernel-rt-modules-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 650a6b35805fa4ea09a870ea6d88a59e
    SHA-256: 64ee3309bc90424267408a8d190cf82e0c21040e198cdeeb275dbfee8c1b61a4
    Size: 40.01 MB
  30. kernel-rt-modules-core-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 8d9564082bd36462d06653c47f6e0f1b
    SHA-256: d2cdde7483e90e4eb1f9c96a60de784bef5b7da6a3fef0ca63b4218c1365f7f8
    Size: 31.11 MB
  31. kernel-rt-modules-extra-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: aa62ffc878b2b6b1eb2f6dd40dce830a
    SHA-256: 2195df99771f4d9fab951123207c01aa1cbc040d6e6ff1f8e7910aae84bafb55
    Size: 1.43 MB
  32. kernel-tools-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 59437ae77ca1d47ad068c262f235c871
    SHA-256: db873cd072a91f823211d406b55abd9c3012da3399cec8cdfc31fa56f213c7d3
    Size: 1.27 MB
  33. kernel-tools-libs-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: b868fa9d019c347ace7fca09760f2219
    SHA-256: 53200b06698c1a62cd5ff43b6d40881c9e73742dbd1507b044f98cde68fd6e1a
    Size: 1.00 MB
  34. kernel-tools-libs-devel-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 99cb276ecab8320b28a48e4dd4e8b39c
    SHA-256: 9e1c36a84cd4cdbff4504864c931aae82f0a286a24a545060b27efbb707b254e
    Size: 0.99 MB
  35. kernel-uki-virt-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: e17ecf0f6c68777c52f528409db74d20
    SHA-256: e8bd1c2784ee979a33fa5f8ad5c0e9a2d37f2b9df0caaffb91f3bbedb07fef40
    Size: 66.01 MB
  36. kernel-uki-virt-addons-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 2fc35438f059f157d9b50d11cf83a759
    SHA-256: cf6b7186583582eed3f428dfd5fbc2fac6377073dc3b86ebabfb5ba70e5d5592
    Size: 1.01 MB
  37. libperf-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 32769a833da8b6e69bc066a1ae4c4b02
    SHA-256: a5d206b19688a53597f52f8a069284cd31973c8cf37d2a76653b1203fbe7001f
    Size: 1.01 MB
  38. perf-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 8788a7fe67bf60b76b7e450a04c97c6d
    SHA-256: ee33ab588158a52deb6fe2ff0a9facd55025c9a94f9bae8c3f2f4af7476c38ee
    Size: 3.40 MB
  39. python3-perf-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: 0497467047cbf66d5e74f5c37936f030
    SHA-256: 33515c7ebd3d9c6ae6140de4543998a036104fd68b7169f835c4f46e84cecb76
    Size: 2.57 MB
  40. rtla-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: d8cd2ccf9c8b809f2615e238c224a9fc
    SHA-256: 137d34d80506c86946b26a4b10a28fc22150651da9fc8d2c044a4f53d573d5d5
    Size: 1.05 MB
  41. rv-5.14.0-687.45.1.el9_8.x86_64.rpm
    MD5: b519310b09dcb044de63643fbbba2ed7
    SHA-256: 4d5fbd17adeae5c97e246dcb14634c370283bad805b9f9ed302af5b8db1c2e33
    Size: 1.00 MB