🛡️ CLSA-2025-1739525795 — bpftool

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

kernel: Fix of 24 CVEs

  • media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format {CVE-2024-53104}
  • wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service() {CVE-2024-53156}
  • xsk: fix OOB map writes when deleting elements {CVE-2024-56614}
  • hv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer {CVE-2024-53103}
  • net: inet: do not leave a dangling sk pointer in inet_create() {CVE-2024-56601}
  • scsi: sg: Fix slab-use-after-free read in sg_release() {CVE-2024-56631}
  • scsi: sg: Enable runtime power management {CVE-2024-56631}
  • scsi: sg: Avoid race in error handling & drop bogus warn {CVE-2024-56631}
  • scsi: sg: Avoid sg device teardown race {CVE-2024-56631}
  • initramfs: avoid filename buffer overrun {CVE-2024-53142}
  • Bluetooth: RFCOMM: avoid leaving dangling sk pointer in rfcomm_sock_alloc() {CVE-2024-56604}
  • cifs: Fix use-after-free in rdata->read_into_pages() {CVE-2023-52741}
  • Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create() {CVE-2024-56605}
  • af_packet: avoid erroring out after sock_init_data() in packet_create() {CVE-2024-56606}
  • net: ieee802154: do not leave a dangling sk pointer in ieee802154_create() {CVE-2024-56602}
  • net: inet6: do not leave a dangling sk pointer in inet6_create() {CVE-2024-56600}
  • NFSv4.0: Fix a use-after-free problem in the asynchronous open() {CVE-2024-53173}
  • net: af_can: do not leave a dangling sk pointer in can_create() {CVE-2024-56603}
  • drm/amd: Fix UBSAN array-index-out-of-bounds for SMU7 {CVE-2023-52818}
  • rds: tcp: Fix use-after-free of net in reqsk_timer_handler(). {CVE-2024-26865}
  • tcp: Save unnecessary inet_twsk_purge() calls. {CVE-2024-26865}
  • ceph: prevent use-after-free in encode_cap_msg() {CVE-2024-26689}
  • drm/amd/display: Fix out-of-bounds access in 'dcn21_link_encoder_create' {CVE-2024-56608}
  • bpf: Check validity of link->type in bpf_link_show_fdinfo() {CVE-2024-53099}
  • drm/amd/pm: fix a double-free in si_dpm_init {CVE-2023-52691}
  • netfilter: ipset: add missing range check in bitmap_ip_uadt {CVE-2024-53141}
  • tipc: fix NULL deref in cleanup_bearer() {CVE-2024-56661}
  • tipc: Fix use-after-free of kernel socket in cleanup_bearer(). {CVE-2024-56642}

Affected software

CLSA-2025-1739525795 is recorded against 22 packages.

  • bpftool (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-core (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-cross-headers (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-debug (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-debug-core (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-debug-devel (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-debug-modules (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-debug-modules-extra (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-debug-modules-internal (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-devel (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-headers (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-ipaclones-internal (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-modules (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-modules-extra (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-modules-internal (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-selftests-internal (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-tools (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-tools-libs (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • kernel-tools-libs-devel (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • perf (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)
  • python3-perf (fixed in 4.18.0-348.7.1.el8_5.tuxcare.els25)

Timeline and source

Published on 14 February 2025 and last revised on 1 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

errata.cloudlinux.com (Advisory)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-02-14
Updated 2026-08-12
Modified 2026-06-01
Fix URL N/A

Affected Packages

Software From version Fixed in
bpftool 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-core 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-cross-headers 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-debug 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-debug-core 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-debug-devel 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-debug-modules 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-debug-modules-extra 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-debug-modules-internal 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-devel 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-headers 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-ipaclones-internal 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-modules 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-modules-extra 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-modules-internal 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-selftests-internal 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-tools 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-tools-libs 4.18.0-348.7.1.el8_5.tuxcare.els25
kernel-tools-libs-devel 4.18.0-348.7.1.el8_5.tuxcare.els25
perf 4.18.0-348.7.1.el8_5.tuxcare.els25
python3-perf 4.18.0-348.7.1.el8_5.tuxcare.els25

Similar Threats

Free Vulnerability Check

Is your site affected by CLSA-2025-1739525795?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CLSA-2025-1739525795 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.