The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
- kernel: Bluetooth: l2cap: fix null-ptr-deref in l2capchantimeout (CVE-2024-27399)
- kernel: bpf: Add BPFPROGTYPECGROUPSKB attach type enforcement in BPFLINKCREATE (CVE-2024-38564)
- kernel: bpf: Fix a kernel verifier crash in stacksafe() (CVE-2024-45020)
- kernel: nfsd: ensure that nfsd4fattrargs.context is zeroed out (CVE-2024-46697)
- kernel: bpf: Fix use-after-free in bpfuprobemultilinkattach() (CVE-2024-47675)
- kernel: bpf: Fix a sdiv overflow issue (CVE-2024-49888)
- kernel: arm64: probes: Remove broken LDR (literal) uprobe support (CVE-2024-50099)
- kernel: xfrm: fix one more kernel-infoleak in algo dumping (CVE-2024-50110)
- kernel: Bluetooth: SCO: Fix UAF on scosocktimeout (CVE-2024-50125)
- kernel: Bluetooth: ISO: Fix UAF on isosocktimeout (CVE-2024-50124)
- kernel: KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory (CVE-2024-50115)
- kernel: xfrm: validate new SA's prefixlen using SA family when sel.family is unset (CVE-2024-50142)
- kernel: Bluetooth: bnep: fix wild-memory-access in proto_unregister (CVE-2024-50148)
- kernel: irqchip/gic-v4: Don't allow a VMOVP on a dying VPE (CVE-2024-50192)
- kernel: Bluetooth: hci: fix null-ptr-deref in hcireadsupported_codecs (CVE-2024-50255)
- kernel: sched/numa: Fix the potential null pointer dereference in tasknumawork() (CVE-2024-50223)
- kernel: bpf: Fix out-of-bounds write in triegetnext_key() (CVE-2024-50262)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.