EulerOS Virtualization 2.12.1 : kernel (EulerOS-SA-2026-3590)

high Nessus Plugin ID 347286

Synopsis

The remote EulerOS Virtualization host is missing multiple security updates.

Description

According to the versions of the kernel packages installed, the EulerOS Virtualization installation on the remote host is affected by the following vulnerabilities :

dlm: validate length in dlm_search_rsb_tree(CVE-2026-43125)

net: annotate data-races around sk-sk_{data_ready,write_space}(CVE-2026-23302)

netfilter: ctnetlink: ignore explicit helper on new expectations(CVE-2026-43025)

fbcon: check return value of con2fb_acquire_newinfo()(CVE-2026-43123)

nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set(CVE-2026-43449)

spi: use generic driver_override infrastructure(CVE-2026-31487)

USB: core: Limit the length of unkillable synchronous timeouts(CVE-2026-43428)

qed: fix double free in qed_cxt_tables_alloc()(CVE-2026-64118)

regulator: core: fix locking in regulator_resolve_supply() error path(CVE-2026-46252)

xfrm6: fix uninitialized saddr in xfrm6_get_saddr()(CVE-2026-43139)

rtmutex: Use waiter::task instead of current in remove_waiter()(CVE-2026-43499)

ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O(CVE-2026-45985)

ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()(CVE-2026-53221)

crypto: jitterentropy - replace long-held spinlock with mutex(CVE-2026-52936)

KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0(CVE-2026-46082)

nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free(CVE-2026-46304)

ipmi: Check event message buffer response for bad data(CVE-2026-46128)

sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing(CVE-2026-53246)

libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply()(CVE-2026-46024)

md/raid10: fix divide-by-zero in setup_geo() with zero far_copies(CVE-2026-46161)

xfrm: always flush state and policy upon NETDEV_UNREGISTER event(CVE-2026-43167)

HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure(CVE-2026-43049)

nfsd: never defer requests during idmap lookup(CVE-2026-45983)

iommu/amd: move wait_on_sem() out of spinlock(CVE-2026-43253)

fat: avoid parent link count underflow in rmdir(CVE-2026-45915)

tun: free page on short-frame rejection in tun_xdp_one()(CVE-2026-46321)

openvswitch: cap upcall PID array size and pre-size vport replies(CVE-2026-45840)

tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure(CVE-2026-45941)

xfs: remove xfs_attr_leaf_hasname(CVE-2026-43153)

fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath(CVE-2026-43112)

crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed(CVE-2026-31697)

fanotify: fix false positive on permission events(CVE-2026-46150)

APEI/GHES: ensure that won't go past CPER allocated record(CVE-2026-43277)

xfrm: Wait for RCU readers during policy netns exit(CVE-2026-43091)

netfilter: synproxy: add mutex to guard hook reference counting(CVE-2026-53269)

udf: reject descriptors with oversized CRC length(CVE-2026-53369)

bpf: fix end-of-list detection in cgroup_storage_get_next_key()(CVE-2026-45838)

ipvs: skip ipv6 extension headers for csum checks(CVE-2026-45850)

netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent(CVE-2026-43026)

crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed(CVE-2026-31699)

USB: serial: kl5kusb105: fix bulk-out buffer overflow(CVE-2026-53194)

tipc: fix double-free in tipc_buf_append()(CVE-2026-52993)

spi: fix resource leaks on device setup failure(CVE-2026-46083)

nfsd: fix posix_acl leak on SETACL decode failure(CVE-2026-53397)

RDMA/hns: Fix WQ_MEM_RECLAIM warning(CVE-2026-46265)

net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()(CVE-2026-52982)

RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq()(CVE-2026-46178)

crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed(CVE-2026-31698)

tun: free page on build_skb failure in tun_xdp_one()(CVE-2026-46322)

net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked(CVE-2026-43496)

fs/mbcache: cancel shrink work before destroying the cache(CVE-2026-53129)

ext4: fix dirtyclusters double decrement on fs shutdown(CVE-2026-45920)

bonding: 3ad: implement proper RCU rules for port-aggregator(CVE-2026-52975)

net: use skb_header_pointer() for TCPv4 GSO frag_off check(CVE-2026-43036)

scsi: target: core: Fix integer overflow in UNMAP bounds check(CVE-2026-53021)

KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated(CVE-2026-43483)

SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths(CVE-2026-45870)

sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL(CVE-2026-46227)

ext4: drop extent cache after doing PARTIAL_VALID1 zeroout(CVE-2026-45892)

bnxt_en: Fix NULL pointer dereference(CVE-2026-53177)

pppoe: drop PFC frames(CVE-2026-53003)

ip6_vti: set netns_immutable on the fallback device.(CVE-2026-52909)

KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2(CVE-2026-45987)

scsi: storvsc: Fix scheduling while atomic on PREEMPT_RT(CVE-2026-43475)

HID: usbhid: fix deadlock in hid_post_reset()(CVE-2026-53037)

drm: Account property blob allocations to memcg(CVE-2026-43287)

netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator(CVE-2026-43085)

scsi: sg: Resolve soft lockup issue when opening /dev/sgX(CVE-2026-53304)

libceph: Fix potential out-of-bounds access in osdmap_decode()(CVE-2026-52958)

scsi: csiostor: Fix dereference of null pointer rn(CVE-2026-45857)

KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits(CVE-2026-64106)

netfilter: nf_tables: reject immediate NF_QUEUE verdict(CVE-2026-43024)

dm: fix a buffer overflow in ioctl processing(CVE-2026-46294)

drm/amd/display: Bound VBIOS record-chain walk loops(CVE-2026-53138)

ipv6: xfrm6: release dst on error in xfrm6_rcv_encap()(CVE-2026-46172)

netfilter: ipset: stop hash:* range iteration at end(CVE-2026-52921)

ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all()(CVE-2026-46046)

netfilter: conntrack_irc: fix possible out-of-bounds read(CVE-2026-53268)

tap: free page on error paths in tap_get_user_xdp()(CVE-2026-46320)

net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list(CVE-2026-53230)

padata: Put CPU offline callback in ONLINE section to allow failure(CVE-2026-53314)

scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()(CVE-2026-63888)

crypto: authencesn - reject short ahash digests during instance creation(CVE-2026-46033)

scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf(CVE-2026-63887)

ipv6: fix possible UAF in icmpv6_rcv()(CVE-2026-53006)

netfilter: ctnetlink: ensure safe access to master conntrack(CVE-2026-43116)

net: skbuff: fix missing zerocopy reference in pskb_carve helpers(CVE-2026-52943)

net/sched: fix pedit partial COW leading to page cache corruption(CVE-2026-46331)

bonding: fix type confusion in bond_setup_by_slave()(CVE-2026-43456)

esp: fix skb leak with espintcp and async crypto(CVE-2026-31518)

net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery(CVE-2026-43466)

drm/amd/display: Fix dc_link NULL handling in HPD init(CVE-2026-46245)

fbcon: Avoid OOB font access if console rotation fails(CVE-2026-46191)

netfilter: revalidate bridge ports(CVE-2026-53220)

x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache(CVE-2026-46174)

HID: magicmouse: Do not crash on missing msc-input(CVE-2026-43140)

sctp: stream: fully roll back denied add-stream state(CVE-2026-52929)

selinux: allow multiple opens of /sys/fs/selinux/policy(CVE-2026-46302)

net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr(CVE-2026-53245)

tcp: restrict SO_ATTACH_FILTER to priv users(CVE-2026-53236)

ipv6: mcast: Fix use-after-free when processing MLD queries(CVE-2026-53275)

bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops(CVE-2026-53078)

ipv6: rpl: reserve mac_len headroom when recompressed SRH grows(CVE-2026-43501)

iommu/vt-d: Flush cache for PASID table before using it(CVE-2026-45862)

tcp: secure_seq: add back ports to TS offset(CVE-2026-23247)

netfilter: bridge: make ebt_snat ARP rewrite writable(CVE-2026-53266)

thunderbolt: Reject zero-length property entries in validator(CVE-2026-53150)

drm/nouveau: fix u32 overflow in pushbuf reloc bounds check(CVE-2026-46006)

sctp: diag: reject stale associations in dump_one path(CVE-2026-52917)

dm cache: fix write hang in passthrough mode(CVE-2026-53063)

ipc: limit next_id allocation to the valid ID range(CVE-2026-52923)

bpf: Fix OOB in pcpu_init_value(CVE-2026-53076)

md/bitmap: fix GPF in write_page caused by resize race(CVE-2026-43163)

KVM: SVM: Add missing save/restore handling of LBR MSRs(CVE-2026-46014)

ext4: fix memory leak in ext4_ext_shift_extents()(CVE-2026-45948)

udf: fix partition descriptor append bookkeeping(CVE-2026-45991)

drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()(CVE-2026-46209)

usb: usblp: fix heap leak in IEEE 1284 device ID via short response(CVE-2026-46151)

net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo(CVE-2026-46132)

tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR(CVE-2026-52937)

ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths(CVE-2026-43066)

cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path(CVE-2026-43328)

netfilter: conntrack: remove sprintf usage(CVE-2026-53002)

inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP(CVE-2026-46266)

netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase(CVE-2026-52988)

netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path(CVE-2026-43451)

ext4: drop extent cache when splitting extent fails(CVE-2026-45899)

dm log: fix out-of-bounds write due to region_count overflow(CVE-2026-53059)

hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf(CVE-2026-53199)

drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()(CVE-2026-53330)

sched/psi: fix race between file release and pressure write(CVE-2026-52991)

fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios(CVE-2026-53167)

fuse: reject oversized dirents in page cache(CVE-2026-31694)

libceph: handle rbtree insertion error in decode_choose_args()(CVE-2026-52954)

io_uring/poll: fix signed comparison in io_poll_get_ownership()(CVE-2026-52933)

l2tp: Drop large packets with UDP encap(CVE-2026-43080)

netfilter: require Ethernet MAC header before using eth_hdr()(CVE-2026-53131)

iommu/vt-d: Clear Present bit before tearing down context entry(CVE-2026-45944)

netfilter: ebtables: fix OOB read in compat_mtw_from_user(CVE-2026-52927)

bpf: Fix use-after-free in offloaded map/prog info fill(CVE-2026-53089)

iommu/amd: Fix clone_alias() to use the original device's devid(CVE-2026-53053)

usb: class: cdc-wdm: fix reordering issue in read code path(CVE-2026-43427)

usb: image: mdc800: kill download URB on timeout(CVE-2026-43425)

lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl()(CVE-2026-43492)

netfilter: xt_policy: fix strict mode inbound policy matching(CVE-2026-52920)

ceph: fix i_nlink underrun during async unlink(CVE-2026-43420)

mmc: core: Avoid bitfield RMW for claim/retune flags(CVE-2026-43484)

quota: Fix race of dquot_scan_active() with quota deactivation(CVE-2026-53050)

net: strparser: fix skb_head leak in strp_abort_strp()(CVE-2026-46102)

unshare: fix unshare_fs() handling(CVE-2026-43472)

vsock/virtio: fix accept queue count leak on transport mismatch(CVE-2026-46214)

net: guard timestamp cmsgs to real error queue skbs(CVE-2026-53223)

scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show()(CVE-2026-46149)

ceph: only d_add() negative dentries when they are unhashed(CVE-2026-46052)

nouveau/dpcd: return EBUSY for aux xfer if the device is asleep(CVE-2026-43381)

RDMA/umem: Fix truncation for block sizes = 4G(CVE-2026-53133)

bpf, arm64: Fix off-by-one in check_imm signed range check(CVE-2026-53036)

netfilter: xt_tcpmss: check remaining length before reading optlen(CVE-2026-43190)

sched/rt: Skip currently executing CPU in rto_next_cpu()(CVE-2026-45919)

mm/huge_memory: update file PMD counter before folio_put()(CVE-2026-53189)

ext4: move ext4_percpu_param_init() before ext4_mb_init()(CVE-2026-43288)

dm: remove fake timeout to avoid leak request(CVE-2026-43314)

netfilter: nf_conntrack_sip: don't use simple_strtoul(CVE-2026-52986)

crypto: ccp - copy IV using skcipher ivsize(CVE-2026-53016)

vsock: fix buffer size clamping order(CVE-2026-46234)

signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()(CVE-2026-53352)

netfilter: ip6t_hbh: reject oversized option lists(CVE-2026-52915)

net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info- leak(CVE-2026-43035)

tipc: fix divide-by-zero in tipc_sk_filter_connect()(CVE-2026-43411)

APEI/GHES: ARM processor Error: don't go past allocated memory(CVE-2026-43201)

neigh: let neigh_xmit take skb ownership(CVE-2026-52981)

ext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1(CVE-2026-45858)

netfilter: nf_tables: use list_del_rcu for netlink hooks(CVE-2025-54518)

netfilter: xt_multiport: validate range encoding in checkentry(CVE-2026-46324)

RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path(CVE-2026-31681)

netfilter: nft_fib: fix stale stack leak via the OIFNAME register(CVE-2026-46189)

lib/crypto: chacha: Zeroize permuted_state before it leaves scope(CVE-2026-53134)

netfilter: nfnetlink_osf: fix out-of-bounds read on option matching(CVE-2026-43336)

USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()(CVE-2026-52999)

bridge: br_nd_send: validate ND option lengths(CVE-2026-53195)

iommu/vt-d: Clear Present bit before tearing down PASID entry(CVE-2026-31752)

fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling(CVE-2026-45894)

isofs: validate block number from NFS file handle in isofs_export_iget(CVE-2026-52946)

netfilter: x_tables: avoid leaking percpu counter pointers(CVE-2026-46124)

net/sched: act_api: use RCU with deferred freeing for action lifecycle(CVE-2026-53219)

RDMA/rxe: Reject unknown opcodes before ICRC processing(CVE-2026-53264)

net: af_key: zero aligned sockaddr tail in PF_KEY exports(CVE-2026-46133)

ipc/shm: serialize orphan cleanup with shm_nattch updates(CVE-2026-43088)

AppArmor: Allow apparmor to handle unaligned dfa tables(CVE-2026-52930)

inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush(CVE-2026-46254)

tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func()(CVE-2026-53175)

nvme-pci: Fix race bug in nvme_poll_irqdisable()(CVE-2026-46196)

IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN(CVE-2026-43448)

vrf: Fix a potential NPD when removing a port from a VRF(CVE-2026-53176)

fuse: reject fuse_notify() pagecache ops on directories(CVE-2026-52925)

RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send(CVE-2026-53168)

bpf: reject direct access to nullable PTR_TO_BUF pointers(CVE-2026-45856)

sctp: fix uninit-value in __sctp_rcv_asconf_lookup()(CVE-2026-43333)

netfilter: reject zero shift in nft_bitwise(CVE-2026-53225)

netfilter: nft_exthdr: fix register tracking for F_PRESENT flag(CVE-2026-46101)

netfilter: nf_conntrack: destroy stale expectfn expectations on unregister(CVE-2026-53218)

fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info(CVE-2026-53349)

vxlan: validate ND option lengths in vxlan_na_create(CVE-2026-46065)

inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails(CVE-2026-31738)

RDMA/mlx5: Fix UMR hang in LAG error state unload(CVE-2026-46040)

netfilter: nf_queue: hold bridge skb-dev while queued(CVE-2026-45973)

slip: reject VJ receive packets on instances with no rstate array(CVE-2026-52912)

RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv(CVE-2026-45842)

thunderbolt: Limit XDomain response copy to actual frame size(CVE-2026-46043)

slip: bound decode() reads against the compressed packet length(CVE-2026-53146)

bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec()(CVE-2026-45843)

netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO(CVE-2026-45839)

io-wq: check that the predecessor is hashed in io_wq_remove_pending()(CVE-2026-45841)

RDMA/core: Prefer NLA_NUL_STRING(CVE-2026-46274)

net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure(CVE-2026-63860)

xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete(CVE-2026-53229)

net: phy: clean the sfp upstream if phy probing fails(CVE-2026-46116)

dm-thin: fix metadata refcount underflow(CVE-2026-53232)

netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP(CVE-2026-46107)

usb: xhci: Fix memory leak in xhci_disable_slot()(CVE-2026-31424)

bonding: alb: fix UAF in rlb_arp_recv during bond up/down(CVE-2026-43432)

EFI/CPER: don't go past the ARM processor CPER record buffer(CVE-2026-45970)

RDMA/rxe: Fix double free in rxe_srq_from_init(CVE-2026-43266)

SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path(CVE-2026-45852)

netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check(CVE-2026-45964)

nvmet-tcp: fix race between ICReq handling and queue teardown(CVE-2026-52998)

xfrm_user: fix info leak in build_report()(CVE-2026-46135)

netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry(CVE-2026-31671)

cgroup: fix race between task migration and iteration(CVE-2026-43114)

thermal: core: Fix thermal zone governor cleanup issues(CVE-2026-43439)

ppp: require CAP_NET_ADMIN in target netns for unattached ioctls(CVE-2026-46021)

cpuidle: Skip governor when only one idle state is available(CVE-2026-53075)

xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()(CVE-2026-45968)

netfilter: xtables: restrict several matches to inet family(CVE-2026-53239)

ipvs: do not keep dest_dst if dev is going down(CVE-2026-53001)

ixgbevf: fix use-after-free in VEPA multicast source pruning(CVE-2026-45917)

libceph: Fix potential out-of-bounds access in crush_decode()(CVE-2026-64113)

bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap(CVE-2026-52955)

USB: serial: io_ti: fix heap overflow in get_manuf_info()(CVE-2026-53111)

netfilter: nf_log: validate MAC header was set before dumping it(CVE-2026-53196)

bpf: Fix ld_{abs,ind} failure path analysis in subprogs(CVE-2026-52942)

dm cache policy smq: fix missing locks in invalidating cache blocks(CVE-2026-53090)

net: openvswitch: fix possible kfree_skb of ERR_PTR(CVE-2026-53062)

xfrm: fix ip_rt_bug race in icmp_route_lookup reverse path(CVE-2026-53227)

HID: logitech-hidpp: Check maxfield in hidpp_get_report_length()(CVE-2026-45905)

thunderbolt: Clamp XDomain response data copy to allocation size(CVE-2026-43136)

ice: fix double-free of tx_buf skb(CVE-2026-53148)

sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks(CVE-2026-53009)

tcp: fix potential race in tcp_v6_syn_recv_sock()(CVE-2026-53004)

xfrm: hold dev ref until after transport_finish NF_HOOK(CVE-2026-43198)

media: pvrusb2: fix URB leak in pvr2_send_request_ex(CVE-2026-31663)

media: videobuf2: Set vma_flags in vb2_dma_sg_mmap(CVE-2026-43223)

RDMA/srp: bound SRP_RSP sense copy by the received length(CVE-2026-46312)

pstore/ram: fix buffer overflow in persistent_ram_save_old()(CVE-2026-53186)

md/raid5: fix soft lockup in retry_aligned_read()(CVE-2026-46253)

pmdomain: core: Fix detach procedure for virtual devices in genpd(CVE-2026-46051)

net: bridge: use a stable FDB dst snapshot in RCU readers(CVE-2026-46292)

netlabel: validate unlabeled address and mask attribute lengths(CVE-2026-46086)

ceph: fix a buffer leak in __ceph_setxattr()(CVE-2026-53238)

xfrm: ah: account for ESN high bits in async callbacks(CVE-2026-52962)

locking/rtmutex: Skip remove_waiter() when waiter is not enqueued(CVE-2026-46193)

libceph: Fix potential null-ptr-deref in decode_choose_args()(CVE-2026-53163)

RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event()(CVE-2026-52957)

procfs: fix missing RCU protection when reading real_parent in do_task_stat()(CVE-2026-46181)

netfilter: nft_ct: bail out on template ct in get eval(CVE-2026-46259)

net: sched: act_csum: validate nested VLAN headers(CVE-2026-53267)

nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers(CVE-2026-31684)

xsk: tighten UMEM headroom validation to account for tailroom and min frame(CVE-2026-52989)

ipv6: sit: reload inner IPv6 header after GSO offloads(CVE-2026-43093)

8021q: delete cleared egress QoS mappings(CVE-2026-53228)

mailbox: add sanity check for channel array(CVE-2026-46153)

apparmor: fix NULL sock in aa_sock_file_perm(CVE-2026-53295)

net: hns3: fix double free issue for tx spare buffer(CVE-2026-45848)

USB: serial: cypress_m8: fix memory corruption with small endpoint(CVE-2026-45891)

ipv6: prevent possible UaF in addrconf_permanent_addr()(CVE-2026-63956)

mfd: core: Add locking around 'mfd_of_node_list'(CVE-2026-43339)

dm cache policy smq: check allocation under invalidate lock(CVE-2026-43143)

net: Drop the lock in skb_may_tx_timestamp()(CVE-2026-53265)

crypto: af_alg - Cap AEAD AD length to 0x80000000(CVE-2026-43216)

dm mirror: fix integer overflow in create_dirty_log()(CVE-2026-52972)

thunderbolt: Bound root directory content to block size(CVE-2026-46023)

KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm-lock(CVE-2026-53149)

ipvs: clear the svc scheduler ptr early on edit(CVE-2026-31592)

ipmi:si: Return state to normal if message allocation fails(CVE-2026-53270)

audit: fix incorrect inheritable capability in CAPSET records(CVE-2026-46108)

isofs: validate Rock Ridge CE continuation extent against volume size(CVE-2026-53287)

xfrm: account XFRMA_IF_ID in aevent size calculation(CVE-2026-46303)

usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl(CVE-2026-43107)

bpf: Free reuseport cBPF prog after RCU grace period.(CVE-2026-46167)

dm cache: fix null-deref with concurrent writes in passthrough mode(CVE-2026-52910)

sctp: validate embedded INIT chunk and address list lengths in cookie(CVE-2026-53064)

xfrm_user: fix info leak in build_mapping()(CVE-2026-53224)

smb: client: require a full NFS mode SID before reading mode bits(CVE-2026-43089)

apparmor: fix rlimit for posix cpu timers(CVE-2026-43350)

net: usb: catc: enable basic endpoint checking(CVE-2026-46328)

media: saa7164: add ioremap return checks and cleanups(CVE-2026-45923)

ipmi:ssif: Clean up kthread on errors(CVE-2026-46235)

dm cache: fix dirty mapping checking in passthrough mode switching(CVE-2026-46044)

USB: serial: omninet: fix memory corruption with small endpoint(CVE-2026-53061)

md/raid5: validate payload size before accessing journal metadata(CVE-2026-63928)

md raid: fix hang when stopping arrays with metadata through dm-raid(CVE-2026-46070)

i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl(CVE-2026-43309)

x86-64: rename misleadingly named '__copy_user_nocache()' function(CVE-2026-52948)

net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd()(CVE-2026-43073)

sctp: purge outqueue on stale COOKIE-ECHO handling(CVE-2026-31700)

ice: fix NULL pointer dereference in ice_reset_all_vfs()(CVE-2026-52924)

ipmi: Add limits to event and receive message requests(CVE-2026-53289)

Tenable has extracted the preceding description block directly from the EulerOS Virtualization kernel security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected kernel packages.

See Also

http://www.nessus.org/u?4ff6f617

Plugin Details

Severity: High

ID: 347286

File Name: EulerOS_SA-2026-3590.nasl

Version: 1.1

Type: Local

Published: 9/18/2026

Updated: 9/18/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

Percentile: 99.87

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 6.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-53196

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

CVSS Score Source: CVE-2026-53195

CVSS v4

Risk Factor: High

Base Score: 7.3

Threat Score: 7.3

Threat Vector: CVSS:4.0/E:A

Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2025-54518

Vulnerability Information

CPE: cpe:/o:huawei:euleros:uvp:2.12.1, p-cpe:/a:huawei:euleros:kernel-tools-libs, p-cpe:/a:huawei:euleros:kernel-tools, p-cpe:/a:huawei:euleros:kernel, p-cpe:/a:huawei:euleros:perf-lite, p-cpe:/a:huawei:euleros:perf

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/EulerOS/release, Host/EulerOS/rpm-list, Host/EulerOS/uvp_version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/16/2026

Vulnerability Publication Date: 3/12/2026

Reference Information

CVE: CVE-2025-54518, CVE-2026-23247, CVE-2026-23302, CVE-2026-31424, CVE-2026-31487, CVE-2026-31518, CVE-2026-31592, CVE-2026-31663, CVE-2026-31671, CVE-2026-31681, CVE-2026-31684, CVE-2026-31694, CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31700, CVE-2026-31738, CVE-2026-31752, CVE-2026-43024, CVE-2026-43025, CVE-2026-43026, CVE-2026-43035, CVE-2026-43036, CVE-2026-43049, CVE-2026-43066, CVE-2026-43073, CVE-2026-43080, CVE-2026-43085, CVE-2026-43088, CVE-2026-43089, CVE-2026-43091, CVE-2026-43093, CVE-2026-43107, CVE-2026-43112, CVE-2026-43114, CVE-2026-43116, CVE-2026-43123, CVE-2026-43125, CVE-2026-43136, CVE-2026-43139, CVE-2026-43140, CVE-2026-43143, CVE-2026-43153, CVE-2026-43163, CVE-2026-43167, CVE-2026-43190, CVE-2026-43198, CVE-2026-43201, CVE-2026-43216, CVE-2026-43223, CVE-2026-43253, CVE-2026-43266, CVE-2026-43277, CVE-2026-43287, CVE-2026-43288, CVE-2026-43309, CVE-2026-43314, CVE-2026-43328, CVE-2026-43333, CVE-2026-43336, CVE-2026-43339, CVE-2026-43350, CVE-2026-43381, CVE-2026-43411, CVE-2026-43420, CVE-2026-43425, CVE-2026-43427, CVE-2026-43428, CVE-2026-43432, CVE-2026-43439, CVE-2026-43448, CVE-2026-43449, CVE-2026-43451, CVE-2026-43456, CVE-2026-43466, CVE-2026-43472, CVE-2026-43475, CVE-2026-43483, CVE-2026-43484, CVE-2026-43492, CVE-2026-43496, CVE-2026-43499, CVE-2026-43501, CVE-2026-45838, CVE-2026-45839, CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843, CVE-2026-45848, CVE-2026-45850, CVE-2026-45852, CVE-2026-45856, CVE-2026-45857, CVE-2026-45858, CVE-2026-45862, CVE-2026-45870, CVE-2026-45891, CVE-2026-45892, CVE-2026-45894, CVE-2026-45899, CVE-2026-45905, CVE-2026-45915, CVE-2026-45917, CVE-2026-45919, CVE-2026-45920, CVE-2026-45923, CVE-2026-45941, CVE-2026-45944, CVE-2026-45948, CVE-2026-45964, CVE-2026-45968, CVE-2026-45970, CVE-2026-45973, CVE-2026-45983, CVE-2026-45985, CVE-2026-45987, CVE-2026-45991, CVE-2026-46006, CVE-2026-46014, CVE-2026-46021, CVE-2026-46023, CVE-2026-46024, CVE-2026-46033, CVE-2026-46040, CVE-2026-46043, CVE-2026-46044, CVE-2026-46046, CVE-2026-46051, CVE-2026-46052, CVE-2026-46065, CVE-2026-46070, CVE-2026-46082, CVE-2026-46083, CVE-2026-46086, CVE-2026-46101, CVE-2026-46102, CVE-2026-46107, CVE-2026-46108, CVE-2026-46116, CVE-2026-46124, CVE-2026-46128, CVE-2026-46132, CVE-2026-46133, CVE-2026-46135, CVE-2026-46149, CVE-2026-46150, CVE-2026-46151, CVE-2026-46153, CVE-2026-46161, CVE-2026-46167, CVE-2026-46172, CVE-2026-46174, CVE-2026-46177, CVE-2026-46178, CVE-2026-46181, CVE-2026-46189, CVE-2026-46191, CVE-2026-46193, CVE-2026-46196, CVE-2026-46209, CVE-2026-46214, CVE-2026-46227, CVE-2026-46234, CVE-2026-46235, CVE-2026-46245, CVE-2026-46252, CVE-2026-46253, CVE-2026-46254, CVE-2026-46259, CVE-2026-46265, CVE-2026-46266, CVE-2026-46274, CVE-2026-46292, CVE-2026-46294, CVE-2026-46302, CVE-2026-46303, CVE-2026-46304, CVE-2026-46312, CVE-2026-46320, CVE-2026-46321, CVE-2026-46322, CVE-2026-46324, CVE-2026-46328, CVE-2026-46331, CVE-2026-52909, CVE-2026-52910, CVE-2026-52912, CVE-2026-52915, CVE-2026-52917, CVE-2026-52920, CVE-2026-52921, CVE-2026-52923, CVE-2026-52924, CVE-2026-52925, CVE-2026-52927, CVE-2026-52929, CVE-2026-52930, CVE-2026-52933, CVE-2026-52936, CVE-2026-52937, CVE-2026-52942, CVE-2026-52943, CVE-2026-52946, CVE-2026-52948, CVE-2026-52954, CVE-2026-52955, CVE-2026-52957, CVE-2026-52958, CVE-2026-52962, CVE-2026-52972, CVE-2026-52975, CVE-2026-52981, CVE-2026-52982, CVE-2026-52986, CVE-2026-52988, CVE-2026-52989, CVE-2026-52991, CVE-2026-52993, CVE-2026-52998, CVE-2026-52999, CVE-2026-53001, CVE-2026-53002, CVE-2026-53003, CVE-2026-53004, CVE-2026-53006, CVE-2026-53009, CVE-2026-53016, CVE-2026-53021, CVE-2026-53036, CVE-2026-53037, CVE-2026-53050, CVE-2026-53053, CVE-2026-53059, CVE-2026-53061, CVE-2026-53062, CVE-2026-53063, CVE-2026-53064, CVE-2026-53075, CVE-2026-53076, CVE-2026-53078, CVE-2026-53089, CVE-2026-53090, CVE-2026-53111, CVE-2026-53129, CVE-2026-53131, CVE-2026-53133, CVE-2026-53134, CVE-2026-53138, CVE-2026-53146, CVE-2026-53148, CVE-2026-53149, CVE-2026-53150, CVE-2026-53163, CVE-2026-53167, CVE-2026-53168, CVE-2026-53175, CVE-2026-53176, CVE-2026-53177, CVE-2026-53186, CVE-2026-53189, CVE-2026-53194, CVE-2026-53195, CVE-2026-53196, CVE-2026-53199, CVE-2026-53218, CVE-2026-53219, CVE-2026-53220, CVE-2026-53221, CVE-2026-53223, CVE-2026-53224, CVE-2026-53225, CVE-2026-53227, CVE-2026-53228, CVE-2026-53229, CVE-2026-53230, CVE-2026-53232, CVE-2026-53236, CVE-2026-53238, CVE-2026-53239, CVE-2026-53245, CVE-2026-53246, CVE-2026-53264, CVE-2026-53265, CVE-2026-53266, CVE-2026-53267, CVE-2026-53268, CVE-2026-53269, CVE-2026-53270, CVE-2026-53275, CVE-2026-53287, CVE-2026-53289, CVE-2026-53295, CVE-2026-53304, CVE-2026-53314, CVE-2026-53330, CVE-2026-53349, CVE-2026-53352, CVE-2026-53369, CVE-2026-53397, CVE-2026-63860, CVE-2026-63887, CVE-2026-63888, CVE-2026-63928, CVE-2026-63956, CVE-2026-64106, CVE-2026-64113, CVE-2026-64118