{"schema_version":"1.7.5","id":"ALSA-2025:22854","published":"2025-12-08T00:00:00Z","modified":"2026-05-26T16:45:08.817556247Z","related":["CVE-2025-38737","CVE-2025-39925","CVE-2025-39979","CVE-2025-39981","CVE-2025-39982","CVE-2025-39983","CVE-2025-40047","CVE-2025-40058","CVE-2025-40185"],"summary":"Moderate: kernel security update","details":"The kernel packages contain the Linux kernel, the core of any Linux operating system.  \n\nSecurity Fix(es):  \n\n  * kernel: cifs: Fix oops due to uninitialised variable (CVE-2025-38737)\n  * kernel: can: j1939: implement NETDEV_UNREGISTER notification handler (CVE-2025-39925)\n  * kernel: Bluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync (CVE-2025-39982)\n  * kernel: Bluetooth: MGMT: Fix possible UAFs (CVE-2025-39981)\n  * kernel: net/mlx5: fs, fix UAF in flow counter release (CVE-2025-39979)\n  * kernel: Bluetooth: hci_event: Fix UAF in hci_conn_tx_dequeue (CVE-2025-39983)\n  * kernel: io_uring/waitid: always prune wait queue entry in io_waitid_wait() (CVE-2025-40047)\n  * kernel: iommu/vt-d: Disallow dirty tracking if incoherent page walk (CVE-2025-40058)\n  * kernel: ice: ice_adapter: release xa entry on adapter allocation failure (CVE-2025-40185)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n","affected":[{"package":{"name":"kernel-abi-stablelists","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/kernel-abi-stablelists"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.0-124.20.1.el10_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2025:22854.json"}},{"package":{"name":"kernel-doc","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/kernel-doc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.0-124.20.1.el10_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2025:22854.json"}}],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:22854"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-38737"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-39925"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-39979"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-39981"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-39982"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-39983"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-40047"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-40058"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-40185"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2393527"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2400629"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2404100"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2404105"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2404109"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2404117"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2406758"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2406776"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2414741"},{"type":"ADVISORY","url":"https://errata.almalinux.org/10/ALSA-2025-22854.html"}]}