AlmaLinux 2623 Published by

AlmaLinux released a series of security advisories, targeting versions 8, 9, and 10 of its Linux distribution. The patch cycle addresses code flaws in the standard and real-time kernels, LibRaw, libgcrypt, perl-DBI, golang, and Firefox. Attackers could exploit these moderate to important vulnerabilities to trigger buffer overflows, cause use-after-free crashes, or escalate privileges on affected systems.

ALSA-2026:49871: kernel security, bug fix, and enhancement update (Moderate)
ALSA-2026:51105: LibRaw security update (Important)
ALSA-2026:45192: kernel security, bug fix, and enhancement update (Important)
ALSA-2026:51035: kernel security, bug fix, and enhancement update (Moderate)
ALSA-2026:50147: libgcrypt security update (Moderate)
ALSA-2026:38512: perl-DBI security update (Important)
ALSA-2026:37435: golang security, bug fix, and enhancement update (Important)
ALSA-2026:45116: kernel-rt security update (Important)
ALSA-2026:45115: kernel security update (Important)
ALSA-2026:39180: kernel-rt security update (Important)
ALSA-2026:47105: firefox security update (Important)
ALSA-2026:39179: kernel security update (Important)




ALSA-2026:49871: kernel security, bug fix, and enhancement update (Moderate)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 10
Type: Security
Severity: Moderate
Release date: 2026-08-07

Summary:

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

* kernel: Linux kernel: Denial of Service due to NULL function pointer race in timer shutdown (CVE-2025-68214)
* kernel: procfs: avoid fetching build ID while holding VMA lock (CVE-2026-23199)

Bug Fix(es) and Enhancement(s):

* [Lenovo] Graphics not working on T14 G7 Intel (Pantherlake) (JIRA:AlmaLinux-172832)
* Possible regression with FM350GL [almalinux-10.2.z] (JIRA:AlmaLinux-184266)
* [10.2 FEAT] CNB102: dpll: sync with upstream (JIRA:AlmaLinux-211011)
* backport make module and modules-core provides use variant [almalinux-10.2.z] (JIRA:AlmaLinux-213965)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-49871.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:51105: LibRaw security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-08-07

Summary:

LibRaw is a library for reading RAW files obtained from digital photo cameras (CRW/CR2, NEF, RAF, DNG, and others).

Security Fix(es):

* LibRaw: LibRaw: Buffer Overflow vulnerability in image processing (CVE-2026-51235)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-51105.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:45192: kernel security, bug fix, and enhancement update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-08-07

Summary:

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

* kernel: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (CVE-2025-40026)
* kernel: dm log: fix out-of-bounds write due to region_count overflow (CVE-2026-53059)
* kernel: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (CVE-2026-52976)
* kernel: drm/xe/dma-buf: fix UAF with retry loop (CVE-2026-52950)
* kernel: ipv6: fix possible UAF in icmpv6_rcv() (CVE-2026-53006)

Bug Fix(es) and Enhancement(s):

* scsi device removal may hang from race with error recovery [almalinux-9.8.z] (JIRA:AlmaLinux-187412)
* [AlmaLinux9] kvm fixes for 2026-07-21 [almalinux-9.8.z] (JIRA:AlmaLinux-213468)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-45192.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:51035: kernel security, bug fix, and enhancement update (Moderate)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 9
Type: Security
Severity: Moderate
Release date: 2026-08-07

Summary:

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

* kernel: futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() (CVE-2026-23415)
* kernel: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (CVE-2026-43450)

Bug Fix(es) and Enhancement(s):

* kernel panics caused by NULL pointer dereferences within octeon_ep_vf [almalinux-9.8.z] (JIRA:AlmaLinux-186331)
* [AlmaLinux 9.4] Kernel memory reclaim bug [almalinux-9.8.z] (JIRA:AlmaLinux-211058)
* Bond network interface is not coming up with MTU 9000 while vPMEM is enabled [almalinux-9.8.z] (JIRA:AlmaLinux-215575)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-51035.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:50147: libgcrypt security update (Moderate)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 9
Type: Security
Severity: Moderate
Release date: 2026-08-07

Summary:

The libgcrypt library provides general-purpose implementations of various cryptographic algorithms.

Security Fix(es):

* Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext (CVE-2026-41989)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-50147.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:38512: perl-DBI security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-08-07

Summary:

DBI is a database access Application Programming Interface (API) for the Perl Language. The DBI API Specification defines a set of functions, variables and conventions that provide a consistent database interface independent of the actual database being used.

Security Fix(es):

* DBI: DBI: Buffer overflow in error handling can lead to arbitrary code execution (CVE-2026-9698)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-38512.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:37435: golang security, bug fix, and enhancement update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-08-07

Summary:

The golang packages provide the Go programming language compiler.

Security Fix(es):

* golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
* os: golang: Go os.Root: Symlink following vulnerability allows directory traversal (CVE-2026-39822)

Bug Fix(es) and Enhancement(s):

* Update Go to version 1.26.5+1 [almalinux-9.8.z] (JIRA:AlmaLinux-193476)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-37435.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:45116: kernel-rt security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-08-07

Summary:

The kernel-rt packages provide the Real Time Linux Kernel, which enables
fine-tuning for systems with extremely high determinism requirements.

Security Fix(es):

* kernel: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (CVE-2025-40026)
* kernel: xfrm single-frag length not properly limited
* kernel: dm log: fix out-of-bounds write due to region_count overflow (CVE-2026-53059)
* kernel: tipc: fix double-free in tipc_buf_append() (CVE-2026-52993)

Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-45116.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:45115: kernel security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-08-07

Summary:

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

* kernel: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (CVE-2025-40026)
* kernel: xfrm single-frag length not properly limited
* kernel: dm log: fix out-of-bounds write due to region_count overflow (CVE-2026-53059)
* kernel: tipc: fix double-free in tipc_buf_append() (CVE-2026-52993)

Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-45115.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:39180: kernel-rt security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-08-07

Summary:

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

Security Fix(es):

* kernel: net: bridge: use a stable FDB dst snapshot in RCU readers (CVE-2026-46086)
* kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)
* kernel: XFS data corruption using reflink ()

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-39180.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:47105: firefox security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-08-07

Summary:

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

Security Fix(es):

* libaom: libaom: heap buffer overflow in AV1 encoder first-pass stats buffer via LAP mode (CVE-2026-56208)
* firefox: thunderbird: Site isolation issue in the DOM: Navigation component (CVE-2026-15719)
* firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-15718)
* firefox: thunderbird: Mitigation bypass in the Enterprise Policies component (CVE-2026-16390)
* firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: cubeb component (CVE-2026-16350)
* firefox: thunderbird: Information disclosure in the Storage: IndexedDB component (CVE-2026-16391)
* firefox: thunderbird: Site isolation issue in the Networking: HTTP component (CVE-2026-16375)
* firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16356)
* firefox: thunderbird: JIT miscompilation in the JavaScript: WebAssembly component (CVE-2026-16363)
* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 (CVE-2026-16412)
* firefox: thunderbird: Same-origin policy bypass in the Networking: DNS component (CVE-2026-16381)
* firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2026-16355)
* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 (CVE-2026-16361)
* firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16352)
* firefox: thunderbird: Incorrect boundary conditions in the JavaScript: WebAssembly component (CVE-2026-16368)
* firefox: thunderbird: Mitigation bypass in the PDF Viewer component (CVE-2026-16377)
* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 (CVE-2026-16360)
* firefox: thunderbird: Use-after-free in the WebRTC: Audio/Video component (CVE-2026-16362)
* firefox: thunderbird: Site isolation issue in the Graphics: WebRender component (CVE-2026-16358)
* firefox: thunderbird: Site isolation issue in the Networking component (CVE-2026-16387)
* firefox: thunderbird: Same-origin policy bypass in the DOM: Navigation component (CVE-2026-16349)
* firefox: thunderbird: Incorrect boundary conditions in the Graphics component (CVE-2026-16357)
* firefox: thunderbird: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-16351)
* firefox: thunderbird: Privilege escalation in the DOM: Navigation component (CVE-2026-16371)
* firefox: thunderbird: Privilege escalation in the DOM: Content Processes component (CVE-2026-16379)
* firefox: thunderbird: Information disclosure in the Graphics: ImageLib component (CVE-2026-16354)
* firefox: thunderbird: Information disclosure in the Framework component in DevTools (CVE-2026-16374)
* firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: GMP component (CVE-2026-16359)
* firefox: thunderbird: Mitigation bypass in the DOM: Networking component (CVE-2026-16383)
* firefox: thunderbird: Integer overflow in the JavaScript: WebAssembly component (CVE-2026-16369)
* firefox: thunderbird: Invalid pointer in the DOM: Bindings (WebIDL) component (CVE-2026-16353)
* firefox: thunderbird: Privilege escalation in WebExtensions (CVE-2026-16396)
* firefox: thunderbird: Information disclosure in the Networking: WebSockets component (CVE-2026-16405)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-47105.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:39179: kernel security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-08-07

Summary:

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

* kernel: net: bridge: use a stable FDB dst snapshot in RCU readers (CVE-2026-46086)
* kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)
* kernel: XFS data corruption using reflink ()

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-39179.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team