ALAS2KERNEL-5.10-2026-132


Amazon Linux 2 (EOS) Security Advisory: ALAS2KERNEL-5.10-2026-132
Advisory Released Date: 2026-09-28
Advisory Updated Date: 2026-09-28
Severity: Important

Issue Overview:

In the Linux kernel, the following vulnerability has been resolved:

drm/virtio: use uninterruptible resv lock for plane updates (CVE-2026-64098)

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized

When CONFIG_BPF_LSM=y is set, BPF inode storage maps
(BPF_MAP_TYPE_INODE_STORAGE) are compiled into the kernel. However,
if the BPF LSM is not explicitly enabled at boot time (e.g. omitted
from the "lsm=" boot parameter), lsm_prepare() is never executed for
the BPF LSM.

Consequently, the BPF inode security blob offset
(bpf_lsm_blob_sizes.lbs_inode) is never initialized and remains at
its default compiled size of 8 bytes instead of being updated to a
valid offset past the reserved struct rcu_head (typically 16 bytes
or more).

When a privileged user creates and updates a BPF_MAP_TYPE_INODE_STORAGE
map, bpf_inode() evaluates inode->i_security + 8. This erroneously
aliases the struct rcu_head.func callback pointer at the beginning
of the inode->i_security blob. During subsequent map element cleanup
or inode destruction, writing NULL to owner_storage clears the queued
RCU callback pointer. When rcu_do_batch() later executes the queued
callback, it attempts an instruction fetch at address 0x0, triggering
an immediate kernel panic.

Fix this by introducing a global bpf_lsm_initialized boolean flag
marked with __ro_after_init. Set this flag to true inside bpf_lsm_init()
when the LSM framework successfully registers the BPF LSM. Gate map
allocation in inode_storage_map_alloc() on this flag, returning
-EOPNOTSUPP if the BPF LSM is in turn uninitialized.

This fail-fast approach prevents userspace from allocating inode
storage maps when the supporting BPF LSM infrastructure is absent,
avoiding zombie map states. (CVE-2026-64192)

In the Linux kernel, the following vulnerability has been resolved:

i2c: core: fix adapter deregistration race (CVE-2026-64279)

In the Linux kernel, the following vulnerability has been resolved:

libceph: fix two unsafe bare decodes in decode_lockers() (CVE-2026-68082)

In the Linux kernel, the following vulnerability has been resolved:

audit: fix recursive locking deadlock in audit_dupe_exe() (CVE-2026-68096)

In the Linux kernel, the following vulnerability has been resolved:

super: fix emergency thaw deadlock on frozen block devices (CVE-2026-68132)

In the Linux kernel, the following vulnerability has been resolved:

net: gro: fix double aggregation of flush-marked skbs (CVE-2026-68136)

In the Linux kernel, the following vulnerability has been resolved:

ftrace: Add global mutex to serialize trace_parser access (CVE-2026-68146)

In the Linux kernel, the following vulnerability has been resolved:

libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (CVE-2026-68159)

In the Linux kernel, the following vulnerability has been resolved:

sctp: avoid auth_enable sysctl UAF during netns teardown (CVE-2026-68162)

In the Linux kernel, the following vulnerability has been resolved:

drm/virtio: bound EDID block reads to the response buffer (CVE-2026-68255)

In the Linux kernel, the following vulnerability has been resolved:

drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (CVE-2026-68277)

In the Linux kernel, the following vulnerability has been resolved:

drm/dp/mst: fix buffer overflows in sideband chunk accumulation (CVE-2026-68278)

In the Linux kernel, the following vulnerability has been resolved:

drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (CVE-2026-68279)

In the Linux kernel, the following vulnerability has been resolved:

mmc: vub300: fix use-after-free on probe failure (CVE-2026-72073)

In the Linux kernel, the following vulnerability has been resolved:

scsi: target: Bound PR-OUT TransportID parsing to the received buffer (CVE-2026-72084)

In the Linux kernel, the following vulnerability has been resolved:

scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() (CVE-2026-72087)

In the Linux kernel, the following vulnerability has been resolved:

dm-verity: make error counter atomic (CVE-2026-72096)

In the Linux kernel, the following vulnerability has been resolved:

dm-integrity: don't increment hash_offset twice (CVE-2026-72099)

In the Linux kernel, the following vulnerability has been resolved:

jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() (CVE-2026-72225)

In the Linux kernel, the following vulnerability has been resolved:

selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() (CVE-2026-72242)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_set_pipapo: don't leak bad clone into future transaction (CVE-2026-72252)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_conntrack_sip: validate skb_dst() before accessing it (CVE-2026-72253)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst (CVE-2026-72255)

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (CVE-2026-72288)

In the Linux kernel, the following vulnerability has been resolved:

tipc: restrict socket queue dumps in enqueue tracepoints (CVE-2026-72299)

In the Linux kernel, the following vulnerability has been resolved:

mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (CVE-2026-72308)

In the Linux kernel, the following vulnerability has been resolved:

sctp: add INIT verification after cookie unpacking (CVE-2026-72398)

In the Linux kernel, the following vulnerability has been resolved:

sctp: fix err_chunk memory leaks in INIT handling (CVE-2026-72413)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_compat: ebtables emulation must reject non-bridge targets (CVE-2026-72416)

In the Linux kernel, the following vulnerability has been resolved:

xprtrdma: Repost Receive buffers for malformed replies (CVE-2026-72464)

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (CVE-2026-74378)

In the Linux kernel, the following vulnerability has been resolved:

OPP: Fix race between OPP addition and lookup (CVE-2026-74405)

In the Linux kernel, the following vulnerability has been resolved:

scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write (CVE-2026-74470)

In the Linux kernel, the following vulnerability has been resolved:

net: pktgen: fix proc entry use-after-free (CVE-2026-74479)

In the Linux kernel, the following vulnerability has been resolved:

binfmt_misc: restore write access when removing an entry (CVE-2026-74487)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: make nft_object rhltable per table (CVE-2026-74565)

In the Linux kernel, the following vulnerability has been resolved:

packet: use consistent hard_header_len in non-ring send paths (CVE-2026-74582)

In the Linux kernel, the following vulnerability has been resolved:

sched/psi: Shut down rtpoll_timer in psi_cgroup_free() (CVE-2026-74594)

In the Linux kernel, the following vulnerability has been resolved:

ring-buffer: Use current_context for safe per-CPU buffer swap (CVE-2026-74601)

In the Linux kernel, the following vulnerability has been resolved:

net/sched: act_gact, act_police: range check the fallback control action (CVE-2026-74620)

In the Linux kernel, the following vulnerability has been resolved:

mm/huge_memory: fix huge_zero_pfn race (CVE-2026-74632)

In the Linux kernel, the following vulnerability has been resolved:

perf/core: Fix group leader use-after-free after sibling detach (CVE-2026-74637)

In the Linux kernel, the following vulnerability has been resolved:

ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops (CVE-2026-74657)

In the Linux kernel, the following vulnerability has been resolved:

inet: frags: publish queues before arming timer (CVE-2026-74662)

In the Linux kernel, the following vulnerability has been resolved:

net/sched: reject overly deep qdisc hierarchies (CVE-2026-74663)

In the Linux kernel, the following vulnerability has been resolved:

packet: synchronize pressure clearing with ring reconfiguration (CVE-2026-74666)

In the Linux kernel, the following vulnerability has been resolved:

packet: use consistent hard_header_len in TX_RING send path (CVE-2026-74668)

In the Linux kernel, the following vulnerability has been resolved:

net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (CVE-2026-74684)

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers (CVE-2026-74700)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: publish GC-visible tuple last (CVE-2026-74746)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ipset: fix refcount race between list:set GC and swap (CVE-2026-74748)

In the Linux kernel, the following vulnerability has been resolved:

ceph: fix hanging __ceph_get_caps() with stale mds_wanted (CVE-2026-80527)

In the Linux kernel, the following vulnerability has been resolved:

ceph: avoid fs reclaim while using current->journal_info (CVE-2026-80528)

In the Linux kernel, the following vulnerability has been resolved:

xfs: fix ilock leak on error in xfs_dq_get_next_id (CVE-2026-80534)

In the Linux kernel, the following vulnerability has been resolved:

xfs: bounds-check buffer log item's dirty bitmap (CVE-2026-80536)

In the Linux kernel, the following vulnerability has been resolved:

libceph: fix OOB read in decode_watchers() via missing bounds check (CVE-2026-80557)

In the Linux kernel, the following vulnerability has been resolved:

libceph: Avoid using invalid osd indices from primary_temp (CVE-2026-80558)

In the Linux kernel, the following vulnerability has been resolved:

libceph: fix multiple unsafe decodes in decode_locker() (CVE-2026-80561)

In the Linux kernel, the following vulnerability has been resolved:

mptcp: options: reset DSS fields in case of unexpected size (CVE-2026-80586)

In the Linux kernel, the following vulnerability has been resolved:

inet: frags: strip GSO state from fragments before reassembly (CVE-2026-80590)

In the Linux kernel, the following vulnerability has been resolved:

serial: amba-pl011: synchronize DMA teardown (CVE-2026-80737)

In the Linux kernel, the following vulnerability has been resolved:

af_packet: Don't send zero-byte data in tpacket_snd(). (CVE-2026-80742)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path (CVE-2026-80744)

In the Linux kernel, the following vulnerability has been resolved:

selinux: do not cancel a policy conversion that never started (CVE-2026-80756)

In the Linux kernel, the following vulnerability has been resolved:

selinux: reject a class permission count below its inherited common (CVE-2026-80757)

In the Linux kernel, the following vulnerability has been resolved:

HID: hyperv: validate initial device info bounds (CVE-2026-80765)

In the Linux kernel, the following vulnerability has been resolved:

HID: core: fix OOB read of field->usage in hid_set_field() (CVE-2026-80781)

In the Linux kernel, the following vulnerability has been resolved:

ipv6: fix use-after-free in ip6_finish_output2() (CVE-2026-80792)

In the Linux kernel, the following vulnerability has been resolved:

ipv4: reject undersized MTUs in ip_do_fragment() (CVE-2026-80793)

In the Linux kernel, the following vulnerability has been resolved:

xfs: validate attr entry pointer before field access (CVE-2026-80805)

In the Linux kernel, the following vulnerability has been resolved:

ext4: stop retrying saturated xattr cache entries (CVE-2026-80808)

In the Linux kernel, the following vulnerability has been resolved:

rndis_host: add overflow check in rndis_rx_fixup() (CVE-2026-80814)

In the Linux kernel, the following vulnerability has been resolved:

net: packet: fix wrong transport_header when sending VLAN-tagged frame (CVE-2026-80906)

In the Linux kernel, the following vulnerability has been resolved:

selinux: require every boolean value to be defined (CVE-2026-80913)

In the Linux kernel, the following vulnerability has been resolved:

HID: core: fix number/pointer type confusion on long items (CVE-2026-80918)


Affected Packages:

kernel


Note:

This advisory is applicable to Amazon Linux 2 - Kernel-5.10 Extra. Visit this page to learn more about Amazon Linux 2 (AL2) Extras and this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update kernel or yum update --advisory ALAS2KERNEL-5.10-2026-132 to update your system.
System reboot is required in order to complete this update.

New Packages:
aarch64:
    kernel-5.10.268-266.1092.amzn2.aarch64
    kernel-headers-5.10.268-266.1092.amzn2.aarch64
    kernel-debuginfo-common-aarch64-5.10.268-266.1092.amzn2.aarch64
    perf-5.10.268-266.1092.amzn2.aarch64
    perf-debuginfo-5.10.268-266.1092.amzn2.aarch64
    python-perf-5.10.268-266.1092.amzn2.aarch64
    python-perf-debuginfo-5.10.268-266.1092.amzn2.aarch64
    kernel-tools-5.10.268-266.1092.amzn2.aarch64
    kernel-tools-devel-5.10.268-266.1092.amzn2.aarch64
    kernel-tools-debuginfo-5.10.268-266.1092.amzn2.aarch64
    bpftool-5.10.268-266.1092.amzn2.aarch64
    bpftool-debuginfo-5.10.268-266.1092.amzn2.aarch64
    kernel-devel-5.10.268-266.1092.amzn2.aarch64
    kernel-debuginfo-5.10.268-266.1092.amzn2.aarch64
    kernel-livepatch-5.10.268-266.1092-1.0-0.amzn2.aarch64

i686:
    kernel-headers-5.10.268-266.1092.amzn2.i686

src:
    kernel-5.10.268-266.1092.amzn2.src

x86_64:
    kernel-5.10.268-266.1092.amzn2.x86_64
    kernel-headers-5.10.268-266.1092.amzn2.x86_64
    kernel-debuginfo-common-x86_64-5.10.268-266.1092.amzn2.x86_64
    perf-5.10.268-266.1092.amzn2.x86_64
    perf-debuginfo-5.10.268-266.1092.amzn2.x86_64
    python-perf-5.10.268-266.1092.amzn2.x86_64
    python-perf-debuginfo-5.10.268-266.1092.amzn2.x86_64
    kernel-tools-5.10.268-266.1092.amzn2.x86_64
    kernel-tools-devel-5.10.268-266.1092.amzn2.x86_64
    kernel-tools-debuginfo-5.10.268-266.1092.amzn2.x86_64
    bpftool-5.10.268-266.1092.amzn2.x86_64
    bpftool-debuginfo-5.10.268-266.1092.amzn2.x86_64
    kernel-devel-5.10.268-266.1092.amzn2.x86_64
    kernel-debuginfo-5.10.268-266.1092.amzn2.x86_64
    kernel-livepatch-5.10.268-266.1092-1.0-0.amzn2.x86_64