List of RPMs for HyperScale X Platform Version 2.2601

The following RPMs are included in this version:

RPM Issue

httpd-2.4.6-99.el7_9.7.x86_64.rpm - Fix CVE-2025-58098- httpd: Apache HTTP Server: Server Side Includes adds
query string to #exec cmd=...

httpd-tools-2.4.6-99.el7_9.7.x86_64.rpm - Fix CVE-2025-58098- httpd: Apache HTTP Server: Server Side Includes adds
query string to #exec cmd=...

ipa-client-4.6.8-5.el7_9.24.x86_64.rpm - IPA stops working if HTTP/... service principal was created before FreeIPA 4.4.0 and never modified
Resolves: RHEL-124602

ipa-client-common-4.6.8-5.el7_9.24.noarch.rpm - IPA stops working if HTTP/... service principal was created before FreeIPA 4.4.0 and never modified
Resolves: RHEL-124602

ipa-common-4.6.8-5.el7_9.24.noarch.rpm - IPA stops working if HTTP/... service principal was created before FreeIPA 4.4.0 and never modified
Resolves: RHEL-124602

kernel-3.10.0-1160.144.1.el7.x86_64.rpm - NFSD: Protect against send buffer overflow in NFSv2 READ (Roberto Bergantinos Corpas) [RHEL-116843] {CVE-2022-50410}
- fs: fix UAF/GPF bug in nilfs_mdt_destroy (Xiubo Li) [RHEL-116655] {CVE-2022-50367}
- mm: zswap: fix missing folio cleanup in writeback race path (Jose Guisado) [RHEL-116237] {CVE-2023-53178}
- mm: fix zswap writeback race condition (Jose Guisado) [RHEL-116237] {CVE-2023-53178}
- iomap: iomap: fix memory corruption when recording errors during writeback (John Pittman) [RHEL-119654] {CVE-2022-50406}
- Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp (CKI Backport Bot) [RHEL-118474] {CVE-2023-53297}
- ext4: fix undefined behavior in bit shift for ext4_check_flag_values (Malaya Kumar Rout) [RHEL-117588] {CVE-2022-50403}
- net: sched: sfb: fix null pointer access issue when sfb_init() fails (Xiubo Li) [RHEL-116606] {CVE-2022-50356}
- tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect(). (Xiubo Li) [RHEL-120659] {CVE-2025-39955}
- ALSA: usb-audio: Validate UAC3 power domain descriptors, too (Xiubo Li) [RHEL-114679 RHEL-116019] {CVE-2025-38729 CVE-2025-39757}
- ALSA: usb-audio: Fix size validation in convert_chmap_v3() (Xiubo Li) [RHEL-114679] {CVE-2025-39757}
- ALSA: usb-audio: Validate UAC3 cluster segment descriptors (Xiubo Li) [RHEL-114679] {CVE-2025-39757}
- scsi: qla2xxx: Wait for io return on terminate rport (John Pittman) [RHEL-124590] {CVE-2023-53322}
- Bluetooth: prefetch channel before killing sock (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: L2CAP: Fix user-after-free (Rishikesh Oak) [RHEL-117366] {CVE-2022-50386}
- Bluetooth: L2CAP: Fix use-after-free (Rishikesh Oak) [RHEL-116274] {CVE-2023-53305}
- Bluetooth: Fix l2cap_disconnect_req deadlock (Rishikesh Oak) [RHEL-116274]
- Bluetooth: L2CAP: Fix use-after-free in l2cap_disconnect_{req,rsp} (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: Fix refcount use-after-free issue (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: Check state in l2cap_disconnect_rsp (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: L2CAP: Fix build errors in some archs (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm regression (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: L2CAP: fix use-after-free in l2cap_conn_del() (Rishikesh Oak) [RHEL-116274] {CVE-2022-49909 CVE-2022-3640}
- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_chan_put (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: use the correct print format for L2CAP debug statements (Rishikesh Oak) [RHEL-116274]
- i40e: fix Jumbo Frame support after iPXE boot (Mohammad Heib) [RHEL-97623]
- i40e: Report MFS in decimal base instead of hex (Mohammad Heib) [RHEL-97623]
- i40e: Fix unexpected MFS warning message (Mohammad Heib) [RHEL-97623]
- i40e: Add a check to see if MFS is set (Mohammad Heib) [RHEL-97623]
- bitfield: Add FIELD_MODIFY() helper (Mohammad Heib) [RHEL-97623]
- bitops: Add non-atomic bitops for pointers [partial] (Mohammad Heib) [RHEL-97623]
- wifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit() (Xiubo Li) [RHEL-117940] {CVE-2022-50408}
- cifs: Remove duplicated include in cifsglob.h (Xiubo Li) [RHEL-118059]
- cifs: fix oops during encryption (Xiubo Li) [RHEL-118059] {CVE-2022-50341}
- SMB3: Kernel oops mounting a encryptData share with CONFIG_DEBUG_VIRTUAL (Xiubo Li) [RHEL-118059]
- fix smb3-encryption breakage when CONFIG_DEBUG_SG=y (Xiubo Li) [RHEL-118059]
- sctp: linearize cloned gso packets in sctp_rcv (Xiubo Li) [RHEL-113345] {CVE-2025-38718}
- ip6mr: Fix skb_under_panic in ip6mr_cache_report() (Marc Milgram) [RHEL-118006] {CVE-2023-53365}

kernel-devel-3.10.0-1160.144.1.el7.x86_64.rpm - NFSD: Protect against send buffer overflow in NFSv2 READ (Roberto Bergantinos Corpas) [RHEL-116843] {CVE-2022-50410}
- fs: fix UAF/GPF bug in nilfs_mdt_destroy (Xiubo Li) [RHEL-116655] {CVE-2022-50367}
- mm: zswap: fix missing folio cleanup in writeback race path (Jose Guisado) [RHEL-116237] {CVE-2023-53178}
- mm: fix zswap writeback race condition (Jose Guisado) [RHEL-116237] {CVE-2023-53178}
- iomap: iomap: fix memory corruption when recording errors during writeback (John Pittman) [RHEL-119654] {CVE-2022-50406}
- Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp (CKI Backport Bot) [RHEL-118474] {CVE-2023-53297}
- ext4: fix undefined behavior in bit shift for ext4_check_flag_values (Malaya Kumar Rout) [RHEL-117588] {CVE-2022-50403}
- net: sched: sfb: fix null pointer access issue when sfb_init() fails (Xiubo Li) [RHEL-116606] {CVE-2022-50356}
- tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect(). (Xiubo Li) [RHEL-120659] {CVE-2025-39955}
- ALSA: usb-audio: Validate UAC3 power domain descriptors, too (Xiubo Li) [RHEL-114679 RHEL-116019] {CVE-2025-38729 CVE-2025-39757}
- ALSA: usb-audio: Fix size validation in convert_chmap_v3() (Xiubo Li) [RHEL-114679] {CVE-2025-39757}
- ALSA: usb-audio: Validate UAC3 cluster segment descriptors (Xiubo Li) [RHEL-114679] {CVE-2025-39757}
- scsi: qla2xxx: Wait for io return on terminate rport (John Pittman) [RHEL-124590] {CVE-2023-53322}
- Bluetooth: prefetch channel before killing sock (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: L2CAP: Fix user-after-free (Rishikesh Oak) [RHEL-117366] {CVE-2022-50386}
- Bluetooth: L2CAP: Fix use-after-free (Rishikesh Oak) [RHEL-116274] {CVE-2023-53305}
- Bluetooth: Fix l2cap_disconnect_req deadlock (Rishikesh Oak) [RHEL-116274]
- Bluetooth: L2CAP: Fix use-after-free in l2cap_disconnect_{req,rsp} (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: Fix refcount use-after-free issue (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: Check state in l2cap_disconnect_rsp (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: L2CAP: Fix build errors in some archs (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm regression (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: L2CAP: fix use-after-free in l2cap_conn_del() (Rishikesh Oak) [RHEL-116274] {CVE-2022-49909 CVE-2022-3640}
- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_chan_put (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: use the correct print format for L2CAP debug statements (Rishikesh Oak) [RHEL-116274]
- i40e: fix Jumbo Frame support after iPXE boot (Mohammad Heib) [RHEL-97623]
- i40e: Report MFS in decimal base instead of hex (Mohammad Heib) [RHEL-97623]
- i40e: Fix unexpected MFS warning message (Mohammad Heib) [RHEL-97623]
- i40e: Add a check to see if MFS is set (Mohammad Heib) [RHEL-97623]
- bitfield: Add FIELD_MODIFY() helper (Mohammad Heib) [RHEL-97623]
- bitops: Add non-atomic bitops for pointers [partial] (Mohammad Heib) [RHEL-97623]
- wifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit() (Xiubo Li) [RHEL-117940] {CVE-2022-50408}
- cifs: Remove duplicated include in cifsglob.h (Xiubo Li) [RHEL-118059]
- cifs: fix oops during encryption (Xiubo Li) [RHEL-118059] {CVE-2022-50341}
- SMB3: Kernel oops mounting a encryptData share with CONFIG_DEBUG_VIRTUAL (Xiubo Li) [RHEL-118059]
- fix smb3-encryption breakage when CONFIG_DEBUG_SG=y (Xiubo Li) [RHEL-118059]
- sctp: linearize cloned gso packets in sctp_rcv (Xiubo Li) [RHEL-113345] {CVE-2025-38718}
- ip6mr: Fix skb_under_panic in ip6mr_cache_report() (Marc Milgram) [RHEL-118006] {CVE-2023-53365}

kernel-headers-3.10.0-1160.144.1.el7.x86_64.rpm - NFSD: Protect against send buffer overflow in NFSv2 READ (Roberto Bergantinos Corpas) [RHEL-116843] {CVE-2022-50410}
- fs: fix UAF/GPF bug in nilfs_mdt_destroy (Xiubo Li) [RHEL-116655] {CVE-2022-50367}
- mm: zswap: fix missing folio cleanup in writeback race path (Jose Guisado) [RHEL-116237] {CVE-2023-53178}
- mm: fix zswap writeback race condition (Jose Guisado) [RHEL-116237] {CVE-2023-53178}
- iomap: iomap: fix memory corruption when recording errors during writeback (John Pittman) [RHEL-119654] {CVE-2022-50406}
- Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp (CKI Backport Bot) [RHEL-118474] {CVE-2023-53297}
- ext4: fix undefined behavior in bit shift for ext4_check_flag_values (Malaya Kumar Rout) [RHEL-117588] {CVE-2022-50403}
- net: sched: sfb: fix null pointer access issue when sfb_init() fails (Xiubo Li) [RHEL-116606] {CVE-2022-50356}
- tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect(). (Xiubo Li) [RHEL-120659] {CVE-2025-39955}
- ALSA: usb-audio: Validate UAC3 power domain descriptors, too (Xiubo Li) [RHEL-114679 RHEL-116019] {CVE-2025-38729 CVE-2025-39757}
- ALSA: usb-audio: Fix size validation in convert_chmap_v3() (Xiubo Li) [RHEL-114679] {CVE-2025-39757}
- ALSA: usb-audio: Validate UAC3 cluster segment descriptors (Xiubo Li) [RHEL-114679] {CVE-2025-39757}
- scsi: qla2xxx: Wait for io return on terminate rport (John Pittman) [RHEL-124590] {CVE-2023-53322}
- Bluetooth: prefetch channel before killing sock (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: L2CAP: Fix user-after-free (Rishikesh Oak) [RHEL-117366] {CVE-2022-50386}
- Bluetooth: L2CAP: Fix use-after-free (Rishikesh Oak) [RHEL-116274] {CVE-2023-53305}
- Bluetooth: Fix l2cap_disconnect_req deadlock (Rishikesh Oak) [RHEL-116274]
- Bluetooth: L2CAP: Fix use-after-free in l2cap_disconnect_{req,rsp} (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: Fix refcount use-after-free issue (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: Check state in l2cap_disconnect_rsp (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: L2CAP: Fix build errors in some archs (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm regression (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: L2CAP: fix use-after-free in l2cap_conn_del() (Rishikesh Oak) [RHEL-116274] {CVE-2022-49909 CVE-2022-3640}
- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_chan_put (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: use the correct print format for L2CAP debug statements (Rishikesh Oak) [RHEL-116274]
- i40e: fix Jumbo Frame support after iPXE boot (Mohammad Heib) [RHEL-97623]
- i40e: Report MFS in decimal base instead of hex (Mohammad Heib) [RHEL-97623]
- i40e: Fix unexpected MFS warning message (Mohammad Heib) [RHEL-97623]
- i40e: Add a check to see if MFS is set (Mohammad Heib) [RHEL-97623]
- bitfield: Add FIELD_MODIFY() helper (Mohammad Heib) [RHEL-97623]
- bitops: Add non-atomic bitops for pointers [partial] (Mohammad Heib) [RHEL-97623]
- wifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit() (Xiubo Li) [RHEL-117940] {CVE-2022-50408}
- cifs: Remove duplicated include in cifsglob.h (Xiubo Li) [RHEL-118059]
- cifs: fix oops during encryption (Xiubo Li) [RHEL-118059] {CVE-2022-50341}
- SMB3: Kernel oops mounting a encryptData share with CONFIG_DEBUG_VIRTUAL (Xiubo Li) [RHEL-118059]
- fix smb3-encryption breakage when CONFIG_DEBUG_SG=y (Xiubo Li) [RHEL-118059]
- sctp: linearize cloned gso packets in sctp_rcv (Xiubo Li) [RHEL-113345] {CVE-2025-38718}
- ip6mr: Fix skb_under_panic in ip6mr_cache_report() (Marc Milgram) [RHEL-118006] {CVE-2023-53365}

libpng-1.5.13-8.el7_9.1.x86_64.rpm - Fix a buffer overflow in png_init_read_transformations (CVE-2025-64720)

libpng-devel-1.5.13-8.el7_9.1.x86_64.rpm - Fix a buffer overflow in png_init_read_transformations (CVE-2025-64720)

mariadb-libs-5.5.68-1.el7_9.1.x86_64.rpm - Fixes CVE-2025-13699
Resolves: RHEL-132062

mod_ssl-2.4.6-99.el7_9.7.x86_64.rpm - Fix CVE-2025-58098- httpd: Apache HTTP Server: Server Side Includes adds
query string to #exec cmd=...

perl-5.16.3-299.el7_9.1.x86_64.rpm - Fix CVE-2023-31484 - perl: CPAN.pm does not verify TLS certificates
when downloading distributions over HTTPS

perl-Pod-Escapes-1.04-299.el7_9.1.noarch.rpm - Fix CVE-2023-31484 - perl: CPAN.pm does not verify TLS certificates
when downloading distributions over HTTPS

perl-libs-5.16.3-299.el7_9.1.x86_64.rpm - Fix CVE-2023-31484 - perl: CPAN.pm does not verify TLS certificates
when downloading distributions over HTTPS

perl-macros-5.16.3-299.el7_9.1.x86_64.rpm - Fix CVE-2023-31484 - perl: CPAN.pm does not verify TLS certificates
when downloading distributions over HTTPS

python-perf-3.10.0-1160.144.1.el7.x86_64.rpm - NFSD: Protect against send buffer overflow in NFSv2 READ (Roberto Bergantinos Corpas) [RHEL-116843] {CVE-2022-50410}
- fs: fix UAF/GPF bug in nilfs_mdt_destroy (Xiubo Li) [RHEL-116655] {CVE-2022-50367}
- mm: zswap: fix missing folio cleanup in writeback race path (Jose Guisado) [RHEL-116237] {CVE-2023-53178}
- mm: fix zswap writeback race condition (Jose Guisado) [RHEL-116237] {CVE-2023-53178}
- iomap: iomap: fix memory corruption when recording errors during writeback (John Pittman) [RHEL-119654] {CVE-2022-50406}
- Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp (CKI Backport Bot) [RHEL-118474] {CVE-2023-53297}
- ext4: fix undefined behavior in bit shift for ext4_check_flag_values (Malaya Kumar Rout) [RHEL-117588] {CVE-2022-50403}
- net: sched: sfb: fix null pointer access issue when sfb_init() fails (Xiubo Li) [RHEL-116606] {CVE-2022-50356}
- tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect(). (Xiubo Li) [RHEL-120659] {CVE-2025-39955}
- ALSA: usb-audio: Validate UAC3 power domain descriptors, too (Xiubo Li) [RHEL-114679 RHEL-116019] {CVE-2025-38729 CVE-2025-39757}
- ALSA: usb-audio: Fix size validation in convert_chmap_v3() (Xiubo Li) [RHEL-114679] {CVE-2025-39757}
- ALSA: usb-audio: Validate UAC3 cluster segment descriptors (Xiubo Li) [RHEL-114679] {CVE-2025-39757}
- scsi: qla2xxx: Wait for io return on terminate rport (John Pittman) [RHEL-124590] {CVE-2023-53322}
- Bluetooth: prefetch channel before killing sock (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: L2CAP: Fix user-after-free (Rishikesh Oak) [RHEL-117366] {CVE-2022-50386}
- Bluetooth: L2CAP: Fix use-after-free (Rishikesh Oak) [RHEL-116274] {CVE-2023-53305}
- Bluetooth: Fix l2cap_disconnect_req deadlock (Rishikesh Oak) [RHEL-116274]
- Bluetooth: L2CAP: Fix use-after-free in l2cap_disconnect_{req,rsp} (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: Fix refcount use-after-free issue (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: Check state in l2cap_disconnect_rsp (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: L2CAP: Fix build errors in some archs (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm regression (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: L2CAP: fix use-after-free in l2cap_conn_del() (Rishikesh Oak) [RHEL-116274] {CVE-2022-49909 CVE-2022-3640}
- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_chan_put (Rishikesh Oak) [RHEL-116274] {CVE-2022-3640}
- Bluetooth: use the correct print format for L2CAP debug statements (Rishikesh Oak) [RHEL-116274]
- i40e: fix Jumbo Frame support after iPXE boot (Mohammad Heib) [RHEL-97623]
- i40e: Report MFS in decimal base instead of hex (Mohammad Heib) [RHEL-97623]
- i40e: Fix unexpected MFS warning message (Mohammad Heib) [RHEL-97623]
- i40e: Add a check to see if MFS is set (Mohammad Heib) [RHEL-97623]
- bitfield: Add FIELD_MODIFY() helper (Mohammad Heib) [RHEL-97623]
- bitops: Add non-atomic bitops for pointers [partial] (Mohammad Heib) [RHEL-97623]
- wifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit() (Xiubo Li) [RHEL-117940] {CVE-2022-50408}
- cifs: Remove duplicated include in cifsglob.h (Xiubo Li) [RHEL-118059]
- cifs: fix oops during encryption (Xiubo Li) [RHEL-118059] {CVE-2022-50341}
- SMB3: Kernel oops mounting a encryptData share with CONFIG_DEBUG_VIRTUAL (Xiubo Li) [RHEL-118059]
- fix smb3-encryption breakage when CONFIG_DEBUG_SG=y (Xiubo Li) [RHEL-118059]
- sctp: linearize cloned gso packets in sctp_rcv (Xiubo Li) [RHEL-113345] {CVE-2025-38718}
- ip6mr: Fix skb_under_panic in ip6mr_cache_report() (Marc Milgram) [RHEL-118006] {CVE-2023-53365}

python2-ipaclient-4.6.8-5.el7_9.24.noarch.rpm - IPA stops working if HTTP/... service principal was created before FreeIPA 4.4.0 and never modified
Resolves: RHEL-124602

python2-ipalib-4.6.8-5.el7_9.24.noarch.rpm - IPA stops working if HTTP/... service principal was created before FreeIPA 4.4.0 and never modified
Resolves: RHEL-124602

rsync-3.1.2-12.el7_9.2.x86_64.rpm - Path traversal vulnerability in rsync (CVE-2024-12087)

tzdata-2025c-1.el7.noarch.rpm - Update to tzdata-2025c (RHEL-135218)
- Update leap seconds file expiration date.
- Included NEWS file with docs.

tzdata-java-2025c-1.el7.noarch.rpm - Update to tzdata-2025c (RHEL-135218)
- Update leap seconds file expiration date.
- Included NEWS file with docs.

×

Loading...