Summary
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
This disclosure rolls up all CVEs included in USN-7455-1:
CVE-2022-0995
CVE-2024-26837
CVE-2024-46826
CVE-2024-50248
CVE-2024-50256
CVE-2024-56651
CVE-2025-21700
CVE-2025-21701
CVE-2025-21702
CVE-2025-21703
CVE-2025-21756
CVE-2025-21993
Products Potentially Affected
OS/Product
|
Exposure
|
ExtremeAnalytics for Site Engine
|
Yes
|
ExtremeCloud IQ - Site Engine (XIQ-SE)
|
Yes
|
ExtremeControl for Site Engine
|
Yes
|
Repair Recommendations
ExtremeAnalytics for Site Engine:
- Fixed in 25.5.10 or later.
ExtremeCloud IQ - Site Engine (XIQ-SE):
- Fixed in 25.5.10 or later.
ExtremeControl for Site Engine:
- Fixed in 25.5.10 or later
Please see the full security advisory article here for more details and future updates.