When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested and eventually, SyncInitTrigger() is called. If one of the changes triggers an error, the function will return early, not adding the new sync object. This can be used to cause a use after free when the alarm eventually triggers.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:2500 https://access.redhat.com/errata/RHSA-2025:2500
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:2502 https://access.redhat.com/errata/RHSA-2025:2502
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:2866 https://access.redhat.com/errata/RHSA-2025:2866
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2025:2862 https://access.redhat.com/errata/RHSA-2025:2862
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:2861 https://access.redhat.com/errata/RHSA-2025:2861
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Via RHSA-2025:2865 https://access.redhat.com/errata/RHSA-2025:2865
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:2873 https://access.redhat.com/errata/RHSA-2025:2873
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:2875 https://access.redhat.com/errata/RHSA-2025:2875
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2025:2874 https://access.redhat.com/errata/RHSA-2025:2874
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:2879 https://access.redhat.com/errata/RHSA-2025:2879
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:2880 https://access.redhat.com/errata/RHSA-2025:2880
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION Via RHSA-2025:3976 https://access.redhat.com/errata/RHSA-2025:3976