RLSA-2026:36018

Source
https://errata.rockylinux.org/RLSA-2026:36018
Import Source
https://storage.googleapis.com/resf-osv-data/RLSA-2026:36018.json
JSON Data
https://api.test.osv.dev/v1/vulns/RLSA-2026:36018
Upstream
  • CVE-2025-10263
  • CVE-2026-46155
Published
2026-07-11T12:03:26.258635Z
Modified
2026-07-11T12:30:05.543922298Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
Important: kernel security, bug fix, and enhancement update
Details

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: fs/smb/client: fix out-of-bounds read in cifssanitizeprepath (CVE-2026-43112)

  • kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276)

  • kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323)

  • kernel: xfrm: defensively unhash xfrm_state lists in __xfrmstatedelete (CVE-2026-46116)

  • kernel: sctp: revalidate list cursor after sctpsendmsgtoasoc() in SCTPSENDALL (CVE-2026-46227)

  • kernel: drm/gem: Fix inconsistent plane dimension calculation in drmgemfbinitwith_funcs() (CVE-2026-46209)

  • kernel: smb/client: fix out-of-bounds read in smb2compoundop() (CVE-2026-46155)

  • kernel: netfilter: nftinner: Fix IPv6 innerthoff desync (CVE-2026-46244)

  • kernel: procfs: fix missing RCU protection when reading realparent in dotask_stat() (CVE-2026-46259)

  • kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263)

  • kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316)

Bug Fix(es) and Enhancement(s):

  • WARNING at drivers/gpu/drm/nouveau/nvkm/subdev/gsp/r535.c:1585 r535gspfini+0x2fb/0x310 [nouveau] [rhel-9.8.z] (JIRA:Rocky Linux-160966)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References
Credits
    • Rocky Enterprise Software Foundation
    • Red Hat

Affected packages

Rocky Linux:9 / kernel

Package

Name
kernel
Purl
pkg:rpm/rocky-linux/kernel?distro=rocky-linux-9&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:5.14.0-687.22.1.el9_8
Database specific
{
    "yum_repository": "BaseOS"
}

Database specific

source
"https://storage.googleapis.com/resf-osv-data/RLSA-2026:36018.json"