{"schema_version": "1.7.0", "id": "RLSA-2026:36018", "modified": "2026-07-11T12:07:06.777758Z", "published": "2026-07-11T12:03:26.258635Z", "upstream": ["CVE-2025-10263", "CVE-2026-43112", "CVE-2026-43276", "CVE-2026-46116", "CVE-2026-46155", "CVE-2026-46209", "CVE-2026-46227", "CVE-2026-46244", "CVE-2026-46259", "CVE-2026-46316", "CVE-2026-46323"], "summary": "Important: kernel security, bug fix, and enhancement update", "details": "The kernel packages contain the Linux kernel, the core of any Linux operating system.\n\nSecurity Fix(es):\n\n* kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112)\n\n* kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276)\n\n* kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323)\n\n* kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)\n\n* kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227)\n\n* kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209)\n\n* kernel: smb/client: fix out-of-bounds read in smb2_compound_op() (CVE-2026-46155)\n\n* kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244)\n\n* kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259)\n\n* kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263)\n\n* kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316)\n\nBug Fix(es) and Enhancement(s):\n\n* WARNING at drivers/gpu/drm/nouveau/nvkm/subdev/gsp/r535.c:1585 r535_gsp_fini+0x2fb/0x310 [nouveau] [rhel-9.8.z] (JIRA:Rocky Linux-160966)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "severity": [{"type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}], "affected": [{"package": {"ecosystem": "Rocky Linux:9", "name": "kernel", "purl": "pkg:rpm/rocky-linux/kernel?distro=rocky-linux-9&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:5.14.0-687.22.1.el9_8"}], "database_specific": {"yum_repository": "BaseOS"}}]}], "references": [{"type": "ADVISORY", "url": "https://errata.rockylinux.org/RLSA-2026:36018"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467015"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467113"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2479832"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482523"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482564"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482636"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482660"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484451"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484477"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486958"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486982"}], "credits": [{"name": "Rocky Enterprise Software Foundation"}, {"name": "Red Hat"}]}