{"schema_version": "1.7.0", "id": "RLSA-2026:67471", "modified": "2026-09-16T12:14:02.222300Z", "published": "2026-09-16T12:09:37.746677Z", "upstream": ["CVE-2025-40149", "CVE-2025-68745", "CVE-2026-23466", "CVE-2026-31479", "CVE-2026-31539", "CVE-2026-31566", "CVE-2026-31656", "CVE-2026-31663", "CVE-2026-43248", "CVE-2026-43368", "CVE-2026-43370", "CVE-2026-46149", "CVE-2026-52924", "CVE-2026-53131", "CVE-2026-53239", "CVE-2026-53246", "CVE-2026-53361", "CVE-2026-63889", "CVE-2026-63917", "CVE-2026-63919", "CVE-2026-63921", "CVE-2026-64111", "CVE-2026-68264", "CVE-2026-68426", "CVE-2026-74556"], "summary": "Important: kernel security, bug fix, and enhancement update", "details": "The kernel packages contain the Linux kernel, the core of any Linux operating system.\n\nSecurity Fix(es):\n\n* kernel: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock() (CVE-2025-40149)\n\n* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)\n\n* kernel: drm/xe: Open-code GGTT MMIO access protection (CVE-2026-23466)\n\n* kernel: drm/xe: always keep track of remap prev/next (CVE-2026-31479)\n\n* kernel: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CVE-2026-31566)\n\n* kernel: xfrm: hold dev ref until after transport_finish NF_HOOK (CVE-2026-31663)\n\n* kernel: drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (CVE-2026-31656)\n\n* kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available (CVE-2026-31539)\n\n* kernel: vhost: move vdpa group bound check to vhost_vdpa (CVE-2026-43248)\n\n* kernel: drm/i915: Fix potential overflow of shmem scatterlist length (CVE-2026-43368)\n\n* kernel: drm/amdgpu: Fix use-after-free race in VM acquire (CVE-2026-43370)\n\n* kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)\n\n* kernel: sctp: purge outqueue on stale COOKIE-ECHO handling (CVE-2026-52924)\n\n* kernel: netfilter: require Ethernet MAC header before using eth_hdr() (CVE-2026-53131)\n\n* kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)\n\n* kernel: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (CVE-2026-53239)\n\n* kernel: af_unix: Set gc_in_progress to true in unix_gc() (CVE-2026-53361)\n\n* kernel: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (CVE-2026-63889)\n\n* kernel: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (CVE-2026-63921)\n\n* kernel: xfrm: input: hold netns during deferred transport reinjection (CVE-2026-63919)\n\n* kernel: ip6: vti: Use ip6_tnl.net in vti6_changelink() (CVE-2026-63917)\n\n* kernel: lsm: hold cred_guard_mutex for lsm_set_self_attr() (CVE-2026-64111)\n\n* kernel: drm/xe/pt: Reset current_op in xe_pt_update_ops_init() (CVE-2026-68264)\n\n* kernel: xfrm: fix stale skb->prev after async crypto steals a GSO segment (CVE-2026-68426)\n\n* kernel: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (CVE-2026-74556)\n\nBug Fix(es) and Enhancement(s):\n\n* [rhel-10.2.z]- Backport MSHV patches for hypervisor OOM handling (JIRA:Rocky Linux-245035)\n\n* RHIVOS - [backport] S32G Driver Enablement - ADC (JIRA:Rocky Linux-255233)\n\n* [Rocky Linux10.2z] watchdog: System can panic during reboot when pretimeout is disabled (0) (JIRA:Rocky Linux-255348)\n\n* [usb/xhci] kdump on Arrow Lake systems hangs system with dracut-initqueue Timed out errors [Rocky Linux-10.2.z] (JIRA:Rocky Linux-256731)\n\n* RHIVOS - [backport] S32G Driver Update - ADC, I2C, and eDMA (JIRA:Rocky Linux-256890)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "severity": [{"type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}], "affected": [{"package": {"ecosystem": "Rocky Linux:10", "name": "kernel", "purl": "pkg:rpm/rocky-linux/kernel?distro=rocky-linux-10&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:6.12.0-211.55.1.el10_2"}], "database_specific": {"yum_repository": "BaseOS"}}]}], "references": [{"type": "ADVISORY", "url": "https://errata.rockylinux.org/RLSA-2026:67471"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2414466"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2425039"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2454867"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460699"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461451"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461462"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461525"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2461575"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467084"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468192"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468244"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482566"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492095"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492747"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492771"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492779"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497035"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502320"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502368"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502412"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502434"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502490"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2513452"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2513477"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517010"}, {"type": "ADVISORY", "url": "https://access.redhat.com/errata/RHSA-2026:67471"}], "credits": [{"name": "Rocky Enterprise Software Foundation"}, {"name": "Red Hat"}], "database_specific": {"license": "CC-BY-4.0", "license_url": "https://creativecommons.org/licenses/by/4.0/", "source_advisory": "RHSA-2026:67471"}}