{"schema_version": "1.7.0", "id": "RLSA-2026:75747", "modified": "2026-10-06T06:15:07.487121Z", "published": "2026-10-06T06:01:13.392384Z", "upstream": ["CVE-2022-50756", "CVE-2023-54048", "CVE-2025-39994", "CVE-2025-40242", "CVE-2026-23105", "CVE-2026-45856", "CVE-2026-45861", "CVE-2026-46319", "CVE-2026-52972", "CVE-2026-53049", "CVE-2026-53230", "CVE-2026-53270", "CVE-2026-63794", "CVE-2026-63829", "CVE-2026-63992", "CVE-2026-63994", "CVE-2026-68432", "CVE-2026-72052", "CVE-2026-72255", "CVE-2026-74516", "CVE-2026-74569", "CVE-2026-74669", "CVE-2026-74744", "CVE-2026-74746", "CVE-2026-80921", "CVE-2026-89481", "CVE-2026-89972", "CVE-2026-90227", "CVE-2026-97417"], "summary": "Important: kernel security, bug fix, and enhancement update", "details": "The kernel packages contain the Linux kernel, the core of any Linux operating system.\n\nSecurity Fix(es):\n\n* kernel: Linux kernel: Use-after-free in xc5000 tuner driver due to race condition (CVE-2025-39994)\n\n* kernel: gfs2: Fix unlikely race in gdlm_put_lock (CVE-2025-40242)\n\n* kernel: Linux kernel: Denial of Service in RDMA/bnxt_re driver due to race condition during QP destruction (CVE-2023-54048)\n\n* kernel: nvme-pci: fix mempool alloc size (CVE-2022-50756)\n\n* kernel: Linux kernel: Denial of Service in QFQ scheduler via child qlen manipulation (CVE-2026-23105)\n\n* kernel: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856)\n\n* kernel: gfs2: Fix slab-use-after-free in qd_put (CVE-2026-45861)\n\n* kernel: net/sched: act_ct: Only release RCU read lock after ct_ft (CVE-2026-46319)\n\n* kernel: gfs2: add some missing log locking (CVE-2026-53049)\n\n* kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 (CVE-2026-52972)\n\n* kernel: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (CVE-2026-53230)\n\n* kernel: ipvs: clear the svc scheduler ptr early on edit (CVE-2026-53270)\n\n* kernel: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-63829)\n\n* kernel: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (CVE-2026-63794)\n\n* kernel: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (CVE-2026-63992)\n\n* kernel: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() (CVE-2026-63994)\n\n* kernel: vxlan: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-68432)\n\n* kernel: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-72052)\n\n* kernel: netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst (CVE-2026-72255)\n\n* kernel: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (CVE-2026-74516)\n\n* kernel: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (CVE-2026-74569)\n\n* kernel: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (CVE-2026-74669)\n\n* kernel: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev (CVE-2026-74744)\n\n* kernel: netfilter: flowtable: publish GC-visible tuple last (CVE-2026-74746)\n\n* kernel: KVM: s390: vsie: zero stale crypto bits (CVE-2026-80921)\n\n* kernel: nvme-tcp: fix host memory disclosure on R2T for a read command (CVE-2026-89481)\n\n* kernel: nvme: add missing SRCU grace period in error path (CVE-2026-89972)\n\n* kernel: nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() (CVE-2026-90227)\n\n* kernel: netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() (CVE-2026-97417)\n\nBug Fix(es) and Enhancement(s):\n\n* Rocky Linux8.10 - s390/vfio_ccw: Error path cleanups (JIRA:Rocky Linux-252194)\n\n* Rocky Linux8.10 - s390/topology: Use zero-based numbering (JIRA:Rocky Linux-252199)\n\n* [nfs rhel8.10] Disable async copy on nfsd side (JIRA:Rocky Linux-266661)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "severity": [{"type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}], "affected": [{"package": {"ecosystem": "Rocky Linux:8", "name": "kernel", "purl": "pkg:rpm/rocky-linux/kernel?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:4.18.0-553.171.1.el8_10"}], "database_specific": {"yum_repository": "BaseOS"}}]}], "references": [{"type": "ADVISORY", "url": "https://errata.rockylinux.org/RLSA-2026:75747"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2404123"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2418819"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2425013"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2425209"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2436789"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482129"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482143"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2486979"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492276"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492364"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492728"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492853"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502230"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502241"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502431"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2502444"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2514441"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2516306"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2516717"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2516998"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517052"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2521375"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2524431"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2524483"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2531066"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2532184"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2535140"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2536346"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2540479"}, {"type": "ADVISORY", "url": "https://access.redhat.com/errata/RHSA-2026:75747"}], "credits": [{"name": "Rocky Enterprise Software Foundation"}, {"name": "Red Hat"}], "database_specific": {"license": "CC-BY-4.0", "license_url": "https://creativecommons.org/licenses/by/4.0/", "source_advisory": "RHSA-2026:75747"}}