{"schema_version": "1.7.0", "id": "RXSA-2026:45115", "modified": "2026-07-27T18:09:08.699103Z", "published": "2026-07-27T18:08:18.038173Z", "upstream": ["CVE-2025-40026", "CVE-2026-52993", "CVE-2026-53059"], "summary": "Important: kernel security update", "details": "The kernel packages contain the Linux kernel, the core of any Linux operating system.\n\nSecurity Fix(es):\n\n* kernel: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (CVE-2025-40026)\n\n* kernel: xfrm single-frag length not properly limited\n\n* kernel: dm log: fix out-of-bounds write due to region_count overflow (CVE-2026-53059)\n\n* kernel: tipc: fix double-free in tipc_buf_append() (CVE-2026-52993)", "severity": [{"type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}], "affected": [{"package": {"ecosystem": "Rocky Linux:8", "name": "kernel", "purl": "pkg:rpm/rocky-linux/kernel?distro=rocky-linux-8-sig-cloud&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:4.18.0-553.147.1.el8_10.cloud.0.1"}], "database_specific": {"yum_repository": "cloud-kernel"}}]}], "references": [{"type": "ADVISORY", "url": "https://errata.rockylinux.org/RXSA-2026:45115"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2406712"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492277"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492437"}], "credits": [{"name": "Rocky Enterprise Software Foundation"}, {"name": "Red Hat"}]}