ALSA-2026:64808
Dashboard / Vulnerabilities / ALSA-2026:64808
ALSA-2026:64808
Summary: Important: kernel security update
Details: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: can: bcm: add locking for bcm_op runtime updates (CVE-2025-38004) * kernel: io_uring/poll: fix signed comparison in io_poll_get_ownership() (CVE-2026-52933) * kernel: netfilter: nat: use kfree_rcu to release ops (CVE-2026-53000) * kernel: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (CVE-2026-64136) * kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (CVE-2026-64320) * kernel: nvmet-auth: validate reply message payload bounds against transfer length (CVE-2026-64319) * kernel: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (CVE-2026-64287) * kernel: smb: client: fix change notify replay double-free (CVE-2026-64384) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://access.redhat.com/errata/RHSA-2026:64808, https://access.redhat.com/security/cve/CVE-2025-38004, https://access.redhat.com/security/cve/CVE-2026-52933, https://access.redhat.com/security/cve/CVE-2026-53000, https://access.redhat.com/security/cve/CVE-2026-64136, https://access.redhat.com/security/cve/CVE-2026-64287, https://access.redhat.com/security/cve/CVE-2026-64319, https://access.redhat.com/security/cve/CVE-2026-64320, https://access.redhat.com/security/cve/CVE-2026-64384, https://bugzilla.redhat.com/2370992, https://bugzilla.redhat.com/2492097, https://bugzilla.redhat.com/2492273, https://bugzilla.redhat.com/2502527, https://bugzilla.redhat.com/2507061, https://bugzilla.redhat.com/2507096, https://bugzilla.redhat.com/2507129, https://bugzilla.redhat.com/2507287, https://errata.almalinux.org/9/ALSA-2026-64808.html
Affected packages
Package
Name: kernel
Purl: pkg:rpm/almalinux/kernel
Affected ranges
Type: ECOSYSTEM
Events:
