RLSA-2026:63014

    Dashboard / Vulnerabilities / RLSA-2026:63014

    RLSA-2026:63014

    Published: 4 Sept 2026Last Modified: 4 Sept 2026

    Summary: Important: kernel security, bug fix, and enhancement update

    Details: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: s390/cpum_sf: Handle CPU hotplug remove during sampling (CVE-2024-57849) * kernel: smc91x: fix broken irq-context in PREEMPT_RT (CVE-2025-71132) * kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970) * kernel: zram: fix use-after-free in zram_bvec_write_partial() (CVE-2026-53185) * kernel: pNFS: Fix use-after-free in pnfs_update_layout() (CVE-2026-63800) * kernel: nfsd: fix posix_acl leak on SETACL decode failure (CVE-2026-53397) * kernel: nfsd: release layout stid on setlease failure (CVE-2026-53399) * kernel: NFSv4/flexfiles: reject zero filehandle version count (CVE-2026-53392) * kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (CVE-2026-53391) * kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access (CVE-2026-64018) * kernel: Kernel: Remote out-of-bounds write in RDMA/siw (CVE-2026-64268) * kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (CVE-2026-64298) * kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability (CVE-2026-68480) * kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res->rt6 pointer (CVE-2026-74581) Bug Fix(es) and Enhancement(s): * qede: build_skb failure causes off-by-one BD ring corruption and kernel panic [rhel-8.10.z] (JIRA:Rocky Linux-193045) * powerpc/pseries: lparcfg - fix kbuf[] underflow (JIRA:Rocky Linux-240144) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

    Affected packages

    Package

    Name: kernel

    Purl: pkg:rpm/rocky-linux/kernel?distro=rocky-linux-8&epoch=0

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0:4.18.0-553.159.1.el8_10

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High