RLSA-2026:63128
Dashboard / Vulnerabilities / RLSA-2026:63128
RLSA-2026:63128
Summary: Important: kernel security update
Details: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error (CVE-2026-53073) * kernel: exfat: fix potential use-after-free in exfat_find_dir_entry() (CVE-2026-63808) * kernel: KEYS: fix overflow in keyctl_pkey_params_get_2() (CVE-2026-63824) * kernel: smb: client: fix query directory replay double-free (CVE-2026-64387) * kernel: iomap: fix out-of-bounds bitmap_set() with zero-length range (CVE-2026-68145) * kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res->rt6 pointer (CVE-2026-74581) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://errata.rockylinux.org/RLSA-2026:63128, https://bugzilla.redhat.com/show_bug.cgi?id=2502248, https://bugzilla.redhat.com/show_bug.cgi?id=2502235, https://bugzilla.redhat.com/show_bug.cgi?id=2513392, https://bugzilla.redhat.com/show_bug.cgi?id=2492447, https://bugzilla.redhat.com/show_bug.cgi?id=2520980, https://bugzilla.redhat.com/show_bug.cgi?id=2507046, https://access.redhat.com/errata/RHSA-2026:63128
Affected packages
Package
Name: kernel
Purl: pkg:rpm/rocky-linux/kernel?distro=rocky-linux-10&epoch=0
Affected ranges
Type: ECOSYSTEM
Events:
