RLSA-2026:64808
Dashboard / Vulnerabilities / RLSA-2026:64808
RLSA-2026:64808
Summary: Important: kernel security update
Details: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: can: bcm: add locking for bcm_op runtime updates (CVE-2025-38004) * kernel: io_uring/poll: fix signed comparison in io_poll_get_ownership() (CVE-2026-52933) * kernel: netfilter: nat: use kfree_rcu to release ops (CVE-2026-53000) * kernel: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (CVE-2026-64136) * kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (CVE-2026-64320) * kernel: nvmet-auth: validate reply message payload bounds against transfer length (CVE-2026-64319) * kernel: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (CVE-2026-64287) * kernel: smb: client: fix change notify replay double-free (CVE-2026-64384) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://errata.rockylinux.org/RLSA-2026:64808, https://bugzilla.redhat.com/show_bug.cgi?id=2370992, https://bugzilla.redhat.com/show_bug.cgi?id=2492097, https://bugzilla.redhat.com/show_bug.cgi?id=2492273, https://bugzilla.redhat.com/show_bug.cgi?id=2502527, https://bugzilla.redhat.com/show_bug.cgi?id=2507061, https://bugzilla.redhat.com/show_bug.cgi?id=2507096, https://bugzilla.redhat.com/show_bug.cgi?id=2507129, https://bugzilla.redhat.com/show_bug.cgi?id=2507287, https://access.redhat.com/errata/RHSA-2026:64808
Affected packages
Package
Name: kernel
Purl: pkg:rpm/rocky-linux/kernel?distro=rocky-linux-9&epoch=0
Affected ranges
Type: ECOSYSTEM
Events:
