RLSA-2026:65334
Dashboard / Vulnerabilities / RLSA-2026:65334
RLSA-2026:65334
Summary: Important: kernel security, bug fix, and enhancement update
Details: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133) * kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334) * kernel: Bluetooth: virtio_bt: clamp rx length before skb_put (CVE-2026-46123) * kernel: Bluetooth: serialize accept_q access (CVE-2026-52918) * kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091) * kernel: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CVE-2026-53072) * kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (CVE-2026-52947) * kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256) * kernel: wifi: nl80211: reject oversized EMA RNR lists (CVE-2026-53182) * kernel: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CVE-2026-53209) * kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254) * kernel: vfio/pci: Clean up DMABUFs before disabling function (CVE-2026-53322) * kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975) * kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015) * kernel: Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CVE-2026-63947) * kernel: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CVE-2026-63944) * kernel: Bluetooth: ISO: fix UAF in iso_recv_frame (CVE-2026-63946) * kernel: wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb (CVE-2026-64117) * kernel: wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (CVE-2026-64037) * kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning (CVE-2026-64113) * kernel: vfio/pci: Check BAR resources before exporting a DMABUF (CVE-2026-64042) * kernel: accel/qaic: Add overflow check to remap_pfn_range during mmap (CVE-2026-64051) * kernel: wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (CVE-2026-64255) * kernel: wifi: mac80211: fix MLE defragmentation (CVE-2026-64515) * kernel: wifi: mac80211: defer link RX stats percpu free to RCU (CVE-2026-68409) * kernel: wifi: mt76: mt7925: fix crash in reset link replay (CVE-2026-68307) * kernel: wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (CVE-2026-68193) * kernel: dm-verity: fix buffer overflow in FEC calculation (CVE-2026-72098) * kernel: nvmet-rdma: handle inline data with a nonzero offset (CVE-2026-72129) Bug Fix(es) and Enhancement(s): * rtla-timerlat-top doesn't stop properly when threshold is reached on multiple CPUs at once [rhel-10.2.z] (JIRA:Rocky Linux-193027) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://errata.rockylinux.org/RLSA-2026:65334, https://bugzilla.redhat.com/show_bug.cgi?id=2492717, https://bugzilla.redhat.com/show_bug.cgi?id=2502541, https://bugzilla.redhat.com/show_bug.cgi?id=2502388, https://bugzilla.redhat.com/show_bug.cgi?id=2516501, https://bugzilla.redhat.com/show_bug.cgi?id=2492432, https://bugzilla.redhat.com/show_bug.cgi?id=2467065, https://bugzilla.redhat.com/show_bug.cgi?id=2506782, https://bugzilla.redhat.com/show_bug.cgi?id=2492092, https://bugzilla.redhat.com/show_bug.cgi?id=2502446, https://bugzilla.redhat.com/show_bug.cgi?id=2502547, https://bugzilla.redhat.com/show_bug.cgi?id=2516731, https://bugzilla.redhat.com/show_bug.cgi?id=2493709, https://bugzilla.redhat.com/show_bug.cgi?id=2507292, https://bugzilla.redhat.com/show_bug.cgi?id=2468050, https://bugzilla.redhat.com/show_bug.cgi?id=2502477, https://bugzilla.redhat.com/show_bug.cgi?id=2492270, https://bugzilla.redhat.com/show_bug.cgi?id=2482554, https://bugzilla.redhat.com/show_bug.cgi?id=2502346, https://bugzilla.redhat.com/show_bug.cgi?id=2513299, https://bugzilla.redhat.com/show_bug.cgi?id=2492408, https://bugzilla.redhat.com/show_bug.cgi?id=2513342, https://bugzilla.redhat.com/show_bug.cgi?id=2502518, https://bugzilla.redhat.com/show_bug.cgi?id=2492722, https://bugzilla.redhat.com/show_bug.cgi?id=2502413, https://bugzilla.redhat.com/show_bug.cgi?id=2502613, https://bugzilla.redhat.com/show_bug.cgi?id=2502380, https://bugzilla.redhat.com/show_bug.cgi?id=2492762, https://bugzilla.redhat.com/show_bug.cgi?id=2492795, https://bugzilla.redhat.com/show_bug.cgi?id=2513386, https://access.redhat.com/errata/RHSA-2026:65334
Affected packages
Package
Name: kernel
Purl: pkg:rpm/rocky-linux/kernel?distro=rocky-linux-10&epoch=0
Affected ranges
Type: ECOSYSTEM
Events:
