Issued at: 2026-07-23
Updated at: 2026-07-23
Synopsis
Important: kernel security, bug fix, and enhancement update
Description
The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
* kernel: crypto: af_alg - zero initialize memory allocated via sock_kmalloc (CVE-2025-71113)
* kernel: scsi: core: Wake up the error handler when final completions race against each other (CVE-2026-23110)
* kernel: Linux kernel: xfrm single-frag length not properly limited ()
* kernel: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (CVE-2026-46099)
* kernel: fanotify: fix false positive on permission events (CVE-2026-46150)
* kernel: drm: Set old handle to NULL before prime swap in change_handle (CVE-2026-46215)
* kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071)
* kernel: can: bcm: thrtimer use-after-free during RX operation teardown ()
Bug Fix(es) and Enhancement(s):
* [Rocky Linux9] tools/lib/perf/Makefile: libperf includes appended after CFLAGS causes parallel build race, breaking kernel builds [rhel-9.8.z] (JIRA:Rocky Linux-183980)
* [Rocky Linux-9.8.z]: mlx5: include bug fixes (JIRA:Rocky Linux-188121)
* dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() [rhel-9.8.z] (JIRA:Rocky Linux-212061)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.