Issued at: 2026-07-27
Updated at: 2026-07-28
Synopsis
Important: kernel security, bug fix, and enhancement update
Description
The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
* kernel: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (CVE-2025-40026)
* kernel: dm log: fix out-of-bounds write due to region_count overflow (CVE-2026-53059)
* kernel: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (CVE-2026-52976)
* kernel: drm/xe/dma-buf: fix UAF with retry loop (CVE-2026-52950)
* kernel: ipv6: fix possible UAF in icmpv6_rcv() (CVE-2026-53006)
Bug Fix(es) and Enhancement(s):
* scsi device removal may hang from race with error recovery [rhel-9.8.z] (JIRA:Rocky Linux SIG Cloud-187412)
* [Rocky Linux SIG Cloud9] kvm fixes for 2026-07-21 [rhel-9.8.z] (JIRA:Rocky Linux SIG Cloud-213468)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.