{"id":"RLSA-2026:65334","summary":"Important: kernel security, bug fix, and enhancement update","details":"The kernel packages contain the Linux kernel, the core of any Linux operating system.\n\nSecurity Fix(es):\n\n* kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133)\n\n* kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)\n\n* kernel: Bluetooth: virtio_bt: clamp rx length before skb_put (CVE-2026-46123)\n\n* kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)\n\n* kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)\n\n* kernel: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CVE-2026-53072)\n\n* kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (CVE-2026-52947)\n\n* kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)\n\n* kernel: wifi: nl80211: reject oversized EMA RNR lists (CVE-2026-53182)\n\n* kernel: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CVE-2026-53209)\n\n* kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)\n\n* kernel: vfio/pci: Clean up DMABUFs before disabling function (CVE-2026-53322)\n\n* kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)\n\n* kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)\n\n* kernel: Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CVE-2026-63947)\n\n* kernel: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CVE-2026-63944)\n\n* kernel: Bluetooth: ISO: fix UAF in iso_recv_frame (CVE-2026-63946)\n\n* kernel: wifi: mac80211: capture fast-RX rate before mesh reuses skb-\u003ecb (CVE-2026-64117)\n\n* kernel: wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (CVE-2026-64037)\n\n* kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning (CVE-2026-64113)\n\n* kernel: vfio/pci: Check BAR resources before exporting a DMABUF (CVE-2026-64042)\n\n* kernel: accel/qaic: Add overflow check to remap_pfn_range during mmap (CVE-2026-64051)\n\n* kernel: wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (CVE-2026-64255)\n\n* kernel: wifi: mac80211: fix MLE defragmentation (CVE-2026-64515)\n\n* kernel: wifi: mac80211: defer link RX stats percpu free to RCU (CVE-2026-68409)\n\n* kernel: wifi: mt76: mt7925: fix crash in reset link replay (CVE-2026-68307)\n\n* kernel: wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (CVE-2026-68193)\n\n* kernel: dm-verity: fix buffer overflow in FEC calculation (CVE-2026-72098)\n\n* kernel: nvmet-rdma: handle inline data with a nonzero offset (CVE-2026-72129)\n\nBug Fix(es) and Enhancement(s):\n\n* rtla-timerlat-top doesn't stop properly when threshold is reached on multiple CPUs at once [rhel-10.2.z] (JIRA:Rocky Linux-193027)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","modified":"2026-09-10T00:30:02.480986494Z","published":"2026-09-10T00:09:11.134895Z","upstream":["CVE-2026-43133","CVE-2026-43334","CVE-2026-46123","CVE-2026-52918","CVE-2026-52947","CVE-2026-53072","CVE-2026-53091","CVE-2026-53182","CVE-2026-53209","CVE-2026-53254","CVE-2026-53256","CVE-2026-53322","CVE-2026-63944","CVE-2026-63946","CVE-2026-63947","CVE-2026-63975","CVE-2026-64015","CVE-2026-64037","CVE-2026-64042","CVE-2026-64051","CVE-2026-64113","CVE-2026-64117","CVE-2026-64255","CVE-2026-64515","CVE-2026-68193","CVE-2026-68307","CVE-2026-68409","CVE-2026-72098","CVE-2026-72129"],"database_specific":{"license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","source_advisory":"RHSA-2026:65334"},"references":[{"type":"ADVISORY","url":"https://errata.rockylinux.org/RLSA-2026:65334"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492717"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502541"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502388"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2516501"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492432"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2467065"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2506782"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492092"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502446"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502547"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2516731"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493709"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2507292"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2468050"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502477"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492270"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2482554"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502346"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2513299"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492408"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2513342"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502518"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492722"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502413"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502613"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502380"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492762"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492795"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2513386"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:65334"}],"affected":[{"package":{"name":"kernel","ecosystem":"Rocky Linux:10","purl":"pkg:rpm/rocky-linux/kernel?distro=rocky-linux-10&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:6.12.0-211.53.1.el10_2"}],"database_specific":{"yum_repository":"BaseOS"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2026:65334.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"}],"credits":[{"name":"Rocky Enterprise Software Foundation"},{"name":"Red Hat"}]}