{"id":"RLSA-2026:67471","summary":"Important: kernel security, bug fix, and enhancement update","details":"The kernel packages contain the Linux kernel, the core of any Linux operating system.\n\nSecurity Fix(es):\n\n* kernel: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock() (CVE-2025-40149)\n\n* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)\n\n* kernel: drm/xe: Open-code GGTT MMIO access protection (CVE-2026-23466)\n\n* kernel: drm/xe: always keep track of remap prev/next (CVE-2026-31479)\n\n* kernel: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CVE-2026-31566)\n\n* kernel: xfrm: hold dev ref until after transport_finish NF_HOOK (CVE-2026-31663)\n\n* kernel: drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (CVE-2026-31656)\n\n* kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available (CVE-2026-31539)\n\n* kernel: vhost: move vdpa group bound check to vhost_vdpa (CVE-2026-43248)\n\n* kernel: drm/i915: Fix potential overflow of shmem scatterlist length (CVE-2026-43368)\n\n* kernel: drm/amdgpu: Fix use-after-free race in VM acquire (CVE-2026-43370)\n\n* kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)\n\n* kernel: sctp: purge outqueue on stale COOKIE-ECHO handling (CVE-2026-52924)\n\n* kernel: netfilter: require Ethernet MAC header before using eth_hdr() (CVE-2026-53131)\n\n* kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)\n\n* kernel: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (CVE-2026-53239)\n\n* kernel: af_unix: Set gc_in_progress to true in unix_gc() (CVE-2026-53361)\n\n* kernel: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (CVE-2026-63889)\n\n* kernel: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (CVE-2026-63921)\n\n* kernel: xfrm: input: hold netns during deferred transport reinjection (CVE-2026-63919)\n\n* kernel: ip6: vti: Use ip6_tnl.net in vti6_changelink() (CVE-2026-63917)\n\n* kernel: lsm: hold cred_guard_mutex for lsm_set_self_attr() (CVE-2026-64111)\n\n* kernel: drm/xe/pt: Reset current_op in xe_pt_update_ops_init() (CVE-2026-68264)\n\n* kernel: xfrm: fix stale skb-\u003eprev after async crypto steals a GSO segment (CVE-2026-68426)\n\n* kernel: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (CVE-2026-74556)\n\nBug Fix(es) and Enhancement(s):\n\n* [rhel-10.2.z]- Backport MSHV patches for hypervisor OOM handling  (JIRA:Rocky Linux-245035)\n\n* RHIVOS - [backport] S32G Driver Enablement - ADC (JIRA:Rocky Linux-255233)\n\n* [Rocky Linux10.2z] watchdog: System can panic during reboot when pretimeout is disabled (0) (JIRA:Rocky Linux-255348)\n\n* [usb/xhci] kdump on Arrow Lake systems hangs system with dracut-initqueue Timed out errors [Rocky Linux-10.2.z] (JIRA:Rocky Linux-256731)\n\n* RHIVOS - [backport] S32G Driver Update - ADC, I2C, and eDMA (JIRA:Rocky Linux-256890)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","modified":"2026-09-16T12:30:02.337431690Z","published":"2026-09-16T12:09:37.746677Z","upstream":["CVE-2025-40149","CVE-2025-68745","CVE-2026-23466","CVE-2026-31479","CVE-2026-31539","CVE-2026-31566","CVE-2026-31656","CVE-2026-31663","CVE-2026-43248","CVE-2026-43368","CVE-2026-43370","CVE-2026-46149","CVE-2026-52924","CVE-2026-53131","CVE-2026-53239","CVE-2026-53246","CVE-2026-53361","CVE-2026-63889","CVE-2026-63917","CVE-2026-63919","CVE-2026-63921","CVE-2026-64111","CVE-2026-68264","CVE-2026-68426","CVE-2026-74556"],"database_specific":{"license_url":"https://creativecommons.org/licenses/by/4.0/","source_advisory":"RHSA-2026:67471","license":"CC-BY-4.0"},"references":[{"type":"ADVISORY","url":"https://errata.rockylinux.org/RLSA-2026:67471"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2414466"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2425039"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2454867"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2460699"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2461451"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2461462"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2461525"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2461575"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2467084"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2468192"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2468244"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2482566"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492095"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492747"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492771"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492779"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2497035"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502320"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502368"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502412"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502434"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502490"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2513452"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2513477"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517010"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:67471"}],"affected":[{"package":{"name":"kernel","ecosystem":"Rocky Linux:10","purl":"pkg:rpm/rocky-linux/kernel?distro=rocky-linux-10&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:6.12.0-211.55.1.el10_2"}],"database_specific":{"yum_repository":"BaseOS"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2026:67471.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"credits":[{"name":"Rocky Enterprise Software Foundation"},{"name":"Red Hat"}]}