Moderate: kernel security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:3963", "synopsis": "Moderate: kernel security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for kernel.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The kernel packages contain the Linux kernel, the core of any Linux operating system.\n\nSecurity Fix(es):\n\n* kernel: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (CVE-2025-71085)\n\n* kernel: macvlan: fix possible UAF in macvlan_forward_source() (CVE-2026-23001)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2429026", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2429026", "description": ""}, {"ticket": "2432664", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2432664", "description": ""}], "cves": [{"name": "CVE-2025-71085", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-71085", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-190"}, {"name": "CVE-2026-23001", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-23001", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-416"}], "references": [], "publishedAt": "2026-03-26T12:00:47.711472Z", "rpms": {"Rocky Linux 8": {"nvras": ["bpftool-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "bpftool-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "bpftool-debuginfo-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "bpftool-debuginfo-0:4.18.0-553.111.1.el8_10.x86_64.rpm","kernel-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-0:4.18.0-553.111.1.el8_10.src.rpm", "kernel-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-abi-stablelists-0:4.18.0-553.111.1.el8_10.noarch.rpm", "kernel-core-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-core-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-debug-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-debug-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-debug-core-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-debug-core-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-debug-debuginfo-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-debug-debuginfo-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-debug-devel-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-debug-devel-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-debuginfo-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-debuginfo-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-debuginfo-common-aarch64-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-debuginfo-common-x86_64-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-debug-modules-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-debug-modules-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-debug-modules-extra-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-debug-modules-extra-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-devel-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-devel-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-doc-0:4.18.0-553.111.1.el8_10.noarch.rpm", "kernel-modules-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-modules-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-modules-extra-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-modules-extra-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-tools-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-tools-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-tools-debuginfo-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-tools-debuginfo-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-tools-libs-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-tools-libs-0:4.18.0-553.111.1.el8_10.x86_64.rpm","kernel-tools-libs-devel-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-tools-libs-devel-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "perf-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "perf-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "perf-debuginfo-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "perf-debuginfo-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "python3-perf-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "python3-perf-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "python3-perf-debuginfo-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "python3-perf-debuginfo-0:4.18.0-553.111.1.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A kernel security update is now available for Rocky Linux with critical fixes and updates for system safety.. Rocky Linux kernel patch security update. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-50152 http://linux.oracle.com/errata/ELSA-2026-50152.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: dtrace-2.0.6-1.el8.x86_64.rpm dtrace-devel-2.0.6-1.el8.x86_64.rpm dtrace-testsuite-2.0.6-1.el8.x86_64.rpm aarch64: dtrace-2.0.6-1.el8.aarch64.rpm dtrace-devel-2.0.6-1.el8.aarch64.rpm dtrace-testsuite-2.0.6-1.el8.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/dtrace-2.0.6-1.el8.src.rpm Related CVEs: CVE-2026-21991 Description of changes: [2.0.6-1] - Fix dtprobed unsafe probe description handling (CVE-2026-21991). [Orabug: 39054018] Credit Statement: The following people or organizations reported security vulnerabilities addressed by this ELSA to Oracle: Dhiraj Mishra: CVE-2026-21991 _______________________________________________ El-errata mailing list
An update that solves three vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 48 for SLE 15 SP3) Announcement ID: SUSE-SU-2025:0246-1 Release Date: 2025-01-27T12:04:06Z Rating: important References: * bsc#1226324 * bsc#1232637 * bsc#1233712 Cross-References: * CVE-2022-48956 * CVE-2024-36971 * CVE-2024-50264 CVSS scores: * CVE-2022-48956 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-48956 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-36971 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-36971 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise Live Patching 15-SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves three vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.3.18-150300_59_174 fixes several issues. The following security issues were fixed: * CVE-2024-36971: Fixed __dst_negative_advice() race (bsc#1226324). * CVE-2024-50264: vsock/virtio: Initialization of the dangling pointer occurring in vsk-> trans (bsc#1233712). * CVE-2022-48956: ipv6: avoid use-after-free in ip6_fragment() (bsc#1232637). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-246=1 * SUSE LinuxEnterprise Live Patching 15-SP3 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2025-246=1 ## Package List: * openSUSE Leap 15.3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_174-default-debuginfo-3-150300.7.6.1 * kernel-livepatch-SLE15-SP3_Update_48-debugsource-3-150300.7.6.1 * kernel-livepatch-5_3_18-150300_59_174-default-3-150300.7.6.1 * openSUSE Leap 15.3 (x86_64) * kernel-livepatch-5_3_18-150300_59_174-preempt-debuginfo-3-150300.7.6.1 * kernel-livepatch-5_3_18-150300_59_174-preempt-3-150300.7.6.1 * SUSE Linux Enterprise Live Patching 15-SP3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_174-default-3-150300.7.6.1 ## References: * https://www.suse.com/security/cve/CVE-2022-48956.html * https://www.suse.com/security/cve/CVE-2024-36971.html * https://www.suse.com/security/cve/CVE-2024-50264.html * https://bugzilla.suse.com/show_bug.cgi?id=1226324 * https://bugzilla.suse.com/show_bug.cgi?id=1232637 * https://bugzilla.suse.com/show_bug.cgi?id=1233712 . Essential security enhancement for openSUSE Kernel addresses significant safety flaws. Implement the most recent update to ensure system protection.. openSUSE Kernel Update, security update, important patch. . Severity: Important. LinuxSecurity.com Team
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-40ee18b2e7 2024-06-02 03:36:56.060441 -------------------------------------------------------------------------------- Name : rust-procs Product : Fedora 39 Version : 0.14.4 Release : 5.fc39 URL : Summary : Modern replacement for ps Description : A modern replacement for ps. -------------------------------------------------------------------------------- Update Information: This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html -------------------------------------------------------------------------------- ChangeLog: * Thu May 23 2024 Fabio Valentini - 0.14.4-5 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade--advisory FEDORA-2024-40ee18b2e7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ce2936b568 2024-05-26 01:25:15.719720 -------------------------------------------------------------------------------- Name : rust-uu_yes Product : Fedora 40 Version : 0.0.23 Release : 3.fc40 URL : Summary : yes ~ (uutils) repeatedly display a line with STRING (or 'y') Description : yes ~ (uutils) repeatedly display a line with STRING (or 'y'). -------------------------------------------------------------------------------- Update Information: This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html -------------------------------------------------------------------------------- ChangeLog: * Thu May 23 2024 Fabio Valentini - 0.0.23-3 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces -------------------------------------------------------------------------------- This updatecan be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ce2936b568' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ce2936b568 2024-05-26 01:25:15.719720 -------------------------------------------------------------------------------- Name : rust-uu_truncate Product : Fedora 40 Version : 0.0.23 Release : 3.fc40 URL : Summary : truncate ~ (uutils) truncate (or extend) FILE to SIZE Description : truncate ~ (uutils) truncate (or extend) FILE to SIZE. -------------------------------------------------------------------------------- Update Information: This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html -------------------------------------------------------------------------------- ChangeLog: * Thu May 23 2024 Fabio Valentini - 0.0.23-3 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces -------------------------------------------------------------------------------- This update can beinstalled with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ce2936b568' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ce2936b568 2024-05-26 01:25:15.719720 -------------------------------------------------------------------------------- Name : rust-uu_base64 Product : Fedora 40 Version : 0.0.23 Release : 3.fc40 URL : Summary : Base64 ~ (uutils) decode/encode input (base64-encoding) Description : Base64 ~ (uutils) decode/encode input (base64-encoding). -------------------------------------------------------------------------------- Update Information: This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html -------------------------------------------------------------------------------- ChangeLog: * Thu May 23 2024 Fabio Valentini - 0.0.23-3 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces -------------------------------------------------------------------------------- This update can beinstalled with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ce2936b568' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ce2936b568 2024-05-26 01:25:15.719720 -------------------------------------------------------------------------------- Name : rust-speakersafetyd Product : Fedora 40 Version : 0.1.9 Release : 3.fc40 URL : Summary : Speaker protection daemon for embedded Linux systems Description : Speaker protection daemon for embedded Linux systems. -------------------------------------------------------------------------------- Update Information: This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html -------------------------------------------------------------------------------- ChangeLog: * Thu May 23 2024 Fabio Valentini - 0.1.9-3 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces -------------------------------------------------------------------------------- This update can beinstalled with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ce2936b568' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.