Security update provided to RockyLinux 9 kernel (RLSA-2026:2212, RLSA-2026:1143, RLSA-2026:1617)
37949
28 July 2026
28 July 2026
CLOSED
MEDIUM
Varies
CVE-2025-37789, CVE-2025-37819, CVE-2025-38022, CVE-2025-38024, CVE-2025-38403, CVE-2025-38415, CVE-2025-38459, CVE-2025-38730, CVE-2025-39760, CVE-2025-40135, CVE-2025-40141, CVE-2025-40158, CVE-2025-40170, CVE-2025-40269, CVE-2025-40271, CVE-2025-40318, CVE-2025-38141, CVE-2025-38349, CVE-2025-38731, CVE-2025-40248, CVE-2025-40258, CVE-2025-40294, CVE-2025-68301, CVE-2025-68305, CVE-2025-38568, CVE-2025-40154, CVE-2025-40251
|
Brocade Security Advisory ID |
BSA-2026-3682 |
|
Component |
Rocky Linux |
|
|
|
Summary
Brocade SANnav OVA has provided Security updates for RockyLinux 9 kernel (RLSA-2026:2212, RLSA-2026:1143, RLSA-2026:1617) vulnerabilities.
Rocky Linux 9 : kernel (RLSA-2026:2212)
- kernel: net: openvswitch: fix nested key length validation in the set() action (CVE-2025-37789)
- kernel: Linux kernel: irqchip/gic-v2m use-after-free vulnerability (CVE-2025-37819)
- kernel: RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem (CVE-2025-38022)
- kernel: Linux kernel: RDMA/rxe use-after-free vulnerability leading to potential arbitrary code execution (CVE-2025-38024)
- kernel: Linux kernel: Memory corruption in Squashfs due to incorrect block size calculation (CVE-2025-38415)
- kernel: vsock/vmci: Clear the vmci transport packet properly when initializing it (CVE-2025-38403)
- kernel: Linux kernel: Denial of Service in ATM CLIP module via infinite recursion (CVE-2025-38459)
- kernel: Linux kernel: Data corruption and system instability due to improper io_uring/net buffer handling (CVE-2025-38730)
- kernel: Linux kernel: Denial of Service via out-of-bounds read in USB configuration parsing (CVE-2025-39760)
- kernel: net: use dst_dev_rcu() in sk_setup_caps() (CVE-2025-40170)
- kernel: ipv6: use RCU in ip6_xmit() (CVE-2025-40135)
- kernel: Bluetooth: ISO: Fix possible UAF on iso_conn_free (CVE-2025-40141)
- kernel: ipv6: use RCU in ip6_output() (CVE-2025-40158)
- kernel: Linux kernel: Use-after-free in proc_readdir_de() can lead to privilege escalation or denial of service. (CVE-2025-40271)
- kernel: Linux kernel ALSA USB audio driver: Buffer overflow leading to information disclosure and denial of service (CVE-2025-40269)
- kernel: Bluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once (CVE-2025-40318)
Rocky Linux 9: kernel (RLSA-2026:1143)
- kernel: Linux kernel: Use-after-free in device mapper due to race condition in zone reporting (CVE-2025-38141)
- kernel: Linux kernel use-after-free in eventpoll (CVE-2025-38349)
- kernel: drm/xe: Fix vm_bind_ioctl double free bug (CVE-2025-38731)
- kernel: Linux kernel: vsock vulnerability may lead to memory corruption (CVE-2025-40248)
- kernel: mptcp: fix race condition in mptcp_schedule_work() (CVE-2025-40258)
- kernel: Linux kernel: Out-of-bounds write in Bluetooth MGMT can lead to information disclosure and denial of service (CVE-2025-40294)
- kernel: net: atlantic: fix fragment overflow handling in RX path (CVE-2025-68301)
- kernel: Bluetooth: hci_sock: Prevent race in socket write iter and sock bind (CVE-2025-68305)
Rocky Linux 9 : kernel (RLSA-2026:1617)
- kernel: net/sched: mqprio: fix stack out-of-bounds write in tc entry parsing (CVE-2025-38568)
- kernel: ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping (CVE-2025-40154)
- kernel: devlink: rate: Unset parent pointer in devl_rate_nodes_destroy (CVE-2025-40251)
Products Affected
- Brocade SANnav OVA Base OS OVA versions before 3.0.1 for the following CVEs: CVE-2025-37789, CVE-2025-37819, CVE-2025-38022, CVE-2025-38024, CVE-2025-38403, CVE-2025-38415, CVE-2025-38459, CVE-2025-39760, CVE-2025-40135, CVE-2025-40158, CVE-2025-40170, CVE-2025-40269, CVE-2025-40271, CVE-2025-40248, CVE-2025-40258, CVE-2025-68301, CVE-2025-38568, CVE-2025-40154.
- Brocade SANnav OVA Base OS versions 3.0.0 through 3.0.0a for the following CVEs: CVE-2025-38730, CVE-2025-40141, CVE-2025-40318, CVE-2025-38141, CVE-2025-38349, CVE-2025-38731, CVE-2025-40294, CVE-2025-68305, CVE-2025-40251,
Products Confirmed not Affected
- Brocade SANnav Standard Deployment (management portal)
Solution
- Security update provided in Brocade SANnav OVA Base OS 3.0.1. The same update is provided in OVA OS Patch OVA_9x_os_06_2026.
- The OVA_9x_os_06_2026 supports Brocade SANnav versions 3.0.0, and 3.0.0a.
- Security update is also provided in Brocade SANnav OVA OS Patch OVA_8x_os_06_2026 for the following CVEs: CVE-2025-37789, CVE-2025-37819, CVE-2025-38022, CVE-2025-38024, CVE-2025-38403, CVE-2025-38415, CVE-2025-38459, CVE-2025-39760, CVE-2025-40135, CVE-2025-40158, CVE-2025-40170, CVE-2025-40269, CVE-2025-40271, CVE-2025-40248, CVE-2025-40258, CVE-2025-68301, CVE-2025-38568, CVE-2025-40154.
Note:
- The following vulnerabilities are not applicable for the Brocade SANnav OVA_8x_os-06_2026: CVE-2025-38730, CVE-2025-40141, CVE-2025-40318, CVE-2025-38141, CVE-2025-38349, CVE-2025-38731, CVE-2025-40294, CVE-2025-68305, CVE-2025-40251,
Revision History
|
Version |
Change |
Date |
|
1.0 |
Initial Publication |
July 28th, 2026 |
Disclaimer
THIS DOCUMENT IS PROVIDED ON AN AS-IS BASIS SOLELY FOR INFORMATIONAL PURPOSES AND DOES NOT IMPLY ANY KIND OF GUARANTY OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. YOUR USE OF THE INFORMATION CONTAINED HEREIN IS AT YOUR OWN RISK. ALL INFORMATION PROVIDED HEREIN IS BASED ON BROCADE'S CURRENT KNOWLEDGE AND UNDERSTANDING OF THE VULNERABILITY AND IMPACT TO BROCADE HARDWARE AND SOFTWARE PRODUCTS. BROCADE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.