RockyLinux security update for glibc (RLSA-2026:2786) and kernel (RLSA-2026:2722), curl (RLSA-2026:1350)
37951
28 July 2026
28 July 2026
CLOSED
MEDIUM
Varies
CVE-2025-9086, CVE-2023-53034, CVE-2025-40064, CVE-2025-40304, CVE-2025-40322, CVE-2025-68349, CVE-2025-68811, CVE-2026-22998, CVE-2026-0861, CVE-2026-0915, CVE-2025-15281
|
Brocade Security Advisory ID |
BSA-2026-3167 |
|
Component |
Rocky Linux |
|
|
|
Summary
Rocky Linux Security Update for curl (RLSA-2026:1350)
- curl: libcurl: Curl out of bounds read for cookie path (CVE-2025-9086)
Rocky Linux Security Update for kernel (RLSA-2026:2722)
- kernel: ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans (CVE-2023-53034)
- kernel: smc: Fix use-after-free in __pnet_find_base_ndev() (CVE-2025-40064)
- kernel: Linux kernel: Out-of-bounds write in fbdev can lead to privilege escalation, information disclosure, or denial of service. (CVE-2025-40304)
- kernel: Linux kernel: Information disclosure and denial of service via out-of-bounds read in font glyph handling (CVE-2025-40322)
- kernel: NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid (CVE-2025-68349)
- kernel: svcrdma: use rc_pageoff for memcpy byte offset (CVE-2025-68811)
- kernel: nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec (CVE-2026-22998)
Rocky Linux Security Update for glibc (RLSA-2026:2786)
- glibc: Integer overflow in memalign leads to heap corruption (CVE-2026-0861)
- glibc: Information disclosure via zero-valued network query (CVE-2026-0915)
- glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory (CVE-2025-15281)
Products Affected
- Brocade SANnav OVA Base OS OVA versions before 3.0.1
Products Confirmed not Affected
- Brocade SANnav Standard Deployment (management portal)
Solution
- Security update provided in Brocade SANnav OVA Base OS 3.0.1. The same update is provided in OVA OS Patches OVA_9x_os_06_2026 and the SANnav_ova_8x_os_06_2026.
- The OVA_9x_os_06_2026 supports Brocade SANnav versions 3.0.0, and CSI patch 3.0.0.1.
- The Brocade SANnav OVA_8x_os_06_2026 patch supports Brocade SANnav versions 2.4.0, 2.4.0a, 2,4,0b
Revision History
|
Version |
Change |
Date |
|
1.0 |
Initial Publication |
July 28th, 2026 |
Disclaimer
THIS DOCUMENT IS PROVIDED ON AN AS-IS BASIS SOLELY FOR INFORMATIONAL PURPOSES AND DOES NOT IMPLY ANY KIND OF GUARANTY OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. YOUR USE OF THE INFORMATION CONTAINED HEREIN IS AT YOUR OWN RISK. ALL INFORMATION PROVIDED HEREIN IS BASED ON BROCADE'S CURRENT KNOWLEDGE AND UNDERSTANDING OF THE VULNERABILITY AND IMPACT TO BROCADE HARDWARE AND SOFTWARE PRODUCTS. BROCADE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.