Rocky Linux Security Update for kernel, libssg, gnupg2, python3.9 & tar
37952
28 July 2026
28 July 2026
CLOSED
MEDIUM
Varies
CVE-2025-39925, CVE-2025-39979, CVE-2025-38499, CVE-2025-39966, CVE-2025-40176, CVE-2025-5987, CVE-2024-5642, CVE-2025-6069, CVE-2025-8291, CVE-2025-6075, CVE-2025-58183, CVE-2025-45582, CVE-2025-39806, CVE-2025-39840, CVE-2025-39883, CVE-2025-40240, CVE-2025-68973
|
Brocade Security Advisory ID |
BSA-2026-3682 |
|
Component |
Rocky Linux |
|
|
|
Summary
Brocade SANnav OVA has provided Security updates for the following vulnerabilities.
Rocky Linux 9 : Security Update for python3.9 (RLSA-2026:1478)
- cpython: Quadratic algorithm in xml.dom.minidom leads to denial of service (CVE-2025-12084)
Rocky Linux Security Update for kernel (RLSA-2025:22865)
- kernel: can: j1939: implement NETDEV_UNREGISTER notification handler (CVE-2025-39925)
- kernel: net/mlx5: fs, fix UAF in flow counter release (CVE-2025-39979)
Rocky Linux Security Update for kernel (RLSA-2025:23241)
- kernel: clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns (CVE-2025-38499)
- kernel: iommufd: Fix race during abort for file descriptors (CVE-2025-39966)
- kernel: tls: wait for pending async decryptions if tls_strp_msg_hold fails (CVE-2025-40176)
Rocky Linux Security Update for libssh (RLSA-2025:23483)
- libssh: Invalid return code for chacha20 poly1305 with OpenSSL backend (CVE-2025-5987)
Rocky Linux Security Update for python3.9 (RLSA-2025:23342)
- python: Invalid value for OpenSSL API may cause Buffer over-read when NPN is used (CVE-2024-5642)
- cpython: Python HTMLParser quadratic complexity (CVE-2025-6069)
- cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked (CVE-2025-8291)
- python: Quadratic complexity in os.path.expandvars() with user-controlled template (CVE-2025-6075)
Rocky Linux Security Update for podman (RLSA-2025:23325)
- golang: archive/tar: Unbounded allocation when parsing GNU sparse map (CVE-2025-58183)
Rocky Linux Security Update for tar (RLSA-2026:0067)
- tar: Tar path traversal (CVE-2025-45582)
Rocky Linux Security Update for kernel (RLSA-2026:0445)
- kernel: HID: multitouch: fix slab out-of-bounds access in mt_report_fixup() (CVE-2025-39806)
- kernel: audit: fix out-of-bounds read in audit_compare_dname_path() (CVE-2025-39840)
- kernel: mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory (CVE-2025-39883)
- kernel: sctp: avoid NULL dereference when chunk data buffer is missing (CVE-2025-40240)
Rocky Linux Security Update for gnupg2 (RLSA-2026:0719)
- GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write (CVE-2025-68973)
Products Affected
- Brocade SANnav OVA Base OS versions before 3.0.1 for the following CVEs: CVE-2025-39979, CVE-2025-39966, CVE-2025-5987, CVE-2024-5642, CVE-2025-6069, CVE-2025-8291, CVE-2025-6075, CVE-2025-58183, CVE-2025-45582, CVE-2025-39883, CVE-2025-40240, CVE-2025-68973
- Brocade SANnav OVA Base OS versions 3.0.0 through 3.0.0a for the following CVEs: CVE-2025-39925, CVE-2025-38499, CVE-2025-40176, CVE-2025-39806, CVE-2025-39840.
Products Confirmed not Affected
- Brocade SANnav Standard Deployment (management portal)
Solution
- Security update provided in Brocade SANnav OVA Base OS 3.0.1. The same update is provided in OVA OS Patches OVA_9x_os_06_2026.
- The OVA_9x_os_06_2026 supports Brocade SANnav versions 3.0.0, and 3.0.0a
- Security update is also provided in Brocade SANnav OVA OS Patch OVA_8x_os_06_2026 for the following CVEs: CVE-2025-39979, CVE-2025-39966, CVE-2025-5987, CVE-2024-5642, CVE-2025-6069, CVE-2025-8291, CVE-2025-6075, CVE-2025-58183, CVE-2025-45582, CVE-2025-39883, CVE-2025-40240, CVE-2025-68973
Note:
The following vulnerabilities are not applicable for the Brocade SANnav OVA_8x_os-06_2026: CVE-2025-39925, CVE-2025-38499, CVE-2025-40176, CVE-2025-39806, CVE-2025-39840.
Revision History
|
Version |
Change |
Date |
|
1.0 |
Initial Publication |
July 28th, 2026 |
Disclaimer
THIS DOCUMENT IS PROVIDED ON AN AS-IS BASIS SOLELY FOR INFORMATIONAL PURPOSES AND DOES NOT IMPLY ANY KIND OF GUARANTY OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. YOUR USE OF THE INFORMATION CONTAINED HEREIN IS AT YOUR OWN RISK. ALL INFORMATION PROVIDED HEREIN IS BASED ON BROCADE'S CURRENT KNOWLEDGE AND UNDERSTANDING OF THE VULNERABILITY AND IMPACT TO BROCADE HARDWARE AND SOFTWARE PRODUCTS. BROCADE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.