Rocky Linux Security Update for glibc (RLSA-2026:2786) and kernel (RLSA-2026:2722)
37953
28 July 2026
28 July 2026
CLOSED
MEDIUM
Varies
CVE-2026-0915 CVE-2026-0861 CVE-2025-15281, CVE-2025-68349, CVE-2025-68811 CVE-2025-40304 CVE-2026-22998 CVE-2025-40322 CVE-2025-40064 CVE-2023-53034
|
Brocade Security Advisory ID |
BSA-2026-3478 |
|
Component |
Rocky Linux |
|
|
|
Summary
Brocade SANnav OVA has provided security updates for Multiple vulnerabilities ias referenced in glibc (RLSA-2026:2786), kernel (RLSA-2026:2722)
glibc (RLSA-2026:2786)
- glibc: Integer overflow in memalign leads to heap corruption (CVE-2026-0861)
- glibc: glibc: Information disclosure via zero-valued network query (CVE-2026-0915)
- glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory (CVE-2025-15281)
kernel (RLSA-2026:2722)
- kernel: ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans (CVE-2023-53034)
- kernel: smc: Fix use-after-free in __pnet_find_base_ndev() (CVE-2025-40064)
- kernel: Linux kernel: Out-of-bounds write in fbdev can lead to privilege escalation, information disclosure, or denial of service. (CVE-2025-40304)
- kernel: Linux kernel: Information disclosure and denial of service via out-of-bounds read in font glyph handling (CVE-2025-40322)
- kernel: NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid (CVE-2025-68349)
- kernel: svcrdma: use rc_pageoff for memcpy byte offset (CVE-2025-68811)
- kernel: nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec (CVE-2026-22998)
Products Affected
- Brocade SANnav OVA Base OS versions before 3.0.1 for the following CVEs: CVE-2026-0915, CVE-2025-15281, CVE-2025-68349, CVE-2025-40304 CVE-2026-22998 CVE-2025-40322 CVE-2025-40064 CVE-2023-53034
- Brocade SANnav OVA Base OS versions 3.0.0 through 3.0.0a for the following CVEs: CVE-2026-0861, CVE-2025-68811
Products Confirmed not Affected
- Brocade SANnav Standard Deployment (management portal)
Solution
- Security update provided in Brocade SANnav OVA Base OS 3.0.1. The same update is provided in OVA OS Patches OVA_9x_os_06_2026.
- The OVA_9x_os_06_2026 supports Brocade SANnav versions 3.0.0 and 3.0.0a
- Security update is also provided in Brocade SANnav OVA OS Patch OVA_8x_os_06_2026 for the following CVEs: Affected CVE:CVE-2026-0915, CVE-2025-15281, CVE-2025-68349, CVE-2025-40304 CVE-2026-22998 CVE-2025-40322 CVE-2025-40064, CVE-2023-53034.
- The OVA_8x_os_06_2026 supports Brocade SANnav versions 2.4.0, 2.4.0a, 2.4.0b
Note:
- The following vulnerabilities are not applicable for the Brocade SANnav OVA_8x_os-06_2026: CVE-2026-0861, CVE-2025-68811, CVE-2023-53034.
Revision History
|
Version |
Change |
Date |
|
1.0 |
Initial Publication |
July 28th, 2026 |
Disclaimer
THIS DOCUMENT IS PROVIDED ON AN AS-IS BASIS SOLELY FOR INFORMATIONAL PURPOSES AND DOES NOT IMPLY ANY KIND OF GUARANTY OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. YOUR USE OF THE INFORMATION CONTAINED HEREIN IS AT YOUR OWN RISK. ALL INFORMATION PROVIDED HEREIN IS BASED ON BROCADE'S CURRENT KNOWLEDGE AND UNDERSTANDING OF THE VULNERABILITY AND IMPACT TO BROCADE HARDWARE AND SOFTWARE PRODUCTS. BROCADE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.