Rocky Linux update in Brocade ASCG OVA 3.5.0
|
Brocade Security Advisory ID |
BSA-2026--4108 |
|
Component |
Rocky Linux |
|
|
|
Summary
Multiple third-party open-source components integrated within the ASCG platform including the Linux Kernel, OpenSSL, GnuTLS, BIND, libxml2, and container tools were evaluated for known CVEs. The majority of identified vulnerabilities reside in non-executable code paths or are mitigated by environment constraints.
Brocade has released Security update in Brocade ASCG 3.5.0 release.
Vulnerability Details
- CVE-2026-43110: Wi-Fi brcmfmac Driver Array Index Validation Flaw
- CVE-2026-46056: Bluetooth Passkey Handler Use-After-Free
- CVE-2026-43051: Wacom HID Bluetooth Driver Out-of-Bounds Read
- CVE-2026-43020: Bluetooth MGMT LTK Encryption Size Validation Flaw
- CVE-2026-46054: OverlayFS mmap and mprotect Access Control Bypass
- CVE-2026-43037: IPv6 Tunneling Buffer Overflow via Malformed IPv4 Header
- CVE-2026-46135: NVMe-over-Fabrics TCP Double Free via Race Condition
- CVE-2026-43279: ALSA USB-Audio Out-of-Bounds Write
- CVE-2026-46090: ALSA Loopback Driver Use-After-Free
- CVE-2026-46145: Microsoft Azure Network Adapter (MANA) Buffer Overflow
- CVE-2026-43056: Microsoft MANA Driver Use-After-Free in Error Path
- CVE-2024-474: Use After Free with SSL_free_buffers
- CVE-2024-34459: Libxml2 xmllint --htmlout Heap Buffer Over-Read
- CVE-2026-28390: Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo
- CVE-2026-46333 : ptrace: slightly saner 'get_dumpable()' logic
- CVE-2026-46300: net: skbuff: preserve shared-frag marker during coalescing
- CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation
- CVE-2026-5946: Invalid handling of CLASS != IN
- CVE-2026-45447: Heap Use-After-Free in the PKCS7_verify() Function
- CVE-2026-46331 sched: fix pedit partial COW leading to page cache corruption
- CVE-2026-42009 gnutls: denial of service via dtls packet reordering vulnerability
- CVE-2026-33846 Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly
- CVE-2026-42015 gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling
- CVE-2026-42011: gnutls: security bypass due to incorrect name constraint handling
- CVE-2026-46243: client: reject userspace cifs.spnego descriptions
- CVE-2026-45186: Expat XML Entity Resolution Recursion Stack Overflow
- CVE-2025-21858: Fix use-after-free in geneve_find_dev()
- CVE-2026-45852: RDMA/rxe: Fix double free in rxe_srq_from_init
- CVE-2025-68366: Linux Kernel NBD Subsystem nbd_genl_connect Use-After-Free
- CVE-2026-23392: Linux Kernel File System Subsystem Privilege Escalation
- CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
- CVE-2026-43125: dlm: validate length in dlm_search_rsb_tree
- CVE-2026-31786: Buffer overflow in drivers/xen/sys-hypervisor.c
- CVE-2026-31669:mptcp: fix slab-use-after-free in __inet_lookup_established
- CVE-2026-43329: flowtable: strictly check for maximum number of actions
- CVE-2026-23455: nf_conntrack_h323: check for zero length in DecodeQ931() CVE-2026-23243: RDMA/umad: Reject negative data_len in ib_umad_write
- CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets
- CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks
- CVE-2025-71116: libceph: make decode_pool() more resilient against corrupted osdmaps
- CVE-2026-31684:net: sched: act_csum: validate nested VLAN headers
- CVE-2026-31532: kernel - can: raw: fix ro->uniq use-after-free in raw_rcv()
- CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup
- CVE-2025-68183: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr
- CVE-2026-43163: Title: md/bitmap: fix GPF in write_page caused by resize race
- CVE-2026-43190: Title: netfilter: xt_tcpmss: check remaining length before reading optlen
- CVE-2026-23270:Title: net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks
- CVE-2026-31709: Title: smb: client: validate the whole DACL before rewriting it in cifsacl
- CVE-2025-68347: Linux Kernel Media Subsystem Buffer Overflow Flaw
- CVE-2026-5260: ]gnutls: information disclosure via heap overread in rsa key exchange
- CVE-2026-39830: Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
- CVE-2023-53781: smc: Fix use-after-free in tcp_write_timer_handler().
- CVE-2025-10911: Libxslt: use-after-free with key data stored cross-rvt
- CVE-2025-13151: Stack-based buffer overflow in libtasn1 version: v4.20.0.
- CVE-2025-5994: Cache poisoning via the ECS-enabled Rebirthday Attack
- CVE-2025-6170: Libxml2: stack buffer overflow in xmllint interactive shell command handling
- CVE-2026-15308: Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
- CVE-2026-2291: dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries
- CVE-2026-22984: Title: libceph: prevent potential out-of-bounds reads in handle_auth_done()
- CVE-2026-22990: libceph: replace overzealous BUG_ON in osdmap_apply_incremental()
- CVE-2026-25679: Incorrect parsing of IPv6 host literals in net/url
- CVE-2026-3012: Samba: group policy certificate enrollment uses http:// without validation
- CVE-2026-31408: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold
- CVE-2026-31419: net: bonding: fix use-after-free in bond_xmit_broadcast()
- CVE-2026-31488: drm/amd/display: Do not skip unrelated mode changes in DSC validation
- CVE-2026-31581: ALSA: 6fire: fix use-after-free on disconnect
- CVE-2026-31613: smb: client: fix OOB reads parsing symlink error response
- CVE-2026-31787: xen/privcmd: fix double free via VMA splitting
- CVE-2026-32280: Unexpected work during chain building in crypto/x509
- CVE-2026-32281: Inefficient policy validation in crypto/x509
- CVE-2026-32283: Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
- CVE-2026-33416:LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE`
- CVE-2026-33811:Crash when handling long CNAME response in net
- CVE-2026-33845: Gnutls: gnutls: denial of service via dtls zero-length fragment
- CVE-2026-34986:Go JOSE affect by a panic in JWE decryption
- CVE-2026-35177:Path traversal issue with zip.vim in Vim
- CVE-2026-3833:gnutls: policy bypass due to case-sensitive nameconstraints comparison
- CVE-2026-39829:Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh
- CVE-2026-39832: Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
- CVE-2026-39835:Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh
- CVE-2026-4046: iconv crash due to assertion failure with untrusted input
- CVE-2026-42010: gnutls: authentication bypass via nul character in username
- CVE-2026-42012: Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans
- CVE-2026-42013: Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name
- CVE-2026-46117: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()
- CVE-2026-53071:l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp
- CVE-2026-5435: Potential buffer overflow in ns_sprintrrf TSIG handling path
- CVE-2026-54369:acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions
- CVE-2026-54370: acl < 2.4.0 TOCTOU Symlink Traversal via getfacl/setfacl/chacl
- CVE-2026-58016: integer underflow in gio/gdbusintrospection.c via"g_dbus_node_info_new_for_xml"
- CVE-2026-5928: Potential buffer under-read in ungetwc
- CVE-2026-6238:Buffer overread in ns_printrrf with corrupted RDATA field
- CVE-2026-53006: Linux Kernel IPv6 icmpv6_rcv Use-After-Free Vulnerability
- CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
- CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack
- CVE-2026-46150: fanotify: fix false positive on permission events
- CVE-2026-31692: rtnetlink: add missing netlink_ns_capable() check for peer netns
- CVE-2026-52923: ipc: limit next_id allocation to the valid ID range
- CVE-2026-14476: gpo cache path traversal via unsanitized gpcfilesyspath allows kerberos authentication bypass
- CVE-2026-14474: sudo ldap provider searches entire directory tree for sudorole objects by default, enabling privilege escalation
- CVE-2026-6893 root code execution via dhcp options command injection
- CVE-2025-4435 - Tarfile extracts filtered members when errorlevel=0
- CVE-2026-4878 - Libcap: libcap: privilege escalation via toctou race condition in cap_set_file()
- CVE-2026-4878 - Time-of-check Time-of-use (TOCTOU) Race Condition
- CVE-2026-48864 - heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
- CVE-2026-41411 - Command injection via backtick expansion in tag filenames
- CVE-2026-5928 GNU C Library Potential buffer under-read in ungetwc
- CVE-2026-4802: cockpit: arbitrary command execution via crafted links in system logs ui
Product Not Affected
- Brocade ASCG: Vulnerable_code_not_in_execute_path
Solution
- Although Brocade ASCG is not affected, a security update is provided in Brocade ASCG 3.5.0 OVA
Revision History
|
Version |
Change |
Date |
|
1.0 |
Initial Publication |
9/30/2026 |
Disclaimer
THIS DOCUMENT IS PROVIDED ON AN AS-IS BASIS SOLELY FOR INFORMATIONAL PURPOSES AND DOES NOT IMPLY ANY KIND OF GUARANTY OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. YOUR USE OF THE INFORMATION CONTAINED HEREIN IS AT YOUR OWN RISK. ALL INFORMATION PROVIDED HEREIN IS BASED ON BROCADE'S CURRENT KNOWLEDGE AND UNDERSTANDING OF THE VULNERABILITY AND IMPACT TO BROCADE HARDWARE AND SOFTWARE PRODUCTS. BROCADE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.