RockyLinux 9 : kernel (RLSA-2026:77689)

medium Nessus Plugin ID 364451

Synopsis

The remote RockyLinux host is missing one or more security updates.

Description

The remote RockyLinux 9 host has packages installed that are affected by multiple vulnerabilities as referenced in the RLSA-2026:77689 advisory.

* kernel: ipvlan: Make the addrs_lock be per port (CVE-2026-23103)

* kernel: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (CVE-2026-53360)

* kernel: vsock/virtio: fix zerocopy completion for multi-skb sends (CVE-2026-53365)

* kernel: NFSD: Fix SECINFO_NO_NAME decode error cleanup (CVE-2026-53398)

* kernel: vsock/virtio: bind uarg before filling zerocopy skb (CVE-2026-63970)

* kernel: igc: set tx buffer type for SMD frames (CVE-2026-64035)

* kernel: idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() (CVE-2026-64162)

* kernel: vsock/vmci: fix UAF when peer resets connection during handshake (CVE-2026-64115)

* kernel: SUNRPC: pin upper rpc_clnt across the TLS connect_worker (CVE-2026-72317)

* kernel: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev (CVE-2026-74744)

* kernel: nfsd: defer vfree of compound ops to fix rpc_status UAF (CVE-2026-89690)

* kernel: nfsd: initialize copy-notify stateid before publishing it (CVE-2026-89669)

* kernel: svcrdma: Reject inline replies that overflow the pull-up buffer (CVE-2026-89530)

* kernel: nfsd: revoke copy-notify stateids before dropping their reference (CVE-2026-89663)

Bug Fix(es) and Enhancement(s):

* iavf: refactor iavf_clean_rx_irq to support legacy and flex descriptors broke rx-vlan-offload on rhel-9.7 [rhel-9.8.z] (JIRA:Rocky Linux-169480)

* [GNR-D] missing interfaces tspll_cfg (JIRA:Rocky Linux-183201)

* Rocky Linux9.8z KVM guest panicked in vmmouse driver (JIRA:Rocky Linux-186577)

* Add Epson RX8111 support to Rocky Linux9.9 [rhel-9.8.z] (JIRA:Rocky Linux-212014)

* RT scheduler livelock: migrate-disabled task at pushable-list head causes repeated RT push/stopper retries, starving a critical RT task (remaining issue after CVE-2026-45919 fix in 94894c9c477e) [rhel-9.8.z] (JIRA:Rocky Linux-256279)

Tenable has extracted the preceding description block directly from the RockyLinux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.redhat.com/show_bug.cgi?id=2436771

https://bugzilla.redhat.com/show_bug.cgi?id=2497032

https://bugzilla.redhat.com/show_bug.cgi?id=2499742

https://bugzilla.redhat.com/show_bug.cgi?id=2502222

https://bugzilla.redhat.com/show_bug.cgi?id=2502411

https://bugzilla.redhat.com/show_bug.cgi?id=2502476

https://bugzilla.redhat.com/show_bug.cgi?id=2502521

https://bugzilla.redhat.com/show_bug.cgi?id=2502593

https://bugzilla.redhat.com/show_bug.cgi?id=2516705

https://bugzilla.redhat.com/show_bug.cgi?id=2524431

https://bugzilla.redhat.com/show_bug.cgi?id=2532103

https://bugzilla.redhat.com/show_bug.cgi?id=2532111

https://bugzilla.redhat.com/show_bug.cgi?id=2532218

https://bugzilla.redhat.com/show_bug.cgi?id=2532231

https://errata.rockylinux.org/RLSA-2026:77689

Plugin Details

Severity: Medium

ID: 364451

File Name: rocky_linux_RLSA-2026-77689.nasl

Version: 1.1

Type: Local

Published: 10/9/2026

Updated: 10/9/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.8

Percentile: 99.34

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-53365

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 5.1

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:rocky:linux:9, p-cpe:/a:rocky:linux:kernel-64k-core, p-cpe:/a:rocky:linux:kernel-64k-debug-core, p-cpe:/a:rocky:linux:kernel-64k-debug-debuginfo, p-cpe:/a:rocky:linux:kernel-64k-debug-devel-matched, p-cpe:/a:rocky:linux:kernel-64k-debug-devel, p-cpe:/a:rocky:linux:kernel-64k-debug-modules-core, p-cpe:/a:rocky:linux:kernel-64k-debug-modules-extra, p-cpe:/a:rocky:linux:kernel-64k-debug-modules, p-cpe:/a:rocky:linux:kernel-64k-debug, p-cpe:/a:rocky:linux:kernel-64k-debuginfo, p-cpe:/a:rocky:linux:kernel-64k-devel-matched, p-cpe:/a:rocky:linux:kernel-64k-devel, p-cpe:/a:rocky:linux:kernel-64k-modules-core, p-cpe:/a:rocky:linux:kernel-64k-modules-extra, p-cpe:/a:rocky:linux:kernel-64k-modules, p-cpe:/a:rocky:linux:kernel-64k, p-cpe:/a:rocky:linux:kernel-abi-stablelists, p-cpe:/a:rocky:linux:kernel-core, p-cpe:/a:rocky:linux:kernel-debug-core, p-cpe:/a:rocky:linux:kernel-debug-debuginfo, p-cpe:/a:rocky:linux:kernel-debug-devel-matched, p-cpe:/a:rocky:linux:kernel-debug-devel, p-cpe:/a:rocky:linux:kernel-debug-modules-core, p-cpe:/a:rocky:linux:kernel-debug-modules-extra, p-cpe:/a:rocky:linux:kernel-debug-modules, p-cpe:/a:rocky:linux:kernel-debug-uki-virt, p-cpe:/a:rocky:linux:kernel-debug, p-cpe:/a:rocky:linux:kernel-debuginfo-common-aarch64, p-cpe:/a:rocky:linux:kernel-debuginfo-common-ppc64le, p-cpe:/a:rocky:linux:kernel-debuginfo-common-s390x, p-cpe:/a:rocky:linux:kernel-debuginfo-common-x86_64, p-cpe:/a:rocky:linux:kernel-debuginfo, p-cpe:/a:rocky:linux:kernel-devel-matched, p-cpe:/a:rocky:linux:kernel-devel, p-cpe:/a:rocky:linux:kernel-modules-core, p-cpe:/a:rocky:linux:kernel-modules-extra, p-cpe:/a:rocky:linux:kernel-modules, p-cpe:/a:rocky:linux:kernel-rt-64k-core, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-core, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-debuginfo, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-devel, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-modules-core, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-modules-extra, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-modules, p-cpe:/a:rocky:linux:kernel-rt-64k-debug, p-cpe:/a:rocky:linux:kernel-rt-64k-debuginfo, p-cpe:/a:rocky:linux:kernel-rt-64k-devel, p-cpe:/a:rocky:linux:kernel-rt-64k-modules-core, p-cpe:/a:rocky:linux:kernel-rt-64k-modules-extra, p-cpe:/a:rocky:linux:kernel-rt-64k-modules, p-cpe:/a:rocky:linux:kernel-rt-64k, p-cpe:/a:rocky:linux:kernel-rt-core, p-cpe:/a:rocky:linux:kernel-rt-debug-core, p-cpe:/a:rocky:linux:kernel-rt-debug-debuginfo, p-cpe:/a:rocky:linux:kernel-rt-debug-devel, p-cpe:/a:rocky:linux:kernel-rt-debug-modules-core, p-cpe:/a:rocky:linux:kernel-rt-debug-modules-extra, p-cpe:/a:rocky:linux:kernel-rt-debug-modules, p-cpe:/a:rocky:linux:kernel-rt-debug, p-cpe:/a:rocky:linux:kernel-rt-debuginfo, p-cpe:/a:rocky:linux:kernel-rt-devel, p-cpe:/a:rocky:linux:kernel-rt-modules-core, p-cpe:/a:rocky:linux:kernel-rt-modules-extra, p-cpe:/a:rocky:linux:kernel-rt-modules, p-cpe:/a:rocky:linux:kernel-rt, p-cpe:/a:rocky:linux:kernel-tools-debuginfo, p-cpe:/a:rocky:linux:kernel-tools-libs-devel, p-cpe:/a:rocky:linux:kernel-tools-libs, p-cpe:/a:rocky:linux:kernel-tools, p-cpe:/a:rocky:linux:kernel-uki-virt-addons, p-cpe:/a:rocky:linux:kernel-uki-virt, p-cpe:/a:rocky:linux:kernel-zfcpdump-core, p-cpe:/a:rocky:linux:kernel-zfcpdump-debuginfo, p-cpe:/a:rocky:linux:kernel-zfcpdump-devel-matched, p-cpe:/a:rocky:linux:kernel-zfcpdump-devel, p-cpe:/a:rocky:linux:kernel-zfcpdump-modules-core, p-cpe:/a:rocky:linux:kernel-zfcpdump-modules-extra, p-cpe:/a:rocky:linux:kernel-zfcpdump-modules, p-cpe:/a:rocky:linux:kernel-zfcpdump, p-cpe:/a:rocky:linux:kernel, p-cpe:/a:rocky:linux:libperf-debuginfo, p-cpe:/a:rocky:linux:libperf, p-cpe:/a:rocky:linux:perf-debuginfo, p-cpe:/a:rocky:linux:perf, p-cpe:/a:rocky:linux:python3-perf-debuginfo, p-cpe:/a:rocky:linux:python3-perf, p-cpe:/a:rocky:linux:rtla, p-cpe:/a:rocky:linux:rv

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RockyLinux/release, Host/RockyLinux/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/9/2026

Vulnerability Publication Date: 2/4/2026

Reference Information

CVE: CVE-2026-23103, CVE-2026-53360, CVE-2026-53365, CVE-2026-53398, CVE-2026-63970, CVE-2026-64035, CVE-2026-64115, CVE-2026-64162, CVE-2026-72317, CVE-2026-74744, CVE-2026-89530, CVE-2026-89663, CVE-2026-89669, CVE-2026-89690