Rocky Linux 8.10 - Patch Version Inquiry for CVE-2026-8924 and CVE-2026-43503

Hello,

I am using Rocky Linux 8.10 and would like to confirm the security status of the following CVEs:

  • CVE-2026-8924 (using Linux Kernel 4.18.0-553.8.1 and 4.18.0-553.34.1)
  • CVE-2026-43503 (using curl 7.61.1-34.el8.x86_64)

Could you please let me know:

  1. Is Rocky Linux 8.10 affected by these CVEs?
  2. If affected, which Rocky Linux package version (or release version) contains the fix?
  3. If Rocky Linux 8.10 is not affected, could you provide the reason (for example, the vulnerable code is not included or the fix has already been backported)?
  4. Is there a corresponding RLSA/RHSA advisory for these CVEs?

I would appreciate any information you can provide regarding the applicable package versions or security advisories.

Thank you for your support.

Since Rocky is pretty much exactly the same as RHEL it’s easy to google search and find links like: cve-details which shows that for RHEL8 Vulnerable Code not Present

This means the same result/answer for Rocky 8.10 as well.

As for the other CVE, from a quick google I haven’t found anything but you can try and google it and review the search results longer than I have spent doing it. You can also search Rocky Errata here: https://errata.rockylinux.org/ and also see if there are bugs open for it here: https://bugs.rockylinux.org/