Red Hat released Important security updates for the Linux kernel across RHEL 8, RHEL 9, and RHEL 10, including kernel-rt for Real Time deployments, fixing vulnerabilities in core subsystems such as SMB/CIFS client code, iSCSI target handling, SMC, sched/psi, memfd, UDF, netfilter, POSIX CPU timers, and AMD GPU drivers. The advisories cover nine CVEs in RHEL 8, 26 CVEs in RHEL 9, and 24 CVEs in RHEL 10, with affected offerings spanning standard, Extended Life Cycle, Extended Update Support, SAP, NFV, and CodeReady Linux Builder channels across x86_64, s390x, ppc64le, and aarch64. Red Hat said systems should be rebooted after applying the updates and reiterated that kernel errata should be treated as security-relevant because of the kernel’s central role.
Among the patched flaws, Red Hat detailed CVE-2026-53143, a buffer overflow in the drm/amdkfd driver on GFX11 that could leak or corrupt adjacent GTT memory during CRIU checkpoint and restore operations because SDMA queues used compute-specific handlers with the wrong MQD size. The company also fixed CVE-2026-63952 in memfd, where writable mappings could persist even when SEAL_EXEC implicitly applied SEAL_WRITE, weakening the expected write-seal guarantees and undermining W^X protections. The RHEL 9 advisory also includes non-security fixes, including a regression in 5.14.0-687.5.1.el9_8 that broke Wi-Fi when FIPS was enabled.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-20, a Red Hat Bugzilla entry described the resolution of CVE-2026-53356, a drm/i915/gem flaw in phys BO pread/pwrite handling where a non-zero offset could access the wrong parts of a buffer object due to incorrect pointer scaling. The entry states the fix was delivered in RHEL 9 and RHEL 10 through RHSA-2026:57252 and RHSA-2026:57251.
On 2026-08-20, a Red Hat Bugzilla entry described the resolution of CVE-2026-64382, an SMB client double-free in SMB2_open() replay handling caused by stale response bookkeeping across retry attempts. The entry states the fix was delivered in RHEL 9 and RHEL 10 through RHSA-2026:57252 and RHSA-2026:57251.
On 2026-08-20, a Red Hat Bugzilla entry described the resolution of CVE-2026-64386, an SMB client query_info() replay double-free caused by stale response bookkeeping across retry attempts. The entry states the fix was delivered in RHEL 9 and RHEL 10 through RHSA-2026:57252 and RHSA-2026:57251.
On 2026-08-20, a Red Hat Bugzilla entry described the resolution of CVE-2026-63952, a memfd sealing flaw that could leave writable mappings in place when SEAL_EXEC implicitly applied SEAL_WRITE. The entry states the fix was shipped in RHEL 9 and RHEL 10 via RHSA-2026:57252 and RHSA-2026:57251.
On 2026-08-20, a Red Hat Bugzilla entry described the resolution of CVE-2026-53143, a drm/amdkfd GFX11 SDMA queue checkpoint/restore buffer overflow that could leak or corrupt 1536 bytes of adjacent GTT memory. The entry states the fix was delivered in RHEL 9 and RHEL 10 through RHSA-2026:57252 and RHSA-2026:57251.
On 2026-08-20, Red Hat published Important advisory RHSA-2026:57251 for the RHEL 10 kernel. The update delivers security, bug-fix, and enhancement updates covering 24 CVEs across AMD GPU, SMB/CIFS, iSCSI, memfd, blk-mq, UDF, sched/psi, and POSIX CPU timer components.
On 2026-08-20, Red Hat published Important advisory RHSA-2026:57252 for the RHEL 9 kernel. The update addresses 26 CVEs affecting subsystems including netfilter, AMD GPU drivers, SMB client, iSCSI target, memfd, UDF, SMC, and POSIX CPU timers, and also includes several non-security bug fixes.
On 2026-08-20, Red Hat published Important advisory RHSA-2026:57254 for the kernel-rt package in RHEL 8. The update fixes nine kernel vulnerabilities and includes an additional fix for sfc TX queue stalls and NIC resets, with a reboot required after applying the package.
On 2026-08-20, Red Hat published Important advisory RHSA-2026:57253 for the RHEL 8 Linux kernel. The update provides fixes for nine CVEs across ieee802154, ip6_gre, sched/psi, huge memory, iSCSI, SMC, and SMB client code, and requires a reboot after installation.
On 2026-08-17, Red Hat published Important advisory RHSA-2026:55765 for the kernel-rt package in RHEL 8. The update addresses ten kernel vulnerabilities across components including mm/slub, drm/amdkfd, drm/amdgpu, drm/amd/display, drm/i915, crypto:ccp, and can:bcm, and requires a reboot after installation.
On 2026-08-17, Red Hat published Important advisory RHSA-2026:55764 for the RHEL 8 Linux kernel. The update addresses ten CVEs across components including mm/slub, drm/amdkfd, drm/amdgpu, drm/amd/display, drm/i915, crypto ccp, and can:bcm, and requires a reboot after installation.
On 2026-08-17, a Red Hat Bugzilla entry described the resolution of CVE-2026-53374, an amdgpu GART table initialization flaw that could let the GPU use stale garbage page table entries due to uninitialized PTEs being speculatively loaded. The entry states the fix was addressed in RHEL 8, 9, and 10 through RHSA-2026:55765, RHSA-2026:55764, RHSA-2026:57252, and RHSA-2026:57251.
On 2026-08-17, a Red Hat Bugzilla entry described the resolution of CVE-2026-63879, a drm/amdgpu flaw in amdgpu_hmm_range_get_pages where reading the notifier sequence more than once could cause the code to operate on invalid pages. The entry states the fix was addressed in RHEL 8, 9, and 10 through RHSA-2026:55765, RHSA-2026:55764, RHSA-2026:57252, and RHSA-2026:57251.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.