Red Hat released Important security updates for the Linux kernel across RHEL 8, RHEL 9, and RHEL 10, including kernel-rt for Real Time deployments, fixing vulnerabilities in core subsystems such as SMB/CIFS client code, iSCSI target handling, SMC, sched/psi, memfd, UDF, netfilter, POSIX CPU timers, and AMD GPU drivers. The advisories cover nine CVEs in RHEL 8, 26 CVEs in RHEL 9, and 24 CVEs in RHEL 10, with affected offerings spanning standard, Extended Life Cycle, Extended Update Support, SAP, NFV, and CodeReady Linux Builder channels across x86_64, s390x, ppc64le, and aarch64. Red Hat said systems should be rebooted after applying the updates and reiterated that kernel errata should be treated as security-relevant because of the kernel’s central role.
Among the patched flaws, Red Hat detailed CVE-2026-53143, a buffer overflow in the drm/amdkfd driver on GFX11 that could leak or corrupt adjacent GTT memory during CRIU checkpoint and restore operations because SDMA queues used compute-specific handlers with the wrong MQD size. The company also fixed CVE-2026-63952 in memfd, where writable mappings could persist even when SEAL_EXEC implicitly applied SEAL_WRITE, weakening the expected write-seal guarantees and undermining W^X protections. The RHEL 9 advisory also includes non-security fixes, including a regression in 5.14.0-687.5.1.el9_8 that broke Wi-Fi when FIPS was enabled.

See real exploitation activity before you spend the cycle.
47 events from the most recent confirmed update back to the earliest known activity.
On 2026-09-04, Red Hat published Important advisory RHSA-2026:63538 for standard RHEL 7 kernel packages. The update fixes CVE-2026-74480, a network-reachable bridge fast-leave use-after-free after port-group deletion, and addresses an nft_rbtree_lookup NULL-pointer dereference tracked as RHEL-235483.
On 2026-09-04, Red Hat published Important advisory RHSA-2026:63539 for affected RHEL 7 Real Time kernel packages. The update fixes CVE-2026-74480, a network-reachable bridge fast-leave use-after-free issue after port-group deletion, and includes a fix for an nft_rbtree_lookup NULL-pointer dereference tracked as JIRA:RHEL-235483.
On 2026-09-03, Red Hat issued Important advisory RHSA-2026:63014 for RHEL 8 kernel packages, including RHEL 8.10 Extended Life Cycle variants. The update installs kernel 4.18.0-553.159.1.el8_10, fixes 14 CVEs including bonding, zram, pNFS, IPv6, MANA, and RDMA/siw flaws, and requires affected systems to reboot.
On 2026-09-03, Red Hat issued Important advisory RHSA-2026:63013 for RHEL 8 kernel-rt packages, including Real Time, Real Time for NFV, and RHEL 8.10 Extended Life Cycle systems. The update installs kernel-rt 4.18.0-553.159.1.rt7.500.el8_10 and fixes 14 CVEs, including use-after-free flaws in bonding, zram, pNFS, and IPv6, as well as a remote RDMA/siw out-of-bounds write; affected systems must reboot.
On 2026-09-03, AlmaLinux published advisory ALSA-2026:63013 for AlmaLinux 8 real-time kernel packages. The update addresses 14 CVEs, including CVE-2024-57849 and CVEs assigned in 2025 and 2026; Tenable reported no known exploits.
On 2026-09-02, Red Hat published Important advisory RHSA-2026:62508 for RHEL 9.2 SAP Solutions, AUS, and Extended Life Cycle offerings. Kernel version 5.14.0-284.190.1.el9_2 fixes CVE-2026-64002 in IPv4 sysctl cleanup and CVE-2026-74480 in bridge fast-leave handling; administrators must reboot after installation.
On 2026-09-02, Red Hat published Important advisory RHSA-2026:62346 for RHEL 9.4 Update Services for SAP Solutions and related service offerings. The kernel 5.14.0-427.148.1.el9_4 update fixes CVE-2026-64002 in IPv4 sysctl cleanup and CVE-2026-74480 involving bridge fast-leave behavior after port-group deletion; affected systems require a reboot.
On 2026-09-01, AlmaLinux published ALSA-2026:61887 for AlmaLinux 10 kernel packages and variants, referencing RHSA-2026:61887. The update addresses 34 Linux kernel CVEs across standard, 64K-page, real-time, debug, zfcpdump, tools, and related package variants; Tenable reported no known exploits.
On 2026-09-01, Red Hat issued Important advisory RHSA-2026:61887 for the RHEL 10 Linux kernel. The update remediates 34 CVEs across seccomp, networking, NFS/NFSD, SMB, memory management, cryptography, virtualization, and device drivers, including CVE-2026-68166, an arbitrary-code-execution flaw involving userfaultfd shadow-stack manipulation; affected systems must reboot after installation.
On 2026-08-26, AlmaLinux published ALSA-2026:59737 for kernel-rt packages in AlmaLinux 8 repositories. The update addresses eight CVEs, including the network-reachable iSCSI CHAP heap-overflow vulnerability CVE-2026-63886; Tenable reported no known exploits.
On 2026-08-26, Red Hat issued Important advisory RHSA-2026:59821 for the RHEL 8 and RHEL 8.10 Extended Life Cycle kernel. The update provides kernel version 4.18.0-553.158.1.el8_10, fixes eight CVEs affecting SCTP, iSCSI CHAP, Netfilter, I2C, NVMe target discovery, and Synaptics RMI4 drivers, and requires a reboot after installation.
On 2026-08-26, Red Hat released Important advisory RHSA-2026:59737 for affected RHEL 8 and RHEL 8.10 EUS kernel-rt packages. The update remediates eight kernel vulnerabilities affecting SCTP, iSCSI CHAP handling, Netfilter, I2C, NVMe target discovery, and Synaptics RMI4 drivers, including the critical-network-vector CVE-2026-63886.
On 2026-08-20, a Red Hat Bugzilla entry described the resolution of CVE-2026-53356, a drm/i915/gem flaw in phys BO pread/pwrite handling where a non-zero offset could access the wrong parts of a buffer object due to incorrect pointer scaling. The entry states the fix was delivered in RHEL 9 and RHEL 10 through RHSA-2026:57252 and RHSA-2026:57251.
On 2026-08-20, a Red Hat Bugzilla entry described the resolution of CVE-2026-64382, an SMB client double-free in SMB2_open() replay handling caused by stale response bookkeeping across retry attempts. The entry states the fix was delivered in RHEL 9 and RHEL 10 through RHSA-2026:57252 and RHSA-2026:57251.
On 2026-08-20, a Red Hat Bugzilla entry described the resolution of CVE-2026-64386, an SMB client query_info() replay double-free caused by stale response bookkeeping across retry attempts. The entry states the fix was delivered in RHEL 9 and RHEL 10 through RHSA-2026:57252 and RHSA-2026:57251.
On 2026-08-20, a Red Hat Bugzilla entry described the resolution of CVE-2026-63952, a memfd sealing flaw that could leave writable mappings in place when SEAL_EXEC implicitly applied SEAL_WRITE. The entry states the fix was shipped in RHEL 9 and RHEL 10 via RHSA-2026:57252 and RHSA-2026:57251.
On 2026-08-20, a Red Hat Bugzilla entry described the resolution of CVE-2026-53143, a drm/amdkfd GFX11 SDMA queue checkpoint/restore buffer overflow that could leak or corrupt 1536 bytes of adjacent GTT memory. The entry states the fix was delivered in RHEL 9 and RHEL 10 through RHSA-2026:57252 and RHSA-2026:57251.
On 2026-08-20, AlmaLinux 10 published advisory ALSA-2026:57251 for its kernel package set, referencing RHSA-2026:57251 and numerous affected kernel, realtime, debug, and tooling packages across multiple repositories. The notice lists multiple CVEs, including CVE-2026-53143, CVE-2026-53356, CVE-2026-53374, CVE-2026-63879, CVE-2026-63952, CVE-2026-64382, and CVE-2026-64386, and states exploits are available.
On 2026-08-20, Red Hat published Important advisory RHSA-2026:57251 for the RHEL 10 kernel. The update delivers security, bug-fix, and enhancement updates covering 24 CVEs across AMD GPU, SMB/CIFS, iSCSI, memfd, blk-mq, UDF, sched/psi, and POSIX CPU timer components.
On 2026-08-20, Red Hat published Important advisory RHSA-2026:57252 for the RHEL 9 kernel. The update addresses 26 CVEs affecting subsystems including netfilter, AMD GPU drivers, SMB client, iSCSI target, memfd, UDF, SMC, and POSIX CPU timers, and also includes several non-security bug fixes.
On 2026-08-20, Red Hat published Important advisory RHSA-2026:57254 for the kernel-rt package in RHEL 8. The update fixes nine kernel vulnerabilities and includes an additional fix for sfc TX queue stalls and NIC resets, with a reboot required after applying the package.
On 2026-08-20, Red Hat published Important advisory RHSA-2026:57253 for the RHEL 8 Linux kernel. The update provides fixes for nine CVEs across ieee802154, ip6_gre, sched/psi, huge memory, iSCSI, SMC, and SMB client code, and requires a reboot after installation.
On 2026-08-17, Red Hat published Important advisory RHSA-2026:55765 for the kernel-rt package in RHEL 8. The update addresses ten kernel vulnerabilities across components including mm/slub, drm/amdkfd, drm/amdgpu, drm/amd/display, drm/i915, crypto:ccp, and can:bcm, and requires a reboot after installation.
On 2026-08-17, Red Hat published Important advisory RHSA-2026:55764 for the RHEL 8 Linux kernel. The update addresses ten CVEs across components including mm/slub, drm/amdkfd, drm/amdgpu, drm/amd/display, drm/i915, crypto ccp, and can:bcm, and requires a reboot after installation.
On 2026-08-17, a Red Hat Bugzilla entry described the resolution of CVE-2026-53374, an amdgpu GART table initialization flaw that could let the GPU use stale garbage page table entries due to uninitialized PTEs being speculatively loaded. The entry states the fix was addressed in RHEL 8, 9, and 10 through RHSA-2026:55765, RHSA-2026:55764, RHSA-2026:57252, and RHSA-2026:57251.
On 2026-08-17, a Red Hat Bugzilla entry described the resolution of CVE-2026-63879, a drm/amdgpu flaw in amdgpu_hmm_range_get_pages where reading the notifier sequence more than once could cause the code to operate on invalid pages. The entry states the fix was addressed in RHEL 8, 9, and 10 through RHSA-2026:55765, RHSA-2026:55764, RHSA-2026:57252, and RHSA-2026:57251.
On 2026-01-19, Red Hat issued Important advisory RHSA-2026:0759 for the RHEL 8 Linux kernel. The update fixes five vulnerabilities affecting SMB/CIFS client processing, Intel i915 DRM, DRM scheduling, and the Atlantic network driver, and requires affected systems to reboot after installing kernel version 4.18.0-553.94.1.el8_10.
Red Hat documented CVE-2026-74480, a bridge multicast fast-leave flaw where continued iteration after deleting a port group can leave mp->ports pointing to freed state. The issue has a reported public exploit, including one targeting RHEL 10.2, and Red Hat lists fixes across supported RHEL 7, 8, 9, and 10 lifecycle offerings, including RHSA-2026:62346.
Red Hat documented CVE-2026-64490, in which the ALSA virtio-snd driver trusted device-supplied control type and value-count metadata for fixed-size array indexing, loop sizing, and memory copies, enabling a malicious or faulty virtio sound device to cause out-of-bounds kernel memory access. The fix validates the metadata in virtsnd_kctl_parse_cfg(); remediation is listed for RHEL 10 via RHSA-2026:61887 and RHEL 9 via RHSA-2026:63129.
Red Hat documented CVE-2026-72130, in which a remote authenticated NVMe-oF initiator could send a one-byte AUTH_RECEIVE allocation length and trigger a 16-byte heap out-of-bounds write while an auth-enabled target constructed DH-HMAC-CHAP responses. The fix validates the state-specific minimum response size before response construction; remediation is listed for RHEL 10 via RHSA-2026:61887 and RHEL 9 via RHSA-2026:63129.
Red Hat documented CVE-2026-64438, a use-after-free in the Intel QAT driver's SR-IOV teardown path where queued or executing VF2PF response work could dereference freed per-VF state. The fix blocks VF2PF work during teardown, synchronizes the MSI-X interrupt, and flushes the response workqueue; remediation is listed for RHEL 10 via RHSA-2026:61887 and RHEL 9 via RHSA-2026:63129.
Red Hat documented CVE-2026-64002, in which ipv4_sysctl_exit_net() could free net->ipv4.sysctl_local_reserved_ports before unregister_net_sysctl_table() had prevented concurrent access to IPv4 sysctls. The fix defers freeing the data until after sysctl-table unregistration; Red Hat lists remediation in multiple RHEL 8, 9, and 10 support channels, including RHSA-2026:61310, RHSA-2026:61932, RHSA-2026:62346, RHSA-2026:62568, RHSA-2026:62609, and RHSA-2026:63129.
Red Hat documented CVE-2026-72069, in which the real-time rt_spin_unlock() implementation released RCU read-side protection before completing lock-unlock operations, enabling a race that could result in use-after-free during RT mutex operations. The fix moves rcu_read_unlock() until after the unlock path; Red Hat lists remediation in RHEL 10 through RHSA-2026:61887 and RHEL 9 through RHSA-2026:63129.
Red Hat documented CVE-2026-43450, an 8-byte out-of-bounds read in netfilter's nfnl_cthelper_dump_table() that could occur when restart logic bypassed the loop bounds check after a conntrack helper was deleted between dump rounds. The fix moves restart processing into the bounded loop; Red Hat lists remediation for RHEL 8 through RHSA-2026:36348 and RHSA-2026:36349, and for RHEL 9 through RHSA-2026:51035.
Red Hat documented CVE-2025-71132, a smc91x network-driver flaw under PREEMPT_RT where smc_special_trylock() disables interrupts without smc_special_unlock() restoring them, causing workqueue warnings about leaked atomic, lock, or RCU state. The upstream fix replaces the locking operation with spin_trylock_irqsave(); Red Hat lists RHEL 8 remediation through RHSA-2026:63013 and RHSA-2026:63014.
Red Hat documented CVE-2026-63800, a pNFS use-after-free in pnfs_update_layout() where the NFS_LAYOUT_RETURN path could release a layout header before trace_pnfs_update_layout() accessed it. The upstream fix moves the tracepoint before pnfs_put_layout_hdr(); Red Hat lists remediation in RHEL 10 via RHSA-2026:61887, RHEL 8 via RHSA-2026:63013 and RHSA-2026:63014, and RHEL 9 via RHSA-2026:63129.
Red Hat documented CVE-2026-45970, a bonding ALB receive-path use-after-free in which rlb_arp_recv() can race with rlb_deinitialize() during bond interface teardown and ARP processing, causing a kernel crash. The fix clears recv_probe and calls synchronize_net() before freeing resources; Red Hat lists remediation in RHEL 10 via RHSA-2026:61887, RHEL 8 via RHSA-2026:63013 and RHSA-2026:63014, and RHEL 9 via RHSA-2026:63129.
Red Hat documented CVE-2024-57849, a use-after-free in s390 CPUMF sampling during CPU hot-remove, where performance-event cleanup could access sampling data buffers after they were freed. The upstream fix checks PMU_F_RESERVED before accessing the buffers; Red Hat lists RHEL 8 remediation through RHSA-2026:63013 and RHSA-2026:63014.
Red Hat documented CVE-2026-68166, in which userfaultfd registration on shadow-stack VMAs could let an attacker discard and replace a return-address page using UFFDIO_COPY, undermining shadow-stack control-flow integrity. The fix rejects VM_SHADOW_STACK and VM_SPECIAL mappings in vma_can_userfault(); Red Hat lists remediation in RHEL 10 via RHSA-2026:61887 and RHEL 9 via RHSA-2026:63129.
Red Hat documented CVE-2026-53185, a zram_bvec_write_partial() use-after-free where an asynchronous backing-device read could remain in flight and write into a page after it was freed. The issue was remediated for RHEL 9 via RHSA-2026:59723, RHEL 10 via RHSA-2026:61887, and RHEL 8 via RHSA-2026:63013 and RHSA-2026:63014.
Red Hat documented CVE-2026-63913, a Netfilter TCP conntrack flaw in which an invalid-sequence TCP RST could force a conntrack entry into the CLOSE state and prematurely terminate an active NAT entry. The fix permits RST-triggered CLOSE transitions only for valid responses to a previously observed SYN in the correct direction; remediation is listed for RHEL 8 in RHSA-2026:59737 and RHSA-2026:59821.
Red Hat documented CVE-2026-64189, a netfilter/ipset race in which dump paths could access a freed ip_set_list array while a concurrent ip_set_create() resized it, causing a slab use-after-free, kernel fault, or panic. The fix adds RCU read-side protection around the array access; Red Hat lists remediation for RHEL 8 and 9 via RHSA-2026:59737, RHSA-2026:59821, and RHSA-2026:59723.
Red Hat documented CVE-2026-64191, in which invalid I2C block-transfer lengths in the modular i2c-stub test driver could cause out-of-bounds reads or writes. The fix rejects zero-length and overlong transfers; Red Hat lists remediation for RHEL 8 via RHSA-2026:59737 and RHSA-2026:59821, and for RHEL 9 via RHSA-2026:59723.
Red Hat documented CVE-2026-63886, an iSCSI target CHAP-authentication heap overflow where Base64-decoded responses could exceed the allocated client_digest buffer by up to 79 bytes. The fix validates unpadded Base64 input length before decoding; Red Hat lists remediation in RHEL 10 via RHSA-2026:57251 and RHEL 8 via RHSA-2026:59737 and RHSA-2026:59821.
Red Hat documented resolution of CVE-2023-52707, a Linux kernel sched/psi use-after-free in ep_remove_wait_queue(). The issue was addressed for RHEL 9.2 EUS through RHSA-2024:4823 and RHSA-2024:4831, and for RHEL 8 through RHSA-2024:5102 and RHSA-2024:5101.
Red Hat documented resolution of CVE-2025-38396, a secretmem regression in which anonymous inode file descriptors retained S_PRIVATE after alloc_anon_inode(), bypassing LSM and SELinux checks. The issue was addressed for RHEL 10 through RHSA-2025:16904 and for RHEL 9 through RHSA-2025:20518.
Red Hat documented resolution of CVE-2025-39881, a Linux kernel kernfs polling use-after-free affecting PSI monitoring through cgroup pressure files. Fixes using kernfs_get_active_of() were issued for RHEL 10 via RHSA-2025:19469 and RHSA-2025:21118, RHEL 9 via RHSA-2025:21469, and RHEL 9.6 EUS via RHSA-2025:22392.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
50 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.