Red Hat released Important Linux kernel updates for RHEL 9 under RHSA-2026:57252, addressing 26 CVEs across subsystems including netfilter, DRM/AMD GPU drivers, SMB client, iSCSI target, memfd, UDF, SMC, and POSIX CPU timers. The advisory highlights memory-safety issues such as buffer overflows, out-of-bounds reads and writes, use-after-free, double-free, and validation flaws, and requires affected systems to be rebooted after patching. Downstream distributions and vendors including Oracle Linux, Rocky Linux, AlmaLinux, and Unity Linux published corresponding kernel notices and scanner coverage, with several notices indicating local exploitation risk and, in some cases, that exploits are available.
Two AMD-related kernel flaws illustrate the update set: CVE-2026-45878 in drm/amdkfd fixed inconsistent signed/unsigned handling of a userspace-supplied watch_id, which could trigger invalid bit shifts, out-of-bounds access to the watch_points array, and a buffer overflow; and CVE-2026-53329 in drm/amd/display replaced krealloc() with krealloc_array() to prevent integer-overflow-driven undersized allocations that could lead to heap overflows during vector growth. The weaknesses align with well-known classes such as CWE-131 (incorrect calculation of buffer size), CWE-120 (classic buffer overflow), and in some bundled advisories CWE-279 (incorrect execution-assigned permissions), underscoring the need to prioritize kernel package updates across supported enterprise Linux fleets.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
A Nessus plugin entry says Rocky Linux 10 published patch information for RLSA-2026:57251 on 2026-08-21. The advisory covers a broad kernel package set and fixes multiple CVEs including CVE-2026-45878, CVE-2026-53329, CVE-2026-53143, and others.
A Nessus plugin entry says Rocky Linux 9 published patch information for RLSA-2026:57252 on 2026-08-21. The advisory bundles fixes for multiple kernel CVEs, including CVE-2026-43206, CVE-2026-45878, CVE-2026-53143, and related issues.
A Nessus plugin entry says AlmaLinux 8 published advisory ALSA-2026:57253 on 2026-08-20. The bundled kernel update addresses multiple CVEs, including CVE-2026-46120, CVE-2026-63888, CVE-2026-64048, CVE-2026-64379, and CVE-2026-68388.
A Nessus plugin states that Oracle Linux 9 advisory ELSA-2026-57252 published patches on 2026-08-20 for multiple kernel vulnerabilities. The advisory covers CVE-2026-45878, CVE-2026-53329, CVE-2026-53143, and other kernel issues affecting Oracle Linux 9 BaseOS patch level 8.
A Nessus plugin states that Oracle Linux 10 advisory ELSA-2026-57251 published patches on 2026-08-20 for multiple kernel vulnerabilities. The advisory includes CVE-2026-45878, CVE-2026-53329, CVE-2026-53143, and numerous other kernel flaws.
On 2026-08-20, Red Hat published RHSA-2026:57252, an Important kernel security advisory for Red Hat Enterprise Linux 9. The update fixes 26 CVEs across multiple kernel subsystems, including CVE-2026-45878 and CVE-2026-53329, and requires a reboot after installation.
A Nessus plugin entry says Unity Linux advisory UTSA-2026-102101 published a patch for CVE-2026-53329 on 2026-08-17. The update addresses the kernel drm/amd/display allocation overflow issue tracked in the advisory.
A Nessus plugin for Unity Linux states that CVE-2026-53329 was published on 2026-07-01. The flaw affects the Linux kernel drm/amd/display component, where integer overflow in dal_vector_reserve() could lead to an undersized allocation and heap overflow.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
13 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcebugzilla.redhat.com
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.