Red Hat released Important kernel security updates and live patches for multiple Red Hat Enterprise Linux versions to remediate several Linux kernel vulnerabilities, including CVE-2026-43499, CVE-2026-46116, and CVE-2026-46227. The updates span standard kernel packages for RHEL 7 ELS and RHEL 9, as well as kpatch live-patch modules for RHEL 9 and RHEL 10, allowing some systems to receive fixes without a reboot. The advisories also bundle additional kernel issues such as CVE-2026-45984, CVE-2026-53166, CVE-2026-64531, and CVE-2026-31684, affecting a broad set of x86_64, ppc64le, s390x, and aarch64 product variants, including SAP, EUS, and ELS offerings.
The patched flaws include an rtmutex bug in remove_waiter() that could manipulate the wrong task state during futex proxy locking, an xfrm state-deletion bug that triggered slab use-after-free and out-of-bounds writes under repeated list removal, and an SCTP SCTP_SENDALL iterator flaw that could leave a stale association pointer after the socket lock was dropped, creating use-after-free or type-confusion conditions. Red Hat said fixes were propagated across numerous RHEL 8, 9, and 10 streams and support channels, with standard kernel packages requiring a reboot and kpatch updates available for selected RHEL 9 and RHEL 10 kernels.

See real exploitation activity before you spend the cycle.
44 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:59148, an Important security advisory for multiple kpatch live kernel patch packages on Red Hat Enterprise Linux 9.6 Extended Update Support and related service variants. The live patch update fixed CVE-2026-43499, CVE-2026-45984, CVE-2026-46116, and CVE-2026-46227 for affected x86_64 and ppc64le offerings.
Red Hat published RHSA-2026:59145, an Important security advisory for multiple kpatch live patch packages in Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions and related RHEL 9.4 channels. The live patch update fixed CVE-2026-43499, CVE-2026-45984, CVE-2026-46116, CVE-2026-46227, and CVE-2026-64531.
Red Hat published RHSA-2026:59147, an Important security advisory for multiple kpatch live kernel patch packages in Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and related 9.2 variants. The live patch update fixed CVE-2026-43499, CVE-2026-45984, CVE-2026-46116, CVE-2026-46227, and CVE-2026-64531.
Red Hat published RHSA-2026:59142, an Important security advisory for multiple kpatch live patch packages in Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions. The live patch update fixed CVE-2026-43499, CVE-2026-45984, CVE-2026-46116, and CVE-2026-46227 for affected RHEL 8.8 SAP and related 8.8 offerings.
Red Hat published RHSA-2026:59146, an Important security advisory for multiple kpatch live patch packages on Red Hat Enterprise Linux 8. The live patch update fixed CVE-2026-43499, CVE-2026-45984, CVE-2026-46116, and CVE-2026-46227 for RHEL 8 and ELS 8.10 systems.
Red Hat published RHSA-2026:59149 for kpatch-patch-5_14_0-687_10_1 on Red Hat Enterprise Linux 9. The live kernel patch fixed CVE-2026-43499, CVE-2026-46116, and CVE-2026-46227 together with CVE-2026-45984 and CVE-2026-64531.
Red Hat published RHSA-2026:59143 for kpatch-patch-6_12_0-211_16_1 on Red Hat Enterprise Linux 10. The live kernel patch fixed CVE-2026-43499, CVE-2026-46116, and CVE-2026-46227 along with two additional kernel vulnerabilities.
Red Hat published RHSA-2026:53330, an Important kernel security update for Red Hat Enterprise Linux 10. The advisory fixed seven vulnerabilities including CVE-2024-53143, CVE-2025-71072, CVE-2026-23415, CVE-2026-31488, CVE-2026-52923, CVE-2026-64368, and CVE-2026-64531 across multiple RHEL 10 variants and architectures.
Red Hat published RHSA-2026:52764, an Important kernel security update for Red Hat Enterprise Linux 10.0 Extended Update Support and related 10.0 channels. The advisory fixed eight vulnerabilities including CVE-2026-31787, CVE-2026-52923, CVE-2026-46054, CVE-2026-31613, CVE-2026-43112, CVE-2026-52976, CVE-2026-22990, and CVE-2025-71116 in kernel version 6.12.0-55.95.1.el10_0 across multiple architectures.
Red Hat published RHSA-2026:51603, an Important security advisory for kernel packages in Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and related RHEL 9.2 variants. The update fixed six vulnerabilities including CVE-2025-40026, CVE-2026-31787, CVE-2026-45984, CVE-2025-10263, CVE-2026-52923, and CVE-2026-64531.
Red Hat published RHSA-2026:51604, an Important security advisory for the kernel-rt package in Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. The update fixed six vulnerabilities, including CVE-2025-40026, CVE-2026-31787, CVE-2026-45984, CVE-2025-10263, CVE-2026-52923, and CVE-2026-64531.
Red Hat published RHSA-2026:49033, an Important kernel security update for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and 8.6 Extended Update Support Long-Life Add-On. The advisory fixed five vulnerabilities including CVE-2026-46116, CVE-2026-46113, CVE-2026-53359, CVE-2026-64530, and CVE-2025-10263.
Red Hat published RHSA-2026:47632, an Important security advisory for the kernel-rt package in Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and Extended Life Cycle 9.2. The update fixed four vulnerabilities: CVE-2026-31488, CVE-2026-31684, CVE-2026-46116, and CVE-2026-46209 in kernel-rt package version 5.14.0-284.183.1.rt14.468.el9_2.
Red Hat published RHSA-2026:47633, an Important kernel security update for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On. The advisory fixed ten vulnerabilities including CVE-2025-68183, CVE-2025-68724, CVE-2026-31613, CVE-2026-31684, CVE-2026-43027, CVE-2026-43279, CVE-2026-46116, CVE-2026-46189, CVE-2026-46209, and CVE-2026-46135 in kernel package version 4.18.0-305.199.1.el8_4.
Red Hat published RHSA-2026:47739, an Important kernel security update for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and related RHEL 9.2 variants. The advisory fixed four vulnerabilities: CVE-2026-31488, CVE-2026-31684, CVE-2026-46116, and CVE-2026-46209 in kernel package version 5.14.0-284.183.1.el9_2 across multiple architectures.
Red Hat published RHSA-2026:47869, an Important kernel security update for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Telecommunications Update Service. The advisory fixed multiple vulnerabilities including CVE-2025-40026, CVE-2026-31488, CVE-2026-31684, CVE-2026-46116, and CVE-2026-46135 in kernel package version 4.18.0-477.156.1.el8_8.
Red Hat published RHSA-2026:43231, an Important kernel security update for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions and related 9.4 variants. The advisory fixed five vulnerabilities—CVE-2026-31488, CVE-2026-31684, CVE-2026-46116, CVE-2026-46135, and CVE-2026-46209—and included an NVMe-FC panic bug fix in kernel version 5.14.0-427.139.1.el9_4.
Red Hat published RHSA-2026:42919 for Red Hat Enterprise Linux 10 kernel packages, providing a fix for CVE-2026-46116 in the xfrm IPSec framework. The CVE page states the RHEL 10 kernel packages were fixed on July 21, 2026.
Red Hat published RHSA-2026:41920, an Important kernel security update for Red Hat Enterprise Linux 6 Extended Lifecycle Support Extension. The advisory fixed CVE-2026-43499 in kernel package version 2.6.32-754.62.1.el6 across x86_64, i386, and IBM z Systems s390x offerings.
Red Hat published RHSA-2026:41236, a Critical security advisory for the kernel-rt package in Red Hat Enterprise Linux 7 Extended Lifecycle Support. The update released kernel-rt 3.10.0-1160.155.1.rt56.1307.el7 for x86_64 and fixed 16 vulnerabilities including CVE-2026-23243, CVE-2026-23455, CVE-2026-43163, CVE-2026-43198, CVE-2026-45852, CVE-2026-46090, and CVE-2026-46243.
Red Hat published RHSA-2026:41235, an Important kernel security update for Red Hat Enterprise Linux 7 Extended Lifecycle Support. The advisory fixed CVE-2026-43499 and CVE-2026-46116 together with CVE-2026-31684 and CVE-2026-53166.
Red Hat published RHSA-2026:41234 for the RHEL 7 Extended Lifecycle Support kernel-rt package. The update fixed CVE-2026-43499 and CVE-2026-46116 alongside two other kernel vulnerabilities.
Red Hat published RHSA-2026:41063, an Important kernel security update for Red Hat Enterprise Linux 9.4 offerings, including Update Services for SAP Solutions and Extended Life Cycle variants. The advisory fixed CVE-2026-43499, CVE-2026-53166, and CVE-2026-64600 in kernel package version 5.14.0-427.138.1.el9_4 across multiple architectures.
Red Hat published RHSA-2026:41062, an Important kernel security update for Red Hat Enterprise Linux 10.0 Extended Update Support and related 10.0 channels. The advisory fixed CVE-2026-43499, CVE-2026-53166, and CVE-2026-64600 in kernel package version 6.12.0-55.89.1.el10_0 across multiple architectures.
Red Hat published RHSA-2026:40760, an Important kernel security update for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. The advisory fixed eight vulnerabilities including CVE-2026-43499 and CVE-2026-53166 in kernel package version 4.18.0-477.152.1.el8_8.
Red Hat published RHSA-2026:40425, an Important kernel security update for Red Hat Enterprise Linux 9.6 Extended Update Support and related RHEL 9.6 service variants. The advisory fixed CVE-2026-43499, CVE-2026-53166, and CVE-2026-64600 in kernel package version 5.14.0-570.128.1.el9_6 across multiple architectures.
Red Hat published RHSA-2026:40068, an Important kernel security update for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and 8.6 Extended Update Support Long-Life Add-On. The advisory fixed nine vulnerabilities including CVE-2026-43499, CVE-2026-53166, CVE-2026-31684, CVE-2026-46209, and several additional kernel flaws in package version 4.18.0-372.201.1.el8_6.
Red Hat published RHSA-2026:39984, an Important kernel security update for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On. The advisory fixed CVE-2026-43499, CVE-2026-53166, and CVE-2026-64600 in kernel package version 4.18.0-305.198.1.el8_4 for affected x86_64 offerings.
Red Hat published RHSA-2026:39371, an Important kernel security update for Red Hat Enterprise Linux 10.0 Extended Update Support and related 10.0 channels. The advisory updated kernel packages to version 6.12.0-55.88.1.el10_0 and fixed 14 vulnerabilities including CVE-2025-38653, CVE-2025-68183, CVE-2025-68724, CVE-2026-31408, CVE-2026-46116, CVE-2026-46135, and CVE-2026-53359.
Red Hat published RHSA-2026:39082, an Important security update for kernel-rt on Red Hat Enterprise Linux 8. The advisory fixed eight vulnerabilities including CVE-2026-43499, CVE-2026-53166, CVE-2026-46113, CVE-2026-53359, CVE-2026-53266, CVE-2026-31411, CVE-2025-71066, and CVE-2025-71089 across RHEL for Real Time 8, Real Time for NFV 8, and ELC 8.10 x86_64 offerings.
Red Hat published RHSA-2026:38492, an Important kernel security update for Red Hat Enterprise Linux 10. The advisory fixed CVE-2026-43163, CVE-2026-43499, and CVE-2026-53166 across multiple RHEL 10 variants and architectures.
Red Hat published RHSA-2026:37728, an Important security advisory for the kernel in NVIDIA for RHEL 10 on ARM 64 10 aarch64. The update fixed CVE-2026-43499 and CVE-2026-53166 in kernel package version 6.12.0-231.16.el10nv.
Red Hat published RHSA-2026:36956, an Important kernel security update for Red Hat Enterprise Linux 10. The advisory fixed four vulnerabilities: CVE-2025-71066, CVE-2026-46227, CVE-2026-46113, and CVE-2026-53359 across multiple RHEL 10 variants and architectures.
Red Hat published RHSA-2026:36348, an Important security advisory for kernel-rt on Red Hat Enterprise Linux 8. The update fixed six vulnerabilities including CVE-2026-43198, CVE-2026-43450, CVE-2026-46227, CVE-2026-46209, CVE-2026-46259, and CVE-2025-10263 across RHEL for Real Time 8, Real Time for NFV 8, and ELC 8.10 x86_64 offerings.
Red Hat published RHSA-2026:36349, an Important kernel security update for Red Hat Enterprise Linux 8. The advisory fixed six vulnerabilities including CVE-2026-43198, CVE-2026-43450, CVE-2026-46227, CVE-2026-46209, CVE-2026-46259, and CVE-2025-10263 across multiple RHEL 8 variants and architectures.
Red Hat published RHSA-2026:36018, an Important kernel security update for Red Hat Enterprise Linux 9. The advisory included fixes for CVE-2026-46116 in xfrm and CVE-2026-46227 in SCTP among other kernel vulnerabilities.
Red Hat published RHSA-2026:33899, an Important kernel security update for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and 8.6 Extended Update Support Long-Life Add-On. The advisory fixed nine vulnerabilities including CVE-2025-71116, CVE-2026-22984, CVE-2026-22990, CVE-2026-23455, CVE-2026-43125, CVE-2026-43329, CVE-2026-45852, CVE-2026-46090, and CVE-2026-46227 in kernel package version 4.18.0-372.198.1.el8_6.
An upstream Linux kernel advisory documented CVE-2026-53166, a futex/requeue flaw where FUTEX_CMP_REQUEUE_PI could trigger a NULL pointer dereference in remove_waiter() and crash the kernel. The fix added a self-deadlock check for non-top waiters before calling rt_mutex_start_proxy_lock().
Red Hat published RHSA-2026:27735, an Important kernel security update for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions and related RHEL 9.4 variants. The advisory updated kernel packages to version 5.14.0-427.132.1.el9_4 and fixed 10 vulnerabilities including CVE-2025-71116, CVE-2026-22984, CVE-2026-22990, CVE-2026-43116, CVE-2026-43158, CVE-2026-46125, CVE-2026-46227, CVE-2026-46243, and CVE-2026-46323.
Red Hat published RHSA-2026:27789, an Important kernel security update for Red Hat Enterprise Linux 9. The advisory fixed 17 vulnerabilities including CVE-2026-45984, CVE-2026-31787, CVE-2026-31474, and multiple Bluetooth, Wi-Fi, RDMA, SCSI, and nvmet-tcp flaws across several RHEL 9 variants and architectures.
An upstream Linux kernel advisory documented CVE-2026-46116, an xfrm_state deletion flaw in __xfrm_state_delete() that could cause slab use-after-free and out-of-bounds writes. The fix switched affected list removals to hlist_del_init_rcu() and used hlist_unhashed() checks so repeated deletions become harmless.
Keith Grant linked the upstream lore.kernel.org advisory for CVE-2026-45984, covering a GFS2 use-after-free in the iomap inline data write path and its fix to retain the buffer head until gfs2_iomap_end().
Keith Grant referenced the upstream linux-cve-announce advisory for CVE-2026-43499, covering the rtmutex remove_waiter() flaw and its fix to use waiter::task instead of current.
An upstream Linux kernel advisory documented CVE-2026-31787, a Xen privcmd double-free flaw caused by VMA splitting of privcmd mappings after partial munmap(). The fix added a .may_split callback to deny splitting of the affected VMA and prevent both VMAs from freeing the same pages array.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 34 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
48 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.