Red Hat released two Important security advisories for the Linux kernel in Red Hat Enterprise Linux 9.6 Extended Update Support, updating affected systems first to 5.14.0-570.129.1.el9_6 and later to 5.14.0-570.132.1.el9_6. The earlier advisory addressed eight kernel CVEs spanning components including VMCI, vt, Bluetooth, AMD display, SMB client, traffic scheduling, xfrm, and DRM GEM, alongside several bug fixes and enhancements. Red Hat said affected systems must be rebooted after applying the packages.
A subsequent advisory fixed three additional kernel vulnerabilities: CVE-2025-71131, CVE-2026-46054, and CVE-2026-52976. Red Hat’s Bugzilla entry for CVE-2025-71131 said the flaw was in the kernel crypto: seqiv code, where req->iv could be used after crypto_aead_encrypt returns even though the underlying request may already have been freed through asynchronous completion; the fix replaces that unsafe post-call check with a separate variable, unaligned_info. Red Hat said the issue was remediated for RHEL 9.6 EUS through RHSA-2026:52667, and customers were again instructed to apply the update and reboot.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
A vulnerability notice for Red Hat Enterprise Linux 9.6 EUS kernel packages reports that a patch was published for RHSA-2026:60486. The affected package family includes standard, 64K-page, real-time, debug, development, tools, and performance-related kernel components; no known exploits were reported.
On 2026-08-10, Red Hat published Important advisory RHSA-2026:52667 for Red Hat Enterprise Linux 9.6 Extended Update Support and related channels. The update shipped kernel version 5.14.0-570.132.1.el9_6 and fixed CVE-2025-71131, CVE-2026-46054, and CVE-2026-52976.
On 2026-07-23, Red Hat published Important advisory RHSA-2026:44385 for Red Hat Enterprise Linux 9.6 Extended Update Support and related channels. The update shipped kernel version 5.14.0-570.129.1.el9_6 and fixed eight kernel CVEs, including flaws in VMCI, vt, Bluetooth, AMD display, SMB client, traffic scheduling, xfrm, and DRM GEM.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.