Red Hat released a series of Important security updates for Red Hat Enterprise Linux and OpenShift Container Platform to address Linux kernel vulnerabilities including CVE-2025-40026 in KVM on x86 and CVE-2026-52923 in the SysV IPC checkpoint/restore path. The KVM flaw affects nested virtualization: after KVM has allowed an L2 guest I/O operation, changes to L1 or host userspace I/O interception during the userspace exit can cause KVM to wrongly re-check intercepts, leave vcpu->arch.pio.count non-zero, trigger a WARN, and disrupt guest execution. The IPC flaw stems from ipc_idr_alloc() passing ids->next_id to idr_alloc() without enforcing the valid ipc_mni range, allowing out-of-range allocation, stale IDR entries, and a potential use-after-free during /proc/sysvipc/shm traversal.
Affected fixes were published across multiple product streams, including RHEL 8.4, RHEL 8.8, RHEL 9.4, RHEL 9.6, and OpenShift Container Platform 4.18.53, alongside other kernel CVEs such as CVE-2025-10263, CVE-2026-31787, and CVE-2026-53059. Red Hat rated both headline issues as Moderate, but noted that CVE-2026-52923 has been associated with a reported local privilege-escalation exploit targeting RHEL 10, while CVE-2025-40026 can be mitigated by disabling nested virtualization for kvm_intel and kvm_amd. Red Hat said updated kernel packages and release images are available for multiple architectures and advised customers to reboot systems after applying kernel updates and upgrade OpenShift clusters through the supported release channels.

See real exploitation activity before you spend the cycle.
20 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:59091, an Important kernel security advisory for RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On that fixes CVE-2025-40026.
Red Hat released OpenShift Container Platform 4.18.53 as an Important security update that includes a fix for CVE-2025-40026 alongside other vulnerabilities.
Red Hat published RHSA-2026:52649, an Important kernel security advisory for RHEL 8.8 Update Services for SAP Solutions and Telecommunications Update Service that includes a fix for CVE-2026-52923.
Red Hat published RHSA-2026:49031, an Important kernel security advisory for RHEL 9.6 Extended Update Support and related channels that fixes CVE-2025-40026 and CVE-2026-52923.
Red Hat published RHSA-2026:48386, an Important kernel security advisory for RHEL 9.4 Update Services for SAP Solutions and related variants that fixes CVE-2025-40026 and CVE-2026-52923.
Red Hat published RHSA-2026:47248, an Important kernel security advisory for RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On that includes a fix for CVE-2026-52923.
Red Hat states CVE-2025-40026 was addressed for Red Hat Enterprise Linux 9 in advisory RHSA-2026:45192.
Red Hat states CVE-2025-40026 was fixed for Red Hat Enterprise Linux 8 through advisories RHSA-2026:45115 and RHSA-2026:45116.
Red Hat published its CVE entry for CVE-2026-52923, classifying the Linux kernel IPC ID allocation bug as a moderate-severity use-after-free issue with primarily local denial-of-service impact.
An upstream advisory for CVE-2026-52923 was published, documenting a Linux kernel SysV IPC checkpoint/restore flaw caused by unbounded next_id allocation in ipc_idr_alloc().
Red Hat published RHSA-2026:13577, an Important kernel security advisory for Red Hat Enterprise Linux 8. The update remediates multiple Linux kernel vulnerabilities, including CVE-2026-23401 in KVM, and provides updated kernel packages for RHEL 8 and Extended Life Cycle 8.10 variants.
Red Hat published its CVE record for CVE-2026-31402, describing an Important-severity heap overflow in the Linux kernel's NFSv4.0 server component nfsd that can lead to arbitrary code execution or denial of service. The entry also notes that multiple Red Hat Enterprise Linux kernel packages are fixed through later security errata.
Red Hat published its CVE record for CVE-2025-40026, describing a Linux kernel KVM x86 flaw involving incorrect re-checking of L1 intercepts during userspace I/O completion in nested virtualization.
A public local privilege escalation exploit targeting RHEL 10 for CVE-2026-52923 was reported as released, with the exploit referenced in the NebuSec CyberMeowfia GitHub repository.
Red Hat lists Red Hat Enterprise Linux 10 as fixed for CVE-2026-52923 in RHSA-2026:53330.
Red Hat lists Red Hat Enterprise Linux 10.0 Extended Update Support as fixed for CVE-2026-52923 in RHSA-2026:52764.
Red Hat lists Red Hat Enterprise Linux 8 kernel and kernel-rt packages as fixed for CVE-2026-52923 in advisories RHSA-2026:49851 and RHSA-2026:49857.
Red Hat lists Red Hat Enterprise Linux 10.0 Extended Update Support as fixed for CVE-2025-40026 in RHSA-2026:49030.
Red Hat lists Red Hat Enterprise Linux 9 as fixed for CVE-2026-52923 in advisory RHSA-2026:49212.
Red Hat states CVE-2025-40026 was addressed for RHEL 8.8 Update Services for SAP Solutions and Telecommunications Update Service in RHSA-2026:47869.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
20 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.