Red Hat released multiple kernel security advisories for Red Hat Enterprise Linux 8 and RHEL 9.2 variants, including Update Services for SAP Solutions and Extended Life Cycle channels, to address a set of Linux kernel vulnerabilities affecting locking, virtualization, and networking code. The updates remediate five flaws in the RHEL 9.2 packages—CVE-2026-43027, CVE-2026-43499, CVE-2026-46113, CVE-2026-53166, and CVE-2026-53359—covering issues in netfilter, rtmutex, futex/requeue, and two KVM x86 shadow paging use-after-free conditions. A separate RHEL 8 advisory fixes eight kernel vulnerabilities spanning net/sched, IOMMU, ATM networking, rtmutex, futex, KVM x86 shadow paging, and netfilter ebtables.
One of the patched bugs, CVE-2026-53166, is a moderate-severity flaw in the futex requeue mechanism that can trigger a NULL pointer dereference and crash the kernel during a self-deadlock scenario, resulting in local denial of service. Red Hat grouped that issue with CVE-2026-43499 in its "GhostLock" bulletin, warning that the affected futex priority-inheritance code is built into standard RHEL kernels and that no runtime mitigation is available. The company urged customers to install the updated kernel packages and reboot affected systems for the fixes to take effect.

See real exploitation activity before you spend the cycle.
14 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2026:40082 for Red Hat Enterprise Linux 9.2 kernel packages version 5.14.0-284.181.1.el9_2 across multiple architectures and lifecycle channels. The update addressed five vulnerabilities: CVE-2026-43027, CVE-2026-43499, CVE-2026-46113, CVE-2026-53166, and CVE-2026-53359.
Red Hat published Moderate advisory RHSA-2026:39983 for kernel-rt packages in Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. The update fixed five kernel vulnerabilities, including CVE-2026-43027, CVE-2026-43499, CVE-2026-46113, CVE-2026-53166, and CVE-2026-53359, and required a reboot.
Red Hat issued Important advisory RHSA-2026:39083 for Red Hat Enterprise Linux 8 kernel packages version 4.18.0-553.143.1.el8_10. The update fixed eight kernel vulnerabilities, including CVE-2026-53166, CVE-2026-43499, CVE-2026-46113, and CVE-2026-53359, and required a reboot after installation.
Red Hat last modified its CVE-2026-53166 page and recorded multiple product fix states, including NVIDIA for RHEL 10 fixed via RHSA-2026:37728. The updated entry also linked the issue to Bugzilla 2492805 and mitigation bulletin RHSB-2026-010.
Red Hat published security bulletin RHSB-2026-010 covering the locking-subsystem flaws CVE-2026-43499 and CVE-2026-53166 across RHEL 6 through 10 and kernel-dependent products. Red Hat said there was no runtime mitigation, that fixes were being expedited, and that customers should update to patched kernels and reboot when errata became available.
Red Hat published its CVE record for CVE-2026-53166, classifying the Linux kernel futex/requeue flaw as Moderate severity with a CVSS v3.1 score of 5.5. The entry states the bug can trigger a NULL pointer dereference and kernel crash, resulting in local denial of service.
The Linux kernel CVE team announced CVE-2026-53166, a futex/requeue NULL pointer dereference bug that can crash the kernel during a self-deadlock condition. The announcement described the root cause in remove_waiter() and identified fixed upstream kernel versions including 6.18.36 and 7.0.13.
Red Hat published its CVE record for CVE-2026-31532, describing a Moderate-severity use-after-free flaw in the Linux kernel CAN raw socket implementation that can let a local attacker crash the kernel. The entry assessed the likely impact as denial of service and recommended blacklisting the `can` kernel module as a mitigation when CAN functionality is not needed.
Red Hat published Moderate advisory RHSA-2026:3267 for Red Hat Enterprise Linux 9.2 kernel update streams, including SAP Solutions, AUS, 4-year updates, and Extended Life Cycle variants. The update provided new kernel packages fixing multiple vulnerabilities across components including xHCI, SCSI mpi3mr, Squashfs, USB parsing, VXLAN, SMB, Bluetooth, ALSA USB audio, ext4, and NFSv4/pNFS, and required a reboot after installation.
Red Hat published Important advisory RHSA-2026:0535 for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and related AUS, 4-year update, and Extended Life Cycle variants. The kernel update fixed 11 vulnerabilities across subsystems including NFSD, SMB client, CAN J1939, Bluetooth, RDMA/rxe, SCSI SES, TLS, USB DWC3, and libceph, and required a reboot after installation.
An upstream Linux kernel advisory published in October 2025 disclosed CVE-2023-53539, an RDMA/rxe flaw caused by incomplete state saving in rxe_requester after failed packet transmission. The bug could corrupt retransmitted packets under heavy stress, and the patch restored the missing dma-related state.
Red Hat issued Important advisory RHSA-2025:10671 for RHEL 9.2 SAP Solutions, AUS, and Extended Life Cycle kernel update streams. Kernel version 5.14.0-284.124.1.el9_2 fixed CVE-2023-1652, CVE-2025-37738, CVE-2022-49846, and CVE-2022-50066; affected systems required a reboot after installation.
Rohit Keshri reported CVE-2023-1652, a medium-severity use-after-free in the Linux NFS server function nfsd4_ssc_setup_dul() that affects kernels through v6.2-rc4 and can cause denial of service. Upstream commit e6cf91b7b47ff82b624bdfe2fdcde32bb52e71dd fixed the issue, with kernel 6.2 RC5 identified as fixed.
Red Hat updated advisory RHSA-2026:39083 after its initial release. The advisory remained the vehicle for the RHEL 8 kernel security update fixing eight vulnerabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
14 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.