Red Hat released Linux kernel security updates for multiple Red Hat Enterprise Linux branches, including RHEL 10 and RHEL 9.6 Extended Update Support, addressing several vulnerabilities led by CVE-2026-53059 and CVE-2026-23110. The RHEL 10 advisory rated Important and the RHEL 9.6 EUS advisory rated Moderate deliver updated kernel packages across major architectures and product variants, with Red Hat noting that systems should be rebooted after installation. The updates also bundle fixes for additional kernel issues such as CVE-2025-40237, CVE-2026-31411, CVE-2026-31692, CVE-2026-46099, CVE-2026-52973, and related defects.
One of the patched flaws, CVE-2026-53059, affects the Linux kernel device-mapper log component, where a 64-bit to 32-bit truncation can cause an integer overflow, undersized allocation, and out-of-bounds kernel write, enabling a low-privileged local attacker to crash the system. Another, CVE-2026-23110, is a SCSI core race condition that can stop the error handler from waking correctly and leave I/O stuck on affected hosts due to ordering and memory-barrier issues. Red Hat said fixes for these vulnerabilities have been incorporated into multiple supported RHEL releases, including RHEL 8, RHEL 9, RHEL 10, and associated extended support channels.

See real exploitation activity before you spend the cycle.
15 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-security advisory RHSA-2026:62568 for RHEL 9.6, providing kernel version 5.14.0-570.138.1.el9_6 across EUS, AUS, SAP, and Extended Life Cycle channels. The update fixes 12 kernel CVEs, including flaws in Squashfs, KSM, Bluetooth, netfilter, IPv4/IPv6 networking, RDMA, cryptography, bridge networking, and vhost; installed systems require a reboot.
Red Hat published RHSA-2026:59663 for RHEL 9 Real Time Linux Kernel (kernel-rt) packages, fixing CVE-2026-53059 along with CVE-2026-31411, CVE-2026-43112, and CVE-2026-46099. The Important-severity update also includes fixes for a bonding-interface reporting issue and vhost vring metadata cache handling.
Red Hat issued RHSA-2026:56574, a Moderate-severity kernel update for Red Hat Enterprise Linux 9.6 Extended Update Support and related channels, fixing CVE-2026-23110, CVE-2026-31411, CVE-2026-53016, and CVE-2026-53059.
Red Hat last modified its CVE-2026-53059 entry, reflecting package-fix information across multiple RHEL streams and errata.
Red Hat issued security advisory RHSA-2026:45114 for Red Hat Enterprise Linux 10, providing updated kernel packages that fix multiple vulnerabilities including CVE-2026-23110 and CVE-2026-53059.
Red Hat published RHSA-2026:43307 for Red Hat Enterprise Linux 9 kernel packages, delivering security, bug fix, and enhancement updates across multiple RHEL 9 variants. The advisory fixes six vulnerabilities, including CVE-2026-23110, but does not mention CVE-2026-53059.
Red Hat published its CVE record for CVE-2026-53059, describing a Linux kernel device-mapper log integer overflow that can lead to undersized allocations, out-of-bounds writes, and local denial of service.
An upstream Linux CVE announcement disclosed CVE-2026-43114, in which nftables pipapo AVX2 matching could return a non-matching multi-field entry after an expired or flushed entry was skipped, resulting in a false element-clash error. The issue stemmed from AVX2 matching functions returning before all key fields were processed and stale match-map bits cleared.
Red Hat documented CVE-2026-43023, a race in Linux Bluetooth SCO sco_sock_connect() that could permit concurrent connect calls to revive a closed socket, causing double sock_put(), use-after-free, and HCI/SCO connection leaks. Red Hat stated the issue was fixed for RHEL 9 and RHEL 10 through RHSA-2026:21556 and RHSA-2026:21557.
Red Hat documented CVE-2026-46099, in which seg6 and RPL lightweight-tunnel input paths could cache an unreferenced IPv6 destination and trigger a WARN or use-after-free during a PREEMPT_RT race. The fix calls skb_dst_force() after ip6_route_input() to obtain a refcounted destination; Red Hat states the issue was addressed in RHEL 9 and RHEL 10 through RHSA-2026:43307 and RHSA-2026:45114.
Red Hat documented CVE-2026-31411, in which a malicious ATM signaling daemon could supply a forged userspace-controlled VCC pointer to sigd_send(), causing a kernel crash. The fix validates the pointer against vcc_hash via find_get_vcc() and holds a socket reference to preserve memory safety; Red Hat reported fixes in RHEL 8, RHEL 9, RHEL 9.4 SAP Solutions, and RHEL 9.6 EUS.
Red Hat fixed CVE-2026-53059 in Red Hat Enterprise Linux 10.0 Extended Update Support kernel packages through advisory RHSA-2026:55445.
Red Hat fixed CVE-2026-53059 in Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and 8.6 Extended Update Support Long-Life Add-On kernel packages via RHSA-2026:53989.
Red Hat fixed CVE-2026-53059 in Red Hat Enterprise Linux 8.8 Telecommunications Update Service and Update Services for SAP Solutions kernel packages via RHSA-2026:52649.
Red Hat fixed CVE-2026-53059 in Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On kernel packages via RHSA-2026:47248.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.