Red Hat released RHSA-2026:21557, an Important security update for the Linux kernel in Red Hat Enterprise Linux 10 and related channels, addressing 18 vulnerabilities across subsystems including CAN J1939, IMA, memory management, netfilter, conntrack, io_uring, Bluetooth, HID, Wi-Fi, XFS, and dpaa2-switch. The advisory applies to multiple RHEL 10 variants on x86_64, ARM64, IBM z Systems, and Power little endian, including Extended Update Support and Extended Life Cycle offerings, and Red Hat said affected systems must be rebooted after patching for the fixes to take effect.
Among the flaws covered were CVE-2026-31684, a network scheduler bug triggered by specially crafted packets with nested VLAN headers that can cause an out-of-bounds read and system crash, and CVE-2026-43027, a netfilter nf_conntrack_helper cleanup flaw that can lead to a use-after-free condition, enabling denial of service and potentially privilege escalation. Red Hat rated both issues moderate severity with CVSS v3 scores of 7.1, and said fixes were issued across multiple RHEL kernel package streams, including RHEL 7, 8, and 10 for the VLAN-related flaw and additional errata for the conntrack issue.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2026:21706 for RHEL 8 kernel packages and RHSA-2026:21745 for RHEL 8 kernel-rt packages, listing fixes for both CVE-2026-31684 and CVE-2026-43027.
Red Hat issued RHSA-2026:21557, an Important kernel security advisory for Red Hat Enterprise Linux 10 and related channels. The update fixes 18 Linux kernel vulnerabilities, including CVE-2026-31684 and CVE-2026-43027, and requires a reboot after installation.
Red Hat published its CVE record for CVE-2026-43027, a netfilter nf_conntrack_helper use-after-free vulnerability that could let a local attacker crash the system or potentially escalate privileges.
Red Hat published its CVE record for CVE-2026-31684, describing a Linux kernel network scheduler flaw involving nested VLAN headers that can cause an out-of-bounds read and denial of service.
Red Hat issued RHSA-2026:47633 for RHEL 8.4 support streams, listing fixes for both CVE-2026-31684 and CVE-2026-43027.
Red Hat listed the RHEL 10.0 Extended Update Support kernel as fixed for CVE-2026-31684 through advisory RHSA-2026:44694.
Red Hat issued RHSA-2026:41234 for RHEL 7 Extended Lifecycle Support kernel-rt and RHSA-2026:41235 for RHEL 7 Extended Lifecycle Support kernel, listing fixes for CVE-2026-31684.
Red Hat issued RHSA-2026:40760 for the RHEL 8.8 Telecommunications Update Service and SAP Solutions kernel streams, listing fixes for CVE-2026-43027.
Red Hat issued RHSA-2026:40068 for RHEL 8.6 support streams, listing fixes for both CVE-2026-31684 and CVE-2026-43027.
Red Hat listed the RHEL 10.0 Extended Update Support kernel as fixed for CVE-2026-43027 through advisory RHSA-2026:39371.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.