Red Hat released kernel security updates across multiple RHEL 8 product streams to fix CVE-2026-43163, a Linux kernel flaw in the md/bitmap component caused by a use-after-free race during array resize operations. The bug occurs when bitmap_daemon_work() and __bitmap_resize() run concurrently, allowing bitmap->storage.filemap pages to be accessed after they have been freed by md_bitmap_file_unmap(), which can trigger a General Protection Fault and crash the system. Red Hat classifies the issue as moderate severity with a CVSS v3 score of 4.7 and maps it to CWE-825: Expired Pointer Dereference.
The flaw was addressed by holding mddev->bitmap_info.mutex during bitmap updates to prevent the race, and Red Hat shipped the fix in several advisories, including RHSA-2026:26563 for RHEL 8.8 SAP Solutions and Telecommunications Update Service and RHSA-2026:53989 for RHEL 8.6 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On. The later advisory bundled the md/bitmap fix with other kernel issues such as a double free in xen/privcmd, SMB client memory errors, a Xen privilege-escalation flaw on AMD Zen 2 processors, and a dm log out-of-bounds write. Red Hat said affected systems should be rebooted after applying the updated kernel packages.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2026:53989, an Important kernel security update for RHEL 8.6 AM-CUS and EUS Long-Life Add-On that fixes CVE-2026-43163 and four additional kernel vulnerabilities.
Red Hat published the customer portal page for CVE-2026-43163, listing a CVSS v3 score of 4.7 and summarizing the denial-of-service risk from the md/bitmap use-after-free race.
Red Hat released RHSA-2026:26563, an Important kernel security update for RHEL 8.8 SAP Solutions and Telecommunications Update Service that includes a fix for CVE-2026-43163 along with 17 other kernel vulnerabilities.
Red Hat's Bugzilla entry documented that CVE-2026-43163 stems from a race between bitmap_daemon_work() and __bitmap_resize(), and noted the fix of holding mddev->bitmap_info.mutex during bitmap updates.
Red Hat published its CVE record for CVE-2026-43163, classifying the Linux kernel md/bitmap flaw as a moderate-severity use-after-free race mapped to CWE-825.
An upstream advisory for CVE-2026-43163 was posted on lore.kernel.org describing an md/bitmap use-after-free race that can cause a general protection fault in write_page() during array resize operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.