Red Hat released a series of kernel and kernel-rt security advisories affecting RHEL 7 ELS, RHEL 8, RHEL 9, and RHEL 10 product streams, including AUS, EUS, SAP Solutions, Telecommunications, Extended Life Cycle, and Extended Update Support channels. The updates fix clusters of vulnerabilities across networking, storage, memory management, and filesystem components, with repeated remediation for flaws such as CVE-2026-23270 in traffic control act_ct, CVE-2026-31419 in the bonding driver, CVE-2026-43163 in md/bitmap, and multiple libceph, netfilter, RDMA, SMB, IPv6, SCTP, ALSA, and BPF issues. Red Hat rated several advisories Important and some Critical, citing impacts that include denial of service, memory corruption, out-of-bounds reads, use-after-free conditions, and possible local privilege escalation.
The advisories span updated kernel builds including 3.10.0-1160.151.1.el7, 4.18.0-305.197.1.el8_4, 4.18.0-477.150.1.el8_8, 4.18.0-553.132.1.el8_10, 5.14.0-284.176.1.el9_2, 5.14.0-427.127.1.el9_4, 5.14.0-570.119.1.el9_6, and 6.12.0-55.82.1.el10_0, and Red Hat said affected systems must be rebooted after patching. One separately documented flaw, CVE-2025-71116, was traced to libceph decode_pool() parsing of malformed osdmap data, allowing an authenticated remote Ceph OSD or monitor to crash a client kernel; Red Hat said the issue was fixed with explicit bounds checks and advised preventing the libceph module from loading where Ceph is not used.

See real exploitation activity before you spend the cycle.
20 events from the most recent confirmed update back to the earliest known activity.
Red Hat published its CVE page for CVE-2025-71116, describing the libceph decode_pool() out-of-bounds read issue, rating it Moderate, and noting the CVE had been made public on January 14, 2026. The page also lists RHSA-2026:52764 as fixing the issue for the RHEL 10.0 Extended Update Support kernel on August 10, 2026.
Red Hat's CVE page for CVE-2025-71116 states that the entry was last modified on July 30, 2026. The page reflects updated fix and metadata information for the libceph out-of-bounds read vulnerability.
Red Hat published RHSA-2026:35896, an Important kernel security update for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On. The advisory updated kernel packages to version 4.18.0-305.197.1.el8_4 and fixed 11 vulnerabilities including CVE-2025-71116, CVE-2026-22984, CVE-2026-31669, and CVE-2026-46181.
Red Hat published RHSA-2026:35863, an Important kernel security update for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Telecommunications Update Service. The advisory delivered kernel version 4.18.0-477.150.1.el8_8 and fixed 10 CVEs including CVE-2026-23270, CVE-2026-31669, CVE-2026-43279, and multiple RDMA and netfilter flaws.
Red Hat's CVE record lists RHSA-2026:33899 as the advisory that fixed CVE-2025-71116 for the Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support kernel. The fix release date is given as July 1, 2026.
Red Hat published RHSA-2026:27731, an Important kernel security update for Red Hat Enterprise Linux 10.0 Extended Update Support. The update delivered kernel version 6.12.0-55.82.1.el10_0 and fixed 13 vulnerabilities including CVE-2025-38154, CVE-2026-23136, CVE-2026-43116, CVE-2026-46227, and CVE-2026-46125.
Red Hat's CVE record states that CVE-2025-71116 was fixed for the Red Hat Enterprise Linux 8.8 Telecommunications Update Service kernel in RHSA-2026:26563. The fix release date is listed as June 17, 2026.
Red Hat published RHSA-2026:26515, an Important kernel security update for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and related 9.2 variants. The advisory shipped kernel version 5.14.0-284.176.1.el9_2 and fixed 20 CVEs across networking, IPv6, netfilter, Ceph, iSCSI, XFS, SMB, SCTP, Wi-Fi, crypto, IOMMU, and NBD components.
Red Hat published RHSA-2026:25191, a Critical kernel security update for Red Hat Enterprise Linux 10 and related support channels. The advisory fixed seven vulnerabilities including CVE-2026-31419, CVE-2026-31467, CVE-2026-31532, CVE-2026-31581, CVE-2026-43501, and CVE-2026-46054.
Red Hat published RHSA-2026:25095, an Important kernel security update for Red Hat Enterprise Linux 7 Extended Lifecycle Support. The advisory updated kernel packages to version 3.10.0-1160.151.1.el7 and fixed CVE-2026-31532, CVE-2026-31607, CVE-2026-31685, and CVE-2026-43163.
Red Hat published RHSA-2026:25121, a Critical kernel security update for Red Hat Enterprise Linux 8. The update delivered kernel version 4.18.0-553.132.1.el8_10 and fixed 13 vulnerabilities across components including geneve, smc, nbd, libceph, nf_tables, SMB, DLM, and RDMA.
Red Hat published RHSA-2026:24343, an Important kernel security update for Red Hat Enterprise Linux 10.0 Extended Update Support and related channels. The advisory shipped kernel version 6.12.0-55.77.1.el10_0 and fixed nine vulnerabilities including CVE-2026-23270, CVE-2026-23392, CVE-2026-31607, and CVE-2026-43110.
Red Hat published RHSA-2026:23224, an Important kernel security update for Red Hat Enterprise Linux 9.6 Extended Update Support and related 9.6 channels. The update delivered kernel version 5.14.0-570.119.1.el9_6 and fixed 13 vulnerabilities including CVE-2026-23270, CVE-2026-31419, CVE-2026-31709, and CVE-2026-43163.
Red Hat published RHSA-2026:22940 for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and related 9.2 variants. The Important kernel update provided version 5.14.0-284.174.1.el9_2 and fixed seven vulnerabilities including CVE-2026-23270, CVE-2026-31419, CVE-2026-31709, and CVE-2026-43163.
Red Hat published RHSA-2026:22900 for kernel-rt packages in RHEL 9.2 SAP Solutions and Extended Life Cycle channels on x86_64. The Important update fixed seven vulnerabilities including CVE-2026-23270, CVE-2026-31419, CVE-2026-31709, and CVE-2026-43163.
Red Hat published RHSA-2026:21209, an Important kernel security update for Red Hat Enterprise Linux 9.4 Extended Update Support and related offerings. The update delivered kernel version 5.14.0-427.127.1.el9_4 and fixed nine vulnerabilities including CVE-2026-23243, CVE-2026-23270, CVE-2026-31419, and CVE-2026-43163.
Red Hat published RHSA-2026:20593 for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and related 9.2 variants. The Important kernel update fixed several vulnerabilities including CVE-2025-21999, CVE-2025-71238, CVE-2026-23243, CVE-2026-23401, CVE-2026-31532, CVE-2026-46300, and CVE-2026-46333.
Red Hat published RHSA-2026:19568, an Important kernel security update for Red Hat Enterprise Linux 9. The advisory fixed multiple kernel flaws including CVE-2025-71116, CVE-2026-23136, CVE-2026-23270, Dirty Frag, and Fragnesia, and required a reboot after installation.
Red Hat published RHSA-2026:9644, a Moderate kernel security update for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and related 9.2 variants. The advisory shipped kernel version 5.14.0-284.166.1.el9_2 and fixed nine vulnerabilities including CVE-2025-38248, CVE-2025-39981, CVE-2026-23066, and CVE-2026-23231.
Red Hat issued RHSA-2026:1909, an Important security update for RHEL 9.2 Update Services for SAP Solutions and associated channels. The update shipped kernel 5.14.0-284.155.1.el9_2 and fixed CVE-2025-40248, CVE-2023-53751, CVE-2025-68301, and CVE-2022-50865; systems require a reboot after installation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 22 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
17 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.