Red Hat disclosed CVE-2026-23243, a Linux kernel flaw in the RDMA umad (User Mode Access Device) component that can let a local user trigger an integer underflow and out-of-bounds memory write. The bug stems from mismatched MAD and RMPP header size calculations in the umad write path, leading to kernel memory corruption during send MAD allocation. Red Hat rated the issue moderate severity with a CVSS v3 score of 7.3, warning that successful exploitation can crash systems and may also cause limited information disclosure and data integrity problems. As a mitigation, Red Hat advised preventing the ib_umad kernel module from loading where possible.
Red Hat shipped kernel security updates for multiple supported product lines to address the flaw alongside other kernel vulnerabilities, including RHEL 9.0, RHEL 8.6 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On, and RHEL 7 Extended Lifecycle Support. The advisories include RHSA-2026:13936, RHSA-2026:26570, and RHSA-2026:27729, with the RHEL 7 advisory rated Critical and covering multiple architectures such as x86_64, aarch64, ppc64le, and s390x. Red Hat said affected systems must be rebooted after applying the updated kernel packages for the fixes to take effect.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2026:27729 for Red Hat Enterprise Linux 7 Extended Lifecycle Support, providing updated kernel packages that fix CVE-2026-23243 along with five other vulnerabilities.
Red Hat issued RHSA-2026:26570 for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and 8.6 Extended Update Support Long-Life Add-On, including a kernel update that fixes CVE-2026-23243 among seven vulnerabilities.
Red Hat released a fix for CVE-2026-23243 for the Red Hat Enterprise Linux 10 kernel in advisory RHSA-2026:18134.
Red Hat released a fix for CVE-2026-23243 in the Red Hat Enterprise Linux 10.0 Extended Update Support kernel through advisory RHSA-2026:15883.
Red Hat issued RHSA-2026:13936 for Red Hat Enterprise Linux 9.0 offerings, including Update Services for SAP Solutions, and included a kernel update that fixes CVE-2026-23243 among multiple vulnerabilities.
Red Hat published CVE-2026-23243, describing a Linux kernel RDMA umad flaw in which an integer underflow can lead to an out-of-bounds memory write, causing denial of service and possible memory corruption impacts.
Red Hat released a fix for CVE-2026-23243 in the Red Hat Enterprise Linux 7 Extended Lifecycle Support kernel-rt package through advisory RHSA-2026:41236.
Red Hat released a fix for CVE-2026-23243 in the Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support kernel through advisory RHSA-2026:26535.
Red Hat released fixes for CVE-2026-23243 for Red Hat Enterprise Linux 8 kernel and kernel-rt packages via advisories RHSA-2026:21706 and RHSA-2026:21745.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.