Red Hat released multiple kernel security advisories across RHEL 8, 9, and 10 product streams to remediate a set of Linux kernel vulnerabilities affecting core subsystems including CAN raw sockets, RDMA/umad, and the qla2xxx SCSI driver. The updates span standard, real-time, Extended Update Support, Extended Life Cycle, SAP, Telecommunications, and mission-critical channels, with advisories including RHSA-2026:13932, RHSA-2026:18134, RHSA-2026:19521, RHSA-2026:19875, RHSA-2026:20130, and RHSA-2026:27353. Red Hat rated several of the releases Important and said affected systems must be rebooted after installation for the fixes to take effect.
Among the patched issues, CVE-2026-31532 fixes a use-after-free in net/can/raw.c where raw_rcv() could access freed ro->uniq memory during deferred receiver deletion, while CVE-2026-23243 addresses an RDMA umad flaw in ib_umad_write() that could turn a negative data_len into memory corruption through an out-of-bounds memset. Red Hat advisories also include CVE-2025-71238, a double-free bug in qla2xxx BSG request handling that can crash the kernel and may enable privilege escalation, alongside other kernel flaws such as local privilege escalation, denial of service, and unauthorized file reads. Upstream Linux kernel guidance for the CAN issue points administrators to updated stable kernel releases rather than cherry-picking individual commits.

See real exploitation activity before you spend the cycle.
21 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2026:27353, an Important kernel security advisory for Red Hat Enterprise Linux 8 that delivered updated kernel packages and fixed eight CVEs including CVE-2026-31419, CVE-2026-31488, CVE-2026-43056, CVE-2026-43279, CVE-2026-46331, CVE-2026-46090, CVE-2026-46145, and CVE-2026-46135.
Red Hat Bugzilla documented CVE-2026-31532, describing the CAN raw socket use-after-free and the fix that moved freeing ro->uniq into a socket destructor.
Red Hat Bugzilla documented CVE-2026-23243, describing the RDMA/umad flaw and the fix to reject negative data_len in ib_umad_write.
Red Hat issued RHSA-2026:13932, an Important kernel security update for RHEL 9.4 Extended Update Support that included fixes for CVE-2025-71238 and CVE-2026-31532 among other kernel flaws.
The Linux kernel CVE team published an announcement for CVE-2026-31532, a CAN raw socket use-after-free in raw_rcv(), and noted fixes in kernel versions 6.12.83, 6.18.24, 6.19.14, and 7.0.1.
Red Hat issued RHSA-2026:6954, a Moderate kernel security update for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Telecommunications Update Service. The advisory delivered kernel 4.18.0-477.135.1.el8_8 and fixed seven Linux kernel vulnerabilities including CVE-2025-71238, CVE-2026-23001, and CVE-2026-23209.
An upstream advisory at lore.kernel.org identified the Linux kernel RDMA/umad negative data_len flaw as CVE-2026-23243.
Red Hat issued RHSA-2026:4011, a Moderate Linux kernel security update for RHEL 9.6 Extended Update Support and related update-service channels. It delivered kernel 5.14.0-570.96.1.el9_6 and fixed seven vulnerabilities, including CVE-2024-56603, CVE-2025-22056, CVE-2025-38024, CVE-2025-38129, and CVE-2025-38141.
An upstream advisory at lore.kernel.org identified the Linux kernel qla2xxx double-free issue as CVE-2025-71238.
Red Hat issued RHSA-2026:3268, an Important kernel security update for multiple Red Hat Enterprise Linux 8.6 service variants including AMCS, AUS, SAP, TUS, and Extended Life Cycle Long Life. The advisory delivered kernel version 4.18.0-372.181.1.el8_6 and fixed eight Linux kernel vulnerabilities including CVE-2025-38022, CVE-2025-40271, CVE-2023-53821, and CVE-2026-23074.
Red Hat issued RHSA-2026:1662, a Moderate kernel security update for Red Hat Enterprise Linux 8 that provided updated kernel packages fixing multiple Linux kernel vulnerabilities including CVE-2022-50865, CVE-2024-26766, and several 2025 CVEs. The advisory applied across RHEL 8 architectures and Extended Life Cycle 8.10 variants.
Red Hat listed CVE-2025-21999 as fixed for the Red Hat Enterprise Linux 10 kernel in advisory RHSA-2025:9348.
Red Hat listed CVE-2025-21999 as fixed for the Red Hat Enterprise Linux 9 kernel in advisory RHSA-2025:9080.
Red Hat published its CVE entry for CVE-2025-21999, describing a Linux kernel use-after-free in proc_get_inode() caused by a race between module removal and /proc inode instantiation.
Red Hat documented CVE-2024-56603, a CAN af_can can_create() error-path flaw that can leave a dangling socket pointer and cause a use-after-free. Red Hat shipped fixes for RHEL 9, RHEL 9.6 EUS, RHEL 10, and RHEL 10.0 EUS through listed RHSA advisories.
Red Hat listed CVE-2025-21999 as fixed for the Red Hat Enterprise Linux 9.4 Extended Update Support kernel in advisory RHSA-2026:21209.
Red Hat listed CVE-2025-21999 as fixed for the Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions kernel in advisory RHSA-2026:20593.
Red Hat issued RHSA-2026:20130, an Important kernel security update for RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On that fixed CVE-2026-31532.
Red Hat issued RHSA-2026:19875, an Important kernel-rt security update for RHEL 9.2 Update Services for SAP Solutions that fixed CVE-2026-23243, CVE-2026-31532, and CVE-2025-21999 among other issues.
Red Hat issued RHSA-2026:19521, an Important kernel security update for RHEL 8.8 Update Services for SAP Solutions and Telecommunications Update Service that fixed CVE-2026-23243 and CVE-2026-31532 among other flaws.
Red Hat issued RHSA-2026:18134, a Moderate kernel security update for RHEL 10 that included a fix for CVE-2026-23243 along with numerous other Linux kernel vulnerabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
17 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.