Red Hat released multiple Important kernel security advisories for RHEL 8, RHEL 9, and RHEL 10, including standard kernel updates and kpatch live patches, to remediate a broad set of Linux kernel vulnerabilities across x86_64, ppc64le, aarch64, s390x, and IBM Z platforms. The updates span base, Extended Update Support, Extended Life Cycle, SAP Solutions, AUS, and real-time offerings, with affected advisories covering RHEL 8 and 10 kernel packages as well as live patch modules for RHEL 8.8, 8.10, 9.2, 9.4, 9.6, 9.8, and 10.2. Several advisories require reboots for standard kernel package updates, while the kpatch releases allow remediation without rebooting on supported kernels.
The fixes address recurring kernel issues including CVE-2026-43038 in IPv6 ICMP handling, CVE-2026-43125 in DLM length validation, CVE-2026-43329 in netfilter flowtable action checking, CVE-2026-46244 involving nft_inner IPv6 offset desynchronization, and CVE-2026-64530, a use-after-free flaw in net scheduler qevent handling. Red Hat also patched CVE-2026-31692, a privilege-related flaw in rtnetlink where missing netlink_ns_capable() checks could let an unprivileged user in a user namespace create paired interfaces such as veth in arbitrary network namespaces, including init_net; that issue was specifically tied to RHEL 8 and RHEL 10 fixes. Additional CVEs cited across the advisories include CVE-2025-40237, CVE-2026-23110, CVE-2026-31641, CVE-2026-43116, CVE-2026-46099, CVE-2026-46150, CVE-2026-52973, CVE-2026-53059, CVE-2026-64561, and CVE-2026-64530.

See real exploitation activity before you spend the cycle.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2026:56225, an Important kpatch live patch advisory for Red Hat Enterprise Linux 9.6 Extended Update Support and related service variants. The update for kernel-5.14.0-570.17.1.el9_6 fixes CVE-2026-43038, CVE-2026-43125, CVE-2026-43329, CVE-2026-46244, and CVE-2026-64530.
Red Hat issued RHSA-2026:56224, an Important kpatch live patch advisory for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions and related offerings. The update for kernel-5.14.0-427.68.2.el9_4 fixes CVE-2026-43038, CVE-2026-43125, CVE-2026-43329, and CVE-2026-64530.
Red Hat issued RHSA-2026:55837, an Important kpatch live patch advisory for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and related offerings. The update for kernel-5.14.0-284.117.1.el9_2 fixes CVE-2026-43038, CVE-2026-43125, CVE-2026-43329, and CVE-2026-64530.
Red Hat issued RHSA-2026:55763, an Important kpatch live patch advisory for Red Hat Enterprise Linux 9 targeting kernel-5.14.0-687.10.1.el9_8. The update fixes CVE-2026-43038, CVE-2026-43125, CVE-2026-43329, CVE-2026-46244, and CVE-2026-64530.
Red Hat issued RHSA-2026:55762, an Important kpatch live patch advisory for Red Hat Enterprise Linux 8 targeting kernel-4.18.0-553.53.1.el8_10. The update addresses CVE-2026-43038, CVE-2026-43125, CVE-2026-43329, and CVE-2026-64530.
Red Hat issued RHSA-2026:55761, an Important kpatch live patch advisory for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and related offerings. The update for kernel-4.18.0-477.97.1.el8_8 fixes CVE-2026-43038, CVE-2026-43125, CVE-2026-43329, and CVE-2026-64530.
Red Hat published RHSA-2026:55618, an Important live kernel patch advisory for Red Hat Enterprise Linux 10 targeting kernel-6.12.0-211.16.1.el10_2. The kpatch update remediates CVE-2026-31641, CVE-2026-43038, CVE-2026-43329, CVE-2026-46244, and CVE-2026-64530.
Red Hat published RHSA-2026:49214, an Important kernel security advisory for Red Hat Enterprise Linux 8. The update fixes CVE-2026-31692, CVE-2026-43116, CVE-2026-46150, and CVE-2026-64530 across multiple RHEL 8 variants and architectures, and Red Hat says systems must be rebooted after applying it.
Red Hat published RHSA-2026:49213, an Important kernel-rt security advisory for Red Hat Enterprise Linux 8 real-time offerings. The update fixes CVE-2026-31692, CVE-2026-43116, CVE-2026-46150, and CVE-2026-64530 and requires a reboot after installation.
A Red Hat Bugzilla entry described CVE-2026-31692 in rtnl_newlink(), where a missing CAP_NET_ADMIN check in the peer network namespace could let an unprivileged user create interfaces in arbitrary namespaces. The entry states the fix adds a netlink_ns_capable() check and notes the issue was addressed in RHEL 10 and RHEL 8 advisories.
Red Hat published RHSA-2026:45114, an Important kernel security advisory for Red Hat Enterprise Linux 10. The update fixes multiple Linux kernel vulnerabilities including CVE-2025-40237, CVE-2026-23110, CVE-2026-31692, CVE-2026-46099, CVE-2026-52973, and CVE-2026-53059.
Red Hat published RHSA-2026:23470, an Important security advisory for multiple Red Hat Enterprise Linux 8 kpatch live patch packages covering the 4.18.0-553 kernel series. The update fixes Linux kernel flaws including CVE-2026-46300 ("Fragnesia") and CVE-2026-46333 for RHEL 8 and Extended Life Cycle 8.10 variants.
Red Hat updated advisory RHSA-2026:55761 after its initial publication. The source content states the RHEL 8.8 SAP kpatch advisory was updated on 2026-08-19.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
12 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.