Red Hat released Important live kernel patch advisories for Red Hat Enterprise Linux 8, 9, and 10 to remediate two Linux kernel vulnerabilities: CVE-2026-46243 in the SMB/CIFS client and CVE-2026-46331 in net/sched/act_pedit. The updates were published across multiple kpatch streams, including RHEL 8.8 and 8.10, RHEL 9.2, 9.4, 9.6, and 9.8 variants, and RHEL 10, covering x86_64 and ppc64le platforms as well as AUS, SAP Solutions, Extended Update Support, and Extended Life Cycle channels.
CVE-2026-46243 stems from the kernel SMB client accepting userspace-created cifs.spnego key descriptions whose authority-bearing fields could be trusted by cifs.upcall as if they came from the kernel; the fix restricts acceptance to requests made while CIFS is using its private spnego_cred. CVE-2026-46331 affects tcf_pedit_act(), where packet edits could shift later header-relative offsets and cause writes beyond the originally ensured writable packet range; the fix expands the writable range using each key’s final computed write offset before mutation. Red Hat delivered the remediations through updated live patch modules so affected systems can be patched without rebooting.

See real exploitation activity before you spend the cycle.
11 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:33225, an Important-rated advisory for RHEL 10 kpatch packages fixing CVE-2026-46243 and CVE-2026-46331. The live patch targets kernel-6.12.0-211.16.1.el10_2 and covers multiple x86_64 and ppc64le RHEL 10 offerings, including Extended Update Support and Extended Life Cycle variants.
Red Hat published RHSA-2026:33224, an Important-rated advisory for RHEL 9 kpatch packages that remediate CVE-2026-46243 and CVE-2026-46331. The live patch targets kernel-5.14.0-687.10.1.el9_8 and applies to multiple RHEL 9 x86_64 and ppc64le variants.
Red Hat published RHSA-2026:33223, an Important-rated advisory for RHEL 9.6 Extended Update Support and related service variants that fixes CVE-2026-46243 and CVE-2026-46331. The live patch modules target kernel-5.14.0-570.17.1.el9_6 for x86_64 and ppc64le systems.
Red Hat published RHSA-2026:33222, an Important-rated advisory for RHEL 9.4 Update Services for SAP Solutions kpatch packages addressing CVE-2026-46243 and CVE-2026-46331. The live patch targets kernel version 5.14.0-427.68.2.el9_4 and covers multiple x86_64 and ppc64le variants.
Red Hat published RHSA-2026:33221, an Important-rated advisory for RHEL 9.2 Update Services for SAP Solutions and related channels that fixes CVE-2026-46243 and CVE-2026-46331. The live patch modules target kernel-5.14.0-284.117.1.el9_2 across x86_64 and ppc64le offerings.
Red Hat published RHSA-2026:33219, an Important-rated advisory delivering RHEL 8.8 Update Services for SAP Solutions kpatch packages that fix CVE-2026-46243 and CVE-2026-46331. The live patch targets kernel-4.18.0-477.97.1.el8_8 for supported x86_64 and ppc64le product variants.
Red Hat published RHSA-2026:33220, an Important-rated advisory for RHEL 8 kpatch live patch packages that remediate both CVE-2026-46243 and CVE-2026-46331. The update provides live patch modules for kernel-4.18.0-553.53.1.el8_10 across x86_64 and ppc64le RHEL 8 and Extended Life Cycle 8.10 variants.
Red Hat described CVE-2026-46331 as a Linux kernel flaw in tcf_pedit_act() where earlier key mutations could shift later header-relative offsets and cause writes outside the originally ensured writable skb prefix. The fix expands the ensured writable range using each key's final computed write offset before loading or storing the edited word.
Red Hat issued Important-rated RHSA-2026:25908 for RHEL 10.0, providing kernel version 6.12.0-55.79.1.el10_0. The update fixes CVE-2026-46243 along with CVE-2024-56603 and CVE-2024-56645; affected systems must be rebooted after installation.
Red Hat described CVE-2026-46243 as a Linux kernel SMB client issue in which cifs.upcall trusted authority-bearing fields from userspace-created cifs.spnego key descriptions. The documented fix is to accept cifs.spnego descriptions only while CIFS is using its private spnego_cred to request the key.
Red Hat documented CVE-2024-56645, a Linux CAN J1939 vulnerability in which j1939_session_new() did not give the initial skb the extra reference applied to subsequently queued skbs, potentially causing a reference-count underflow. Red Hat states fixes are available for RHEL 9, RHEL 9.6 EUS, RHEL 10, and RHEL 10.0 EUS through listed RHSA advisories.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.