Red Hat released multiple Important kernel advisories across RHEL 8, 9, and 10 to address Linux kernel flaws including CVE-2025-39766 in net/sched and CVE-2025-68741 in the qla2xxx SCSI driver. Advisories RHSA-2026:8921 and RHSA-2026:9264 patched both issues for broad RHEL 9 and RHEL 10 product lines, while RHSA-2026:9131, RHSA-2026:9135, and RHSA-2026:10996 included fixes for CVE-2025-68741 alongside other kernel bugs in standard, real-time, and extended support channels. Red Hat said affected systems should be rebooted after applying the updated kernel packages.
CVE-2025-39766 stems from the Linux traffic-control scheduler, where cake_enqueue() could return NET_XMIT_SUCCESS after dropping packets past buffer_limit, allowing htb_enqueue() to activate an empty child qdisc and trigger a kernel warning; the fix changes the return value to NET_XMIT_CN. CVE-2025-68741 affects drivers/scsi/qla2xxx/qla_nvme.c, where an error path improperly frees a purex item with kfree() instead of qla24xx_free_purex_item(), creating a risk of memory corruption. Additional Red Hat kernel advisories in the same period also bundled other flaws such as race conditions, heap overflows, use-after-free bugs, and privilege-escalation issues across legacy, SAP, real-time, and extended lifecycle offerings.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:14925 for Red Hat Enterprise Linux 7 Extended Lifecycle Support, fixing CVE-2018-16885, CVE-2025-40240, CVE-2026-23191, and CVE-2026-31402. The update covered x86_64, s390x, ppc64, and ppc64le ELS systems.
Red Hat issued RHSA-2026:14301 for kernel-rt on Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and 9.2 Extended Life Cycle. The advisory fixed multiple kernel vulnerabilities including CVE-2026-23097, CVE-2026-23193, CVE-2026-23191, CVE-2026-31402, and CVE-2026-31431.
Red Hat published RHSA-2026:14230 for several RHEL 8.6 service variants, fixing CVE-2026-23191, CVE-2026-23401, and CVE-2026-31431. The update applied to Advanced Mission Critical Update Support, SAP Solutions, and Telecommunications Update Service offerings.
Red Hat issued RHSA-2026:10996 for Red Hat Enterprise Linux 10.0 Extended Update Support, fixing CVE-2025-68741 along with CVE-2026-23001 and CVE-2026-23111. The advisory covered x86_64, s390x, ppc64le, and aarch64 channels.
Red Hat published RHSA-2026:9264 for Red Hat Enterprise Linux 10, fixing CVE-2025-39766 in net/sched and CVE-2025-68741 in qla2xxx. The update covered multiple RHEL 10 product variants, including EUS, ELC, and CodeReady Linux Builder channels.
Red Hat issued RHSA-2026:9135 for RHEL 8 real-time offerings, fixing CVE-2025-68741 and CVE-2026-23191 in kernel-rt packages. The advisory applied to Real Time, Real Time for NFV, and x86_64 ELC 8.10 variants.
Red Hat issued RHSA-2026:9131 for Red Hat Enterprise Linux 8, fixing CVE-2025-68741 in the qla2xxx SCSI component and CVE-2026-23191 in ALSA aloop. Updated kernel packages were released for multiple RHEL 8 architectures and ELC variants.
Red Hat published RHSA-2026:8921 for Red Hat Enterprise Linux 9, fixing CVE-2025-39766 in net/sched along with CVE-2025-68741. The advisory covered multiple RHEL 9 variants and instructed customers to reboot after applying the update.
The Linux kernel CVE team assigned and announced CVE-2025-68741 for an improper freeing bug in the qla2xxx SCSI driver that can lead to memory corruption. The announcement said the issue was fixed in kernel versions 6.12.63, 6.17.13, 6.18.2, and 6.19-rc1.
An upstream advisory for CVE-2025-39766 was published on lore.kernel.org, documenting the Linux kernel net/sched flaw involving cake_enqueue returning NET_XMIT_SUCCESS after packet drops past buffer_limit.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.