Red Hat released multiple Important security advisories for the Linux kernel in Red Hat Enterprise Linux 9.6 channels, including Extended Update Support, delivering fixes for a broad set of vulnerabilities and requiring customers to reboot systems after installation. The newer advisory, RHSA-2026:34094, updates the kernel to 5.14.0-570.125.1.el9_6 across x86_64, aarch64, ppc64le, and s390x, and addresses 18 CVEs spanning subsystems such as netfilter, ALSA, MPTCP, RDMA, TCP, DLM, SCSI, IPv6, SCTP, and process exit handling. An earlier advisory, RHSA-2026:14339, also targeted RHEL 9.6 kernel packages and listed impacts including denial of service, memory corruption, privilege escalation, and use-after-free flaws in components including nfsd, qla2xxx, RDMA umad, KVM, crypto algif_aead, and CAN raw.
One of the patched issues, CVE-2025-68741, affects the Linux kernel's qla2xxx SCSI driver and stems from improper freeing of a purex item in qla2xxx_process_purls_iocb(). Red Hat and Bugzilla records say the flaw occurs when memory obtained from qla24xx_alloc_purex_item() is incorrectly released with kfree() instead of qla24xx_free_purex_item(), creating a CWE-763 invalid pointer release condition that can cause memory corruption. Red Hat rated the issue Moderate for its products, noted that fixes were shipped across multiple RHEL 8, 9, and 10 kernel packages, and said RHEL 6 is not affected because the vulnerable code is absent.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Important advisory RHSA-2026:34094 for RHEL 9.6 Extended Update Support and related channels, providing kernel version 5.14.0-570.125.1.el9_6. The advisory addresses 18 CVEs across multiple kernel subsystems including netfilter, ALSA, RDMA, TCP, SCSI, IPv6, SCTP, and process exit handling, and requires a reboot after applying the update.
Red Hat issued Important advisory RHSA-2026:14339 for RHEL 9.6 Extended Update Support and related channels, shipping kernel version 5.14.0-570.112.1.el9_6. The update fixes multiple kernel CVEs including CVE-2025-68741, and Red Hat instructed administrators to reboot after installation.
A Red Hat Bugzilla record documented the qla2xxx vulnerability details, explaining that qla2xxx_process_purls_iocb() incorrectly used kfree() on items that might come from a pre-allocated pool. The record states the fix replaced kfree() with qla24xx_free_purex_item().
Red Hat published Moderate-severity advisory RHSA-2026:1194 for RHEL 9.6 Extended Update Support and related offerings, shipping kernel version 5.14.0-570.81.1.el9_6. The update fixes 11 Linux kernel vulnerabilities across components including openvswitch, drm/xe, irqchip/gic-v2m, scsi lpfc, Bluetooth, mptcp, devlink, and vmwgfx, and requires a reboot after installation.
Red Hat published its CVE page for CVE-2025-68741, describing a Linux kernel qla2xxx flaw caused by improper freeing of a purex item that can lead to memory corruption. The entry rates the issue Moderate and notes affected and fixed Red Hat product streams.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.