Red Hat released a series of Important and Critical kernel security advisories across RHEL 8, 9, and 10 product lines, including kernel-rt, Extended Update Support, SAP, and RHEL for NVIDIA, to remediate multiple Linux kernel vulnerabilities. The updates cover issues such as CVE-2026-23270, a use-after-free in traffic control act_ct that can cause denial of service and may allow privilege escalation under specific misconfigurations; CVE-2026-31419, a bonding driver race condition that can trigger a use-after-free and kernel crash; CVE-2026-31402, a heap overflow in the NFSv4.0 LOCK replay cache that can be triggered remotely by unauthenticated attackers; and CVE-2026-31431 in crypto: algif_aead, alongside several other kernel flaws affecting networking, storage, virtualization, and memory handling.
Advisories including RHSA-2026:13566, RHSA-2026:14137, RHSA-2026:22334, RHSA-2026:27354, and RHSA-2026:33486 show the fixes were distributed across standard and specialized kernels for x86_64, aarch64, s390x, and ppc64le systems. Red Hat said some updates also address local privilege-escalation bugs such as Dirty Frag and Fragnesia, as well as kernel panic conditions in real-time builds. Affected environments include Real Time Linux, NFV, SAP-focused deployments, and NVIDIA-enabled RHEL 10 systems, and Red Hat instructed customers to install the updated kernel packages and reboot for the protections to take effect.

See real exploitation activity before you spend the cycle.
11 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:33486, a Critical kernel security advisory for Red Hat Enterprise Linux for NVIDIA on ARM 64 10. The update fixes multiple Linux kernel vulnerabilities, including CVE-2026-31431, CVE-2026-43284, CVE-2026-46300, and CVE-2026-46333.
Red Hat published RHSA-2026:27354, an Important kernel-rt update for Red Hat Enterprise Linux 8 Real Time variants. The advisory fixes eight kernel vulnerabilities, including CVE-2026-31419, and also resolves a kernel panic in replenish_dl_entity().
Red Hat published RHSA-2026:22334, an Important kernel security update for Red Hat Enterprise Linux 10.0 Extended Update Support. The advisory includes a fix for CVE-2026-31419 in the bonding driver along with four other kernel vulnerabilities.
Red Hat published RHSA-2026:19540 for NVIDIA for RHEL 10 on aarch64, rated Critical by Red Hat Product Security. The advisory fixes Linux kernel vulnerabilities including CVE-2026-46300 and CVE-2026-46333 and requires a reboot after installation.
Red Hat published RHSA-2026:14137, an Important kernel-rt security update for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions on x86_64. The update fixes multiple kernel vulnerabilities, including CVE-2026-31402 and CVE-2026-31431, and requires a reboot after installation.
Red Hat published RHSA-2026:13566, an Important kernel security update for Red Hat Enterprise Linux 10. The advisory fixes multiple vulnerabilities including CVE-2026-23270, CVE-2026-31402, CVE-2026-31419, and CVE-2026-31431.
An upstream advisory was published for CVE-2026-31402, detailing a heap overflow in the Linux kernel NFSv4.0 LOCK replay cache that can be triggered remotely by unauthenticated attackers using cooperating clients.
Red Hat published its CVE entry for CVE-2026-23270, classifying the Linux kernel act_ct flaw as Moderate severity and noting it requires a specific traffic control configuration to trigger.
An upstream linux-cve-announce advisory for CVE-2026-23270 was published, describing a Linux kernel act_ct use-after-free issue in traffic control that can lead to denial of service or possible privilege escalation.
Red Hat released RHSA-2026:35863 to fix CVE-2026-23270 for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and 8.8 Telecommunications Update Service kernel packages.
Red Hat last modified its CVE-2026-23270 record, reflecting updated tracking information for the Linux kernel act_ct vulnerability and its remediation across Red Hat product streams.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.