Red Hat released a series of kernel security advisories across RHEL 8 and RHEL 9 product lines, covering standard, real-time, SAP, telecommunications, NFV, and extended life cycle channels. The updates address multiple high-impact flaws including CVE-2026-23216 (use-after-free in iSCSI target code), CVE-2026-45984 (use-after-free in the GFS2 iomap inline data write path), CVE-2026-46189 (double free in RDMA/vmw_pvrdma), CVE-2026-23191 (ALSA aloop), CVE-2026-23401 (KVM privilege escalation or denial of service), and CVE-2026-31431 (crypto algif_aead). Red Hat also disclosed broader kernel rollups for some RHEL 8.6 and 8.8 channels, including fixes for older and newer CVEs spanning NVMe, IPv6, tunneling, networking, memory corruption, overflow, and denial-of-service conditions.
The advisories include Important and Critical ratings depending on the affected branch, with one RHEL 8.6 Extended Update Support and Advanced Mission Critical update fixing 16 kernel vulnerabilities. Affected offerings include RHEL 8.6, 8.8, and 8 standard and specialized variants, plus RHEL 9.2 SAP-related builds across x86_64, ppc64le, aarch64, and s390x. Red Hat said updated kernel packages are available for each channel, noted some releases also include non-security fixes such as an .sbat section addition and an NFS log correction, and instructed customers to reboot systems after applying the updates for protections to take effect.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-07, Red Hat published RHSA-2026:36049, an Important security advisory for kernel-rt on RHEL 8. The Real Time kernel update fixed the same three vulnerabilities: CVE-2026-23216, CVE-2026-45984, and CVE-2026-46189.
On 2026-06-30, Red Hat issued RHSA-2026:33743, an Important kernel security advisory for RHEL 8. The update fixed three kernel vulnerabilities: CVE-2026-23216 in iSCSI target code, CVE-2026-45984 in GFS2, and CVE-2026-46189 in RDMA/vmw_pvrdma.
On 2026-06-12, Red Hat published RHSA-2026:25533, a Critical kernel security advisory for RHEL 8.6 Extended Update Support Long-Life Add-On and Advanced Mission Critical Update Support. The update released kernel version 4.18.0-372.195.1.el8_6 and addressed 16 vulnerabilities, including CVE-2024-41073, CVE-2023-53372, CVE-2025-40170, CVE-2026-23216, CVE-2026-31532, and several other 2025 and 2026 CVEs.
On 2026-06-03, Red Hat issued RHSA-2026:22964, an Important kernel security advisory for RHEL 8.8 SAP Solutions and Telecommunications Update Service variants. The update shipped kernel version 4.18.0-477.145.1.el8_8 and fixed seven vulnerabilities including CVE-2024-41073, CVE-2025-40170, CVE-2025-40135, CVE-2025-40158, CVE-2026-23216, CVE-2026-43037, and CVE-2026-43038.
On 2026-05-06, Red Hat issued RHSA-2026:14230, an Important kernel security advisory for several RHEL 8.6 service variants. The update provided kernel version 4.18.0-372.191.1.el8_6 and fixed CVE-2026-23191, CVE-2026-23401, and CVE-2026-31431.
On 2026-05-05, Red Hat published RHSA-2026:13734, an Important kernel security advisory for RHEL 9.2 variants. The update delivered kernel version 5.14.0-284.169.1.el9_2 and fixed multiple flaws including CVE-2026-23191, CVE-2026-23097, CVE-2026-23193, CVE-2026-31402, and CVE-2026-31431.
On 2026-06-04, Red Hat updated advisory RHSA-2026:22964 after its initial issuance the previous day. The source notes the advisory revision but does not describe additional technical changes beyond the existing kernel security update.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.