Red Hat released Important security updates for multiple kpatch live patch packages on Red Hat Enterprise Linux 8 to address several Linux kernel flaws, including CVE-2026-31419, a use-after-free bug in the bonding driver. The issue occurs in bond_xmit_broadcast() because of a race condition during concurrent slave enslave and release operations, which can double-free the original socket buffer and crash the system. Red Hat said a local low-privilege attacker could exploit the flaw to trigger a denial of service, and rated the vulnerability with a CVSS v3 score of 7.0.
The fixes were included in advisory RHSA-2026:36530 for kernel live patch modules for kernel-4.18.0-553.53.1.el8_10, alongside patches for CVE-2026-23401 and CVE-2026-31402, which affect KVM and nfsd. Red Hat said the bonding-driver flaw affects RHEL 8.8 and later, RHEL 9.2 and later, RHEL 10, RHEL 6, and Red Hat In-Vehicle OS 2.0, while RHEL 7, 8.2, 8.4, 8.6, and 9.0 are not affected; the July advisory specifically covers affected RHEL 8 x86_64 and ppc64le systems, including Extended Life Cycle 8.10 variants.

See real exploitation activity before you spend the cycle.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Important security advisory RHSA-2026:36534 for multiple Red Hat Enterprise Linux 9.6 kpatch live patch packages, including Extended Update Support, AUS, SAP Solutions, and Extended Life Cycle variants. The update fixes CVE-2026-23401, CVE-2026-31402, and CVE-2026-31419 for kernel-5.14.0-570.17.1.el9_6 on x86_64 and ppc64le.
Red Hat published Important security advisory RHSA-2026:36533 for multiple Red Hat Enterprise Linux 9.4 kpatch live patch packages, including AUS, SAP Solutions, and Extended Life Cycle variants on x86_64 and ppc64le. The update fixes CVE-2026-23401, CVE-2026-31402, and CVE-2026-31419 for kernel 5.14.0-427 series builds.
Red Hat published Important security advisory RHSA-2026:36532 for multiple Red Hat Enterprise Linux 9.2 kpatch live patch packages, including AUS, SAP Solutions, and Extended Life Cycle variants on x86_64 and ppc64le. The update fixes CVE-2026-23401, CVE-2026-31402, and CVE-2026-31419 for kernel-5.14.0-284.117.1.el9_2.
Red Hat issued Important security advisory RHSA-2026:36530 for multiple Red Hat Enterprise Linux 8 kpatch live patch packages. The update fixed CVE-2026-23401, CVE-2026-31402, and CVE-2026-31419 for kernel-4.18.0-553.53.1.el8_10 on x86_64 and ppc64le, including Extended Life Cycle 8.10 variants.
Red Hat published security advisory RHSA-2026:13566 for the Red Hat Enterprise Linux 10 kernel to address CVE-2026-31419.
Red Hat published details for CVE-2026-31419, describing an Important-severity Linux kernel bonding driver use-after-free flaw that a low-privileged local attacker could exploit to cause denial of service. The entry also identified affected and unaffected Red Hat product versions and assigned a CVSS v3 score of 7.0.
Greg Kroah-Hartman published the Linux kernel CVE announcement for CVE-2026-31419, describing a use-after-free flaw in the bonding driver’s bond_xmit_broadcast() caused by a race during slave list iteration. The notice identified upstream fixes in kernel versions 6.18.22, 6.19.12, and 7.0 and recommended upgrading to the latest stable kernel release.
Red Hat published RHSA-2026:36531 for the Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions kpatch-patch package to remediate CVE-2026-31419.
Red Hat published RHSA-2026:35870 for the Red Hat Enterprise Linux 10 kpatch-patch package to address CVE-2026-31419.
Red Hat published RHSA-2026:27353 for the Red Hat Enterprise Linux 8 kernel and RHSA-2026:27354 for the RHEL 8 kernel-rt package to fix CVE-2026-31419.
Red Hat published RHSA-2026:25191 for the Red Hat Enterprise Linux 10 kernel as another advisory addressing CVE-2026-31419.
Red Hat published RHSA-2026:22334 for the Red Hat Enterprise Linux 10.0 Extended Update Support kernel to remediate CVE-2026-31419.
Red Hat published RHSA-2026:19521 on May 20, 2026 for Red Hat Enterprise Linux 8.8 Telecommunications Update Service and Update Services for SAP Solutions kernel packages to fix CVE-2026-31419.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
9 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.