Red Hat released multiple kernel security advisories for Red Hat Enterprise Linux 8, 9, and 10 channels to address several Linux kernel vulnerabilities, including CVE-2026-23097, CVE-2026-23193, CVE-2026-31402, CVE-2026-31431, and CVE-2026-43077. The flaws span a hugetlb folio migration deadlock that can trigger system hangs and denial of service, a use-after-free in iSCSI target code, a qla2xxx double-free that may enable denial of service or privilege escalation, a heap overflow in the NFSv4.0 LOCK replay cache, and a crypto algif_aead buffer-size validation issue that could lead to crashes, memory corruption, memory disclosure, or possible code execution in some contexts.
The updates were published through advisories including RHSA-2026:11313, RHSA-2026:13664, RHSA-2026:13681, RHSA-2026:13887, and RHSA-2026:14165, covering product variants such as RHEL 8.4, 8.6, 8.8, 9.6, and 10.0 support channels. Red Hat rated several of the kernel updates as Important and noted that no acceptable mitigation was available for the hugetlb deadlock issue; affected systems require installation of the updated kernel packages and a reboot for protections to take effect.

See real exploitation activity before you spend the cycle.
14 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:14165, an Important kernel security update for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On. The advisory fixed CVE-2026-23193 along with CVE-2025-71238, CVE-2026-31402, and CVE-2026-31431.
Red Hat published RHSA-2026:13681, an Important kernel security update for Red Hat Enterprise Linux 8.8 SAP Solutions and Telecommunications Update Service. The advisory fixed CVE-2026-23097, CVE-2026-23193, CVE-2026-31402, and CVE-2026-31431.
Red Hat published RHSA-2026:13664, an Important kernel security update for several Red Hat Enterprise Linux 8.6 service variants. The advisory fixed CVE-2026-23097 along with CVE-2026-23193, CVE-2025-71238, and CVE-2026-31402.
Red Hat published RHSA-2026:13887 for Red Hat Enterprise Linux 10.0 Extended Update Support and related channels. The advisory fixed CVE-2026-31431 in the Linux kernel algif_aead crypto component.
Red Hat published RHSA-2026:11313, a Moderate-severity kernel security update for Red Hat Enterprise Linux 9.6. The advisory fixed CVE-2026-23097 and CVE-2026-31402 across multiple RHEL 9.6 channels and architectures.
Red Hat published RHSA-2026:6572, a Moderate-severity security advisory for Red Hat Enterprise Linux 8 kernel-rt packages. The update fixed CVE-2024-26984, CVE-2026-23193, CVE-2026-23231, and CVE-2025-71238 across RHEL for Real Time 8, NFV 8, and Extended Life Cycle 8.10 systems.
Red Hat fixed CVE-2026-23097 in Red Hat Enterprise Linux 10 kernel packages via RHSA-2026:4012. The update addressed the hugetlb folio migration deadlock flaw.
An upstream advisory posted at lore.kernel.org disclosed CVE-2026-23231, a Linux kernel netfilter nf_tables use-after-free in nf_tables_addchain(). The advisory described race conditions in both chain dumping and packet processing and the fix of adding synchronize_rcu() before chain destruction.
Red Hat issued RHSA-2026:3463 and RHSA-2026:3464 to fix CVE-2026-23097 in Red Hat Enterprise Linux 8 kernel-rt and kernel packages. These were the first fixes listed for the vulnerability.
Red Hat published the CVE-2026-23097 entry describing a Linux kernel deadlock vulnerability in hugetlb folio migration that can cause denial of service. Red Hat said no acceptable mitigation was currently available.
Red Hat issued additional fixes for CVE-2026-23097 in older supported RHEL 8 streams. RHSA-2026:26535 covered RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On.
Red Hat last modified its CVE-2026-43077 entry. The update followed the initial publication and listed fixed package advisories across multiple RHEL streams.
Red Hat fixed CVE-2026-23097 in Red Hat Enterprise Linux 10.0 Extended Update Support kernel packages via RHSA-2026:15883. This expanded remediation for the vulnerability to the 10.0 EUS stream.
Red Hat published the CVE-2026-43077 entry for a Linux kernel algif_aead decryption buffer-size validation flaw. The issue was described as an incorrect minimum receive buffer size check that failed to account for the authentication tag size.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 22 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.