Red Hat released multiple kernel and kernel-rt security advisories to remediate Linux kernel vulnerabilities affecting RHEL 8, 9, and 10 product streams, including SAP, NFV, Extended Life Cycle, and Real Time variants. The updates address CVE-2026-23097, a hugetlb folio migration bug that can trigger a denial of service through deadlock caused by incorrect lock ordering; CVE-2026-23193, a use-after-free in the SCSI target iSCSI path iscsit_dec_session_usage_count(); and CVE-2024-41073, an NVMe flaw described as a double free of a special payload. Red Hat also bundled these fixes with other kernel issues such as race conditions, heap overflow, information disclosure, and local privilege escalation bugs in broader kernel update rollups.
The hugetlb flaw was traced to a locking inversion between folio_lock and i_mmap_rwsem, with the fix extending i_mmap_lock coverage around remove_migration_ptes() to prevent deadlock. The iSCSI bug stemmed from calling complete() while sess->session_usage_lock remained held, allowing a waiting thread to free the session structure before the current path finished using it; the fix releases the lock before signaling completion. Red Hat published these remediations through advisories including RHSA-2026:3463, RHSA-2026:6571, RHSA-2026:4012, and RHSA-2026:14301, and said affected systems should be rebooted after applying the updated kernel packages.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:14301 for RHEL 9.2 Update Services for SAP Solutions and RHEL 9.2 Extended Life Cycle, fixing multiple kernel flaws. The advisory includes fixes for CVE-2024-41073, CVE-2026-23097, and CVE-2026-23193 among other vulnerabilities.
Red Hat published RHSA-2026:6571 for Red Hat Enterprise Linux 8, including a fix for CVE-2026-23193 in the kernel SCSI target iSCSI code. The advisory identifies the flaw as a use-after-free in iscsit_dec_session_usage_count().
Red Hat published RHSA-2026:4012, a kernel security update for Red Hat Enterprise Linux 10 that included a fix for CVE-2026-23097. The advisory lists the issue among multiple kernel vulnerabilities remediated in the update.
Red Hat published RHSA-2026:3464 for Red Hat Enterprise Linux 8, providing a kernel security update that fixes CVE-2026-23097. The advisory describes the flaw as a denial-of-service issue caused by a deadlock in hugetlb folio migration and shipped updated kernel packages version 4.18.0-553.109.1.el8_10.
Red Hat published RHSA-2026:3463 to fix CVE-2026-23097 in kernel-rt packages for Red Hat Enterprise Linux 8. The advisory describes the flaw as a denial-of-service issue caused by a deadlock in hugetlb folio migration.
An upstream advisory for CVE-2026-23193 was published on lore.kernel.org for the Linux kernel iSCSI use-after-free flaw in iscsit_dec_session_usage_count(). The bug involved calling complete() while sess->session_usage_lock was still held, enabling a race to free the session structure too early.
Mauro Matteo Cascella reported Red Hat bug 2301637 for the Linux kernel NVMe vulnerability later assigned CVE-2024-41073. The issue was described as "nvme: avoid double free special payload."
Red Hat states CVE-2024-41073 was addressed in Red Hat Enterprise Linux 9 via advisory RHSA-2024:6567. The references do not provide the publication date of that advisory.
The CVE-2024-41073 bug record states the vulnerability was resolved upstream in Linux kernel versions 5.15.164, 6.1.101, 6.6.42, 6.9.11, and 6.10. No explicit release date for those upstream fixes is provided in the references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.