Red Hat released Important kernel security updates for RHEL 8.4 and RHEL 8.2 support channels, including Advanced Mission Critical Update Support, Extended Update Support Long-Life Add-On, and Advanced Update Support. The advisories RHSA-2026:3360 and RHSA-2026:3388 update Linux kernel packages to remediate multiple vulnerabilities affecting supported x86_64 systems, with impact ranging from memory corruption and out-of-bounds read/write to denial of service, information disclosure, integer overflow, incomplete input validation, and potential privilege escalation.
Among the patched issues is CVE-2023-53827, a Bluetooth L2CAP use-after-free flaw in l2cap_disconnect_req and l2cap_disconnect_rsp that could occur when a channel was referenced as it was being destroyed. Red Hat said the bug was fixed by using l2cap_chan_hold_unless_zero, and confirmed the remediation is included in both advisories. Affected organizations are advised to install the updated kernel packages and reboot systems for the fixes to take effect.

See real exploitation activity before you spend the cycle.
11 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-25, Red Hat issued Moderate-rated RHSA-2026:5821 for RHEL 8.4 Extended Life Cycle Long Life and Server AUS x86_64 channels. The update provides kernel 4.18.0-305.187.1.el8_4 to fix CVE-2025-38024, CVE-2025-38129, and CVE-2025-40269, and requires a reboot after installation.
On 2026-02-26, Red Hat published RHSA-2026:3388, an Important kernel security advisory for Red Hat Enterprise Linux Server - AUS 8.2 x86_64. The update ships kernel 4.18.0-193.187.1.el8_2 packages, fixes ten CVEs including CVE-2026-23074 and CVE-2023-53827, and requires a reboot after installation.
On 2026-02-25, Red Hat Bugzilla entry 2420376 described CVE-2023-53827 as a Bluetooth L2CAP use-after-free in l2cap_disconnect_req and l2cap_disconnect_rsp. The entry states the fix uses l2cap_chan_hold_unless_zero and notes the issue was addressed in RHEL 8.4 and RHEL 8.2 through RHSA-2026:3360 and RHSA-2026:3388.
On 2026-02-25, Red Hat published RHSA-2026:3360, an Important kernel security advisory for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On. The update to kernel version 4.18.0-305.186.1.el8_4 fixes multiple CVEs, including CVE-2026-23074 and CVE-2023-53827, and requires a reboot after installation.
On 2026-02-04, Red Hat published Important-rated RHSA-2026:1886 for RHEL 8.4 AUS and Extended Life Cycle Long Life x86_64 deployments. The update provides kernel 4.18.0-305.184.1.el8_4 to address eight vulnerabilities, including CVE-2022-49290, CVE-2023-53751, and CVE-2025-68301, and requires a reboot after installation.
On 2025-10-13, Red Hat published Moderate-rated RHSA-2025:17812 for RHEL 8 kernel-rt packages, including Real Time 8, Real Time for NFV 8, and RHEL 8.10 Extended Life Cycle. The update provides kernel-rt 4.18.0-553.79.1.rt7.420.el8_10 and remediates CVE-2022-50228 and the CVE-2023-53305 Bluetooth L2CAP use-after-free; a reboot is required.
On 2025-09-18, an upstream advisory referenced CVE-2022-50386, a Linux Bluetooth L2CAP channel-lifetime use-after-free detected by KASAN. The remediation uses l2cap_chan_hold_unless_zero() after __l2cap_get_chan_blah() to prevent use of a channel whose reference count has reached zero; Red Hat subsequently issued fixes for affected RHEL 7, 8, and 9 streams.
On 2025-09-16, the Linux kernel CVE process referenced CVE-2023-53305, a potential Bluetooth L2CAP use-after-free in l2cap_le_command_rej. Red Hat subsequently addressed the issue through multiple RHSA advisories for RHEL 7, 8, and 9 variants.
Red Hat Bugzilla documented CVE-2022-50228, in which userspace can inject an interrupt while AMD SVM's Global Interrupt Flag is cleared through KVM_SET_VCPU_EVENTS, triggering a BUG or WARN and potentially an invalid-opcode kernel crash in svm_inject_irq. The upstream fix prevents KVM SVM from issuing a BUG or WARN solely for this userspace-forced interrupt-injection state; Red Hat addressed it through advisories for multiple RHEL 8 and 9 streams.
Red Hat Bugzilla documented CVE-2022-3640, a critical Linux Bluetooth use-after-free flaw in l2cap_conn_del in net/bluetooth/l2cap_core.c. The issue was fixed upstream by commit 42cf46dea905a80f6de218e837ba4d4cc33d6979 and remediated through RHSA advisories for affected RHEL 7, 8, and 9 releases.
Red Hat Bugzilla documented CVE-2025-40248, in which signal or timeout handling during an already-established vsock connect() can disconnect the socket and race with sendmsg() or sockmap operations, potentially causing use-after-free or null-pointer dereference conditions. The upstream fix preserves established sockets when connect() receives a signal or times out, and Red Hat remediated the issue through RHSA advisories across RHEL 7 through 10 and multiple update streams.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.