Red Hat released a series of Moderate-severity kernel and kernel-rt security advisories across multiple Red Hat Enterprise Linux product lines, including RHEL 9.0, 9.2, 9.4 EUS, 9.6 EUS, RHEL 10, RHEL 10.0 EUS, and RHEL 7 ELS. The updates address several Linux kernel vulnerabilities tied to use-after-free, double-free, memory leak, race condition, denial-of-service, and privilege-escalation conditions. Repeatedly cited issues include CVE-2026-23171 in the bonding module, which can cause a system crash or arbitrary code execution, CVE-2026-23231 in nf_tables_addchain(), which can enable privilege escalation or denial of service, and CVE-2026-23204 in net/sched cls_u32.
Red Hat also highlighted CVE-2026-23001, a macvlan use-after-free in macvlan_forward_source(), with Bugzilla detailing an upstream fix that adds RCU protection so entries queued for freeing are skipped safely. That flaw, along with related macvlan issues such as CVE-2026-23209, was included in updates for several RHEL branches and SAP-related offerings. Advisories consistently state that affected systems must be rebooted after applying the updated kernel packages for the fixes to take effect.

See real exploitation activity before you spend the cycle.
38 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Important-severity advisory RHSA-2026:62641 for RHEL 9.6 kpatch live-patch packages. The update addresses CVE-2026-23111 plus CVE-2026-43114, CVE-2026-43112, CVE-2026-46323, and CVE-2026-53264, covering nf_tables, nft_set_pipapo_avx2, SMB/CIFS, Generic Receive Offload, and traffic-control action lifecycle flaws.
A working local root exploit for the Linux traffic-control action API use-after-free vulnerability CVE-2026-53264 was publicly reported targeting CentOS Stream 9. The report stated that CentOS-Stream-9-20260706.0 remained vulnerable.
Red Hat published RHSA-2026:10756, a Moderate kernel-rt security advisory for RHEL 7 Extended Lifecycle Support. The update fixed nine Linux kernel vulnerabilities, including CVE-2026-23231 and CVE-2025-71238, and required affected systems to be rebooted.
Red Hat published RHSA-2026:10996 for Red Hat Enterprise Linux 10.0 Extended Update Support to fix CVE-2026-23111, a netfilter nf_tables use-after-free flaw that could allow local privilege escalation or denial of service. The Bugzilla entry also notes related fixes for other RHEL streams, including RHEL 9.4 EUS via RHSA-2026:10108.
Red Hat issued RHSA-2026:9836, a Moderate kernel security update for RHEL 9.0 Update Services for SAP Solutions. It released kernel 5.14.0-70.175.1.el9_0 packages fixing CVE-2026-23001, CVE-2026-23204, and CVE-2026-23231.
Red Hat issued RHSA-2026:9835 for kernel-rt packages in RHEL 9.0 Update Services for SAP Solutions on x86_64. The advisory fixed CVE-2026-23001, CVE-2026-23204, and CVE-2026-23231 and stated that systems must be rebooted after applying the update.
Red Hat published RHSA-2026:9512, a Moderate kernel-rt security advisory for RHEL 9.2 Update Services for SAP Solutions and Extended Life Cycle offerings. The update fixed nine Linux kernel vulnerabilities, including CVE-2026-23171 and CVE-2026-23231, and required a system reboot.
Red Hat issued RHSA-2026:9095, a Moderate kernel security advisory for RHEL 10.0 Extended Update Support and related 4-year update/support channels. The update fixed multiple Linux kernel flaws including CVE-2026-23066, CVE-2026-23156, CVE-2026-23193, and CVE-2026-23231, and required a system reboot after installation.
Red Hat issued RHSA-2026:9112, a Moderate kernel security advisory for RHEL 9.6 Extended Update Support and related offerings. The update fixed six vulnerabilities, including CVE-2026-23066, CVE-2026-23111, CVE-2026-23144, CVE-2026-23171, CVE-2026-23193, and CVE-2026-23204.
Red Hat published RHSA-2026:8342, a Moderate kernel update for RHEL 10.0 Extended Update Support and related channels. It fixed CVE-2026-23144, CVE-2026-23171, CVE-2026-23204, and CVE-2025-71238, with a reboot required after applying the packages.
Red Hat published RHSA-2026:7013, a Moderate kernel security update for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions across x86_64, ppc64le, aarch64, and s390x. The advisory fixed five Linux kernel vulnerabilities, including CVE-2026-23209 and four 2025 CVEs, and required systems to be rebooted after installation.
Red Hat published RHSA-2026:6570, a Moderate kernel security update for Red Hat Enterprise Linux 9 and related product variants. The advisory fixed four Linux kernel vulnerabilities including CVE-2025-38109, CVE-2026-23111, CVE-2026-23210, and CVE-2026-23231, and required systems to be rebooted after installation.
Red Hat issued RHSA-2026:6632, a Moderate kernel security update for RHEL 10 and related support streams across multiple architectures. The update addressed seven Linux kernel flaws including CVE-2026-23144, CVE-2026-23171, CVE-2026-23193, and CVE-2026-23204.
Red Hat published RHSA-2026:6310, a Moderate kernel security update for RHEL 9.4 Extended Update Support and related channels. It fixed four vulnerabilities including CVE-2026-23001 and CVE-2026-23209, and required a reboot after installation.
Red Hat published RHSA-2026:6053, a Moderate kernel security update for Red Hat Enterprise Linux 10 and related support streams across multiple architectures. The advisory fixed CVE-2026-23231 and CVE-2025-71238 and stated that systems must be rebooted after applying the update.
Red Hat issued Moderate-severity advisory RHSA-2026:5813 for RHEL 9.2 Update Services for SAP Solutions and associated lifecycle channels. Kernel 5.14.0-284.161.1.el9_2 fixes CVE-2025-38129, CVE-2025-38154, CVE-2025-40240, and CVE-2025-71085; affected systems require a reboot after updating.
Red Hat issued Moderate-severity advisory RHSA-2026:4111 for RHEL 10.0 EUS, four-year support channels, and related CodeReady Linux Builder repositories. Kernel version 6.12.0-55.63.1.el10_0 fixes six flaws, including page_pool, lpfc SCSI, eventpoll, and SMC use-after-free issues; affected systems must be rebooted after updating.
Red Hat issued RHSA-2026:3579, a Moderate-severity kernel security update for RHEL 10.0 and related CodeReady Linux Builder, EUS, and four-year support offerings. Kernel build 6.12.0-55.62.1.el10_0 fixed CVE-2025-37882, CVE-2025-38106, and CVE-2025-38415; Red Hat said systems must be rebooted after installation.
Red Hat issued Moderate-severity advisory RHSA-2026:3124 for RHEL 10.0 EUS and specified four-year support channels. Kernel version 6.12.0-55.61.1.el10_0 fixed CVE-2025-38730, involving io_uring and network-buffer handling, and CVE-2025-39760, a USB configuration-parsing out-of-bounds read; systems require a reboot after updating.
Red Hat issued Moderate-severity advisory RHSA-2026:2761 for RHEL 10.0 EUS and applicable four-year support streams. Kernel version 6.12.0-55.60.1.el10_0 fixes five flaws, including SMB/CIFS and procfs use-after-free issues, a vmalloc data race, Bluetooth MGMT out-of-bounds write, and ALSA USB audio buffer overflow; a reboot is required.
Red Hat published RHSA-2026:2282, a Moderate kernel security advisory for Red Hat Enterprise Linux 10 and related variants. The update addressed eight Linux kernel vulnerabilities including CVE-2025-38415, CVE-2025-40304, CVE-2025-40322, and CVE-2025-68811, and required a system reboot after installation.
An upstream linux-cve-announce advisory disclosed CVE-2026-23001, a possible use-after-free in the Linux kernel macvlan subsystem's macvlan_forward_source(). The issue was later tracked by Red Hat as Bugzilla 2432664.
Red Hat issued Moderate-severity advisory RHSA-2025:23947 for RHEL 7 Extended Lifecycle Support, providing kernel 3.10.0-1160.144.1.el7 for x86_64, s390x, ppc64, and ppc64le. The update fixed 11 kernel CVEs, including ALSA USB-audio, zswap, Bluetooth L2CAP, NILFS, NFSD, iomap, and TCP Fast Open issues; systems require a reboot after installation.
Red Hat issued Moderate-security advisory RHSA-2025:22571 for RHEL 10.0 Extended Update Support, delivering kernel 6.12.0-55.47.1.el10_0. The update fixed flaws in NFS server handling, e1000e and i40e drivers, mt76 Wi-Fi, and TCP Fast Open handling, and required affected systems to be rebooted.
Red Hat issued Moderate-severity advisory RHSA-2025:21118 for RHEL 10 and applicable RHEL 10.2 lifecycle, EUS, and CodeReady Linux Builder channels. The kernel update fixed 12 vulnerabilities, including mount and NFS races, virtio-vsock and audio buffer-overflow issues, and a kernfs polling use-after-free; affected systems require a reboot.
Red Hat issued Moderate-severity advisory RHSA-2025:16904 for RHEL 10 and associated EUS, ELS, four-year support, and CodeReady Linux Builder channels. The kernel update fixed six flaws including CVE-2025-38396, CVE-2025-38527, CVE-2025-38523, CVE-2025-39682, CVE-2025-39698, and CVE-2025-39694; affected systems require a reboot.
An upstream Linux CVE advisory disclosed CVE-2025-39760, an out-of-bounds read in usb_parse_ss_endpoint_companion() during USB SuperSpeed endpoint companion descriptor parsing. The flaw resulted from checking descriptor type before validating descriptor length; the fix validates the descriptor size before accessing its fields.
An upstream Linux kernel disclosure resolved CVE-2025-39682, a TLS recvmsg() handling flaw involving a zero-length initial record sourced from the rx_list receive queue. Red Hat subsequently issued fixes for RHEL 9, RHEL 10, RHEL 9.4 EUS, and RHEL 9.2 SAP Solutions, including RHSA-2025:16880, RHSA-2025:16904, RHSA-2025:19104, RHSA-2025:19223, and RHSA-2025:19224.
An upstream advisory identified CVE-2025-38415, a Squashfs memory-corruption issue triggered by a race between mounting a Squashfs filesystem and changing a loop device block size. The fix added a check for a zero return from sb_min_blocksize() to prevent an invalid 64-bit shift.
An upstream Linux kernel advisory documented CVE-2025-38349, an eventpoll/epoll use-after-free race in which an epoll object's reference count could be decremented before its mutex was fully released. The fix moves the reference-count decrement until after mutex_unlock(), preventing another context from freeing the object while mutex unlock processing may still access it.
An upstream advisory documented CVE-2025-38106, an io_uring use-after-free in __io_uring_show_fdinfo() involving sq->thread. The fix uses RCU-protected thread-pointer access and obtains a task_struct reference before use, preventing dereference of a freed task.
An upstream linux-cve-announce advisory disclosed CVE-2025-37882, a race in USB xHCI isochronous Ring Underrun/Overrun event handling. A delayed interrupt can cause an event TRB pointer to match a newly queued transfer descriptor, risking skipped transfers, data loss, or buffer use-after-free by the controller.
Red Hat Bugzilla 2402699 tracks CVE-2025-39955 in the Linux kernel TCP subsystem. The issue concerns clearing tcp_sk(sk)->fastopen_rsk during tcp_disconnect().
CVE-2025-40064 was documented as a use-after-free in the Linux SMC subsystem's __pnet_find_base_ndev() during connect() processing, where a net_device could be freed before RTNL was acquired. The fix holds a device reference before affected resource lookups and uses __sk_dst_get() and dst_dev_rcu() for safe device access; Red Hat listed fixes across RHEL 8, 9, and 10 streams.
CVE-2025-38730 affects io_uring networking retries using ring-provided buffers: partial retries could retain a buffer beyond its valid execution context, allowing use-after-invalidation after ring unregistration or multiple receives to use the same userspace memory. The fix prevents partial retries from pinning ring-provided buffers across executions; Red Hat remediated the issue through advisories including RHSA-2026:2212, RHSA-2026:2282, RHSA-2026:2759, RHSA-2026:2766, and RHSA-2026:3124.
CVE-2025-40271 was documented as a use-after-free in fs/proc proc_readdir_de(), where a proc directory-entry node removed with rb_erase() was not cleared and could later be returned as a stale pointer during concurrent traversal and netdevice removal. The fix clears the erased red-black-tree node with RB_CLEAR_NODE(), and Red Hat shipped fixes across multiple RHEL releases and support channels.
CVE-2025-40269 was documented as a potential ALSA USB-audio PCM transfer-buffer overflow caused when rate- and PPS-derived URB packet sizes exceed the USB endpoint maximum. The patch adds parameter-setup validation and returns -EINVAL when the computed size is greater than maxpacksize.
Red Hat states that Red Hat Enterprise Linux 10 received a fix for CVE-2026-23210 via RHSA-2026:18134. The bug involved a race condition in the Linux kernel ice driver that could trigger a NULL pointer dereference and kernel crash during VSI rebuild.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
41 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.