Red Hat released kernel security updates for RHEL 8, RHEL 8 Real Time, and RHEL 9.6 to address multiple Linux kernel vulnerabilities, including CVE-2026-23209 in the macvlan subsystem and CVE-2026-23204 in net/sched cls_u32. The macvlan flaw stems from improper error recovery in macvlan_common_newlink(), where a failed device creation path could leave stale references in vlan_source_hash and trigger a use-after-free when packets are later processed. The cls_u32 flaw was caused by skb_header_pointer() not fully validating negative offsets, creating a slab out-of-bounds condition in u32_classify().
Upstream fixes changed the affected code paths by ensuring macvlan_flush_sources() runs on the relevant error path and by replacing skb_header_pointer() with skb_header_pointer_careful(). Red Hat published the fixes through advisories including RHSA-2026:6037, RHSA-2026:6036, and RHSA-2026:6164, covering multiple architectures and support channels such as Extended Life Cycle, CodeReady Linux Builder, and real-time offerings. Red Hat rated the updates Moderate and said affected systems must be rebooted after patching for the kernel fixes to take effect.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:9515 for RHEL 8.8 update service variants, delivering a kernel update that fixes CVE-2026-23204 in net/sched cls_u32. The advisory also addressed CVE-2026-23231 in nf_tables_addchain() and instructed customers to reboot after applying the update.
Red Hat published RHSA-2026:6953 for RHEL Server Advanced Update Support 8.2 on x86_64, delivering kernel version 4.18.0-193.193.1.el8_2 with a fix for CVE-2026-23209 in macvlan_common_newlink(). The update also addressed CVE-2022-49674, CVE-2025-38180, and CVE-2021-4460; affected systems require a reboot.
Red Hat published RHSA-2026:6692 for RHEL 10.0, delivering kernel version 6.12.0-55.66.1.el10_0. The update fixes the svcrdma memcpy byte-offset flaw CVE-2025-68811 and the macvlan error-recovery flaw CVE-2026-23209; affected systems require a reboot.
Red Hat published RHSA-2026:6164 for Red Hat Enterprise Linux 9.6 Extended Update Support channels, including a fix for CVE-2026-23209 in macvlan_common_newlink(). The advisory also addressed three other kernel vulnerabilities and instructed customers to reboot after applying the update.
Red Hat published RHSA-2026:6036 and RHSA-2026:6037 to deliver kernel-rt and kernel updates for Red Hat Enterprise Linux 8, fixing CVE-2026-23204 and CVE-2026-23209 along with CVE-2025-38180. The advisories cover RHEL 8 real-time and standard product streams and require a reboot after installation.
An upstream Linux kernel advisory for CVE-2026-23204 was published, documenting the net/sched cls_u32 flaw caused by insufficient validation of negative offset values in skb_header_pointer(). The fix replaced skb_header_pointer() with skb_header_pointer_careful().
An upstream Linux kernel advisory disclosed CVE-2025-38180, a use-after-free vulnerability in /proc/net/atm/lec handling. Unsafe dev_lec[] changes could allow dev_put() without a preceding dev_hold(), creating a reference-count imbalance.
Red Hat addressed the dm-raid out-of-bounds vulnerability CVE-2022-49674 in RHSA-2026:6961 for specified RHEL 8.6 service variants and RHSA-2026:7003 for specified RHEL 8.4 extended-support variants. The flaw could access beyond the allocated rs->devs RAID-member array during RAID layout changes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.