Red Hat released Moderate-severity Linux kernel updates for affected Red Hat Enterprise Linux 8.6, 9.6, and 10 support streams, remediating memory-safety, denial-of-service, information-disclosure, data-corruption, and potential local privilege-escalation vulnerabilities. The updates cover multiple architectures and specialized support offerings, including EUS, ELS, SAP, telecommunications, and Advanced Mission Critical channels; RHEL 8.6 receives kernel 4.18.0-372.185.1.el8_6.
Among the fixed issues is CVE-2025-71085, an IPv6 CALIPSO flaw that can trigger a kernel oops through a BUG_ON condition in pskb_expand_head(). A local attacker able to configure CALIPSO and send crafted IPv6 traffic could exploit an integer-cast issue that turns an oversized headroom value negative; the fix restricts skb_cow() use in calipso_skbuff_setattr() to headroom growth. Organizations should apply the relevant RHSA kernel packages and reboot systems to activate the fixes.

See real exploitation activity before you spend the cycle.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2026:5693 for the standard kernel on RHEL 9.0 Update Services for SAP Solutions. Kernel version 5.14.0-70.171.1.el9_0 fixes CVE-2022-49985, CVE-2025-40240, and CVE-2025-71085 across x86_64, ppc64le, aarch64, and s390x systems; a reboot is required.
Red Hat issued Moderate-severity advisory RHSA-2026:5732 for kernel-rt on RHEL 9.0 Update Services for SAP Solutions on x86_64. Kernel-rt version 5.14.0-70.171.1.rt21.243.el9_0 fixes CVE-2022-49985, CVE-2025-40240, and CVE-2025-71085; affected systems require a reboot.
Red Hat issued Moderate-severity advisory RHSA-2026:5691 for RHEL 8.6 specialized support channels, releasing kernel version 4.18.0-372.185.1.el8_6. It fixes four kernel vulnerabilities, including CVE-2025-71085, and requires systems to be rebooted after installation.
Red Hat issued Moderate-severity advisory RHSA-2026:4745 for supported RHEL 9.6 channels, providing kernel version 5.14.0-570.98.1.el9_6. The update fixes five vulnerabilities, including CVE-2024-53229, CVE-2025-38206, CVE-2025-40240, CVE-2025-71085, and CVE-2025-68811; systems require a reboot after installation.
Red Hat issued Moderate-severity advisory RHSA-2026:3964 for RHEL 8 kernel-rt packages used by Real Time, Real Time for NFV, and RHEL 8.10 Extended Life Cycle offerings. The update provides kernel-rt version 4.18.0-553.111.1.rt7.452.el8_10, fixing CVE-2025-71085 and the potential macvlan use-after-free CVE-2026-23001; a reboot is required.
Red Hat issued Moderate-severity advisory RHSA-2026:3963 for the standard RHEL 8 kernel, providing version 4.18.0-553.111.1.el8_10 for supported architectures and RHEL 8.10 Extended Life Cycle channels. The update fixes CVE-2025-71085 in IPv6 CALIPSO handling and the macvlan use-after-free CVE-2026-23001; affected systems require a reboot.
Red Hat issued Moderate-severity advisory RHSA-2026:4012 for RHEL 10 and associated support offerings. The kernel update fixes 10 vulnerabilities, including CVE-2025-71085 in IPv6 CALIPSO handling, and requires a system reboot to take effect.
Red Hat issued Moderate-severity advisory RHSA-2026:3488 for RHEL 9 kernel packages, fixing CVE-2025-40168, CVE-2025-71085, and CVE-2026-23097. The update applies across RHEL 9 variants and architectures; systems must be rebooted after installation.
Red Hat issued Moderate-severity advisory RHSA-2026:2759 for RHEL 9.6 support channels, shipping kernel version 5.14.0-570.89.1.el9_6. The update fixes eight vulnerabilities, including use-after-free, data-corruption, denial-of-service, and potential privilege-escalation issues; a reboot is required.
Red Hat issued Moderate-severity advisory RHSA-2025:22006 for supported RHEL 8.6 service variants, providing kernel version 4.18.0-372.170.1.el8_6. The update fixes 18 CVEs across networking, Bluetooth, Wi-Fi, USB audio, NFS, CIFS, ext4, RDMA, memory-failure handling, and x86 VMSCAPE mitigation; systems must be rebooted after installation.
Red Hat issued Moderate-severity advisory RHSA-2025:13589 for RHEL 8, providing kernel version 4.18.0-553.69.1.el8_10. The update fixes six vulnerabilities, including IPv6, use-after-free, race-condition, and Wi-Fi driver flaws, and requires a reboot after installation.
Red Hat documented CVE-2025-38718, in which SCTP's sctp_rcv() processing of cloned GSO packets can access unsafe shared fragment-list buffers and trigger KMSAN-reported use-of-uninitialized-memory conditions. The upstream fix linearizes cloned GSO packets before processing, and Red Hat issued advisories for affected RHEL 7, 8, 9, and 10 product streams.
Red Hat documented CVE-2024-46679, an ethtool link-settings race in which access during network-device reset or removal could use state from a no-longer-present device and panic the kernel. The fix moves device-presence validation into ethtool's link-settings path, and Red Hat addressed the issue through advisories for multiple RHEL 8 and 9 support channels.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
14 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.