Red Hat released Important RHEL 8 kernel and real-time kernel updates to remediate CVE-2026-46117 and CVE-2026-53071. The updates include kernel version 4.18.0-553.146.1.el8_10 and real-time kernel version 4.18.0-553.146.1.rt7.487.el8_10, covering supported RHEL 8, RHEL 8.10 Extended Life Cycle, Real Time 8, and Real Time for NFV 8 deployments across applicable architectures.
CVE-2026-46117 affects the RDMA/MANA mana_ib_create_qp_rss() path, where user-supplied work queues sharing a completion queue could trigger WARN_ON() and lead to kernel corruption; the fix rejects the invalid configuration. CVE-2026-53071 fixes a missing lock in Bluetooth L2CAP enhanced credit-based reconfiguration handling that could let a remote BLE device corrupt the channel list through a crafted response. Organizations should install the applicable RHSA updates and reboot affected systems to activate the patched kernels.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2026:42552 for standard RHEL 8 kernel packages across supported architectures. The update fixes the RDMA/MANA WARN_ON issue tracked as CVE-2026-46117 and the Bluetooth L2CAP locking flaw tracked as CVE-2026-53071.
Red Hat issued Important-rated RHSA-2026:42550 for RHEL 8 kernel-rt packages, including Real Time and Real Time for NFV offerings. The update fixes CVE-2026-46117 and CVE-2026-53071 and addresses the vmd_pci_write lock-order deadlock tracked as RHEL-174916.
Red Hat issued Important-rated advisory RHSA-2026:30129 for Red Hat Enterprise Linux 10 kernel packages. The update remediates eight vulnerabilities, including CVE-2026-46117, and fixes unexpected execmem SELinux denials following the CVE-2026-46054 fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.