Red Hat released kernel security updates for RHEL 9.6 and RHEL 10.0 that address multiple vulnerabilities across NFSD, NFS, KVM on ARM64, ALSA UMP, Intel ASoC, libceph, and other kernel subsystems. RHSA-2026:0804 provides kernel 5.14.0-570.79.1.el9_6 for RHEL 9.6 support channels and is rated Important, while Moderate-rated RHSA-2026:1236 provides kernel 6.12.0-55.55.1.el10_0 for RHEL 10.0, including applicable EUS and CodeReady Linux Builder repositories across supported architectures.
The updates remediate CVE-2025-37891, an ALSA Universal MIDI Packet conversion flaw in which a four-byte buffer could receive up to six bytes of malformed SysEx data, potentially causing memory corruption; the upstream correction expands the buffer to six bytes. Red Hat also previously updated RHEL 8 kernels through RHSA-2025:21917 to fix an NFS write-update race condition, CVE-2025-39697, and an i40e driver index-validation flaw, CVE-2025-39971. Administrators should deploy the applicable kernel packages and reboot affected systems for fixes to take effect.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity RHSA-2026:1236 for RHEL 10.0, providing kernel version 6.12.0-55.55.1.el10_0. The update remediated seven CVEs, including the ALSA UMP buffer overflow CVE-2025-37891, and required a reboot for fixes to take effect.
Red Hat issued Important-rated advisory RHSA-2026:0786 for RHEL 10 kernel packages, fixing CVE-2025-68285, a potential use-after-free flaw in libceph's have_mon_and_osd_map() function. The update applies across supported RHEL 10 architectures and requires affected systems to reboot.
Red Hat issued Important-rated RHSA-2026:0804 for RHEL 9.6 support channels, delivering kernel version 5.14.0-570.79.1.el9_6. It fixed six vulnerabilities, including CVE-2025-37891 in ALSA UMP handling, and required affected systems to reboot.
Red Hat addressed the ALSA UMP SysEx-message buffer-overflow vulnerability, CVE-2025-37891, for RHEL 9.4 Extended Update Support through RHSA-2026:0917. The upstream remediation expands the affected MIDI 1.0-to-UMP conversion buffer from four to six bytes.
Red Hat issued Moderate-severity advisory RHSA-2025:21917 for RHEL 8, providing kernel version 4.18.0-553.85.1.el8_10. The update remediated CVE-2025-39697 and CVE-2025-39971; affected systems require a reboot.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.