Red Hat released Important kernel updates to fix CVE-2026-74581, a use-after-free flaw in the Linux IPv6 FIB rule lookup path. In fib6_rule_suppress, a stale res->rt6 pointer can be returned after its associated rt6_info route object has been freed and later released again, creating a potential kernel crash or privilege-escalation condition. Exploitation requires the ability to configure IPv6 routing or FIB rules; the issue is classified as CWE-416.
The remediation is included in RHEL 9 kernel updates, including RHSA-2026:59723 and applicable kernel-rt updates, and in selected RHEL 8.4 AUS and Extended Life Cycle/Long-Life support channels through advisories including RHSA-2026:59994 and RHSA-2026:60485. Administrators should update affected kernel packages and reboot to activate the fix. Blacklisting IPv6 modules does not mitigate affected kernels with IPv6 built in; organizations that do not require IPv6 can consider disabling it through kernel command-line configuration. Related Oracle Linux and AlmaLinux 9 kernel updates also incorporate the broader RHEL 9 kernel fixes; available notices reported no known public exploits.

See real exploitation activity before you spend the cycle.
12 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:61351 for RHEL 10 and RHEL EUS 10.0, updating standard, real-time, 64K-page-size, debug, module, development, tool, and zfcpdump kernel package variants. The referenced record does not identify the underlying CVE or vulnerability class and reports no known public exploits.
Red Hat published Important advisory RHSA-2026:60485 to fix CVE-2026-74581 in affected RHEL 8 kernel packages. The update covers kernel components including kernel-core, kernel-modules, kernel-devel, and kernel tools.
Rocky Linux published RLSA-2026:59821 and RLSA-2026:59737 for Rocky Linux 8 kernel and kernel-rt packages. The advisories address eight kernel vulnerabilities, including CVE-2026-63886, CVE-2026-64320, the ipset race CVE-2026-64189, and Synaptics RMI4 flaws.
Red Hat issued Important advisory RHSA-2026:60438 to remediate CVE-2026-74581 in affected RHEL 9 kernel-rt packages, including the Real Time Linux Kernel components.
AlmaLinux published ALSA-2026:59723 for kernel packages across its AlmaLinux 9 repositories. The update addresses 13 CVEs, including race-condition, use-after-free, and out-of-bounds memory-safety issues.
Oracle Linux released ELSA-2026-59723 for Oracle Linux 9 and 9.8 BaseOS Patch systems. The kernel update addresses the same 13 CVEs covered by RHSA-2026:59723, including CVE-2026-74581.
Red Hat issued Important advisory RHSA-2026:59994 for RHEL 8.4 Extended Life Cycle Long Life and Server AUS systems, fixing CVE-2026-74581 through updated kernel packages. Systems must be rebooted for the remediation to take effect.
Red Hat issued RHSA-2026:59723, an Important RHEL 9 kernel update addressing 13 CVEs, including CVE-2026-74581, CVE-2026-53185, and several Netfilter, SCTP, I2C, and Synaptics driver flaws. A reboot is required after installation.
The Linux kernel upstream advisory for CVE-2026-74581 was published. The issue could be triggered by a local attacker able to configure IPv6 routing or FIB rules, potentially causing a kernel crash or privilege escalation.
CVE-2026-74581 was published as a use-after-free flaw in Linux IPv6 FIB rule lookup. A stale res->rt6 pointer in fib6_rule_suppress can result in operations on freed route memory.
CVE-2026-63886, an iSCSI target CHAP_R length-validation flaw that can lead to unsafe Base64 decoding, was published.
CVE-2026-23003, affecting Linux kernel IPv6 tunneling, was published. The flaw can be exploited locally with low privileges to cause a high availability impact.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
12 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.