Red Hat released RHSA-2026:66000, an Important-rated update for Red Hat Enterprise Linux 8, fixing seven Linux kernel vulnerabilities in cryptographic request handling, Netfilter conntrack and SYN proxy processing, rhashtable iteration, SMB DFS referrals, NVMe-over-RDMA inline-data handling, and bridge fast-leave behavior. The fixed release, 4.18.0-553.160.1.el8_10, is available for x86_64, s390x, ppc64le, and aarch64 systems, including applicable Extended Life Cycle and CodeReady Linux Builder repositories.
Notable fixes include a stack out-of-bounds write in SIP/SDP NAT processing (CVE-2026-53002), a potential use-after-free caused by a stale TCP-header pointer in Netfilter SYN proxy handling (CVE-2026-64007), a use-after-free in rhashtable iterator restarts (CVE-2026-64563), and insufficient validation of SMB DFS referral PathConsumed values (CVE-2026-68343). AlmaLinux 8 has issued a corresponding update for the same seven CVEs; no known exploitation was reported in the referenced notices. Administrators should update affected kernel packages and reboot systems to load the patched kernel.

See real exploitation activity before you spend the cycle.
22 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:67720 for RHEL EUS 9.6 and RHSA-2026:67723 for RHEL 9.2, addressing separate sets of 11 and 10 kernel CVEs, respectively. Both notices state that no known exploits were available.
Red Hat published RHSA-2026:67277 to patch an unspecified vulnerability affecting RHEL 10 kernel-related packages.
Red Hat published RHSA-2026:67114 to patch an unspecified vulnerability affecting RHEL 10 and RHEL EUS 10.0 kernel package variants.
Miracle Linux published AXSA-2026-1815 for Miracle Linux 8 kernel packages, addressing 14 CVEs including CVE-2024-57849, CVE-2025-71132, and multiple 2026 kernel vulnerabilities.
Rocky Linux published RLSA-2026:66355 and Oracle Linux published ELSA-2026-66355-0 to patch the unspecified kernel vulnerability affecting their Linux 10 distributions.
Red Hat issued Important-rated RHSA-2026:66325 for RHEL 8, updating the kernel to 4.18.0-553.162.1.el8_10 and fixing 15 CVEs across SCSI, networking, Netfilter, SCTP, TIPC, key-management, and ixgbevf components. Systems require a reboot after installation.
A patch for the unspecified vulnerability affecting CentOS 9 kernel packages and related tooling was published.
Oracle Linux published ELSA-2026-64808-0 for Oracle Linux 9 kernel packages, addressing eight CVEs including CVE-2025-38004 and seven CVEs assigned in 2026.
A kernel patch for the unspecified vulnerability affecting RHEL 10.2 was published under RHSA-2026:66355.
Red Hat issued Important-rated RHSA-2026:66000 for RHEL 8, updating the kernel to 4.18.0-553.160.1.el8_10 and fixing seven CVEs, including CVE-2026-43493, CVE-2026-53002, and CVE-2026-64007. Updated systems must be rebooted for the fixes to take effect.
AlmaLinux published a kernel patch for AlmaLinux 9 under ALSA-2026:64808, covering the vulnerability information associated with the advisory 64808 update.
Vulnerability information was published for an unspecified kernel issue affecting RHEL 10.2, Rocky Linux 10, and Oracle Linux 10. The supplied notices state that no known exploits were available.
An unspecified vulnerability affecting RHEL 10 kernel-related packages was published.
The Linux kernel upstream published an advisory for CVE-2026-64007, involving a stale TCP-header pointer in Netfilter SYN proxy processing after skb_ensure_writable().
The Linux kernel upstream published an advisory for CVE-2026-53091, a GSO packet-processing issue in qdisc_pkt_len_segs_init(). The remediation pulls required headers with pskb_may_pull() and drops malformed GSO packets earlier.
An unspecified vulnerability affecting RHEL 10 and RHEL EUS 10.0 kernel package variants was published.
Vulnerability information was published for 11 CVEs affecting RHEL EUS 9.6 kernel packages, including CVE-2026-46117, CVE-2026-53000, CVE-2026-63887, and CVE-2026-68166.
Vulnerability information was published for seven Linux kernel flaws later addressed in RHEL 8 by RHSA-2026:66000, including pcrypt, Netfilter, rhashtable, SMB, NVMe-over-RDMA, and bridge issues.
Vulnerability information for a set of ten kernel CVEs affecting RHEL 9.2 was published, including CVE-2026-43114, CVE-2026-45998, CVE-2026-53006, and CVE-2026-64304.
A vulnerability affecting CentOS 9 kernel packages and related tooling was published. The supplied notice does not identify the CVE.
Vulnerability information dated June 8, 2025 was published for the kernel update later tracked as ELSA-2026-64808 for Oracle Linux 9 and ALSA-2026:64808 for AlmaLinux 9; the Oracle notice includes CVE-2025-38004 and seven 2026 CVEs.
Vulnerability information for CVE-2024-57849 was published, describing a local kernel issue with potentially high confidentiality, integrity, and availability impact.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
29 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.