RHSA 2026:61887
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
The kernel packages contain the Linux kernel, the core of any Linux operating system.
kernel: seccomp: passthrough uretprobe systemcall without filtering (CVE-2025-21834)
kernel: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() (CVE-2026-23003)
kernel: netfilter: nf_tables: Fix for duplicate device in netdev hooks (CVE-2026-43454)
kernel: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (CVE-2026-43450)
kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970)
kernel: ip6_gre: Use cached t->net in ip6erspan_changelink() (CVE-2026-46120)
kernel: iommu/amd: Fix clone_alias() to use the original device's devid (CVE-2026-53053)
kernel: NFSD: fix nfs4_file access extra count in nfsd4_add_rdaccess_to_wrdeleg (CVE-2026-53026)
kernel: zram: fix use-after-free in zram_bvec_write_partial() (CVE-2026-53185)
kernel: USB: serial: io_ti: fix heap overflow in get_manuf_info() (CVE-2026-53196)
kernel: mm/huge_memory: update file PMD counter before folio_put() (CVE-2026-53189)
kernel: mm/list_lru: drain before clearing xarray entry on reparent (CVE-2026-53153)
kernel: pNFS: Fix use-after-free in pnfs_update_layout() (CVE-2026-63800)
kernel: nfsd: fix posix_acl leak on SETACL decode failure (CVE-2026-53397)
kernel: nfsd: release layout stid on setlease failure (CVE-2026-53399)
kernel: NFSv4/flexfiles: reject zero filehandle version count (CVE-2026-53392)
kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (CVE-2026-53391)
kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access (CVE-2026-64018)
kernel: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (CVE-2026-64136)
kernel: netfilter: ipset: fix race between dump and ip_set_list resize (CVE-2026-64189)
kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (CVE-2026-64320)
kernel: crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() (CVE-2026-64438)
kernel: crypto: qat - validate RSA CRT component lengths (CVE-2026-64304)
kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (CVE-2026-64298)
kernel: ALSA: virtio: Validate control metadata from the device (CVE-2026-64490)
kernel: mm: shrinker: fix shrinker_info teardown race with expansion (CVE-2026-64418)
kernel: smb: client: fix change notify replay double-free (CVE-2026-64384)
kernel: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (CVE-2026-64277)
kernel: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (CVE-2026-64276)
kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability (CVE-2026-68480)
kernel: mm/khugepaged: write all dirty file folios when collapsing (CVE-2026-68086)
kernel: Linux kernel: Arbitrary code execution via userfaultfd shadow stack manipulation (CVE-2026-68166)
kernel: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (CVE-2026-72069)
kernel: nvmet-auth: reject short AUTH_RECEIVE buffers (CVE-2026-72130)
Bug Fix(es) and Enhancement(s):
RHEL 10: s390: Revert support for DCACHE_WORD_ACCESS [rhel-10.2.z] (JIRA:RHEL-188180)
qede: build_skb failure causes off-by-one BD ring corruption and kernel panic [rhel-10.2.z] (JIRA:RHEL-193043)
ss core dumped when there is an SCTP session [rhel-10.2.z] (JIRA:RHEL-212393)
[RHEL-10.2.z] Intel CWF: CPU is unable to obtain cstate1 on idle system (JIRA:RHEL-218627)
RHEL10.0 - s390/pfault: Fix virtual vs physical address confusion [rhel-10.2.z] (JIRA:RHEL-222507)
For more details the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
For details on how to apply this update, which includes the changes described in this advisory, refer to:
The system must be rebooted for this update to take effect.
Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture.
Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available.
Red Hat Enterprise Linux for x86_64 10 x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64
Red Hat Enterprise Linux for IBM z Systems 10 s390x
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x
Red Hat Enterprise Linux for Power, little endian 10 ppc64le
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le
Red Hat Enterprise Linux for ARM 64 10 aarch64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64
Red Hat CodeReady Linux Builder for x86_64 10 x86_64
Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le
Red Hat CodeReady Linux Builder for ARM 64 10 aarch64
Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x
Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le
Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x
BZ - 2350398 - CVE-2025-21834 kernel: seccomp: passthrough uretprobe systemcall without filtering
BZ - 2432681 - CVE-2026-23003 kernel: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv()
BZ - 2468145 - CVE-2026-43454 kernel: netfilter: nf_tables: Fix for duplicate device in netdev hooks
BZ - 2468228 - CVE-2026-43450 kernel: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table()
BZ - 2482006 - CVE-2026-45970 kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down
BZ - 2482614 - CVE-2026-46120 kernel: ip6_gre: Use cached t->net in ip6erspan_changelink()
BZ - 2492310 - CVE-2026-53053 kernel: iommu/amd: Fix clone_alias() to use the original device's devid
BZ - 2492454 - CVE-2026-53026 kernel: NFSD: fix nfs4_file access extra count in nfsd4_add_rdaccess_to_wrdeleg
BZ - 2492735 - CVE-2026-53185 kernel: zram: fix use-after-free in zram_bvec_write_partial()
BZ - 2492750 - CVE-2026-53196 kernel: USB: serial: io_ti: fix heap overflow in get_manuf_info()
BZ - 2492788 - CVE-2026-53189 kernel: mm/huge_memory: update file PMD counter before folio_put()
BZ - 2492790 - CVE-2026-53153 kernel: mm/list_lru: drain before clearing xarray entry on reparent
BZ - 2502219 - CVE-2026-63800 kernel: pNFS: Fix use-after-free in pnfs_update_layout()
BZ - 2502227 - CVE-2026-53397 kernel: nfsd: fix posix_acl leak on SETACL decode failure
BZ - 2502239 - CVE-2026-53399 kernel: nfsd: release layout stid on setlease failure
BZ - 2502240 - CVE-2026-53392 kernel: NFSv4/flexfiles: reject zero filehandle version count
BZ - 2502260 - CVE-2026-53391 kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
BZ - 2502421 - CVE-2026-64018 kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access
BZ - 2502527 - CVE-2026-64136 kernel: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
BZ - 2502889 - CVE-2026-64189 kernel: netfilter: ipset: fix race between dump and ip_set_list resize
BZ - 2507061 - CVE-2026-64320 kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
BZ - 2507118 - CVE-2026-64438 kernel: crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()
BZ - 2507119 - CVE-2026-64304 kernel: crypto: qat - validate RSA CRT component lengths
BZ - 2507208 - CVE-2026-64298 kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC
BZ - 2507277 - CVE-2026-64490 kernel: ALSA: virtio: Validate control metadata from the device
BZ - 2507285 - CVE-2026-64418 kernel: mm: shrinker: fix shrinker_info teardown race with expansion
BZ - 2507287 - CVE-2026-64384 kernel: smb: client: fix change notify replay double-free
BZ - 2507290 - CVE-2026-64277 kernel: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count
BZ - 2507301 - CVE-2026-64276 kernel: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
BZ - 2508363 - CVE-2026-68480 kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability
BZ - 2513141 - CVE-2026-68086 kernel: mm/khugepaged: write all dirty file folios when collapsing
BZ - 2513167 - CVE-2026-68166 kernel: Linux kernel: Arbitrary code execution via userfaultfd shadow stack manipulation
BZ - 2516248 - CVE-2026-72069 kernel: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
BZ - 2516448 - CVE-2026-72130 kernel: nvmet-auth: reject short AUTH_RECEIVE buffers
Red Hat Enterprise Linux for x86_64 10
Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2
Red Hat Enterprise Linux for IBM z Systems 10
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2
Red Hat Enterprise Linux for Power, little endian 10
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2
Red Hat Enterprise Linux for ARM 64 10
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2
Red Hat CodeReady Linux Builder for x86_64 10
Red Hat CodeReady Linux Builder for Power, little endian 10
Red Hat CodeReady Linux Builder for ARM 64 10
Red Hat CodeReady Linux Builder for IBM z Systems 10
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2
Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2
Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2
The Red Hat security is [email protected] . More details at .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
