Skip to content

RHSA 2026:61887

access.redhat.com September 2, 2026

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

kernel: seccomp: passthrough uretprobe systemcall without filtering (CVE-2025-21834)

kernel: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() (CVE-2026-23003)

kernel: netfilter: nf_tables: Fix for duplicate device in netdev hooks (CVE-2026-43454)

kernel: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (CVE-2026-43450)

kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970)

kernel: ip6_gre: Use cached t->net in ip6erspan_changelink() (CVE-2026-46120)

kernel: iommu/amd: Fix clone_alias() to use the original device's devid (CVE-2026-53053)

kernel: NFSD: fix nfs4_file access extra count in nfsd4_add_rdaccess_to_wrdeleg (CVE-2026-53026)

kernel: zram: fix use-after-free in zram_bvec_write_partial() (CVE-2026-53185)

kernel: USB: serial: io_ti: fix heap overflow in get_manuf_info() (CVE-2026-53196)

kernel: mm/huge_memory: update file PMD counter before folio_put() (CVE-2026-53189)

kernel: mm/list_lru: drain before clearing xarray entry on reparent (CVE-2026-53153)

kernel: pNFS: Fix use-after-free in pnfs_update_layout() (CVE-2026-63800)

kernel: nfsd: fix posix_acl leak on SETACL decode failure (CVE-2026-53397)

kernel: nfsd: release layout stid on setlease failure (CVE-2026-53399)

kernel: NFSv4/flexfiles: reject zero filehandle version count (CVE-2026-53392)

kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (CVE-2026-53391)

kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access (CVE-2026-64018)

kernel: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (CVE-2026-64136)

kernel: netfilter: ipset: fix race between dump and ip_set_list resize (CVE-2026-64189)

kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (CVE-2026-64320)

kernel: crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() (CVE-2026-64438)

kernel: crypto: qat - validate RSA CRT component lengths (CVE-2026-64304)

kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (CVE-2026-64298)

kernel: ALSA: virtio: Validate control metadata from the device (CVE-2026-64490)

kernel: mm: shrinker: fix shrinker_info teardown race with expansion (CVE-2026-64418)

kernel: smb: client: fix change notify replay double-free (CVE-2026-64384)

kernel: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (CVE-2026-64277)

kernel: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (CVE-2026-64276)

kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability (CVE-2026-68480)

kernel: mm/khugepaged: write all dirty file folios when collapsing (CVE-2026-68086)

kernel: Linux kernel: Arbitrary code execution via userfaultfd shadow stack manipulation (CVE-2026-68166)

kernel: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (CVE-2026-72069)

kernel: nvmet-auth: reject short AUTH_RECEIVE buffers (CVE-2026-72130)

Bug Fix(es) and Enhancement(s):

RHEL 10: s390: Revert support for DCACHE_WORD_ACCESS [rhel-10.2.z] (JIRA:RHEL-188180)

qede: build_skb failure causes off-by-one BD ring corruption and kernel panic [rhel-10.2.z] (JIRA:RHEL-193043)

ss core dumped when there is an SCTP session [rhel-10.2.z] (JIRA:RHEL-212393)

[RHEL-10.2.z] Intel CWF: CPU is unable to obtain cstate1 on idle system (JIRA:RHEL-218627)

RHEL10.0 - s390/pfault: Fix virtual vs physical address confusion [rhel-10.2.z] (JIRA:RHEL-222507)

For more details the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

For details on how to apply this update, which includes the changes described in this advisory, refer to:

The system must be rebooted for this update to take effect.

Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture.

Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available.

Red Hat Enterprise Linux for x86_64 10 x86_64

Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64

Red Hat Enterprise Linux for IBM z Systems 10 s390x

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x

Red Hat Enterprise Linux for Power, little endian 10 ppc64le

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le

Red Hat Enterprise Linux for ARM 64 10 aarch64

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64

Red Hat CodeReady Linux Builder for x86_64 10 x86_64

Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le

Red Hat CodeReady Linux Builder for ARM 64 10 aarch64

Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x

Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64

Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le

Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x

Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x

Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le

Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64

Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64

Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le

Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x

BZ - 2350398 - CVE-2025-21834 kernel: seccomp: passthrough uretprobe systemcall without filtering

BZ - 2432681 - CVE-2026-23003 kernel: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv()

BZ - 2468145 - CVE-2026-43454 kernel: netfilter: nf_tables: Fix for duplicate device in netdev hooks

BZ - 2468228 - CVE-2026-43450 kernel: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table()

BZ - 2482006 - CVE-2026-45970 kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down

BZ - 2482614 - CVE-2026-46120 kernel: ip6_gre: Use cached t->net in ip6erspan_changelink()

BZ - 2492310 - CVE-2026-53053 kernel: iommu/amd: Fix clone_alias() to use the original device's devid

BZ - 2492454 - CVE-2026-53026 kernel: NFSD: fix nfs4_file access extra count in nfsd4_add_rdaccess_to_wrdeleg

BZ - 2492735 - CVE-2026-53185 kernel: zram: fix use-after-free in zram_bvec_write_partial()

BZ - 2492750 - CVE-2026-53196 kernel: USB: serial: io_ti: fix heap overflow in get_manuf_info()

BZ - 2492788 - CVE-2026-53189 kernel: mm/huge_memory: update file PMD counter before folio_put()

BZ - 2492790 - CVE-2026-53153 kernel: mm/list_lru: drain before clearing xarray entry on reparent

BZ - 2502219 - CVE-2026-63800 kernel: pNFS: Fix use-after-free in pnfs_update_layout()

BZ - 2502227 - CVE-2026-53397 kernel: nfsd: fix posix_acl leak on SETACL decode failure

BZ - 2502239 - CVE-2026-53399 kernel: nfsd: release layout stid on setlease failure

BZ - 2502240 - CVE-2026-53392 kernel: NFSv4/flexfiles: reject zero filehandle version count

BZ - 2502260 - CVE-2026-53391 kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr

BZ - 2502421 - CVE-2026-64018 kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access

BZ - 2502527 - CVE-2026-64136 kernel: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()

BZ - 2502889 - CVE-2026-64189 kernel: netfilter: ipset: fix race between dump and ip_set_list resize

BZ - 2507061 - CVE-2026-64320 kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page

BZ - 2507118 - CVE-2026-64438 kernel: crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()

BZ - 2507119 - CVE-2026-64304 kernel: crypto: qat - validate RSA CRT component lengths

BZ - 2507208 - CVE-2026-64298 kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC

BZ - 2507277 - CVE-2026-64490 kernel: ALSA: virtio: Validate control metadata from the device

BZ - 2507285 - CVE-2026-64418 kernel: mm: shrinker: fix shrinker_info teardown race with expansion

BZ - 2507287 - CVE-2026-64384 kernel: smb: client: fix change notify replay double-free

BZ - 2507290 - CVE-2026-64277 kernel: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count

BZ - 2507301 - CVE-2026-64276 kernel: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count

BZ - 2508363 - CVE-2026-68480 kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability

BZ - 2513141 - CVE-2026-68086 kernel: mm/khugepaged: write all dirty file folios when collapsing

BZ - 2513167 - CVE-2026-68166 kernel: Linux kernel: Arbitrary code execution via userfaultfd shadow stack manipulation

BZ - 2516248 - CVE-2026-72069 kernel: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()

BZ - 2516448 - CVE-2026-72130 kernel: nvmet-auth: reject short AUTH_RECEIVE buffers

Red Hat Enterprise Linux for x86_64 10

Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2

Red Hat Enterprise Linux for IBM z Systems 10

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2

Red Hat Enterprise Linux for Power, little endian 10

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2

Red Hat Enterprise Linux for ARM 64 10

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2

Red Hat CodeReady Linux Builder for x86_64 10

Red Hat CodeReady Linux Builder for Power, little endian 10

Red Hat CodeReady Linux Builder for ARM 64 10

Red Hat CodeReady Linux Builder for IBM z Systems 10

Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2

Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2

Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2

Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2

Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2

Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2

Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2

Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2

Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2

The Red Hat security is [email protected] . More details at .