Critical Kernel Vulnerabilities in openSUSE and Fedora Require Immediate Attention

Critical Kernel Vulnerabilities in openSUSE and Fedora Require Immediate Attention

First seen 22 Jul 2026, 09:46 UTC Linuxsecurity 80% similarity 72.0

Article Content

Browse articles
ThreatCluster

On July 22, 2026, significant security updates were released for both openSUSE and Fedora kernels addressing multiple vulnerabilities. The openSUSE update (CVE-2026-43109, CVE-2026-46052, CVE-2026-46071, CVE-2026-46076, CVE-2026-46116, CVE-2026-46173, CVE-2026-46229, CVE-2026-46242, CVE-2026-46253) includes fixes for various issues, including improper error handling and potential buffer overflows. Fedora's updates (CVE-2026-46071, CVE-2026-46242) also address critical vulnerabilities in the net/can subsystem, with potential exploitation vectors that could lead to system compromise. Both distributions recommend immediate patching to mitigate risks. The vulnerabilities affect multiple versions of their respective kernels, emphasizing the need for system administrators to act swiftly to secure their environments.

Key Points: • openSUSE and Fedora released critical kernel updates on July 22, 2026. • The updates address multiple CVEs, including CVE-2026-43109 and CVE-2026-46242. • System administrators are urged to apply patches immediately to prevent exploitation.

ThreatCluster AI

Timeline

2026-05-06
CVE-2026-43109 published
A vulnerability in the x86 shadow stacks related to improper error handling was disclosed.
Linuxsecurity
2026-05-27
CVE-2026-46071 published
A vulnerability in KVM nSVM was published, potentially allowing for system exploitation.
Linuxsecurity
2026-05-27
CVE-2026-46052 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-27
CVE-2026-46076 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-28
CVE-2026-46173 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-28
CVE-2026-46116 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-28
CVE-2026-46229 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-30
CVE-2026-46242 published
An integer overflow vulnerability in eventpoll was disclosed, with a PoC released on July 5.
Linuxsecurity
2026-06-03
CVE-2026-46253 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-05
First public PoC for CVE-2026-46242
A proof of concept for the integer overflow vulnerability was made public, increasing urgency for patching.
Linuxsecurity

Community

Browse all →