Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.1%top 99%

Red Hat Security Advisory: kernel security, bug fix, and enhancement update

0
High
Published: 06/20/2026 (06/20/2026, 00:28:45 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474) * kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669) * kernel: rxrpc: Fix RxGK token loading to check bounds (CVE-2026-31641) * kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787) * kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786) * kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056) * kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772) * kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260) * kernel: crypto: caam - fix overflow on long hmac keys (CVE-2026-43330) * kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331) * kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056) * kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result (CVE-2026-46152) * kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125) * kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173) * kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166) Bug Fix(es) and Enhancement(s): * RHEL10.0 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [rhel-10.2.z] (JIRA:RHEL-166047) * RHEL9.5 crash due to lpfc NULL ndlp->vport [rhel-10.2.z] (JIRA:RHEL-171774) * objtool static_call check blocks build of out-of-tree livepatch modules on RHEL 10.2 GA kernels ? missing upstream revert f495054bd12e (JIRA:RHEL-178495) * ibmveth Adapter Freeze with Small MSS [rhel-10.2.z] (JIRA:RHEL-179723) * rbd: eliminate a race in lock_dwork draining on unmap [rhel-10.2.z] (JIRA:RHEL-183127) * RHEL10.0 - s390/mm: Add missing secure storage access fixups [rhel-10.2.z] (JIRA:RHEL-183319) * [RHEL10.2.z] Enable Pretimeout Watchdog Panic Functionality on x86 (JIRA:RHEL-182299) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected software

Affected versions
Red HatRed Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 10)Red Hat Enterprise Linux BaseOS (v. 10)Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)Red Hat Enterprise Linux AppStream (v. 9)Red Hat Enterprise Linux BaseOS (v. 9)Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 15:06:23 UTC

Technical Analysis

The advisory covers a set of security fixes for the Linux kernel in Red Hat Enterprise Linux 9, resolving multiple vulnerabilities including use-after-free (CVE-2026-31474, CVE-2026-31669, CVE-2026-45984, CVE-2026-46056), double free (CVE-2026-31787, CVE-2026-43414), stack buffer overflow (CVE-2026-31772), and race conditions (CVE-2026-46135). These issues affect various kernel components such as CAN ISOTP protocol, multipath TCP, Xen hypervisor interface, Bluetooth stack, USB audio subsystem, SCSI drivers, networking scheduler, GFS2 filesystem, WiFi mac80211 driver, RDMA mana driver, and NVMe TCP transport. The advisory includes fixes that prevent memory corruption and potential system instability. The update is rated as Important by Red Hat Product Security and requires rebooting the system to apply.

Potential Impact

The vulnerabilities fixed in this advisory could allow local or remote attackers to cause memory corruption, including use-after-free and double free conditions, stack buffer overflows, and race conditions. These issues may lead to system crashes, denial of service, or potentially other undefined behavior. No known exploits in the wild have been reported at this time. The impact is significant due to the kernel-level nature of the vulnerabilities affecting core system components.

Mitigation Recommendations

An updated kernel package containing fixes for these vulnerabilities is available from Red Hat. Users should apply the update promptly and reboot their systems to ensure the fixes take effect. The vendor advisory confirms the availability of an official fix. No additional mitigations are specified beyond applying the update and rebooting.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:27288
Cve Count
15
Additional Cves
["CVE-2026-31641","CVE-2026-31669","CVE-2026-31772","CVE-2026-31786","CVE-2026-31787","CVE-2026-43056","CVE-2026-43260","CVE-2026-43330","CVE-2026-46056","CVE-2026-46125","CVE-2026-46152","CVE-2026-46166","CVE-2026-46173","CVE-2026-46331"]
Cvss Version
null

Threat ID: 6a3806dceed863c81e005290

Added to database: 06/21/2026, 15:44:28 UTC

Last enriched: 07/30/2026, 15:06:23 UTC

Last updated: 08/04/2026, 12:48:00 UTC

Views: 96

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses