Red Hat Security Advisory: kernel security update
A use-after-free vulnerability (CVE-2026-23074) in the Linux kernel's teql queueing discipline can lead to privilege escalation on Container-Optimized OS nodes. This vulnerability affects certain versions of Red Hat Enterprise Linux 6 Extended Lifecycle Support and specific Google Kubernetes Engine (GKE) node pool versions. GKE Standard clusters are impacted, while GKE Autopilot clusters are not affected by default unless specific insecure configurations are used. GKE Sandbox clusters and bare metal GDC software are not affected. Patch versions are available for affected GKE Ubuntu node pools and Container-Optimized OS node pools. Red Hat has released kernel updates for affected Red Hat Enterprise Linux 6 Extended Lifecycle Support versions. Bare metal GDC software does not require action as it is not affected.
AI Analysis
Technical Summary
CVE-2026-23074 is a use-after-free vulnerability in the Linux kernel's teql queueing discipline that can lead to privilege escalation on Container-Optimized OS nodes. The vulnerability affects Red Hat Enterprise Linux Server Extended Lifecycle Support 6 and certain GKE node pool versions. GKE Standard clusters are vulnerable, while GKE Autopilot clusters are only vulnerable if configured with seccomp Unconfined profile or CAP_NET_ADMIN capability. GKE Sandbox clusters and bare metal GDC software are not impacted. Red Hat has issued kernel security updates for affected versions, and Google has released patched GKE node pool versions for Ubuntu and Container-Optimized OS. The system must be rebooted after applying the Red Hat kernel update. Patch versions for GDC VMware, GKE on AWS, and GKE on Azure are pending.
Potential Impact
Successful exploitation of this use-after-free vulnerability can lead to privilege escalation on affected Container-Optimized OS nodes, potentially allowing an attacker to gain elevated privileges. The vulnerability affects Linux kernel versions used in Red Hat Enterprise Linux 6 Extended Lifecycle Support and specific GKE node pool versions. GKE Standard clusters are impacted, while GKE Autopilot clusters are only vulnerable under certain insecure configurations. Bare metal GDC software is not affected. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat has released kernel updates for Red Hat Enterprise Linux Server Extended Lifecycle Support 6; applying these updates and rebooting the system is required to remediate the vulnerability. For GKE clusters, upgrade Ubuntu node pools to versions 1.30.14-gke.2320000 or later, 1.31.14-gke.1723000 or later, 1.32.13-gke.1258000 or later, 1.33.10-gke.1115000 or later, 1.34.6-gke.1154000 or later, or 1.35.3-gke.1234000 or later. Upgrade Container-Optimized OS node pools to patch versions 1.35.2-gke.1485000 or later, 1.34.5-gke.1076000 or later, 1.33.9-gke.1060000 or later, 1.32.13-gke.1059000 or later, 1.31.14-gke.1476000 or later, or 1.30.14-gke.2117000 or later. GKE Autopilot clusters are not impacted by default, but avoid using seccomp Unconfined profile or granting CAP_NET_ADMIN capability to reduce risk. GKE Sandbox clusters and bare metal GDC software require no action. Patch versions and severity assessments for GDC VMware, GKE on AWS, and GKE on Azure are pending; monitor vendor advisories for updates.
Red Hat Security Advisory: kernel security update
Description
A use-after-free vulnerability (CVE-2026-23074) in the Linux kernel's teql queueing discipline can lead to privilege escalation on Container-Optimized OS nodes. This vulnerability affects certain versions of Red Hat Enterprise Linux 6 Extended Lifecycle Support and specific Google Kubernetes Engine (GKE) node pool versions. GKE Standard clusters are impacted, while GKE Autopilot clusters are not affected by default unless specific insecure configurations are used. GKE Sandbox clusters and bare metal GDC software are not affected. Patch versions are available for affected GKE Ubuntu node pools and Container-Optimized OS node pools. Red Hat has released kernel updates for affected Red Hat Enterprise Linux 6 Extended Lifecycle Support versions. Bare metal GDC software does not require action as it is not affected.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-23074 is a use-after-free vulnerability in the Linux kernel's teql queueing discipline that can lead to privilege escalation on Container-Optimized OS nodes. The vulnerability affects Red Hat Enterprise Linux Server Extended Lifecycle Support 6 and certain GKE node pool versions. GKE Standard clusters are vulnerable, while GKE Autopilot clusters are only vulnerable if configured with seccomp Unconfined profile or CAP_NET_ADMIN capability. GKE Sandbox clusters and bare metal GDC software are not impacted. Red Hat has issued kernel security updates for affected versions, and Google has released patched GKE node pool versions for Ubuntu and Container-Optimized OS. The system must be rebooted after applying the Red Hat kernel update. Patch versions for GDC VMware, GKE on AWS, and GKE on Azure are pending.
Potential Impact
Successful exploitation of this use-after-free vulnerability can lead to privilege escalation on affected Container-Optimized OS nodes, potentially allowing an attacker to gain elevated privileges. The vulnerability affects Linux kernel versions used in Red Hat Enterprise Linux 6 Extended Lifecycle Support and specific GKE node pool versions. GKE Standard clusters are impacted, while GKE Autopilot clusters are only vulnerable under certain insecure configurations. Bare metal GDC software is not affected. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat has released kernel updates for Red Hat Enterprise Linux Server Extended Lifecycle Support 6; applying these updates and rebooting the system is required to remediate the vulnerability. For GKE clusters, upgrade Ubuntu node pools to versions 1.30.14-gke.2320000 or later, 1.31.14-gke.1723000 or later, 1.32.13-gke.1258000 or later, 1.33.10-gke.1115000 or later, 1.34.6-gke.1154000 or later, or 1.35.3-gke.1234000 or later. Upgrade Container-Optimized OS node pools to patch versions 1.35.2-gke.1485000 or later, 1.34.5-gke.1076000 or later, 1.33.9-gke.1060000 or later, 1.32.13-gke.1059000 or later, 1.31.14-gke.1476000 or later, or 1.30.14-gke.2117000 or later. GKE Autopilot clusters are not impacted by default, but avoid using seccomp Unconfined profile or granting CAP_NET_ADMIN capability to reduce risk. GKE Sandbox clusters and bare metal GDC software require no action. Patch versions and severity assessments for GDC VMware, GKE on AWS, and GKE on Azure are pending; monitor vendor advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:3810
- Cve Count
- 1
Threat ID: 6a3da1c34853345fc181eff8
Added to database: 06/25/2026, 21:46:43 UTC
Last enriched: 08/04/2026, 13:07:21 UTC
Last updated: 09/14/2026, 10:01:29 UTC
Views: 493
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.