Skip to main content
EPSS 0.1%top 96%

Red Hat Security Advisory: kernel security update

0
High
Published: 04/28/2026 (04/28/2026, 00:00:00 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

A use-after-free vulnerability (CVE-2026-23074) in the Linux kernel's teql queueing discipline can lead to privilege escalation on Container-Optimized OS nodes. This vulnerability affects certain versions of Red Hat Enterprise Linux 6 Extended Lifecycle Support and specific Google Kubernetes Engine (GKE) node pool versions. GKE Standard clusters are impacted, while GKE Autopilot clusters are not affected by default unless specific insecure configurations are used. GKE Sandbox clusters and bare metal GDC software are not affected. Patch versions are available for affected GKE Ubuntu node pools and Container-Optimized OS node pools. Red Hat has released kernel updates for affected Red Hat Enterprise Linux 6 Extended Lifecycle Support versions. Bare metal GDC software does not require action as it is not affected.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 13:07:21 UTC

Technical Analysis

CVE-2026-23074 is a use-after-free vulnerability in the Linux kernel's teql queueing discipline that can lead to privilege escalation on Container-Optimized OS nodes. The vulnerability affects Red Hat Enterprise Linux Server Extended Lifecycle Support 6 and certain GKE node pool versions. GKE Standard clusters are vulnerable, while GKE Autopilot clusters are only vulnerable if configured with seccomp Unconfined profile or CAP_NET_ADMIN capability. GKE Sandbox clusters and bare metal GDC software are not impacted. Red Hat has issued kernel security updates for affected versions, and Google has released patched GKE node pool versions for Ubuntu and Container-Optimized OS. The system must be rebooted after applying the Red Hat kernel update. Patch versions for GDC VMware, GKE on AWS, and GKE on Azure are pending.

Potential Impact

Successful exploitation of this use-after-free vulnerability can lead to privilege escalation on affected Container-Optimized OS nodes, potentially allowing an attacker to gain elevated privileges. The vulnerability affects Linux kernel versions used in Red Hat Enterprise Linux 6 Extended Lifecycle Support and specific GKE node pool versions. GKE Standard clusters are impacted, while GKE Autopilot clusters are only vulnerable under certain insecure configurations. Bare metal GDC software is not affected. No known exploits in the wild have been reported.

Mitigation Recommendations

Red Hat has released kernel updates for Red Hat Enterprise Linux Server Extended Lifecycle Support 6; applying these updates and rebooting the system is required to remediate the vulnerability. For GKE clusters, upgrade Ubuntu node pools to versions 1.30.14-gke.2320000 or later, 1.31.14-gke.1723000 or later, 1.32.13-gke.1258000 or later, 1.33.10-gke.1115000 or later, 1.34.6-gke.1154000 or later, or 1.35.3-gke.1234000 or later. Upgrade Container-Optimized OS node pools to patch versions 1.35.2-gke.1485000 or later, 1.34.5-gke.1076000 or later, 1.33.9-gke.1060000 or later, 1.32.13-gke.1059000 or later, 1.31.14-gke.1476000 or later, or 1.30.14-gke.2117000 or later. GKE Autopilot clusters are not impacted by default, but avoid using seccomp Unconfined profile or granting CAP_NET_ADMIN capability to reduce risk. GKE Sandbox clusters and bare metal GDC software require no action. Patch versions and severity assessments for GDC VMware, GKE on AWS, and GKE on Azure are pending; monitor vendor advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:3810
Cve Count
1

Threat ID: 6a3da1c34853345fc181eff8

Added to database: 06/25/2026, 21:46:43 UTC

Last enriched: 08/04/2026, 13:07:21 UTC

Last updated: 09/14/2026, 10:01:29 UTC

Views: 493

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses