Red Hat Security Advisory: kernel security update
Red Hat has issued a security advisory for multiple vulnerabilities in the Linux kernel packages included with Red Hat Enterprise Linux 10. The update addresses six distinct vulnerabilities affecting kernel components such as filesystem notification, SCSI core, rtnetlink, IPv6 networking, futex, and device mapper logging. These vulnerabilities have been rated with an overall security impact of Important by Red Hat Product Security. The advisory provides fixes for these issues to prevent potential kernel-level faults and security risks.
AI Analysis
Technical Summary
This advisory covers six kernel vulnerabilities fixed in Red Hat Enterprise Linux 10 kernel packages. The issues include: CVE-2025-40237, a fix to call exportfs_encode_fid with s_umount in fs/notify; CVE-2026-23110, addressing a race condition in the SCSI core error handler; CVE-2026-31692, adding a missing netlink_ns_capable() check for peer network namespaces; CVE-2026-46099, correcting NOREF destination use in IPv6 seg6 and rpl lightweight tunnels; CVE-2026-52973, removing the CLONE_THREAD requirement for private default hash allocation in futex; and CVE-2026-53059, fixing an out-of-bounds write due to region_count overflow in device mapper logging. These fixes are included in updated kernel packages for multiple Red Hat Enterprise Linux 10 variants and related builder products.
Potential Impact
The vulnerabilities affect core kernel components, potentially leading to kernel crashes, race conditions, privilege or capability bypasses, and memory corruption. While no known exploits are reported in the wild, these issues could impact system stability and security if left unpatched. The advisory rates the overall impact as Important, indicating significant security concerns that warrant timely remediation.
Mitigation Recommendations
Red Hat has released updated kernel packages containing fixes for all six vulnerabilities. Users of Red Hat Enterprise Linux 10 and related products should apply the available kernel updates as described in the Red Hat advisory (RHSA-2026:45114) and the referenced article https://access.redhat.com/articles/11258. No additional mitigations or workarounds are indicated. Applying the official update fully addresses these vulnerabilities.
Red Hat Security Advisory: kernel security update
Description
Red Hat has issued a security advisory for multiple vulnerabilities in the Linux kernel packages included with Red Hat Enterprise Linux 10. The update addresses six distinct vulnerabilities affecting kernel components such as filesystem notification, SCSI core, rtnetlink, IPv6 networking, futex, and device mapper logging. These vulnerabilities have been rated with an overall security impact of Important by Red Hat Product Security. The advisory provides fixes for these issues to prevent potential kernel-level faults and security risks.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers six kernel vulnerabilities fixed in Red Hat Enterprise Linux 10 kernel packages. The issues include: CVE-2025-40237, a fix to call exportfs_encode_fid with s_umount in fs/notify; CVE-2026-23110, addressing a race condition in the SCSI core error handler; CVE-2026-31692, adding a missing netlink_ns_capable() check for peer network namespaces; CVE-2026-46099, correcting NOREF destination use in IPv6 seg6 and rpl lightweight tunnels; CVE-2026-52973, removing the CLONE_THREAD requirement for private default hash allocation in futex; and CVE-2026-53059, fixing an out-of-bounds write due to region_count overflow in device mapper logging. These fixes are included in updated kernel packages for multiple Red Hat Enterprise Linux 10 variants and related builder products.
Potential Impact
The vulnerabilities affect core kernel components, potentially leading to kernel crashes, race conditions, privilege or capability bypasses, and memory corruption. While no known exploits are reported in the wild, these issues could impact system stability and security if left unpatched. The advisory rates the overall impact as Important, indicating significant security concerns that warrant timely remediation.
Mitigation Recommendations
Red Hat has released updated kernel packages containing fixes for all six vulnerabilities. Users of Red Hat Enterprise Linux 10 and related products should apply the available kernel updates as described in the Red Hat advisory (RHSA-2026:45114) and the referenced article https://access.redhat.com/articles/11258. No additional mitigations or workarounds are indicated. Applying the official update fully addresses these vulnerabilities.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:45114
- Cve Count
- 6
- Additional Cves
- ["CVE-2026-23110","CVE-2026-31692","CVE-2026-46099","CVE-2026-52973","CVE-2026-53059"]
- Cvss Version
- null
Threat ID: 6a6940099c2644c7f8665d68
Added to database: 07/28/2026, 23:49:29 UTC
Last enriched: 07/29/2026, 12:53:29 UTC
Last updated: 07/29/2026, 20:52:00 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.