Red Hat Security Advisory: kernel security update
🔗 CVE IDs covered (25)
📋 Description
CVE-2024-56633 — kernel: tcp_bpf: Fix the sk_mem_uncharge logic in tcp_bpf_sendmsg CVE-2025-21839 — kernel: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop CVE-2025-37980 — kernel: block: fix resource leak in blk_register_queue() error path CVE-2025-38015 — kernel: dmaengine: idxd: fix memory leak in error handling path of idxd_alloc CVE-2025-38097 — kernel: espintcp: remove encap socket caching to avoid reference leak CVE-2025-38166 — kernel: bpf: fix ktls panic with sockmap CVE-2025-38202 — kernel: bpf: Check rcu_read_lock_trace_held() in bpf_map_lookup_percpu_elem() CVE-2025-38267 — kernel: ring-buffer: Do not trigger WARN_ON() due to a commit_overrun CVE-2025-38275 — kernel: phy: qcom-qmp-usb: Fix an NULL vs IS_ERR() bug CVE-2025-38279 — kernel: bpf: Do not include stack ptr register in precision backtracking bookkeeping CVE-2025-38345 — kernel: ACPICA: fix acpi operand cache leak in dswstate.c CVE-2025-38346 — kernel: ftrace: Fix UAF when lookup kallsym after ftrace disabled CVE-2025-38405 — kernel: nvmet: fix memory leak of bio integrity CVE-2025-38441 — kernel: netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() CVE-2025-38470 — kernel: net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime CVE-2025-39866 — kernel: fs: writeback: fix use-after-free in __mark_inode_dirty() CVE-2025-40034 — kernel: PCI/AER: Avoid NULL pointer dereference in aer_ratelimit() CVE-2025-40134 — kernel: dm: fix NULL pointer dereference in __dm_suspend() CVE-2025-40210 — kernel: Revert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND" CVE-2025-40257 — kernel: Linux kernel MPTCP: Privilege escalation or denial of service via use-after-free in timer handling CVE-2025-40320 — kernel: smb: client: fix potential cfid UAF in smb2_query_info_compound CVE-2026-23040 — kernel: wifi: mac80211_hwsim: fix typo in frequency notification CVE-2026-23111 — kernel: Kernel: Privilege escalation or denial of service in nf_tables via inverted element activity check CVE-2026-23210 — kernel: Linux kernel: Denial of Service in ice driver due to race condition during VSI rebuild CVE-2026-23243 — kernel: Linux kernel: Denial of service and memory corruption in RDMA umad
🔗 References (48)
- selfhttps://access.redhat.com/errata/RHSA-2026:18134
- externalhttps://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/html/10.2_release_notes/index
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2334549
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2350585
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2367614
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2373343
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2376060
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2376065
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2376382
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2379178
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2379187
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2379199
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2379237
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2379239
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2383399
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2383478
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2383906
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2396940
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2406782
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2414468
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2416307
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2418880
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2419945
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2436806
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2439687
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2439895
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448594
- externalhttps://issues.redhat.com/browse/RHEL-101339
- externalhttps://issues.redhat.com/browse/RHEL-101343
- externalhttps://issues.redhat.com/browse/RHEL-105431
- externalhttps://issues.redhat.com/browse/RHEL-106452
- externalhttps://issues.redhat.com/browse/RHEL-107274
- externalhttps://issues.redhat.com/browse/RHEL-107916
- externalhttps://issues.redhat.com/browse/RHEL-108683
- externalhttps://issues.redhat.com/browse/RHEL-114532
- externalhttps://issues.redhat.com/browse/RHEL-114533
- externalhttps://issues.redhat.com/browse/RHEL-116076
- externalhttps://issues.redhat.com/browse/RHEL-116876
- externalhttps://issues.redhat.com/browse/RHEL-116879
- externalhttps://issues.redhat.com/browse/RHEL-118599
- externalhttps://issues.redhat.com/browse/RHEL-120364
- externalhttps://issues.redhat.com/browse/RHEL-126233
- externalhttps://issues.redhat.com/browse/RHEL-134732
- externalhttps://issues.redhat.com/browse/RHEL-135143
- externalhttps://issues.redhat.com/browse/RHEL-145936
- externalhttps://issues.redhat.com/browse/RHEL-42486
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_18134.json