RHSA-2026:20593HighCVSS 8.1
Red Hat Security Advisory: kernel security update
🔗 CVE IDs covered (7)
CVE-2026-46300 →CVE-2026-46333 →CVE-2025-21999 →CVE-2025-71238 · pendingCVE-2026-23243 →CVE-2026-23401 →CVE-2026-31532 →
📋 Description
CVE-2025-21999 — kernel: proc: fix UAF in proc_get_inode() CVE-2025-71238 — kernel: Linux kernel (qla2xxx): Double free vulnerability leads to denial of service and potential privilege escalation. CVE-2026-23243 — kernel: Linux kernel: Denial of service and memory corruption in RDMA umad CVE-2026-23401 — kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling CVE-2026-31532 — kernel: can: raw: fix ro->uniq use-after-free in raw_rcv() CVE-2026-46300 — kernel: "Fragnesia" is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in the Linux kernel CVE-2026-46333 — kernel: Read root-owned files as an unprivileged user
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:20593
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2357134
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2444398
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448594
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2453803
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2461107
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477015
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477802
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_20593.json