RHSA-2026:2352MediumCVSS 7.8

Red Hat Security Advisory: kernel security update

Published
February 9, 2026
Last Modified
August 5, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2024-54456 — kernel: NFS: Fix potential buffer overflowin nfs_sysfs_link_rpc_client() CVE-2025-21647 — kernel: sched: sch_cake: add bounds checks to host bulk flow fairness counts CVE-2025-21786 — kernel: workqueue: Put the pwq after detaching the rescuer from the pool CVE-2025-21791 — kernel: vrf: use RCU protection in l3mdev_l3_out() CVE-2025-38022 — kernel: RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem CVE-2025-38051 — kernel: smb: client: Fix use-after-free in cifs_fill_dirent CVE-2025-38568 — kernel: net/sched: mqprio: fix stack out-of-bounds write in tc entry parsing CVE-2025-40294 — kernel: Linux kernel: Out-of-bounds write in Bluetooth MGMT can lead to information disclosure and denial of service CVE-2025-40322 — kernel: Linux kernel: Information disclosure and denial of service via out-of-bounds read in font glyph handling CVE-2025-68349 — kernel: NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid

🎯 Affected products200

  • Red Hat CodeReady Linux Builder EUS (v.9.6)
  • Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • Red Hat Enterprise Linux Real Time EUS (v.9.6)
  • Red Hat Enterprise Linux Real Time for NFV EUS (v.9.6)
  • kernel-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • kernel-0:5.14.0-570.86.1.el9_6.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • kernel-0:5.14.0-570.86.1.el9_6.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • kernel-0:5.14.0-570.86.1.el9_6.src as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • kernel-0:5.14.0-570.86.1.el9_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • kernel-64k-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • kernel-64k-core-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • kernel-64k-debug-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • kernel-64k-debug-core-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • kernel-64k-debug-debuginfo-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6)
  • kernel-64k-debug-debuginfo-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • kernel-64k-debug-debuginfo-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • kernel-64k-debug-debuginfo-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.6)
  • kernel-64k-debug-devel-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • kernel-64k-debug-devel-matched-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • kernel-64k-debug-modules-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • kernel-64k-debug-modules-core-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • kernel-64k-debug-modules-extra-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • kernel-64k-debuginfo-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6)
  • kernel-64k-debuginfo-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • kernel-64k-debuginfo-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • kernel-64k-debuginfo-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.6)
  • kernel-64k-devel-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • kernel-64k-devel-matched-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
  • kernel-64k-modules-0:5.14.0-570.86.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, the `bluetooth` kernel module can be prevented from loading. Create a file `/etc/modprobe.d/disable-bluetooth.conf` with the content `blacklist bluetooth`. Then, regenerate the initramfs using `dracut -f -v` and reboot the system for the changes to take effect. This mitigation will disable all Bluetooth functionality on the system. Workaround: To mitigate this issue, prevent the `fbdev` kernel module from loading if it is not required for system operation. Create a file named `/etc/modprobe.d/disable-fbdev.conf` with the following content: ``` install fbdev /bin/true blacklist fbdev ``` After creating the file, regenerate the initramfs using `dracut -f -v` and reboot the system for the changes to take effect. This mitigation may impact systems that rely on `fbdev` for console display or specific graphics hardware, requiring careful evaluation before implementation. Workaround: If NFS service not being used, then disable it to prevent possibility of triggering this bug (and usually it is disabled by default): sudo systemctl stop nfs-server sudo systemctl disable nfs-server

🔗 References (13)