RHSA-2026:25191CriticalCVSS 8.8
Red Hat Security Advisory: kernel security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2026-31419 — kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service CVE-2026-31467 — kernel: Linux kernel: Denial of Service in erofs filesystem CVE-2026-31532 — kernel: can: raw: fix ro->uniq use-after-free in raw_rcv() CVE-2026-31581 — kernel: ALSA: 6fire: fix use-after-free on disconnect CVE-2026-43037 — kernel: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() CVE-2026-43501 — kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows CVE-2026-46054 — kernel: selinux: fix overlayfs mmap() and mprotect() access checks
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:25191
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457829
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2460616
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2461107
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2461471
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2464351
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480457
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2482025
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_25191.json