RHSA-2026:36767HighCVSS 7.8

Red Hat Security Advisory: kernel security, bug fix, and enhancement update

Published
July 8, 2026
Last Modified
August 19, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2024-27398 — kernel: Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout CVE-2024-50125 — kernel: Bluetooth: SCO: Fix UAF on sco_sock_timeout CVE-2025-68183 — kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr CVE-2026-31408 — kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold CVE-2026-43027 — kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup CVE-2026-43125 — kernel: dlm: validate length in dlm_search_rsb_tree CVE-2026-43279 — kernel: ALSA: usb-audio: Add sanity check for OOB writes at silencing CVE-2026-45984 — kernel: gfs2: Fix use-after-free in iomap inline data write path CVE-2026-46152 — kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result CVE-2026-46189 — kernel: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path

🎯 Affected products200

  • Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • Red Hat Enterprise Linux Real Time E4S (v.9.4)
  • Red Hat Enterprise Linux Real Time for NFV E4S (v.9.4)
  • bpftool-0:7.3.0-427.136.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • bpftool-0:7.3.0-427.136.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • bpftool-0:7.3.0-427.136.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • bpftool-0:7.3.0-427.136.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.136.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.136.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.136.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.136.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.136.1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.136.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.136.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.136.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.136.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux Real Time E4S (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.136.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV E4S (v.9.4)
  • kernel-0:5.14.0-427.136.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • kernel-0:5.14.0-427.136.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • kernel-0:5.14.0-427.136.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • kernel-0:5.14.0-427.136.1.el9_4.src as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • kernel-0:5.14.0-427.136.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • kernel-64k-0:5.14.0-427.136.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • kernel-64k-core-0:5.14.0-427.136.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • kernel-64k-debug-0:5.14.0-427.136.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • kernel-64k-debug-core-0:5.14.0-427.136.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • kernel-64k-debug-debuginfo-0:5.14.0-427.136.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • kernel-64k-debug-debuginfo-0:5.14.0-427.136.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.4)
  • kernel-64k-debug-devel-0:5.14.0-427.136.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, disable the Wi-Fi interface if wireless networking is not required. This can be achieved by preventing the `mac80211` kernel module from loading. To blacklist the `mac80211` module: `echo "blacklist mac80211" | sudo tee /etc/modprobe.d/blacklist-mac80211.conf`. After modifying the blacklist, regenerate the initramfs and reboot the system for the changes to take effect: `sudo dracut -f -v` and `sudo reboot`. Disabling the `mac80211` module will prevent Wi-Fi functionality on the system.

🔗 References (13)