RHSA-2026:59723HighCVSS 8.1

Red Hat Security Advisory: kernel security, bug fix, and enhancement update

Published
August 26, 2026
Last Modified
August 27, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2025-68211 — kernel: ksm: use range-walk function to jump over holes in scan_get_next_rmap_item CVE-2026-23003 — kernel: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() CVE-2026-43114 — kernel: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry CVE-2026-52920 — kernel: netfilter: xt_policy: fix strict mode inbound policy matching CVE-2026-52924 — kernel: sctp: purge outqueue on stale COOKIE-ECHO handling CVE-2026-53131 — kernel: netfilter: require Ethernet MAC header before using eth_hdr() CVE-2026-53185 — kernel: zram: fix use-after-free in zram_bvec_write_partial() CVE-2026-53268 — kernel: netfilter: conntrack_irc: fix possible out-of-bounds read CVE-2026-64189 — kernel: netfilter: ipset: fix race between dump and ip_set_list resize CVE-2026-64191 — kernel: i2c: stub: Reject I2C block transfers with invalid length CVE-2026-64276 — kernel: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count CVE-2026-64277 — kernel: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count CVE-2026-74581 — kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res->rt6 pointer

🎯 Affected products200

  • Red Hat Enterprise Linux AppStream (v. 9)
  • Red Hat Enterprise Linux BaseOS (v. 9)
  • Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • Red Hat Enterprise Linux Real Time (v. 9)
  • Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • kernel-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-0:5.14.0-687.42.1.el9_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-0:5.14.0-687.42.1.el9_8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-0:5.14.0-687.42.1.el9_8.src as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-0:5.14.0-687.42.1.el9_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-core-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-debug-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-debug-core-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-debug-debuginfo-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • kernel-64k-debug-debuginfo-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-debug-debuginfo-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • kernel-64k-debug-debuginfo-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
  • kernel-64k-debug-devel-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • kernel-64k-debug-devel-matched-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • kernel-64k-debug-modules-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-debug-modules-core-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-debug-modules-extra-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-debuginfo-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • kernel-64k-debuginfo-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-debuginfo-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • kernel-64k-debuginfo-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
  • kernel-64k-devel-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • kernel-64k-devel-matched-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • kernel-64k-modules-0:5.14.0-687.42.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture. Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent module zram from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, disable the `ipv6` kernel module at boot using the kernel command-line parameter: ``` grubby --update-kernel=ALL --args="ipv6.disable=1" ``` A reboot is required for this change to take effect. To verify after reboot: ``` cat /proc/cmdline | grep -o ipv6.disable=1 sysctl net.ipv6.conf.all.disable_ipv6 ``` Applications or services that rely on the IPv6 protocol cannot use this mitigation and should prioritize applying the fix.

🔗 References (16)