Red Hat Security Advisory: kernel security, bug fix, and enhancement update
🔗 CVE IDs covered (12)
📋 Description
CVE-2024-46744 — kernel: Squashfs: sanity check symbolic link size CVE-2025-68211 — kernel: ksm: use range-walk function to jump over holes in scan_get_next_rmap_item CVE-2026-43023 — kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() CVE-2026-43114 — kernel: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry CVE-2026-46056 — kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers CVE-2026-46099 — kernel: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels CVE-2026-46145 — kernel: RDMA/mana: Validate rx_hash_key_len CVE-2026-53006 — kernel: ipv6: fix possible UAF in icmpv6_rcv() CVE-2026-64002 — kernel: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() CVE-2026-64304 — kernel: crypto: qat - validate RSA CRT component lengths CVE-2026-74480 — kernel: net: bridge: stop fast-leave after deleting a port group CVE-2026-74580 — kernel: vhost: reset the vring metadata cache on vring reconfiguration
🎯 Affected products200
- Red Hat CodeReady Linux Builder EUS (v.9.6)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- Red Hat Enterprise Linux Real Time EUS (v.9.6)
- Red Hat Enterprise Linux Real Time for NFV EUS (v.9.6)
- kernel-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-0:5.14.0-570.138.1.el9_6.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-0:5.14.0-570.138.1.el9_6.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-0:5.14.0-570.138.1.el9_6.src as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-0:5.14.0-570.138.1.el9_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-core-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-debug-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-debug-core-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-debug-debuginfo-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6)
- kernel-64k-debug-debuginfo-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- kernel-64k-debug-debuginfo-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-debug-debuginfo-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.6)
- kernel-64k-debug-devel-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- kernel-64k-debug-devel-matched-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- kernel-64k-debug-modules-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-debug-modules-core-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-debug-modules-extra-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-debuginfo-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6)
- kernel-64k-debuginfo-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- kernel-64k-debuginfo-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-debuginfo-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.6)
- kernel-64k-devel-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- kernel-64k-devel-matched-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- kernel-64k-modules-0:5.14.0-570.138.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture. Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: If bridge multicast snooping is not required, it can be disabled to prevent the vulnerable code path from being reached: ``` echo 0 > /sys/class/net/<bridge>/bridge/multicast_snooping ``` The br_multicast_leave_group() code path is only reachable when multicast snooping is active, so disabling it eliminates exposure to this flaw. Alternatively, avoid toggling multicast_to_unicast on bridge ports after it has been enabled. If multicast snooping is required, ensure that multicast_to_unicast is either left at its default (disabled) or, once enabled on a port, is not subsequently disabled while the port has active multicast group memberships.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2026:62568
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2313092
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2422696
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2464496
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2466994
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2481972
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2482181
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2482581
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492363
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2502363
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2507119
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2517046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2521055
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_62568.json