RHSA-2026:65334HighCVSS 8.1

Red Hat Security Advisory: kernel security, bug fix, and enhancement update

Published
September 8, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (29)

📋 Description

CVE-2026-43133 — kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation CVE-2026-43334 — kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response CVE-2026-46123 — kernel: Bluetooth: virtio_bt: clamp rx length before skb_put CVE-2026-52918 — kernel: Bluetooth: serialize accept_q access CVE-2026-52947 — kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove CVE-2026-53072 — kernel: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER CVE-2026-53091 — kernel: net: pull headers in qdisc_pkt_len_segs_init() CVE-2026-53182 — kernel: wifi: nl80211: reject oversized EMA RNR lists CVE-2026-53209 — kernel: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend CVE-2026-53254 — kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers CVE-2026-53256 — kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() CVE-2026-53322 — kernel: vfio/pci: Clean up DMABUFs before disabling function CVE-2026-63944 — kernel: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync CVE-2026-63946 — kernel: Bluetooth: ISO: fix UAF in iso_recv_frame CVE-2026-63947 — kernel: Bluetooth: HIDP: fix missing length checks in hidp_input_report() CVE-2026-63975 — kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp CVE-2026-64015 — kernel: security/keys: fix missed RCU read section on lookup CVE-2026-64037 — kernel: wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled CVE-2026-64042 — kernel: vfio/pci: Check BAR resources before exporting a DMABUF CVE-2026-64051 — kernel: accel/qaic: Add overflow check to remap_pfn_range during mmap CVE-2026-64113 — kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning CVE-2026-64117 — kernel: wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb CVE-2026-64255 — kernel: wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers CVE-2026-64515 — kernel: wifi: mac80211: fix MLE defragmentation CVE-2026-68193 — kernel: wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses CVE-2026-68307 — kernel: wifi: mt76: mt7925: fix crash in reset link replay CVE-2026-68409 — kernel: wifi: mac80211: defer link RX stats percpu free to RCU CVE-2026-72098 — kernel: dm-verity: fix buffer overflow in FEC calculation CVE-2026-72129 — kernel: nvmet-rdma: handle inline data with a nonzero offset

🎯 Affected products200

  • Red Hat Enterprise Linux AppStream (v. 10)
  • Red Hat Enterprise Linux BaseOS (v. 10)
  • Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • Red Hat Enterprise Linux Real Time (v. 10)
  • Red Hat Enterprise Linux Real Time for NFV (v. 10)
  • kernel-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-0:6.12.0-211.53.1.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-0:6.12.0-211.53.1.el10_2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-0:6.12.0-211.53.1.el10_2.src as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-0:6.12.0-211.53.1.el10_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-core-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-core-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-debuginfo-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-debug-debuginfo-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-debuginfo-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • kernel-64k-debug-debuginfo-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux Real Time (v. 10)
  • kernel-64k-debug-devel-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-debug-devel-matched-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-debug-modules-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-modules-core-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-modules-extra-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debuginfo-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-debuginfo-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debuginfo-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • kernel-64k-debuginfo-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux Real Time (v. 10)
  • kernel-64k-devel-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-devel-matched-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-modules-0:6.12.0-211.53.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture. Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available. Workaround: To mitigate this issue, if PCI device passthrough is not required, the `vfio_pci` kernel module can be blacklisted to prevent it from loading. This can be achieved by creating a file such as `/etc/modprobe.d/blacklist-vfio-pci.conf` with the content `blacklist vfio_pci`. A system reboot is required for this change to take effect. Disabling this module may impact functionality that relies on PCI device passthrough. Workaround: To mitigate this issue, prevent the mt7925e module from loading. See https://access.redhat.com/solutions/41278 for instructions. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, prevent the `nvmet_rdma` kernel module from loading if NVMe over RDMA functionality is not required. This can be achieved by creating a modprobe configuration file. 1. Create a file named `/etc/modprobe.d/disable-nvmet_rdma.conf` with the following content: ``` install nvmet_rdma /bin/true ``` 2. Regenerate the initramfs to ensure the change takes effect on boot: ```bash dracut -f -v ``` 3. Reboot the system for the changes to be fully applied. This mitigation may impact systems that rely on NVMe over RDMA for storage operations. If NVMe over RDMA is in use, consider configuring `inline_data_size` to be less than or equal to `PAGE_SIZE` if your workload permits, though this might affect performance.

🔗 References (32)