RHSA-2026:67471HighCVSS 8.8

Red Hat Security Advisory: kernel security, bug fix, and enhancement update

Published
September 15, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (25)

📋 Description

CVE-2025-40149 — kernel: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock() CVE-2025-68745 — kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset CVE-2026-23466 — kernel: drm/xe: Open-code GGTT MMIO access protection CVE-2026-31479 — kernel: drm/xe: always keep track of remap prev/next CVE-2026-31539 — kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available CVE-2026-31566 — kernel: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib CVE-2026-31656 — kernel: drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat CVE-2026-31663 — kernel: xfrm: hold dev ref until after transport_finish NF_HOOK CVE-2026-43248 — kernel: vhost: move vdpa group bound check to vhost_vdpa CVE-2026-43368 — kernel: drm/i915: Fix potential overflow of shmem scatterlist length CVE-2026-43370 — kernel: drm/amdgpu: Fix use-after-free race in VM acquire CVE-2026-46149 — kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() CVE-2026-52924 — kernel: sctp: purge outqueue on stale COOKIE-ECHO handling CVE-2026-53131 — kernel: netfilter: require Ethernet MAC header before using eth_hdr() CVE-2026-53239 — kernel: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() CVE-2026-53246 — kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing CVE-2026-53361 — kernel: af_unix: Set gc_in_progress to true in unix_gc() CVE-2026-63889 — kernel: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 CVE-2026-63917 — kernel: ip6: vti: Use ip6_tnl.net in vti6_changelink() CVE-2026-63919 — kernel: xfrm: input: hold netns during deferred transport reinjection CVE-2026-63921 — kernel: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() CVE-2026-64111 — kernel: lsm: hold cred_guard_mutex for lsm_set_self_attr() CVE-2026-68264 — kernel: drm/xe/pt: Reset current_op in xe_pt_update_ops_init() CVE-2026-68426 — kernel: xfrm: fix stale skb->prev after async crypto steals a GSO segment CVE-2026-74556 — kernel: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer

🎯 Affected products200

  • Red Hat Enterprise Linux AppStream (v. 10)
  • Red Hat Enterprise Linux BaseOS (v. 10)
  • Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • Red Hat Enterprise Linux Real Time (v. 10)
  • Red Hat Enterprise Linux Real Time for NFV (v. 10)
  • kernel-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-0:6.12.0-211.55.1.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-0:6.12.0-211.55.1.el10_2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-0:6.12.0-211.55.1.el10_2.src as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-0:6.12.0-211.55.1.el10_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-core-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-core-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-debuginfo-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-debug-debuginfo-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-debuginfo-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • kernel-64k-debug-debuginfo-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux Real Time (v. 10)
  • kernel-64k-debug-devel-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-debug-devel-matched-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-debug-modules-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-modules-core-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-modules-extra-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debuginfo-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-debuginfo-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debuginfo-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • kernel-64k-debuginfo-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux Real Time (v. 10)
  • kernel-64k-devel-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-devel-matched-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-modules-0:6.12.0-211.55.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture. Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, if the `qla2xxx` SCSI driver is not required, it can be prevented from loading by blacklisting the module. This can be achieved by creating a modprobe configuration file. 1. Create a file named `/etc/modprobe.d/blacklist-qla2xxx.conf` with the following content: ``` blacklist qla2xxx install qla2xxx /bin/true ``` 2. Rebuild the initial ramdisk: ```bash dracut -f -v ``` 3. Reboot the system for the changes to take effect. This mitigation will prevent the `qla2xxx` module from loading, which may impact systems relying on QLogic Fibre Channel HBAs. A system reboot is required for the changes to take full effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, prevent module vdpa from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module sctp from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module ip6_vti from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: If iSCSI initiator functionality is not required, prevent the `libiscsi_tcp` kernel module from loading by blacklisting it. Create a file such as `/etc/modprobe.d/blacklist-iscsi.conf` with the content `blacklist libiscsi_tcp`. A system reboot is required for this change to take effect. This may impact systems relying on iSCSI storage.

🔗 References (28)