RHSA-2026:68570HighCVSS 8.8

Red Hat Security Advisory: kernel security, bug fix, and enhancement update

Published
September 17, 2026
Last Modified
September 28, 2026

🔗 CVE IDs covered (31)

📋 Description

CVE-2026-23172 — kernel: Linux kernel t7xx WWAN driver: Denial of Service via buffer overflow CVE-2026-31663 — kernel: xfrm: hold dev ref until after transport_finish NF_HOOK CVE-2026-45910 — kernel: RDMA/rxe: Fix race condition in QP timer handlers CVE-2026-46043 — kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv CVE-2026-46114 — kernel: RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads CVE-2026-46133 — kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing CVE-2026-52971 — kernel: net: ena: PHC: Fix potential use-after-free in get_timestamp CVE-2026-53176 — kernel: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN CVE-2026-53192 — kernel: ALSA: timer: Fix UAF at snd_timer_user_params() CVE-2026-53193 — kernel: ALSA: timer: Forcibly close timer instances at closing CVE-2026-53196 — kernel: USB: serial: io_ti: fix heap overflow in get_manuf_info() CVE-2026-53239 — kernel: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() CVE-2026-63869 — kernel: wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap CVE-2026-63913 — kernel: netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check CVE-2026-63917 — kernel: ip6: vti: Use ip6_tnl.net in vti6_changelink() CVE-2026-63919 — kernel: xfrm: input: hold netns during deferred transport reinjection CVE-2026-63921 — kernel: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() CVE-2026-64029 — kernel: ALSA: seq: Serialize UMP output teardown with event_input CVE-2026-64174 — kernel: wifi: cfg80211: advance loop vars in cfg80211_merge_profile() CVE-2026-64175 — kernel: wifi: iwlwifi: mld: stop TX during firmware restart CVE-2026-64176 — kernel: wifi: iwlwifi: mvm: fix driver-set TX rates on old devices CVE-2026-64582 — kernel: RDMA/rxe: Fix a use-after-free problem in rxe_mmap CVE-2026-68128 — kernel: Linux kernel (ice): Denial of Service via out-of-range ptype in VIRTCHNL CVE-2026-68159 — kernel: Linux kernel: libceph stack out-of-bounds write via crafted OSDMap CVE-2026-68200 — kernel: Linux kernel: ALSA timer use-after-free vulnerability allows privilege escalation CVE-2026-68363 — kernel: Linux kernel: ath9k Wi-Fi driver use-after-free vulnerability leading to system crash CVE-2026-68426 — kernel: xfrm: fix stale skb->prev after async crypto steals a GSO segment CVE-2026-72003 — kernel: wifi: brcmfmac: cyw: fix heap overflow on a short auth frame CVE-2026-72102 — kernel: dm_early_create: fix freeing used table on dm_resume failure CVE-2026-72243 — kernel: selinux: check connect-related permissions on TCP Fast Open CVE-2026-72298 — kernel: net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()

🎯 Affected products200

  • Red Hat Enterprise Linux AppStream (v. 9)
  • Red Hat Enterprise Linux BaseOS (v. 9)
  • Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • Red Hat Enterprise Linux Real Time (v. 9)
  • Red Hat Enterprise Linux Real Time for NFV (v. 9)
  • kernel-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-0:5.14.0-687.49.1.el9_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-0:5.14.0-687.49.1.el9_8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-0:5.14.0-687.49.1.el9_8.src as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-0:5.14.0-687.49.1.el9_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-core-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-debug-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-debug-core-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-debug-debuginfo-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • kernel-64k-debug-debuginfo-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-debug-debuginfo-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • kernel-64k-debug-debuginfo-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
  • kernel-64k-debug-devel-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • kernel-64k-debug-devel-matched-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • kernel-64k-debug-modules-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-debug-modules-core-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-debug-modules-extra-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-debuginfo-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • kernel-64k-debuginfo-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kernel-64k-debuginfo-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • kernel-64k-debuginfo-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
  • kernel-64k-devel-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • kernel-64k-devel-matched-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • kernel-64k-modules-0:5.14.0-687.49.1.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture. Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: For systems where the `ena` kernel module is not required, it can be blacklisted to prevent it from loading. Create a file such as `/etc/modprobe.d/blacklist-ena.conf` with the content `blacklist ena`. A system reboot is necessary for this change to take effect. Disabling the `ena` module may impact network functionality if Elastic Network Adapters are in use. Workaround: To mitigate this issue, prevent module ib_isert from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module io_ti from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module ip6_vti from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, the `iwlwifi` kernel module can be blacklisted to prevent it from loading. This will disable Wi-Fi functionality on the system. To blacklist the module: 1. Create a file `/etc/modprobe.d/blacklist-iwlwifi.conf` with the following content: ``` blacklist iwlwifi ``` 2. Regenerate the initramfs: ```bash sudo dracut -f -v ``` or ```bash sudo mkinitrd -f -v /boot/initramfs-$(uname -r).img $(uname -r) ``` 3. Reboot the system for the changes to take effect. Note that disabling the `iwlwifi` module will prevent the use of Intel Wi-Fi devices. Workaround: To prevent the `iwlwifi` kernel module from loading, which disables Intel wireless functionality, create a blacklist rule. 1. Create the file `/etc/modprobe.d/blacklist-iwlwifi.conf` with the following content: ``` blacklist iwlwifi install iwlwifi /bin/true ``` 2. Regenerate the initramfs to apply the changes: ```bash dracut -f -v ``` For systems using `mkinitrd`: ```bash mkinitrd -f -v /boot/initramfs-$(uname -r).img $(uname -r) ``` 3. A system reboot is required for this change to take effect. Workaround: To mitigate this issue, prevent the `rxe` kernel module from loading. This can be achieved by blacklisting the module. Create a file named `/etc/modprobe.d/blacklist-rxe.conf` with the following content: ``` blacklist rxe ``` After creating the file, regenerate the initramfs and reboot the system for the changes to take effect. This mitigation may impact functionality that relies on the RDMA/rxe module. Workaround: If Intel Ethernet 800 Series Network Adapters are not in use, the `ice` kernel module can be blacklisted to prevent it from loading. Create a file `/etc/modprobe.d/blacklist-ice.conf` with the content `blacklist ice`. After saving the file, regenerate the initramfs using `dracut -f -v` and reboot the system for the changes to take effect. This action may disrupt network connectivity if the `ice` driver is required for active network interfaces. Workaround: If the system does not require the `libceph` module for Ceph cluster connectivity, prevent the `ceph` kernel module from loading by blacklisting it. Create a file `/etc/modprobe.d/ceph.conf` with the content `blacklist ceph`. After creating the file, regenerate the initramfs using `dracut -f -v` and reboot the system for the changes to take effect. If `libceph` is in use, restrict network access to Ceph monitors to trusted hosts through firewall rules to reduce the attack surface. Workaround: To mitigate this issue, TCP Fast Open (TFO) can be disabled if not required by applications. Disabling TFO prevents the vulnerable code path from being exercised, thereby eliminating the SELinux permission bypass. To disable TCP Fast Open: 1. Check the current setting: `sysctl net.ipv4.tcp_fastopen` 2. To disable it temporarily: `sudo sysctl -w net.ipv4.tcp_fastopen=0` 3. To make the change persistent across reboots, add or modify the following line in `/etc/sysctl.conf`: `net.ipv4.tcp_fastopen = 0` 4. Apply the persistent changes: `sudo sysctl -p` Disabling TCP Fast Open may impact the performance of applications that utilize this feature for faster connection establishment.

🔗 References (34)