RHSA-2026:71233HighCVSS 8.3

Red Hat Security Advisory: kernel security, bug fix, and enhancement update

Published
September 24, 2026
Last Modified
September 30, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2026-23007 — kernel: block: zero non-PI portion of auto integrity buffer CVE-2026-53266 — kernel: netfilter: ebtables SNAT target writes to shared memory pages during ARP hardware address rewrite CVE-2026-63802 — kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() CVE-2026-63831 — kernel: mac802154: llsec: add skb_cow_data() before in-place crypto CVE-2026-64053 — kernel: block: don't overwrite bip_vcnt in bio_integrity_copy_user() CVE-2026-64383 — kernel: smb: client: fix double-free in SMB2_flush() replay CVE-2026-64564 — kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing CVE-2026-68201 — kernel: ALSA: timer: drain a slave's callback before its master detaches it CVE-2026-72243 — kernel: selinux: check connect-related permissions on TCP Fast Open CVE-2026-74569 — kernel: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() CVE-2026-80844 — kernel: xfrm: ah6: validate routing header segments_left CVE-2026-81000 — kernel: net: tun: bound receive headroom CVE-2026-89846 — kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read

🎯 Affected products200

  • Red Hat Enterprise Linux AppStream (v. 10)
  • Red Hat Enterprise Linux BaseOS (v. 10)
  • Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • Red Hat Enterprise Linux Real Time (v. 10)
  • Red Hat Enterprise Linux Real Time for NFV (v. 10)
  • kernel-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-0:6.12.0-211.59.1.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-0:6.12.0-211.59.1.el10_2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-0:6.12.0-211.59.1.el10_2.src as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-0:6.12.0-211.59.1.el10_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-core-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-core-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-debuginfo-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-debug-debuginfo-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-debuginfo-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • kernel-64k-debug-debuginfo-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux Real Time (v. 10)
  • kernel-64k-debug-devel-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-debug-devel-matched-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-debug-modules-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-modules-core-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debug-modules-extra-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debuginfo-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-debuginfo-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • kernel-64k-debuginfo-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • kernel-64k-debuginfo-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux Real Time (v. 10)
  • kernel-64k-devel-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-devel-matched-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • kernel-64k-modules-0:6.12.0-211.59.1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture. Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available. Workaround: Disable ARP hardware address rewriting in ebtables SNAT rules, or remove ebtables SNAT rules that operate on ARP traffic on bridge interfaces. Workaround: To mitigate this issue, prevent the `sctp` kernel module from loading. Create a file named `/etc/modprobe.d/disable-sctp.conf` with the following content: ``` install sctp /bin/true blacklist sctp ``` After creating the file, regenerate the initramfs and reboot the system for the changes to take effect. Applications or services that rely on the SCTP protocol cannot use this mitigation and should prioritize applying the fix. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, TCP Fast Open (TFO) can be disabled if not required by applications. Disabling TFO prevents the vulnerable code path from being exercised, thereby eliminating the SELinux permission bypass. To disable TCP Fast Open: 1. Check the current setting: `sysctl net.ipv4.tcp_fastopen` 2. To disable it temporarily: `sudo sysctl -w net.ipv4.tcp_fastopen=0` 3. To make the change persistent across reboots, add or modify the following line in `/etc/sysctl.conf`: `net.ipv4.tcp_fastopen = 0` 4. Apply the persistent changes: `sudo sysctl -p` Disabling TCP Fast Open may impact the performance of applications that utilize this feature for faster connection establishment. Workaround: See the security bulletin for a detailed mitigation procedure. Workaround: If QLogic Fibre Channel HBAs are not in use, the 'qla2xxx' kernel module can be blacklisted to prevent it from loading. This can be achieved by creating a modprobe configuration file. To blacklist the module: 1. Create a file named `/etc/modprobe.d/blacklist-qla2xxx.conf` with the following content: `blacklist qla2xxx` 2. Regenerate the initramfs to ensure the blacklist is applied during boot: `sudo dracut -f -v` (for RHEL 7/8/9) `sudo mkinitcpio -P` (for Arch-based systems, if applicable) 3. Reboot the system for the changes to take effect. Warning: Blacklisting this module will disable functionality for QLogic Fibre Channel HBAs. Ensure that this hardware is not required before applying this mitigation. A system reboot is required for the changes to take effect.

🔗 References (16)