Red Hat Security Advisory: kernel security, bug fix, and enhancement update
🔗 CVE IDs covered (5)
📋 Description
CVE-2025-39964 — kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg CVE-2026-68121 — kernel: pppoe: reload header pointer after dev_hard_header() CVE-2026-74469 — kernel: sctp: prevent peer transport count overflow CVE-2026-74581 — kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res->rt6 pointer CVE-2026-81000 — kernel: net: tun: bound receive headroom
🎯 Affected products54
- NVIDIA for RHEL 10
- kernel-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-0:6.12.0-259.27.el10nv.src as a component of NVIDIA for RHEL 10
- kernel-64k-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-64k-core-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-64k-debug-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-64k-debug-core-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-64k-debug-debuginfo-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-64k-debug-devel-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-64k-debug-devel-matched-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-64k-debug-modules-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-64k-debug-modules-core-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-64k-debug-modules-extra-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-64k-debuginfo-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-64k-devel-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-64k-devel-matched-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-64k-modules-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-64k-modules-core-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-64k-modules-extra-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-abi-stablelists-0:6.12.0-259.27.el10nv.noarch as a component of NVIDIA for RHEL 10
- kernel-core-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-debug-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-debug-core-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-debug-debuginfo-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-debug-devel-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-debug-devel-matched-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-debug-modules-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-debug-modules-core-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-debug-modules-extra-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- kernel-debuginfo-0:6.12.0-259.27.el10nv.aarch64 as a component of NVIDIA for RHEL 10
- +24 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: See the security bulletin for a detailed mitigation procedure. Workaround: To mitigate this issue, disable the `ipv6` kernel module at boot using the kernel command-line parameter: ``` grubby --update-kernel=ALL --args="ipv6.disable=1" ``` A reboot is required for this change to take effect. To verify after reboot: ``` cat /proc/cmdline | grep -o ipv6.disable=1 sysctl net.ipv6.conf.all.disable_ipv6 ``` Applications or services that rely on the IPv6 protocol cannot use this mitigation and should prioritize applying the fix.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:73788
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2403545
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2513233
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2517043
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2520980
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2532176
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_73788.json