RHSA-2026:77216HighCVSS 8.8

Red Hat Security Advisory: kernel security, bug fix, and enhancement update

Published
October 7, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (22)

📋 Description

CVE-2025-68347 — kernel: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events CVE-2026-31663 — kernel: xfrm: hold dev ref until after transport_finish NF_HOOK CVE-2026-45991 — kernel: udf: fix partition descriptor append bookkeeping CVE-2026-46043 — kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv CVE-2026-46133 — kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing CVE-2026-52923 — kernel: ipc: limit next_id allocation to the valid ID range CVE-2026-52924 — kernel: sctp: purge outqueue on stale COOKIE-ECHO handling CVE-2026-53062 — kernel: dm cache policy smq: fix missing locks in invalidating cache blocks CVE-2026-53239 — kernel: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() CVE-2026-63917 — kernel: ip6: vti: Use ip6_tnl.net in vti6_changelink() CVE-2026-63919 — kernel: xfrm: input: hold netns during deferred transport reinjection CVE-2026-63921 — kernel: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() CVE-2026-64007 — kernel: netfilter: synproxy: refresh tcphdr after skb_ensure_writable CVE-2026-64320 — kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page CVE-2026-64582 — kernel: RDMA/rxe: Fix a use-after-free problem in rxe_mmap CVE-2026-68294 — kernel: net: qrtr: restrict socket creation to the initial network namespace CVE-2026-68426 — kernel: xfrm: fix stale skb->prev after async crypto steals a GSO segment CVE-2026-68480 — kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability CVE-2026-74556 — kernel: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer CVE-2026-74746 — kernel: netfilter: flowtable: publish GC-visible tuple last CVE-2026-80863 — kernel: RDMA/rxe: Fix OOB in free_rd_atomic_resources() CVE-2026-80864 — kernel: RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp

🎯 Affected products123

  • Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • bpftool-0:4.18.0-372.220.1.el8_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • bpftool-0:4.18.0-372.220.1.el8_6.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • bpftool-0:4.18.0-372.220.1.el8_6.s390x as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • bpftool-0:4.18.0-372.220.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • bpftool-0:4.18.0-372.220.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • bpftool-debuginfo-0:4.18.0-372.220.1.el8_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • bpftool-debuginfo-0:4.18.0-372.220.1.el8_6.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • bpftool-debuginfo-0:4.18.0-372.220.1.el8_6.s390x as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • bpftool-debuginfo-0:4.18.0-372.220.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • bpftool-debuginfo-0:4.18.0-372.220.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • kernel-0:4.18.0-372.220.1.el8_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • kernel-0:4.18.0-372.220.1.el8_6.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • kernel-0:4.18.0-372.220.1.el8_6.s390x as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • kernel-0:4.18.0-372.220.1.el8_6.src as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • kernel-0:4.18.0-372.220.1.el8_6.src as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • kernel-0:4.18.0-372.220.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • kernel-0:4.18.0-372.220.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • kernel-abi-stablelists-0:4.18.0-372.220.1.el8_6.noarch as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • kernel-abi-stablelists-0:4.18.0-372.220.1.el8_6.noarch as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • kernel-core-0:4.18.0-372.220.1.el8_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • kernel-core-0:4.18.0-372.220.1.el8_6.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • kernel-core-0:4.18.0-372.220.1.el8_6.s390x as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • kernel-core-0:4.18.0-372.220.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • kernel-core-0:4.18.0-372.220.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • kernel-debug-0:4.18.0-372.220.1.el8_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • kernel-debug-0:4.18.0-372.220.1.el8_6.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • kernel-debug-0:4.18.0-372.220.1.el8_6.s390x as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • kernel-debug-0:4.18.0-372.220.1.el8_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • +93 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture. Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent module ip6_vti from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent the `rxe` kernel module from loading. This can be achieved by blacklisting the module. Create a file named `/etc/modprobe.d/blacklist-rxe.conf` with the following content: ``` blacklist rxe ``` After creating the file, regenerate the initramfs and reboot the system for the changes to take effect. This mitigation may impact functionality that relies on the RDMA/rxe module. Workaround: To mitigate this issue, prevent the `qrtr` kernel module from loading. Create a file `/etc/modprobe.d/blacklist-qrtr.conf` with the content `blacklist qrtr`. A system reboot is required for this change to take effect. This may impact functionality that relies on the QRTR inter-process communication mechanism, such as communication with modems or other remote processors. Workaround: If iSCSI initiator functionality is not required, prevent the `libiscsi_tcp` kernel module from loading by blacklisting it. Create a file such as `/etc/modprobe.d/blacklist-iscsi.conf` with the content `blacklist libiscsi_tcp`. A system reboot is required for this change to take effect. This may impact systems relying on iSCSI storage. Workaround: To mitigate this issue, prevent module rdma_rxe from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent the rdma_rxe kernel module from being loaded. 1. Create a configuration file in /etc/modprobe.d to disable loading of the module: # echo "install rdma_rxe /bin/true" > /etc/modprobe.d/disable-rdma_rxe.conf 2. If the module is currently loaded, attempt to unload it: # modprobe -r rdma_rxe Caveats: Disabling this module prevents the creation and operation of software RDMA over Converged Ethernet (Soft-RoCE) devices. Applications requiring rdma_rxe will fail to initialize. If the module is currently in active use and cannot be unloaded dynamically, a system reboot is required to ensure the module is fully disabled.

🔗 References (25)