Red Hat Security Advisory: kernel security, bug fix, and enhancement update
🔗 CVE IDs covered (16)
📋 Description
CVE-2026-23442 — kernel: ipv6: add NULL checks for idev in SRv6 paths CVE-2026-45910 — kernel: RDMA/rxe: Fix race condition in QP timer handlers CVE-2026-46043 — kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv CVE-2026-46114 — kernel: RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads CVE-2026-46133 — kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing CVE-2026-63920 — kernel: ipv6: validate extension header length before copying to cmsg CVE-2026-63922 — kernel: ipv6: exthdrs: refresh nh after handling HAO option CVE-2026-63924 — kernel: ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() CVE-2026-63984 — kernel: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() CVE-2026-64383 — kernel: smb: client: fix double-free in SMB2_flush() replay CVE-2026-64385 — kernel: Kernel SMB client: Double-free vulnerability allows remote denial of service or privilege escalation CVE-2026-64386 — kernel: smb: client: fix query_info() replay double-free CVE-2026-64582 — kernel: RDMA/rxe: Fix a use-after-free problem in rxe_mmap CVE-2026-80792 — kernel: ipv6: fix use-after-free in ip6_finish_output2() CVE-2026-80863 — kernel: RDMA/rxe: Fix OOB in free_rd_atomic_resources() CVE-2026-80864 — kernel: RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
🎯 Affected products200
- Red Hat CodeReady Linux Builder EUS (v.9.6)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- Red Hat Enterprise Linux Real Time EUS (v.9.6)
- Red Hat Enterprise Linux Real Time for NFV EUS (v.9.6)
- kernel-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-0:5.14.0-570.147.1.el9_6.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-0:5.14.0-570.147.1.el9_6.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-0:5.14.0-570.147.1.el9_6.src as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-0:5.14.0-570.147.1.el9_6.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-core-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-debug-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-debug-core-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-debug-debuginfo-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6)
- kernel-64k-debug-debuginfo-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- kernel-64k-debug-debuginfo-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-debug-debuginfo-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.6)
- kernel-64k-debug-devel-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- kernel-64k-debug-devel-matched-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- kernel-64k-debug-modules-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-debug-modules-core-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-debug-modules-extra-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-debuginfo-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.6)
- kernel-64k-debuginfo-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- kernel-64k-debuginfo-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- kernel-64k-debuginfo-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.6)
- kernel-64k-devel-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- kernel-64k-devel-matched-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.6)
- kernel-64k-modules-0:5.14.0-570.147.1.el9_6.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture. Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, prevent the `rxe` kernel module from loading. This can be achieved by blacklisting the module. Create a file named `/etc/modprobe.d/blacklist-rxe.conf` with the following content: ``` blacklist rxe ``` After creating the file, regenerate the initramfs and reboot the system for the changes to take effect. This mitigation may impact functionality that relies on the RDMA/rxe module. Workaround: To mitigate this issue, prevent module rdma_rxe from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent the rdma_rxe kernel module from being loaded. 1. Create a configuration file in /etc/modprobe.d to disable loading of the module: # echo "install rdma_rxe /bin/true" > /etc/modprobe.d/disable-rdma_rxe.conf 2. If the module is currently loaded, attempt to unload it: # modprobe -r rdma_rxe Caveats: Disabling this module prevents the creation and operation of software RDMA over Converged Ethernet (Soft-RoCE) devices. Applications requiring rdma_rxe will fail to initialize. If the module is currently in active use and cannot be unloaded dynamically, a system reboot is required to ensure the module is fully disabled.
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2026:77219
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2454807
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2482098
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2482127
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2482550
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2482618
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2502326
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2502327
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2502330
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2502395
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2507035
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2507134
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2507216
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2511448
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2528542
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2528646
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2528665
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_77219.json