RHSA-2026:25121: Critical: kernel security update
Critical: kernel security update
Other sources
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: geneve: Fix use-after-free in genevefinddev(). (CVE-2025-21858) kernel: smc: Fix use-after-free in tcpwritetimerhandler() (CVE-2023-53781) kernel: nbd: defer config unlock in nbdgenlconnect (CVE-2025-68366) kernel: libceph: prevent potential out-of-bounds reads in handleauthdone() (CVE-2026-22984) kernel: libceph: replace overzealous BUGON in osdmapapplyincremental() (CVE-2026-22990) kernel: netfilter: nftables: release flowtable after rcu grace period on error (CVE-2026-23392) kernel: ALSA: 6fire: fix use-after-free on disconnect (CVE-2026-31581) kernel: smb: client: fix OOB reads parsing symlink error response (CVE-2026-31613) kernel: ip6tunnel: clear skb2->cb[] in ip4ip6err() (CVE-2026-43037) kernel: ipv6: icmp: clear skb2->cb[] in ip6errgenicmpv6unreach() (CVE-2026-43038) kernel: dlm: validate length in dlmsearchrsbtree (CVE-2026-43125) kernel: RDMA/rxe: Fix double free in rxesrqfrominit (CVE-2026-45852) kernel: RDMA/mlx4: Fix mis-use of RCU in mlx4srqevent() (CVE-2026-46181) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-abi-stableliststo a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-zfcpdumpto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-zfcpdump-coreto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-zfcpdump-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-zfcpdump-develto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-zfcpdump-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-debuginfo-common-aarch64to a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 4.18.0-553.132.1.el8_10.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:25121?
The severity of RHSA-2026:25121 is critical with a score of 9.
How do I fix RHSA-2026:25121?
You can fix RHSA-2026:25121 by applying the kernel security update available for your specific Red Hat Enterprise Linux version.
What vulnerabilities are addressed in RHSA-2026:25121?
RHSA-2026:25121 addresses vulnerabilities related to use-after-free in geneve_find_dev() and tcp_write_timer_handler().
What systems are affected by RHSA-2026:25121?
RHSA-2026:25121 affects various versions of Red Hat Enterprise Linux for Power, x86_64, ARM 64, and IBM z Systems.
Do I need to reboot my system after applying RHSA-2026:25121?
Yes, you must reboot your system for the changes from RHSA-2026:25121 to take effect.