RHSA-2026:26535: Critical: kernel security, bug fix, and enhancement update
Critical: kernel security, bug fix, and enhancement update
Other sources
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: geneve: Fix use-after-free in genevefinddev(). (CVE-2025-21858) kernel: sctp: fix a potential overflow in sctpifwdtsnskip (CVE-2023-53372) kernel: net: use dstdevrcu() in sksetupcaps() (CVE-2025-40170) kernel: ipv6: use RCU in ip6xmit() (CVE-2025-40135) kernel: ipv6: use RCU in ip6output() (CVE-2025-40158) kernel: nbd: defer config unlock in nbdgenlconnect (CVE-2025-68366) kernel: mlxsw: spectrummr: Fix use-after-free when updating multicast route stats (CVE-2025-68800) kernel: iommu: disable SVA when CONFIGX86 is set (CVE-2025-71089) kernel: macvlan: fix possible UAF in macvlanforwardsource() (CVE-2026-23001) kernel: Linux kernel: Denial of Service due to a deadlock in hugetlb folio migration (CVE-2026-23097) kernel: ALSA: aloop: Fix racy access at PCM trigger (CVE-2026-23191) kernel: scsi: target: iscsi: Fix use-after-free in iscsitdecconnusagecount() (CVE-2026-23216) kernel: Linux kernel: Denial of service and memory corruption in RDMA umad (CVE-2026-23243) kernel: netfilter: nftables: release flowtable after rcu grace period on error (CVE-2026-23392) kernel: netfilter: ip6teui64: reject invalid MAC header for all packets (CVE-2026-31685) kernel: ip6tunnel: clear skb2->cb[] in ip4ip6err() (CVE-2026-43037) kernel: ipv6: icmp: clear skb2->cb[] in ip6errgenicmpv6unreach() (CVE-2026-43038) kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116) kernel: wifi: brcmfmac: validate bsscfg indices in IF events (CVE-2026-43110) kernel: md/bitmap: fix GPF in writepage caused by resize race (CVE-2026-43163) kernel: netfilter: xttcpmss: check remaining length before reading optlen (CVE-2026-43190) kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks (CVE-2026-43158) kernel: Linux kernel: smb: client: reject userspace cifs.spnego descriptions (CVE-2026-46243) kernel: sctp: revalidate list cursor after sctpsendmsgtoasoc() in SCTPSENDALL (CVE-2026-46227) Bug Fix(es) and Enhancement(s): NFS client hangs while returning delegations (JIRA:RHEL-112276) Rhel backport of upstream commit "i40e: avoid redundant VF link state update" (JIRA:RHEL-141908) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-abi-stableliststo a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-305.194.1.el8_4 - Operational
Reboot the system for the kernel update to take effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:26535?
The severity of RHSA-2026:26535 is critical with a CVSS score of 9.
What vulnerabilities are addressed in RHSA-2026:26535?
RHSA-2026:26535 addresses a critical security fix for kernel vulnerabilities, including a use-after-free issue in geneve_find_dev() and potential overflow in sctp_ifwdtsn_skip.
How do I fix RHSA-2026:26535?
To fix RHSA-2026:26535, users should update their kernel packages to the latest version provided by Red Hat.
Which software packages are impacted by RHSA-2026:26535?
The impacted software packages include the kernel packages for Red Hat Enterprise Linux and related utilities like bpftool.
When was RHSA-2026:26535 published?
RHSA-2026:26535 was published on June 17, 2026.