RHSA-2026:35844: Important: kernel security update
Important: kernel security update
Other sources
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: netfilter: nfconntrackh323: check for zero length in DecodeQ931() (CVE-2026-23455) kernel: dlm: validate length in dlmsearchrsbtree (CVE-2026-43125) kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090) kernel: RDMA/rxe: Fix double free in rxesrqfrominit (CVE-2026-45852) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-abi-whiteliststo a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/python-perfto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/python-perf-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-kdumpto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-kdump-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-kdump-develto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-bootwrapperto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64to a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 3.10.0-1160.154.1.el7 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-46090 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-45852 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-43125 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-23455 - Operational
Reboot the system for the kernel security update to take effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:35844?
The severity of RHSA-2026:35844 is classified as high with a score of 7.
What does RHSA-2026:35844 address?
RHSA-2026:35844 addresses a security vulnerability in the kernel of Red Hat Enterprise Linux.
How do I fix RHSA-2026:35844?
To fix RHSA-2026:35844, you should apply the latest kernel security update provided by Red Hat.
Which software versions are affected by RHSA-2026:35844?
RHSA-2026:35844 affects several versions of Red Hat Enterprise Linux Server under Extended Life Cycle Support.
When was RHSA-2026:35844 published?
RHSA-2026:35844 was published on July 6, 2026.