RHSA-2026:35863: Important: kernel security, bug fix, and enhancement update
Important: kernel security, bug fix, and enhancement update
Other sources
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: Linux kernel: Use-after-free in traffic control (actct) may lead to denial of service or privilege escalation (CVE-2026-23270) kernel: netfilter: nfconntrackh323: check for zero length in DecodeQ931() (CVE-2026-23455) kernel: mptcp: fix slab-use-after-free in inetlookupestablished (CVE-2026-31669) kernel: ALSA: usb-audio: Add sanity check for OOB writes at silencing (CVE-2026-43279) kernel: tcp: fix potential race in tcpv6synrecvsock() (CVE-2026-43198) kernel: dlm: validate length in dlmsearchrsbtree (CVE-2026-43125) kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090) kernel: RDMA/rxe: Fix double free in rxesrqfrominit (CVE-2026-45852) kernel: RDMA/mlx4: Fix mis-use of RCU in mlx4srqevent() (CVE-2026-46181) Bug Fix(es) and Enhancement(s): NVMe-FC: Panic during NVMe Controller Reset tests (JIRA:RHEL-178449) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-abi-stableliststo a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 4.18.0-477.150.1.el8_8 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch JIRA:RHEL-178449 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-46090 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-43279 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-46181 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-45852 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-43125 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-31669 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-43329 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-23455 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-43198 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-23270 - Operational
Reboot the system after applying the kernel update so it takes effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:35863?
The severity of RHSA-2026:35863 is classified as high with a score of 7.
What vulnerabilities are addressed in RHSA-2026:35863?
RHSA-2026:35863 addresses a use-after-free vulnerability in the traffic control subsystem leading to potential denial of service or privilege escalation.
How do I fix RHSA-2026:35863?
To fix RHSA-2026:35863, you should update your kernel packages to the latest version provided by Red Hat.
What impact does the vulnerability in RHSA-2026:35863 have on my system?
The vulnerability in RHSA-2026:35863 may lead to a denial of service or privilege escalation on affected systems.
Which packages are impacted by RHSA-2026:35863?
The impacted packages include redhat/kernel, redhat/bpftool, and various kernel-related packages.