RHSA-2026:61692: Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: netfilter: nftables: don't skip expired elements during walk (CVE-2023-52924) kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116) kernel: gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984) kernel: ipc: limit nextid allocation to the valid ID range (CVE-2026-52923) kernel: dm log: fix out-of-bounds write due to regioncount overflow (CVE-2026-53059) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-abi-whiteliststo a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-tools-libs-develto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/python-perfto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/python-perf-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-s390xto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-kdumpto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-kdump-debuginfoto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-kdump-develto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-bootwrapperto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64to a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 3.10.0-1160.159.1.el7 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-53059 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-45984 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-52923 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2026-43116 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2023-52924 - Operational
Reboot the system for this kernel security update to take effect.
Event History
Frequently Asked Questions
Which package variants are covered by this update?
The advisory lists kernel, kernel-debug, kernel-devel, kernel-debuginfo, kernel-debug-debuginfo, bpftool, and bpftool-debuginfo packages under Red Hat.