RHSA-2026:61932: Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: ipv6: fix possible UAF in icmpv6rcv() (CVE-2026-53006) kernel: ipv4: free net->ipv4.sysctllocalreservedports after unregisternetsysctltable() (CVE-2026-64002) kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges (CVE-2026-17523) kernel: net: ipv6: use-after-free in fib6rulesuppress due to stale res->rt6 pointer (CVE-2026-74581) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/bpftoolto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/bpftool-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-abi-stableliststo a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-coreto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-cross-headersto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debugto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-develto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-docto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-headersto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-toolsto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-tools-libsto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/perfto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/python3-perfto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/python3-perf-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade
redhat/kernel-debuginfo-common-ppc64leto a version that resolves this vulnerability.Fixed in 4.18.0-477.163.1.el8_8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-17523 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-64002 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-74581 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-53006 - Operational
Reboot the system after applying the kernel security update so the update takes effect.
Event History
Frequently Asked Questions
Is privilege escalation identified as a potential impact in this update?
Yes. The CAN BCM fix, CVE-2026-17523, is described as allowing arbitrary kernel code execution leading to privilege escalation.
Which package variants are listed with this advisory?
The listed software includes kernel, kernel-core, kernel-cross-headers, kernel-debug, kernel-debug-core, kernel-debug-debuginfo, bpftool, and bpftool-debuginfo.
Which networking areas are covered by the listed fixes?
The fixes include IPv6 ICMP reception, IPv4 local reserved-port sysctl cleanup, CAN BCM, and IPv6 route-rule suppression handling. Three of the listed issues are described as use-after-free conditions.