Red Hat Security Advisory: kernel security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2025-38024 — kernel: Linux kernel: RDMA/rxe use-after-free vulnerability leading to potential arbitrary code execution CVE-2026-23191 — kernel: ALSA: aloop: Fix racy access at PCM trigger CVE-2026-23243 — kernel: Linux kernel: Denial of service and memory corruption in RDMA umad CVE-2026-23401 — kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling CVE-2026-31419 — kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service CVE-2026-31532 — kernel: can: raw: fix ro->uniq use-after-free in raw_rcv() CVE-2026-46300 — kernel: "Fragnesia" is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in the Linux kernel CVE-2026-46333 — kernel: Read root-owned files as an unprivileged user
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:19521
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2373354
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2439947
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448594
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2453803
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457829
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2461107
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477015
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477802
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_19521.json