RHSA-2026:22964HighCVSS 7.4
Red Hat Security Advisory: kernel security update
🔗 CVE IDs covered (7)
CVE-2026-43037 →CVE-2026-43038 →CVE-2024-41073 →CVE-2025-40135 →CVE-2025-40158 →CVE-2025-40170 →CVE-2026-23216 · pending
📋 Description
CVE-2024-41073 — kernel: nvme: avoid double free special payload CVE-2025-40135 — kernel: ipv6: use RCU in ip6_xmit() CVE-2025-40158 — kernel: ipv6: use RCU in ip6_output() CVE-2025-40170 — kernel: net: use dst_dev_rcu() in sk_setup_caps() CVE-2026-23216 — kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() CVE-2026-43037 — kernel: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() CVE-2026-43038 — kernel: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:22964
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2301637
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2414506
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2414521
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2414523
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2440630
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2464351
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2464397
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_22964.json