Red Hat Product Errata RHSA-2026:16195 - Security Advisory Issued: 2026-05-12 Updated: 2026-05-12 RHSA-2026:16195 - Security Advisory Overview Updated Packages Synopsis Important: kernel security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): kernel: "Dirty Frag" is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel (CVE-2026-43284) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for x86_64 8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le Red Hat CodeReady Linux Builder for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2467771 - CVE-2026-43284 kernel: "Dirty Frag" ESP XFRM variant is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel CVEs CVE-2026-43284 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM kernel-4.18.0-553.124.1.el8_10.src.rpm SHA-256: 494dbb29900f6281aead7c5c750c5fb29cf4bb921c76a92d249394950fa48546 x86_64 bpftool-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: 7971411a5a26a6b144697354a5f2ffdf7d16bde6c18deabcce3ba8f77d61e0c9 bpftool-debuginfo-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: f559600ff37e4eea44d5de47e50289467f720ae4a851833d05ed9ba3c33c69c8 kernel-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: 38929d0fab52532b4eb58c69bb85f21bc231ba49f8a97679a67264bcda71e7cc kernel-abi-stablelists-4.18.0-553.124.1.el8_10.noarch.rpm SHA-256: 20579c88abbfff08abd8ca0943c99e3a76e7c6426e7b13a4c299ba3cce74a488 kernel-core-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: 6cde010dbff0eb130ccaf37f1d1548440ee2082c01e10453647954d17e7e2a1b kernel-cross-headers-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: 7d5faaf86ca004f85b1e4d6f35a5d1ac9d62b42b0ca568c25ccfd6f0cf177885 kernel-debug-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: 9256576d3f56e239652cc062d21fa9f1be29c85913b25c94ec395b29a8e70b91 kernel-debug-core-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: ff52ca8af9a7c2f4467a160152b78be8035e2e86865d500c1778064ecb70c316 kernel-debug-debuginfo-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: 7c388cb55add77d915eeeb0de6d21916f79571953d7724e56008aa5755066ed9 kernel-debug-devel-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: 8b5bc9ebdc937ff60bfafaf0dc4205586fd0b45891920e5f2b8f399bcb94c05d kernel-debug-modules-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: 75c2b24208d358df334fd040952f743a98b332d7c80d236f3763d8f9f87f90aa kernel-debug-modules-extra-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: a58423b97f7f1d343dda59f788bc6a42c80f704c1033789bae79f9a28391a782 kernel-debuginfo-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: 0d76cf0e8a4d6ed16a4cc6669e2dd14664cb63970844bf6675098b0dd0c0957b kernel-debuginfo-common-x86_64-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: 123ce592141e8fb204581d4508d94499a6c302208c33855ebd4c944809518bf5 kernel-devel-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: fbaea690f9e6a2c92d02389641db2a5e48f98a3877b3b148186b6f25a949ca16 kernel-doc-4.18.0-553.124.1.el8_10.noarch.rpm SHA-256: bafef9dc81fb5a93e6f4132adfffbc0c821ccafa02fbd5c1c5664b3f5e2cf3a1 kernel-headers-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: f1db0d51ff1598a1cde7e5742fae7df98e459b7ee5eac21709733c7d9c0b1f4e kernel-modules-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: faeed390b8d748957276b3a7a5468f06cd0e914fbc0e175f4041a2b787c8385b kernel-modules-extra-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: 024e617645747a880229a0ba8d4b1ccee731acd1841826f90d9d361fd04756f2 kernel-tools-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: 7e0363aac883e16ef73c5467390f85b85ea3d1d55c123133397637d91ce40a5b kernel-tools-debuginfo-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: 6a87a24dc24fd8caf8d89087f34f07a07f439f4da0c046af87edc0f12df6904a kernel-tools-libs-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: 6d3b3e5ab2909a3c276f9aa7b75eea5ed4d8af558c48bcb6469a1a313b6c1be3 perf-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: 15b207626fd6be8144685e89fae40d142ef6028796bc1ba1231280a28872ef1c perf-debuginfo-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: dbc3a747a8209e30d3ec3eb57ee7994f475a0484f47f141046bc45791911f80a python3-perf-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: 3f74d051297092fdbe9948194c81bda120ed0da4efae84e5dc377351054ca2ed python3-perf-debuginfo-4.18.0-553.124.1.el8_10.x86_64.rpm SHA-256: 4801c2db7b6a65613ab2e7e4ac0da410752d82472ea9149639ca5df34aa6f397 Red Hat Enterprise Linux for IBM z Systems 8 SRPM kernel-4.18.0-553.124.1.el8_10.src.rpm SHA-256: 494dbb29900f6281aead7c5c750c5fb29cf4bb921c76a92d249394950fa48546 s390x bpftool-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: 793ec117b9ee06bad6a545336471ff9f1ba49876ca22d105087130074ce1539d bpftool-debuginfo-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: 77dc63d973920cda0dcb4fedf8b3df8bd978fcb25e988e0a5f7b27c4ff430efb kernel-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: cdc7f0e31002de79e6eff1d4b51daaf8ced7bb64149d30e858c26a66b5da5509 kernel-abi-stablelists-4.18.0-553.124.1.el8_10.noarch.rpm SHA-256: 20579c88abbfff08abd8ca0943c99e3a76e7c6426e7b13a4c299ba3cce74a488 kernel-core-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: 5557e1b318477ef45b390895287e4f78671b9ec0d0ee04a6d34a05a7bd47042f kernel-cross-headers-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: 2b0eee3b46cd43bc82789cd3ebf97dd929506ccb26afe21c97a7ac9a4c47c30a kernel-debug-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: 8a3a1ae2ac76ca8c384d65e7a30bdebefd690235a84f71945f24156680e1cd7e kernel-debug-core-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: eb866014797fac2ce4182ba1c029467ce1fd1f7f7d02c189dde658a437b60bfe kernel-debug-debuginfo-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: eea44bd5c9cf03990c05317ed9dd72826a000547e85789c90df94de28c5db20f kernel-debug-devel-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: 0451a85ad8e10cd09544fc7ac135bc4f532b5e2f72169570dd965cdf8d280bf4 kernel-debug-modules-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: fabd5433bffb7c9ac83bd396eb4c9a0306bab820f2ab93e4e4f21e5bc8c19e98 kernel-debug-modules-extra-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: fc535d3a0a996a04797834a21018b4f4f0375edfe9d5e3c7d87cb993fb1af5ea kernel-debuginfo-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: 856f07b12ae66dd04c56226f920c09a24608afc2fb599b1d93387f2a51b1ebc2 kernel-debuginfo-common-s390x-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: 2d2b8bc64fd1058e3c3fc4c014a0b1cfacddeb760618ac1f931de501abbd4beb kernel-devel-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: af5815ef5595d5dd611025e7235745c5d090b2b712aeed5a868054dce6c11917 kernel-doc-4.18.0-553.124.1.el8_10.noarch.rpm SHA-256: bafef9dc81fb5a93e6f4132adfffbc0c821ccafa02fbd5c1c5664b3f5e2cf3a1 kernel-headers-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: 415f58cd72d101773c11da73c049241073e20d41556fc70f0193d2675acab421 kernel-modules-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: a160373045a0e6669aed57c7d65748ec643d112ef4fe6f667e3b1b9ea4f64468 kernel-modules-extra-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: c87ce535792d6874cfd070adaf45ac6cb7c8921da840ab98a955d1f54ef4281d kernel-tools-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: 4c7e00a11a83a0f7307b888c070e32bcd07ed7ddda732e4a3556d365139b0348 kernel-tools-debuginfo-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: 52845a27cdfb8eb2c9600c11e22deb3a8786d2150d8750b72c3ad8d6060834e5 kernel-zfcpdump-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: f305aa5d03b223b25e9e39b0d5ac2206e14d5bf848b16d40f271ea1192b87111 kernel-zfcpdump-core-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: 6430fc92593c7ac092139a021b830c3fbe8181bae6e40adf889da197d3bfb3d2 kernel-zfcpdump-debuginfo-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: f0d3a8d8e10ca23d48306aad600caee834c88a7061170b020f3d785d7de3712a kernel-zfcpdump-devel-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: e4930e62528a4dece61b1cce84b50b2c1e292fd72a8ea85458896bdbeb1bce60 kernel-zfcpdump-modules-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: a0a63fe1b9e39958dc35f3d45dd406d887cf84e5b0baa0c94942e556d09ab239 kernel-zfcpdump-modules-extra-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: f20fed94d58220b253f6a114c1a3142e4c1e6d0b18e94f0e5f0219b402b60704 perf-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: 05441a22462a3a3bbed46d87a3e958b9b173c078c2f9ee07cd05d6ac7b38ddc2 perf-debuginfo-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: 624a5b2ad6ed110c7474ccaed7aae0028ecc1e46155fbf4ebac5741de146c4d8 python3-perf-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: e3ee6835a0f9638de38310663f3f0bd349ddb9165126a40100160bcf2c62ba65 python3-perf-debuginfo-4.18.0-553.124.1.el8_10.s390x.rpm SHA-256: 0dfde93d75d57f19ed248a3df55585dec4b11350f638261bb4c6ba6fb33f12ac Red Hat Enterprise Linux for Power, little endian 8 SRPM kernel-4.18.0-
A critical Local Privilege Escalation vulnerability known as "Dirty Frag" (CVE-2026-43284, CVSS 8.8 High) affects the Linux kernel's ESP XFRM component. The vulnerability impacts a wide range of kernel versions, specifically from 4.11 up to but not including 5.10.255, from 5.12 up to but not including 5.15.205, from 5.16 up to but not including 6.1.171, from 6.2 up to but not including 6.6.138, and from 6.7 up to but not including 6.12.87. Patches are available in kernel versions 5.10.255, 5.15.205, 6.1.171, 6.6.138, 6.12.87, 6.18.28, and 7.0.5, and Red Hat has released updated packages for RHEL 8 requiring a system reboot.