Red Hat Product Errata RHSA-2026:27288 - Security Advisory Issued: 2026-06-19 Updated: 2026-06-19 RHSA-2026:27288 - Security Advisory Overview Updated Packages Synopsis Important: kernel security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for kernel is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474) kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669) kernel: rxrpc: Fix RxGK token loading to check bounds (CVE-2026-31641) kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787) kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786) kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056) kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772) kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260) kernel: crypto: caam - fix overflow on long hmac keys (CVE-2026-43330) kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331) kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056) kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result (CVE-2026-46152) kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125) kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173) kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166) Bug Fix(es) and Enhancement(s): RHEL10.0 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [rhel-10.2.z] (JIRA:RHEL-166047) RHEL9.5 crash due to lpfc NULL ndlp->vport [rhel-10.2.z] (JIRA:RHEL-171774) objtool static_call check blocks build of out-of-tree livepatch modules on RHEL 10.2 GA kernels ? missing upstream revert f495054bd12e (JIRA:RHEL-178495) ibmveth Adapter Freeze with Small MSS [rhel-10.2.z] (JIRA:RHEL-179723) rbd: eliminate a race in lock_dwork draining on unmap [rhel-10.2.z] (JIRA:RHEL-183127) RHEL10.0 - s390/mm: Add missing secure storage access fixups [rhel-10.2.z] (JIRA:RHEL-183319) [RHEL10.2.z] Enable Pretimeout Watchdog Panic Functionality on x86 (JIRA:RHEL-182299) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2460646 - CVE-2026-31474 kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() BZ - 2461503 - CVE-2026-31669 kernel: mptcp: fix slab-use-after-free in __inet_lookup_established BZ - 2461548 - CVE-2026-31641 kernel: rxrpc: Fix RxGK token loading to check bounds BZ - 2464092 - CVE-2026-31787 kernel: xen/privcmd: fix double free via VMA splitting BZ - 2464096 - CVE-2026-31786 kernel: Buffer overflow in drivers/xen/sys-hypervisor.c BZ - 2464449 - CVE-2026-43056 kernel: net: mana: fix use-after-free in add_adev() error path BZ - 2464502 - CVE-2026-31772 kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync BZ - 2467083 - CVE-2026-43260 kernel: bnxt_en: Fix RSS context delete logic BZ - 2468061 - CVE-2026-43330 kernel: crypto: caam - fix overflow on long hmac keys BZ - 2479492 - CVE-2026-46331 kernel: net/sched: act_pedit: extend the writable skb range per key BZ - 2482181 - CVE-2026-46056 kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers BZ - 2482563 - CVE-2026-46152 kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result BZ - 2482608 - CVE-2026-46125 kernel: wifi: mac80211: remove station if connection prep fails BZ - 2482634 - CVE-2026-46173 kernel: exit: prevent preemption of oopsing TASK_DEAD task BZ - 2482645 - CVE-2026-46166 kernel: wifi: mac80211: use safe list iteration in radar detect work CVEs CVE-2026-31474 CVE-2026-31641 CVE-2026-31669 CVE-2026-31772 CVE-2026-31786 CVE-2026-31787 CVE-2026-43056 CVE-2026-43260 CVE-2026-43330 CVE-2026-46056 CVE-2026-46125 CVE-2026-46152 CVE-2026-46166 CVE-2026-46173 CVE-2026-46331 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM kernel-6.12.0-211.26.1.el10_2.src.rpm SHA-256: 8084ecdca45e3d89df00e353bd463b7700faafdfdf923eef0d152cb166f0a84e x86_64 kernel-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: bb496430b2141d99c2199e4e2fa522938994b8564f873a1d1cf54b833adbc07d kernel-abi-stablelists-6.12.0-211.26.1.el10_2.noarch.rpm SHA-256: 63ad3fb305da374121c468f25c817b19b69cbc1afacc63aff7460776b339f611 kernel-core-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: 4537001d374a426e599c571e39c5f89f8e98e087309d7187ea1fd9745ca880aa kernel-debug-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: 14f3ca3892c3657a22405f4cee0353aead987d79fb0b312af069f8d5d7e2f7a8 kernel-debug-core-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: ed98b36aa6caec7e5557a34f00c0d0469060f1ff16c85b824aa406162dc38945 kernel-debug-debuginfo-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: 1f1129c95c284454d4def13d37e534c8924f9a1fa11afa52b2744ff79e40ac9f kernel-debug-debuginfo-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: 1f1129c95c284454d4def13d37e534c8924f9a1fa11afa52b2744ff79e40ac9f kernel-debug-debuginfo-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: 1f1129c95c284454d4def13d37e534c8924f9a1fa11afa52b2744ff79e40ac9f kernel-debug-debuginfo-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: 1f1129c95c284454d4def13d37e534c8924f9a1fa11afa52b2744ff79e40ac9f kernel-debug-devel-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: f6e52dfb63fba01462ecb324b7dbff891b3f6df9ce44d3322eb1b06eec3bf827 kernel-debug-devel-matched-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: 5e0eeb75cff00af54514374f760b7e0f978fe5380280854d16a66f96468402ad kernel-debug-modules-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: c3167228925ddf0287f6b3de67043dcbeda3cb8ea992e3bf04ef273a97f86cfd kernel-debug-modules-core-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: 24939a3b3fd03d620c787f53bc6e212be53a390297ac45c82118100fa01c9a19 kernel-debug-modules-extra-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: 1495340f29f274af0606854fdf404852ab6c7ec40ebb2381c6503c3cea3c1efb kernel-debug-uki-virt-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: 866edd73ab4f92c3d9bbe835cb9192f4776be3617dd8509cd7ba5be961fc6259 kernel-debuginfo-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: f66b49a5ca819b8be5e9bca2dbd5ce7182ced3bb028b776f3a1446fc7f7d40ad kernel-debuginfo-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: f66b49a5ca819b8be5e9bca2dbd5ce7182ced3bb028b776f3a1446fc7f7d40ad kernel-debuginfo-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: f66b49a5ca819b8be5e9bca2dbd5ce7182ced3bb028b776f3a1446fc7f7d40ad kernel-debuginfo-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: f66b49a5ca819b8be5e9bca2dbd5ce7182ced3bb028b776f3a1446fc7f7d40ad kernel-debuginfo-common-x86_64-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: b55016650d288b9ac5dca4dc066b63dca6fd7cd7642df14c0f5a262c27962937 kernel-debuginfo-common-x86_64-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: b55016650d288b9ac5dca4dc066b63dca6fd7cd7642df14c0f5a262c27962937 kernel-debuginfo-common-x86_64-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: b55016650d288b9ac5dca4dc066b63dca6fd7cd7642df14c0f5a262c27962937 kernel-debuginfo-common-x86_64-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: b55016650d288b9ac5dca4dc066b63dca6fd7cd7642df14c0f5a262c27962937 kernel-devel-6.12.0-211.26.1.el10_2.x86_64.rpm SHA-256: 373900a7d1eb43ed24ddc24a49e95441596710b01767365d45540a88c85b9894 kernel-devel-matched-6.12.0-211.26.1.el10_2.x86
This Red Hat security advisory addresses multiple Important-severity kernel vulnerabilities, including use-after-free conditions, buffer overflows, and slab corruption in subsystems like CAN, MPTCP, Bluetooth, and Xen, which could lead to privilege escalation, denial of service, or information disclosure. The update applies to Red Hat Enterprise Linux 10, and while individual CVSS scores are available via the linked CVEs, the overall impact is rated as Important. Affected systems should be patched using the kernel update provided through the Red Hat errata channel.