Red Hat Product Errata RHSA-2026:36018 - Security Advisory Issued: 2026-07-06 Updated: 2026-07-06 RHSA-2026:36018 - Security Advisory Overview Updated Packages Synopsis Important: kernel security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for kernel is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112) kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276) kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323) kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116) kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227) kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209) kernel: smb/client: fix out-of-bounds read in smb2_compound_op() (CVE-2026-46155) kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244) kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259) kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263) kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316) Bug Fix(es) and Enhancement(s): WARNING at drivers/gpu/drm/nouveau/nvkm/subdev/gsp/r535.c:1585 r535_gsp_fini+0x2fb/0x310 [nouveau] [rhel-9.8.z] (JIRA:RHEL-160966) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2467015 - CVE-2026-43112 kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath BZ - 2467113 - CVE-2026-43276 kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path BZ - 2479832 - CVE-2026-46323 kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs BZ - 2482523 - CVE-2026-46116 kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete BZ - 2482564 - CVE-2026-46227 kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL BZ - 2482636 - CVE-2026-46209 kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() BZ - 2482660 - CVE-2026-46155 kernel: smb/client: fix out-of-bounds read in smb2_compound_op() BZ - 2484451 - CVE-2026-46244 kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync BZ - 2484477 - CVE-2026-46259 kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() BZ - 2486958 - CVE-2025-10263 kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources BZ - 2486982 - CVE-2026-46316 kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry CVEs CVE-2025-10263 CVE-2026-43112 CVE-2026-43276 CVE-2026-46116 CVE-2026-46155 CVE-2026-46209 CVE-2026-46227 CVE-2026-46244 CVE-2026-46259 CVE-2026-46316 CVE-2026-46323 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM kernel-5.14.0-687.22.1.el9_8.src.rpm SHA-256: a3de82dca27cfe05703d9bc0ae68d1c8083d14b64dc74b9ccd4dc7b66f03bd82 x86_64 kernel-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: b49e67b8bd810c812dae433406e153d0e0f35b52b0d1b9fc454dce132f71a0c7 kernel-abi-stablelists-5.14.0-687.22.1.el9_8.noarch.rpm SHA-256: a3a0c3df444e0d378d986844f43dec60be810ccdfb44bddfecf4ee0e3c162b05 kernel-core-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: 03bce924cc53b5fa2142812903d479636c5ba90135301f859f2fe0bd869ee361 kernel-debug-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: 49b2b39c2f36f51d469a5a9e51dbf36068ff7b47538e39d980a66d767b704045 kernel-debug-core-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: 1b19b93e9e254ed412605afb551975006cbfe9d21867f6a984f9a4742a458413 kernel-debug-debuginfo-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: 43b9b798a6ee0604a61e6fc361012a473e42a3d58115318a08a7fbc95718dd12 kernel-debug-debuginfo-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: 43b9b798a6ee0604a61e6fc361012a473e42a3d58115318a08a7fbc95718dd12 kernel-debug-debuginfo-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: 43b9b798a6ee0604a61e6fc361012a473e42a3d58115318a08a7fbc95718dd12 kernel-debug-debuginfo-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: 43b9b798a6ee0604a61e6fc361012a473e42a3d58115318a08a7fbc95718dd12 kernel-debug-devel-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: a0ce7412356428369d560058b2950d6aa1a342ea199a256a995701c16b499eb9 kernel-debug-devel-matched-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: dc48fa54684ac038463f71764b8ee7073c9b23e1329d19c2232531f414582182 kernel-debug-modules-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: 94c27f40d950fe0b70a0fe8c322ee23c0a833a89d051d912ba69a83d49bd3ad4 kernel-debug-modules-core-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: 7c6e7cc24e2fd0b8ef69b4bc6c35a6d89af5df48d5e6276fd3cdaa6ecbfb87bf kernel-debug-modules-extra-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: 7a87be8fc0053fe61e1cbbdadfd94e55426675a884f9463cbb3aadc182bae3fb kernel-debug-uki-virt-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: 28ecffba2cce46a01b3e8d916f2731a4a5addc93cefa5667f4a8ef05ca6a4e9a kernel-debuginfo-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: c258e0a2079621750d5544674ed61d47b36d40552d6c92fff8ec870c721862b8 kernel-debuginfo-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: c258e0a2079621750d5544674ed61d47b36d40552d6c92fff8ec870c721862b8 kernel-debuginfo-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: c258e0a2079621750d5544674ed61d47b36d40552d6c92fff8ec870c721862b8 kernel-debuginfo-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: c258e0a2079621750d5544674ed61d47b36d40552d6c92fff8ec870c721862b8 kernel-debuginfo-common-x86_64-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: fd875e138acdb4f23c7723c7abd40786b2f67d2851602b7091ecb08bbef19112 kernel-debuginfo-common-x86_64-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: fd875e138acdb4f23c7723c7abd40786b2f67d2851602b7091ecb08bbef19112 kernel-debuginfo-common-x86_64-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: fd875e138acdb4f23c7723c7abd40786b2f67d2851602b7091ecb08bbef19112 kernel-debuginfo-common-x86_64-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: fd875e138acdb4f23c7723c7abd40786b2f67d2851602b7091ecb08bbef19112 kernel-devel-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: 6a67d688aa97074107100dac115536be73a1457c9dd13b967af27f9326305866 kernel-devel-matched-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: af50efd3a8203a69fd810b3b46c5addcf0a8f7b6e953b610825f2e2e624dd77f kernel-doc-5.14.0-687.22.1.el9_8.noarch.rpm SHA-256: 782f2f7cac0fc86eaa8c73774808672b49772efa241ffc4d296e1cb12a9a9708 kernel-headers-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: 869e0079dae6f5e877a5f74ecaeca359bf21e7cc07e03ccd2806145c19e3cd98 kernel-modules-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: 706f6ba60f345c2f7161b3beb0ed0634156f3fbea44a17869f3bd98f9497102a kernel-modules-core-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: c06fe70aba8c07f5e190387d9d29df567341b88c0304c4b4b5f0e6586bcc7e48 kernel-modules-extra-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: 33efd1d1c914cdfd3195b157eb136a5dc13aaa8b6f8df648144fe7a09dc59e48 kernel-rt-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: 11d417c48f075c7cd10aaa2f3bf5a4124d3f60d1434c8fcf6789c0f0d5523cdf kernel-rt-5.14.0-687.22.1.el9_8.x86_64.rpm SHA-256: 11d417c48f075c7cd10aa
This Red Hat security advisory addresses multiple Important-severity vulnerabilities in the Linux kernel for RHEL 9, including an out-of-bounds read in the SMB client (CVE-2026-43112, CVSS 8.8 High) and a use-after-free in the network GRO subsystem (CVE-2026-46323, CVSS 7.8 High). The advisory provides updated kernel packages to remediate these issues; affected systems must be rebooted after applying the update. Specific fixed kernel version ranges for the upstream Linux kernel are detailed in the NVD data, but the advisory itself specifies only the affected Red Hat Enterprise Linux 9 product versions and directs users to apply the provided Red Hat patches.