- What: Security, bug fix, and enhancement update for Red Hat kernel
- Impact: Addresses multiple security issues in the Linux kernel
Red Hat Product Errata RHSA-2026:52764 - Security Advisory Issued: 2026-08-10 Updated: 2026-08-10 RHSA-2026:52764 - Security Advisory Overview Updated Packages Synopsis Important: kernel security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for kernel is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): kernel: libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116) kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (CVE-2026-22990) kernel: smb: client: fix OOB reads parsing symlink error response (CVE-2026-31613) kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787) kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112) kernel: selinux: fix overlayfs mmap() and mprotect() access checks (CVE-2026-46054) kernel: ipc: limit next_id allocation to the valid ID range (CVE-2026-52923) kernel: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (CVE-2026-52976) Bug Fix(es) and Enhancement(s): xfs corruption from [xfs_trans_cancel] during inode allocation [rhel-10.0.z] (JIRA:RHEL-142606) [RFE] Requesting FOU and GUE/GRE support in RHEL 10 [rhel-10.0.z] (JIRA:RHEL-144983) "Send error in SessSetup" messages fill up the logs [rhel-10.0.z] (JIRA:RHEL-145510) Host kernel panics with "unexpected #NM exception" at restore_fpregs_from_fpstate [rhel-10.0.z] (JIRA:RHEL-148634) blktests throtl/001 failed [rhel-10.0.z] (JIRA:RHEL-180588) RHEL 10: s390: Revert support for DCACHE_WORD_ACCESS [rhel-10.0.z] (JIRA:RHEL-188179) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture. Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available. Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.0 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.0 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2429602 - CVE-2025-71116 kernel: libceph: make decode_pool() more resilient against corrupted osdmaps BZ - 2432400 - CVE-2026-22990 kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() BZ - 2461480 - CVE-2026-31613 kernel: smb: client: fix OOB reads parsing symlink error response BZ - 2464092 - CVE-2026-31787 kernel: xen/privcmd: fix double free via VMA splitting BZ - 2467015 - CVE-2026-43112 kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath BZ - 2482025 - CVE-2026-46054 kernel: selinux: fix overlayfs mmap() and mprotect() access checks BZ - 2492094 - CVE-2026-52923 kernel: ipc: limit next_id allocation to the valid ID range BZ - 2492284 - CVE-2026-52976 kernel: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() CVEs CVE-2025-71116 CVE-2026-22990 CVE-2026-31613 CVE-2026-31787 CVE-2026-43112 CVE-2026-46054 CVE-2026-52923 CVE-2026-52976 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM kernel-6.12.0-55.95.1.el10_0.src.rpm SHA-256: fd446d3521ae06ad5b083ae0ffbe225fcf1f8be81b0c4112df02ee42efe8f53b x86_64 kernel-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: ea47424cea8d0a7f154c3c5adb9c9ec9b58f5ac8add8f1e3a090796d0b61ebbb kernel-abi-stablelists-6.12.0-55.95.1.el10_0.noarch.rpm SHA-256: 9c41f01db2181ffaed4b9e8ef0c62e2ce90d6fb68f9417d1172934cfda0913f3 kernel-core-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: d404461426a391e2deedf46ab1bf0bdab5700a3277d22e3243665a821f58e71f kernel-debug-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: 5f812b5c1f57fbfe8c2eb6d828cee20456964975fb515763f73c94fa6d791b59 kernel-debug-core-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: 10eacd562a4f92b879e11196bb4916926dd8dcb9fafaae5605b3afd94066be7a kernel-debug-debuginfo-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: 412e0805cba1894e6e59eca4cee290323a1c60863655e7ac813afe2afb007b74 kernel-debug-debuginfo-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: 412e0805cba1894e6e59eca4cee290323a1c60863655e7ac813afe2afb007b74 kernel-debug-debuginfo-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: 412e0805cba1894e6e59eca4cee290323a1c60863655e7ac813afe2afb007b74 kernel-debug-debuginfo-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: 412e0805cba1894e6e59eca4cee290323a1c60863655e7ac813afe2afb007b74 kernel-debug-devel-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: f874573cc03fa624e812a68bb185e48abb504259e4d0e4867a478a47683fc34c kernel-debug-devel-matched-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: 5f7d4ee5c7237344ba91f6d4c78e1bec419cc325c2a92bf9aadac107de45f15c kernel-debug-modules-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: f9313cc08bcdf1f330b732b0e09b28ff6cd250098faf275432e1bd8579a7b099 kernel-debug-modules-core-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: 7e5f137879765fa258e4d679a740231a9cec84d52935f3a0a40fb708bfbebac7 kernel-debug-modules-extra-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: 5e06939bceba6201f3c8e6c9134861af47efa72f671cf5096a1797680dc89520 kernel-debug-uki-virt-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: 1460f6015f608c2979d6c4c8b03c4c28b01554c1dff0659691ee0494374907aa kernel-debuginfo-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: f45aea486609ef7f64bc147a6bbac72c17cca67b546ff54811cf2584ce4467a1 kernel-debuginfo-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: f45aea486609ef7f64bc147a6bbac72c17cca67b546ff54811cf2584ce4467a1 kernel-debuginfo-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: f45aea486609ef7f64bc147a6bbac72c17cca67b546ff54811cf2584ce4467a1 kernel-debuginfo-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: f45aea486609ef7f64bc147a6bbac72c17cca67b546ff54811cf2584ce4467a1 kernel-debuginfo-common-x86_64-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: b8a22180e5996dec07b6fb6475325ff3dbb1c4b3f865e70370ff27ee3835f94a kernel-debuginfo-common-x86_64-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: b8a22180e5996dec07b6fb6475325ff3dbb1c4b3f865e70370ff27ee3835f94a kernel-debuginfo-common-x86_64-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: b8a22180e5996dec07b6fb6475325ff3dbb1c4b3f865e70370ff27ee3835f94a kernel-debuginfo-common-x86_64-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: b8a22180e5996dec07b6fb6475325ff3dbb1c4b3f865e70370ff27ee3835f94a kernel-devel-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: c74eec297b4c4c9cb1f416f12bb5d67ddc7c1ce6c5cd8f4599da5b428654441a kernel-devel-matched-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: 794632a74cce21dd15725ae19c4c55cf14b95060b948e21b7c829b1c970632cf kernel-doc-6.12.0-55.95.1.el10_0.noarch.rpm SHA-256: 16903754e5aef354617d4ef1b33f1ed628ddf930cfca7f181aa4d09a969d1df1 kernel-headers-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: e79780bdf9737e3a6e22925281287212a3f4da43c97b2ff10d018d54c2917c2a kernel-modules-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: 4f34a4262a51f048b87ceddf5766b73e83bd5078e7318c08afb025184e498d45 kernel-modules-core-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: e48fec20c4e3304fa564fd548321d2d09c7c2a19653819cfc0d970677b193a73 kernel-modules-extra-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: 34c4b779e139b081ea1c05ac5b755c563c06298f2f2f6ae6231f6c0f3fda7ea4 kernel-rt-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: aa1092faffa0150b0f84a64de98fd77e84e086852a63d53714cf5cba07124b20 kernel-rt-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: aa1092faffa0150b0f84a64de98fd77e84e086852a63d53714cf5cba07124b20 kernel-rt-core-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: da29b0d28cec3a182d0e3c4e959931f3e302d5e742ea400ad868ad7ee201b9c2 kernel-rt-core-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: da29b0d28cec3a182d0e3c4e959931f3e302d5e742ea400ad868ad7ee201b9c2 kernel-rt-debug-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: 03422b9e239a18af97c91c34b3cd3e762c3e1ed45d622390f3d972fd7509881a kernel-rt-debug-6.12.0-55.95.1.el10_0.x86_64.rpm SHA-256: 03422b9e239a18af97c91c34b3cd3e762c3e1ed45d622390f3d972fd7509881a kernel-rt-debug-