Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:53990: Important: kernel security, bug fix, and enhancement update

This Red Hat kernel security update addresses three high-severity vulnerabilities: an out-of-bounds read in the CIFS client (CVE-2026-43112, CVSS 8.8), a privilege escalation via improper CPU cache isolation on AMD Zen 2 processors (CVE-2025-54518, CVSS 7.0), and a use-after-free issue in the network traffic control action API (CVE-2026-53264, CVSS 7.8). The specific affected Linux kernel version ranges are extensive and vary per CVE; for example, CVE-2026-43112 affects versions from 5.16.1 up to but excluding 6.6.136, from 6.7 up to 6.12.83, from 6.13 up to 6.18.24, and from 6.19 up to 6.19.14. The fixed versions are also CVE-specific, such as upgrading to at least kernel 6.6.136, 6.12.83, 6.18.24, or 6.19.14 to resolve CVE-2026-43112.
Read Full Article →

Red Hat Product Errata RHSA-2026:53990 - Security Advisory Issued: 2026-08-12 Updated: 2026-08-12 RHSA-2026:53990 - Security Advisory Overview Updated Packages Synopsis Important: kernel security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for kernel is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112) kernel: xen: AMD Zen 2 Processors: Privilege escalation via improper CPU cache isolation (CVE-2025-54518) kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle (CVE-2026-53264) Bug Fix(es) and Enhancement(s): [HPE-PL 9.9 Bug] Kernel call trace observed when access Intel Granite Rapids-D UART [rhel-9.6.z] (JIRA:RHEL-185342) [RHEL 9.4] Kernel memory reclaim bug [rhel-9.6.z] (JIRA:RHEL-211056) general protection fault during exportfs / nfsd4_revoke_states [rhel-9.6.z] (JIRA:RHEL-188255) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture. Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available. Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.6 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.6 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2467015 - CVE-2026-43112 kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath BZ - 2477784 - CVE-2025-54518 kernel: xen: AMD Zen 2 Processors: Privilege escalation via improper CPU cache isolation BZ - 2492851 - CVE-2026-53264 kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle CVEs CVE-2025-54518 CVE-2026-43112 CVE-2026-53264 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM kernel-5.14.0-570.134.1.el9_6.src.rpm SHA-256: 5e547b56c9a8235870bd21bf9b101468bbc677345c0af94bdff32d7296755060 x86_64 kernel-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 45765fd2dc3400820464e21b850e457eeeb630af079072775aa153d998e8116c kernel-abi-stablelists-5.14.0-570.134.1.el9_6.noarch.rpm SHA-256: dce75ec52516130cfcb73392ecfe34692c8316940079f2dc37ebd022673f6593 kernel-core-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 85e349f34ec4b4cedbde5a863a0bf4c81b8c403b59ec5812d6bcc7fff4f8782f kernel-debug-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 9636fe0f5f6eacafabc9cdecdd21e631a4dea758832e666eb4c0446cdf8e8e54 kernel-debug-core-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 3d6d52d4236b6cadc88a456efc816c18a15d9e9b8d31eccb25d0fe29981a24ac kernel-debug-debuginfo-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: aa8780d9a653186717b6f0d82a17146fc2ecf1c7252803e05498bdad8cf8a124 kernel-debug-debuginfo-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: aa8780d9a653186717b6f0d82a17146fc2ecf1c7252803e05498bdad8cf8a124 kernel-debug-debuginfo-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: aa8780d9a653186717b6f0d82a17146fc2ecf1c7252803e05498bdad8cf8a124 kernel-debug-debuginfo-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: aa8780d9a653186717b6f0d82a17146fc2ecf1c7252803e05498bdad8cf8a124 kernel-debug-devel-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 4e429fef37f4c7688e84569fa82da1f3a5c038dfe6b9bc1a6fc3a50e32bf7f41 kernel-debug-devel-matched-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 6be06fdda7c06d29eb81b5730c8164129dc4abeed768825a16e7deb047540860 kernel-debug-modules-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: afcd0ce9496c0fa1dcaf043f9699e6c938e5cd07224a3f6cdd77ff0ec460b27f kernel-debug-modules-core-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 681978669a325c0d6324a144f3aa4c15cde986b759471d784470bf3fcf89ed57 kernel-debug-modules-extra-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: bd0a0a293ca912605b5ea4fcb2496f1da45f7574d14a2cce4a6e61a54f71a3f5 kernel-debug-uki-virt-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 835fb2de56020da19891fe9fa1c94999fd0f96db45b7b90ae597f6a92b3d4732 kernel-debuginfo-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: dbf091164312719f02d98ed987adae47db8517c1e343983726081f36a4826ccd kernel-debuginfo-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: dbf091164312719f02d98ed987adae47db8517c1e343983726081f36a4826ccd kernel-debuginfo-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: dbf091164312719f02d98ed987adae47db8517c1e343983726081f36a4826ccd kernel-debuginfo-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: dbf091164312719f02d98ed987adae47db8517c1e343983726081f36a4826ccd kernel-debuginfo-common-x86_64-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 881c0250504120b839a4e58e76f6f1879504a538afdc67038d5f9d491d05b7ee kernel-debuginfo-common-x86_64-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 881c0250504120b839a4e58e76f6f1879504a538afdc67038d5f9d491d05b7ee kernel-debuginfo-common-x86_64-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 881c0250504120b839a4e58e76f6f1879504a538afdc67038d5f9d491d05b7ee kernel-debuginfo-common-x86_64-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 881c0250504120b839a4e58e76f6f1879504a538afdc67038d5f9d491d05b7ee kernel-devel-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 0b341dd5987b815d4233cd44dfa2f57ad5863e9611f68dd2e76b8906550780e8 kernel-devel-matched-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: cdd818b32e54171f9de9b6cb7723e91f8f280effb1eea0cbff3af2d5a2e54880 kernel-doc-5.14.0-570.134.1.el9_6.noarch.rpm SHA-256: c5fc876c8d27d1f6c39835f9f281d36cdd4660718e2b0b0ef56b5843ddb88c74 kernel-headers-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: e8075af54454544986aabe4acd86452892eceeede0df84a35ee9a717e2954987 kernel-modules-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 094faefc45f46f104607e42802400596cd9589af55e9e29b79e78787df06bf1a kernel-modules-core-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 8037683444e991b3acdb1e9e235fbae9238aa0265a15333f8023560f20309687 kernel-modules-extra-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 1d845165d68bfd2bfdef5ef3bbdbd193fb2e115f7149cd813265a4aefff37884 kernel-rt-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: e329884dcb73fd3032b85d04f3bbce7e1ec829d089942d70256471794b11b733 kernel-rt-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: e329884dcb73fd3032b85d04f3bbce7e1ec829d089942d70256471794b11b733 kernel-rt-core-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 3fb85f9ffbc9300a1f5d7cdfafaa8cd7520b7dba10c1af4186cfc506fa9070a2 kernel-rt-core-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 3fb85f9ffbc9300a1f5d7cdfafaa8cd7520b7dba10c1af4186cfc506fa9070a2 kernel-rt-debug-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 3c149ff42992308b69a140e807e510b54fa8e630f3857b0d49bdbe684e52d24e kernel-rt-debug-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 3c149ff42992308b69a140e807e510b54fa8e630f3857b0d49bdbe684e52d24e kernel-rt-debug-core-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 39b34e10b8c4447e4752f895e1bd96dbf237274ba2a9dfa6a32d266c6e2840be kernel-rt-debug-core-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 39b34e10b8c4447e4752f895e1bd96dbf237274ba2a9dfa6a32d266c6e2840be kernel-rt-debug-debuginfo-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 6a7c1e2a556fbfba64fc0a39c25f4181d8c99c77d2ba128bb5ce94969593ae2d kernel-rt-debug-debuginfo-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 6a7c1e2a556fbfba64fc0a39c25f4181d8c99c77d2ba128bb5ce94969593ae2d kernel-rt-debug-debuginfo-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 6a7c1e2a556fbfba64fc0a39c25f4181d8c99c77d2ba128bb5ce94969593ae2d kernel-rt-debug-debuginfo-5.14.0-570.134.1.el9_6.x86_64.rpm SHA-256: 6a7c1e2a556fbfba64fc0a39c25f4181d8c99c77d2b

Share this article