- What: Kernel security update with multiple fixes
- Impact: Red Hat Enterprise Linux 9 users need to apply the update
Red Hat Product Errata RHSA-2026:66180 - Security Advisory Issued: 2026-09-09 Updated: 2026-09-09 RHSA-2026:66180 - Security Advisory Overview Updated Packages Synopsis Important: kernel security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for kernel is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133) kernel: ipv6: prevent possible UaF in addrconf_permanent_addr() (CVE-2026-43339) kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (CVE-2026-43493) kernel: tcp: call sk_data_ready() after listener migration (CVE-2026-46015) kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149) kernel: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (CVE-2026-46266) kernel: flow_dissector: do not dissect PPPoE PFC frames (CVE-2026-46306) kernel: Revert "net/smc: Introduce TCP ULP support" (CVE-2026-46330) kernel: netfilter: conntrack: remove sprintf usage (CVE-2026-53002) kernel: net: guard timestamp cmsgs to real error queue skbs (CVE-2026-53223) kernel: ipv6: mcast: Fix use-after-free when processing MLD queries (CVE-2026-53275) kernel: ipv4: account for fraggap on the paged allocation path (CVE-2026-53366) kernel: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (CVE-2026-64034) kernel: rhashtable: clear stale iter->p on table restart (CVE-2026-64563) kernel: smb: client: fix double-free in SMB2_close() replay (CVE-2026-64597) kernel: nvmet-rdma: handle inline data with a nonzero offset (CVE-2026-72129) kernel: net: bridge: stop fast-leave after deleting a port group (CVE-2026-74480) Bug Fix(es) and Enhancement(s): KSM to deduplicate only zero pages [rhel-9.8.z] (JIRA:RHEL-249161) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture. Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available. Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2467065 - CVE-2026-43133 kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation BZ - 2468102 - CVE-2026-43339 kernel: ipv6: prevent possible UaF in addrconf_permanent_addr() BZ - 2479812 - CVE-2026-43493 kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests BZ - 2481936 - CVE-2026-46015 kernel: tcp: call sk_data_ready() after listener migration BZ - 2482566 - CVE-2026-46149 kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() BZ - 2484456 - CVE-2026-46266 kernel: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP BZ - 2486463 - CVE-2026-46306 kernel: flow_dissector: do not dissect PPPoE PFC frames BZ - 2486999 - CVE-2026-46330 kernel: Revert "net/smc: Introduce TCP ULP support" BZ - 2492329 - CVE-2026-53002 kernel: netfilter: conntrack: remove sprintf usage BZ - 2492811 - CVE-2026-53223 kernel: net: guard timestamp cmsgs to real error queue skbs BZ - 2492841 - CVE-2026-53275 kernel: ipv6: mcast: Fix use-after-free when processing MLD queries BZ - 2501252 - CVE-2026-53366 kernel: ipv4: account for fraggap on the paged allocation path BZ - 2502394 - CVE-2026-64034 kernel: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer BZ - 2510892 - CVE-2026-64563 kernel: rhashtable: clear stale iter->p on table restart BZ - 2511932 - CVE-2026-64597 kernel: smb: client: fix double-free in SMB2_close() replay BZ - 2516731 - CVE-2026-72129 kernel: nvmet-rdma: handle inline data with a nonzero offset BZ - 2517046 - CVE-2026-74480 kernel: net: bridge: stop fast-leave after deleting a port group CVEs CVE-2026-43133 CVE-2026-43339 CVE-2026-43493 CVE-2026-46015 CVE-2026-46149 CVE-2026-46266 CVE-2026-46306 CVE-2026-46330 CVE-2026-53002 CVE-2026-53223 CVE-2026-53275 CVE-2026-53366 CVE-2026-64034 CVE-2026-64563 CVE-2026-64597 CVE-2026-72129 CVE-2026-74480 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM kernel-5.14.0-687.46.1.el9_8.src.rpm SHA-256: 378c1016ec891505f10477bf4f32f695033e3d4a94e7366d457bc0b076c826fd x86_64 kernel-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: 8aa7cc896889e3af5a9a6cb498a06072b3718ca21e3b451cfe4128c7d31bcb6b kernel-abi-stablelists-5.14.0-687.46.1.el9_8.noarch.rpm SHA-256: 9af026f4e811d46a5903433db6aeab6c9b903d9ceacf7f047be2b8cd2ef5bfcb kernel-core-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: f4ff861015fceea52ba59fb1831f574cc9ba20928852b00c2be4dc0d5347b750 kernel-debug-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: a40fd5a573d3c296c3be65f1cc687d9e13f692d00d5f652337ab6c5fdda837fa kernel-debug-core-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: 39808bb32aff5b6a1f1d38965264ee0c8929a498e40d9a05ca83802bf5524692 kernel-debug-debuginfo-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: a37ccfce1c7370d7de25ba6c1151248b02ddb58a70b083744255681dd840d0b3 kernel-debug-debuginfo-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: a37ccfce1c7370d7de25ba6c1151248b02ddb58a70b083744255681dd840d0b3 kernel-debug-debuginfo-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: a37ccfce1c7370d7de25ba6c1151248b02ddb58a70b083744255681dd840d0b3 kernel-debug-debuginfo-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: a37ccfce1c7370d7de25ba6c1151248b02ddb58a70b083744255681dd840d0b3 kernel-debug-devel-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: 80d96845a3c6ca3bccdd2ce06af7fd116158cec71ec5cda040c870f4fe978333 kernel-debug-devel-matched-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: 1ee70bdeb316e8cf169a83a64719391dd621db3125daaf0bc363af1c157c263d kernel-debug-modules-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: 6d0eac7f7fa6fc695251bca3247bb1112ee7d17bc21ba68d7ca5381f31e5e23f kernel-debug-modules-core-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: 367629b8765ad315ef9affdef8a0ef88e4e0d434d46a7daffd371b15d61b37a5 kernel-debug-modules-extra-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: 395832923428bee57e08f08f8dc5f04597ae28d6f5b9a053f79d36c08ff8b572 kernel-debug-uki-virt-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: 6e7c32ca8c4467ad57f5286a5311d22b3ca7cad8913b2343afe0ec2ea0fb8fab kernel-debuginfo-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: 97aab93c8434c8615984b48961a1fbe981b19525c7e54177ac79dc74b06b56e5 kernel-debuginfo-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: 97aab93c8434c8615984b48961a1fbe981b19525c7e54177ac79dc74b06b56e5 kernel-debuginfo-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: 97aab93c8434c8615984b48961a1fbe981b19525c7e54177ac79dc74b06b56e5 kernel-debuginfo-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: 97aab93c8434c8615984b48961a1fbe981b19525c7e54177ac79dc74b06b56e5 kernel-debuginfo-common-x86_64-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: 590911bc11a5fd590da5da2f09feb46253e7b22f4e494b34124defb88f29c9ec kernel-debuginfo-common-x86_64-5.14.0-687.46.1.el9_8.x86_64.rpm SHA-256: 590911bc11a5fd590da5da2f09feb46253e7b22f4e494b34124defb88f29c9ec kernel-debuginfo-common-x86_64-5.14.