SB2026092464 - Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION update for kernel



SB2026092464 - Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION update for kernel

Published: September 24, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026092464
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Use-after-free (CVE-ID: CVE-2026-68121)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to a use-after-free in pppoe_sendmsg() when handling a blocked send while a non-Ethernet port is added to an empty team device. A local user can trigger skb head reallocation and subsequent writes through a stale PPPoE header pointer to cause memory corruption.

The issue occurs because device header callbacks may reallocate the skb head and invalidate saved pointers into it.


2) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-80844)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause an out-of-bounds memory access.

The vulnerability exists due to improper validation of routing header segments_left values in ipv6_rearrange_rthdr() when processing raw IPv6 HDRINCL packets with a segments_left value larger than the number of addresses described by hdrlen. A local user can send a crafted packet with an oversized segments_left value to cause an out-of-bounds memory access.


Remediation

Install update from vendor's website.