SB20260928424 - Red Hat Enterprise Linux 9 update for kernel
Published: September 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 9 vulnerabilities.
1) Race condition (CVE-ID: CVE-2026-45942)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in ext4 buddy bitmap handling when processing mixed huge-page workloads and concurrent page migration. A local user can trigger filesystem activity that hits the race window to cause a denial of service.
The issue can lead to ext4 e4b bitmap inconsistency reports and false-positive corruption reports during stress conditions.
2) Incorrect calculation (CVE-ID: CVE-2026-46325)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper memory address conversion in the RDMA RXE memory region handling code when processing memory regions with page sizes different from the system PAGE_SIZE. A local user can register or access a crafted memory region layout to cause a denial of service.
The issue can lead to incorrect iova-to-va translation and a kernel panic.
3) Integer overflow (CVE-ID: CVE-2026-52972)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an integer overflow in the af_alg control message handler when processing a crafted associated data length value for AEAD operations. A local user can send a specially crafted message to cause a denial of service.
4) Use-after-free (CVE-ID: CVE-2026-53341)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in may_decode_fh() when handling open_by_handle_at requests during concurrent mount namespace teardown. A local user can trigger a race condition to cause a denial of service.
The issue is reachable only on systems with CONFIG_PREEMPTION or CONFIG_RCU_STRICT_GRACE_PERIOD enabled.
5) Operation on a Resource after Expiration or Release (CVE-ID: CVE-2026-63875)
CWE-ID: CWE-672 - Operation on a Resource after Expiration or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper cache invalidation in arm64 TLB flushing logic when unsharing PMD tables. A local user can trigger PMD table unsharing to cause a denial of service.
The issue can leave a stale PMD page table entry in the walk cache, which may result in incorrect page table walks.
6) Integer underflow (CVE-ID: CVE-2026-64102)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service and disclose kernel memory contents.
The vulnerability exists due to an integer underflow in the Soft-iWARP receive path (siw_get_hdr/siw_tcp_rx_data) when processing a malformed iWARP FPDU with an MPA length smaller than the fixed header length for the opcode. A remote user can send a specially crafted FPDU to cause a denial of service and disclose kernel memory contents.
The issue is triggered by a malicious connected siw peer, and the negative signed length is later promoted to size_t during skb_copy_bits processing.
7) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-64556)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to corrupt kernel memory.
The vulnerability exists due to improper state management in perf_event_remove_on_exec() and event group handling in the perf subsystem when removing events marked remove_on_exec. A local user can trigger event removal for a group leader with surviving siblings to corrupt kernel memory.
The issue occurs when a removed event is a group leader and sibling events without remove_on_exec remain active in a stale group state.
8) Out-of-bounds write (CVE-ID: CVE-2026-80522)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code or cause a denial of service.
The vulnerability exists due to an out-of-bounds write in tegra_gcm_do_one_req() when processing a decrypt operation without a prior call to tegra_gcm_setauthsize(). A local user can trigger a decrypt operation with an incorrect cryptlen calculation to execute arbitrary code or cause a denial of service.
The issue occurs when ctx->authsize remains zero, causing req->cryptlen to be adjusted using the wrong authentication size value.
9) Use-after-free (CVE-ID: CVE-2026-74753)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a use-after-free in perf_event_open() group handling in kernel/events/core.c when attaching a new event to a group leader in the EXIT state. A local user can open a perf event as a sibling of a detached leader to execute arbitrary code.
The issue occurs because a sibling event can retain a group_leader pointer to a freed event after remove-on-exec detaches the original leader.
Remediation
Install update from vendor's website.