SB20260928425 - Red Hat Enterprise Linux 10 update for kernel
Published: September 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 10 vulnerabilities.
1) Improper access control (CVE-ID: CVE-2026-46076)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass hypercall interception controls.
The vulnerability exists due to improper access control in KVM nested SVM handling when processing VMMCALL from an L2 guest. A remote user can invoke an unhandled VMMCALL to bypass hypercall interception controls.
Exploitation requires an active nested virtualization scenario where L2 is running, L1 does not intercept VMMCALL, nested_svm_l2_tlb_flush_enabled() is true, and the hypercall is not one of the supported Hyper-V hypercalls.
2) Race condition (CVE-ID: CVE-2026-45942)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in ext4 buddy bitmap handling when processing mixed huge-page workloads and concurrent page migration. A local user can trigger filesystem activity that hits the race window to cause a denial of service.
The issue can lead to ext4 e4b bitmap inconsistency reports and false-positive corruption reports during stress conditions.
3) Use-after-free (CVE-ID: CVE-2026-46317)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the nested_mmus array in arm64 KVM nested virtualization when reallocating nested MMU structures while the array is being walked under mmu_lock. A local user can trigger nested vcpu initialization and concurrent MMU notifier activity to cause a denial of service.
The issue arises from a race condition between nested vcpu initialization and the MMU notifier path.
4) Use-after-free (CVE-ID: CVE-2026-53341)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in may_decode_fh() when handling open_by_handle_at requests during concurrent mount namespace teardown. A local user can trigger a race condition to cause a denial of service.
The issue is reachable only on systems with CONFIG_PREEMPTION or CONFIG_RCU_STRICT_GRACE_PERIOD enabled.
5) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-64556)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to corrupt kernel memory.
The vulnerability exists due to improper state management in perf_event_remove_on_exec() and event group handling in the perf subsystem when removing events marked remove_on_exec. A local user can trigger event removal for a group leader with surviving siblings to corrupt kernel memory.
The issue occurs when a removed event is a group leader and sibling events without remove_on_exec remain active in a stale group state.
6) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-68299)
CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of encapsulated packet headers in vmxnet3_get_hdr_len() when processing Geneve-encapsulated packets. A remote attacker can send a specially crafted packet to cause a denial of service.
The issue is triggered when descriptor fields describe the inner header instead of the outer header, including cases where the outer protocol is UDP or the outer and inner IP versions differ.
7) Out-of-bounds write (CVE-ID: CVE-2026-80522)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code or cause a denial of service.
The vulnerability exists due to an out-of-bounds write in tegra_gcm_do_one_req() when processing a decrypt operation without a prior call to tegra_gcm_setauthsize(). A local user can trigger a decrypt operation with an incorrect cryptlen calculation to execute arbitrary code or cause a denial of service.
The issue occurs when ctx->authsize remains zero, causing req->cryptlen to be adjusted using the wrong authentication size value.
8) Use-after-free (CVE-ID: CVE-2026-74753)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a use-after-free in perf_event_open() group handling in kernel/events/core.c when attaching a new event to a group leader in the EXIT state. A local user can open a perf event as a sibling of a detached leader to execute arbitrary code.
The issue occurs because a sibling event can retain a group_leader pointer to a freed event after remove-on-exec detaches the original leader.
9) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-89480)
CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper validation of the received data length in the NVMe/TCP host driver when processing a short C2HData PDU from an NVMe/TCP controller. A remote attacker can respond to a read request with fewer bytes than requested to disclose sensitive information.
10) Incorrect Conversion between Numeric Types (CVE-ID: CVE-2026-89775)
CWE-ID: CWE-681 - Incorrect Conversion between Numeric Types
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to incorrect conversion of a negative mapping level to an unsigned value in the arm64 KVM nested virtualization TLB size evaluation logic when evaluating VNCR TLB invalidation with the S1 MMU disabled. A remote attacker can trigger TLB invalidation evaluation using an S1 MMU-disabled mapping level to compromise confidentiality, integrity, and availability.
Remediation
Install update from vendor's website.