SB20260930117 - Red Hat Enterprise Linux 8 update for kernel



SB20260930117 - Red Hat Enterprise Linux 8 update for kernel

Published: September 30, 2026

Security Bulletin ID SB20260930117
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 40% Low 60%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 vulnerabilities.


1) Integer underflow (CVE-ID: CVE-2026-64102)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service and disclose kernel memory contents.

The vulnerability exists due to an integer underflow in the Soft-iWARP receive path (siw_get_hdr/siw_tcp_rx_data) when processing a malformed iWARP FPDU with an MPA length smaller than the fixed header length for the opcode. A remote user can send a specially crafted FPDU to cause a denial of service and disclose kernel memory contents.

The issue is triggered by a malicious connected siw peer, and the negative signed length is later promoted to size_t during skb_copy_bits processing.


2) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-68299)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of encapsulated packet headers in vmxnet3_get_hdr_len() when processing Geneve-encapsulated packets. A remote attacker can send a specially crafted packet to cause a denial of service.

The issue is triggered when descriptor fields describe the inner header instead of the outer header, including cases where the outer protocol is UDP or the outer and inner IP versions differ.


3) Use-after-free (CVE-ID: CVE-2026-72329)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the liquidio SR-IOV VF pci_dev lookup handling when processing an OCTEON_VF_FLR_REQUEST mailbox command. A local user can trigger a VF FLR request that causes dereference of a stale pci_dev pointer to cause a denial of service.

Exploitation requires the affected device to be operating in SR-IOV mode with allocated virtual functions.


4) Incorrect calculation (CVE-ID: CVE-2026-72099)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper calculation in dm-integrity when processing integrity metadata tags. A local user can trigger incorrect hash offset handling to cause a denial of service.


5) Use-after-free (CVE-ID: CVE-2026-63823)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in request_key_auth handling in the Linux kernel key management subsystem when processing KEYCTL_INSTANTIATE_IOV or related key instantiation and rejection paths concurrently with request_key() completion. A local user can trigger concurrent key operations to cause a denial of service.

The issue occurs because the request_key_auth payload can be freed after helper completion while another path later resumes and accesses rka->target_key.


Remediation

Install update from vendor's website.