SB2026100841 - Red Hat Enterprise Linux 10 update for kernel
Published: October 8, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 16 vulnerabilities.
1) Improper locking (CVE-ID: CVE-2026-23103)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the ipvlan_port_create(), ipvlan_uninit(), ipvlan_open(), ipvlan_stop(), ipvlan_link_new(), ipvlan_link_delete(), ipvlan_add_addr(), ipvlan_del_addr(), ipvlan_add_addr6(), ipvlan_addr6_validator_event() and ipvlan_addr4_validator_event() functions in drivers/net/ipvlan/ipvlan_main.c. A local user can perform a denial of service (DoS) attack.
2) Out-of-bounds write (CVE-ID: CVE-2026-53360)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to corrupt host kernel heap memory and disclose host heap layout information.
The vulnerability exists due to an out-of-bounds read and out-of-bounds write in KVM SEV handling in arch/x86/kvm/svm/sev.c when processing guest-controlled Page State Change requests with a scratch buffer allocated outside the GHCB shared buffer under GHCB v2+. A local user can supply crafted PSC metadata that causes the host to iterate past the allocated scratch buffer to corrupt host kernel heap memory and disclose host heap layout information.
Exploitation requires a malicious SEV-SNP guest, and the issue may also trigger use-after-free conditions across repeated VMGEXITs.
3) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-53365)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in virtio vsock zerocopy completion handling in net/vmw_vsock/virtio_transport_common.c when processing multi-skb MSG_ZEROCOPY sends. A local user can send a large crafted message that is fragmented into multiple skbs to cause a denial of service.
The issue can leave pinned user pages without completion notification, including when the send loop exits before the final skb is processed.
4) Improper Initialization (CVE-ID: CVE-2026-53398)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper initialization in nfsd4_decode_secinfo_no_name() when processing a truncated XDR stream for the SECINFO_NO_NAME operation. A remote attacker can send a specially crafted request to cause a denial of service.
The issue occurs because stale union contents from a previous operation can leave sin_exp non-NULL, leading the error cleanup path to call exp_put() on an invalid value.
5) Improper resource shutdown or release (CVE-ID: CVE-2026-63970)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in virtio_transport_alloc_skb() in the vsock/virtio transport when processing fixed-buffer vectored zerocopy input that hits MAX_SKB_FRAGS. A local user can trigger a partial attachment of managed fragments to cause a denial of service.
Exploitation occurs on the rollback path after io_sg_from_iter() returns -EMSGSIZE, causing an skb with managed fragment references but no bound uarg to be freed through the ordinary fragment unref path.
6) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-64035)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in igc_fpe_init_smd_frame() when initializing SMD transmit frames. A local user can trigger transmission of an SMD skb to cause a denial of service.
The issue arises because a reused igc_tx_buffer entry may retain a stale XDP or XSK type, causing TX completion to use the wrong cleanup path.
7) Use-after-free (CVE-ID: CVE-2026-64115)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in vmci_transport_recv_connecting_server() and vmci_transport_recv_listen() when processing a peer reset during the connection handshake. A remote attacker can send a reset packet during the handshake to cause a denial of service.
The issue is triggered by a race involving pending socket cleanup in the VMCI vsock transport.
8) Use-after-free (CVE-ID: CVE-2026-72317)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the SUNRPC TLS connect_worker when handling a failed TLS handshake on a TLS-secured transport. A local user can trigger a failed TLS handshake that causes the upper rpc_clnt to be freed before the queued worker dereferences it to cause a denial of service.
The issue affects the TLS transport path; the non-TLS connect worker does not use the saved client pointer.
9) Use-after-free (CVE-ID: CVE-2026-74705)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to use-after-free in __skb_udp_tunnel_segment() in net/ipv4/udp_offload.c when processing tunnel segmentation for skb data after pulling the tunnel header into the skb head. A local attacker can trigger skb head reallocation and subsequent use of a stale UDP header pointer to cause a denial of service.
10) Use-after-free (CVE-ID: CVE-2026-74744)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a use-after-free in the ipvlan network device component when handling packet header and tailroom requirements inherited from the underlying physical device. A remote attacker can trigger packet processing that causes insufficient headroom or tailroom reservation to execute arbitrary code.
The issue can occur when the underlying physical or stacked lower device requires extra headroom or tailroom for headers or trailers.
11) Use-after-free (CVE-ID: CVE-2026-89690)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to trigger a use-after-free.
The vulnerability exists due to use-after-free in the NFS server's NFSv4 compound operation buffer handling when an rpc_status netlink dump reads operation numbers concurrently with NFSv4 compound request completion. A local user can initiate concurrent operations to trigger a use-after-free.
12) Use-after-free (CVE-ID: CVE-2026-89669)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a use-after-free condition.
The vulnerability exists due to a use-after-free in copy-notify state initialization when racing a crafted OFFLOAD_CANCEL request against COPY_NOTIFY processing. A remote attacker can send a crafted OFFLOAD_CANCEL request to trigger a use-after-free condition.
Exploitation requires a matching client ID and a guessable state object ID.
13) Heap-based buffer overflow (CVE-ID: CVE-2026-89530)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to corrupt adjacent slab memory.
The vulnerability exists due to a heap-based buffer overflow in svc_rdma_xb_linearize() when processing oversized inline RPC-over-RDMA replies without a Write list or Reply chunk. A remote attacker can request an oversized inline reply without providing a Write list or Reply chunk to corrupt adjacent slab memory.
The posted scatter/gather entry length can cause the device to read beyond the mapped region.
14) Expired pointer dereference (CVE-ID: CVE-2026-89676)
CWE-ID: CWE-825 - Expired pointer dereference
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an expired pointer dereference in the nfsd asynchronous COPY stateid IDR handling when processing asynchronous NFS COPY requests. A remote attacker can submit an asynchronous COPY request to cause a denial of service.
Exploitation requires an IDR walker to dereference reused request memory whose contents resemble an expired NFS4_COPYNOTIFY_STID.
15) Use-after-free (CVE-ID: CVE-2026-89663)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in the NFS server copy-notify stateid revocation logic when revoking copy-notify stateids while concurrent holders retain references. A remote attacker can trigger concurrent copy-notify stateid revocation to cause a denial of service.
The issue involves parent-stateid draining, OFFLOAD_CANCEL handling, and laundromat expiry.
16) Use-after-free (CVE-ID: CVE-2026-89675)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in the nfsd asynchronous copy management code when canceling an asynchronous copy concurrently with its copy kernel thread. A remote attacker can send an NFSv4.2 OFFLOAD_CANCEL request during an asynchronous copy to cause a denial of service.
Remediation
Install update from vendor's website.