Important: kernel security, bug fix, and enhancement update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474) * kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669) * kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787) * kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772) * kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260) * kernel: ALSA: usb-audio: Add sanity check for OOB writes at silencing (CVE-2026-43279) * kernel: scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414) * kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331) * kernel: gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984) * kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056) * kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result (CVE-2026-46152) * kernel: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (CVE-2026-46117) * kernel: RDMA/mana: Validate rx_hash_key_len (CVE-2026-46145) * kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125) * kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173) * kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166) * kernel: nvmet-tcp: fix race between ICReq handling and queue teardown (CVE-2026-46135) Bug Fix(es) and Enhancement(s): * AlmaLinux9.4 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [almalinux-9.8.z] (JIRA:AlmaLinux-166048) * [AlmaLinux 9.8] Hung tasks during both suspend and hibernate operations on systems with Intel E810 NICs [almalinux-9.8.z] (JIRA:AlmaLinux-175699) * DPLL: Add support for pin operational state [almalinux-9.8.z] (JIRA:AlmaLinux-175820) * DPLL: Add support for fractional frequency offset between pin and device [almalinux-9.8.z] (JIRA:AlmaLinux-175823) * ibmveth Adapter Freeze with Small MSS [almalinux-9.8.z] (JIRA:AlmaLinux-178308) * AlmaLinux9.4 - s390/mm: Add missing secure storage access fixups [almalinux-9.8.z] (JIRA:AlmaLinux-183317) * rbd: eliminate a race in lock_dwork draining on unmap [almalinux-9.8.z] (JIRA:AlmaLinux-183130) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474) * kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669) * kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787) * kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772) * kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260) * kernel: ALSA: usb-audio: Add sanity check for OOB writes at silencing (CVE-2026-43279) * kernel: scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414) * kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331) * kernel: gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984) * kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056) * kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result (CVE-2026-46152) * kernel: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (CVE-2026-46117) * kernel: RDMA/mana: Validate rx_hash_key_len (CVE-2026-46145) * kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125) * kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173) * kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166) * kernel: nvmet-tcp: fix race between ICReq handling and queue teardown (CVE-2026-46135) Bug Fix(es) and Enhancement(s): * AlmaLinux9.4 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [almalinux-9.8.z] (JIRA:AlmaLinux-166048) * [AlmaLinux 9.8] Hung tasks during both suspend and hibernate operations on systems with Intel E810 NICs [almalinux-9.8.z] (JIRA:AlmaLinux-175699) * DPLL: Add support for pin operational state [almalinux-9.8.z] (JIRA:AlmaLinux-175820) * DPLL: Add support for fractional frequency offset between pin and device [almalinux-9.8.z] (JIRA:AlmaLinux-175823) * ibmveth Adapter Freeze with Small MSS [almalinux-9.8.z] (JIRA:AlmaLinux-178308) * AlmaLinux9.4 - s390/mm: Add missing secure storage access fixups [almalinux-9.8.z] (JIRA:AlmaLinux-183317) * rbd: eliminate a race in lock_dwork draining on unmap [almalinux-9.8.z] (JIRA:AlmaLinux-183130) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:27789
- https://access.redhat.com/security/cve/CVE-2026-31474
- https://access.redhat.com/security/cve/CVE-2026-31669
- https://access.redhat.com/security/cve/CVE-2026-31772
- https://access.redhat.com/security/cve/CVE-2026-31787
- https://access.redhat.com/security/cve/CVE-2026-43260
- https://access.redhat.com/security/cve/CVE-2026-43279
- https://access.redhat.com/security/cve/CVE-2026-43414
- https://access.redhat.com/security/cve/CVE-2026-45984
- https://access.redhat.com/security/cve/CVE-2026-46056
- https://access.redhat.com/security/cve/CVE-2026-46117
- https://access.redhat.com/security/cve/CVE-2026-46125
- https://access.redhat.com/security/cve/CVE-2026-46135
- https://access.redhat.com/security/cve/CVE-2026-46145
- https://access.redhat.com/security/cve/CVE-2026-46152
- https://access.redhat.com/security/cve/CVE-2026-46166
- https://access.redhat.com/security/cve/CVE-2026-46173
- https://access.redhat.com/security/cve/CVE-2026-46331
- https://bugzilla.redhat.com/2460646
- https://bugzilla.redhat.com/2461503
- https://bugzilla.redhat.com/2464092
- https://bugzilla.redhat.com/2464502
- https://bugzilla.redhat.com/2467083
- https://bugzilla.redhat.com/2467215
- https://bugzilla.redhat.com/2468155
- https://bugzilla.redhat.com/2479492
- https://bugzilla.redhat.com/2481922
- https://bugzilla.redhat.com/2482181
- https://bugzilla.redhat.com/2482563
- https://bugzilla.redhat.com/2482576
- https://bugzilla.redhat.com/2482581
- https://bugzilla.redhat.com/2482608
- https://bugzilla.redhat.com/2482634
- https://bugzilla.redhat.com/2482645
- https://bugzilla.redhat.com/2482654
- https://errata.almalinux.org/9/ALSA-2026-27789.html