Important: kernel security, bug fix, and enhancement update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: eventpoll: defer struct eventpoll free to RCU grace period (CVE-2026-43074) * kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276) * kernel: net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341) * kernel: smb/client: fix out-of-bounds read in smb2_compound_op() (CVE-2026-46155) * kernel: eventpoll: fix ep_remove struct eventpoll / struct file UAF (CVE-2026-46242) * kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259) Bug Fix(es) and Enhancement(s): * CNB103: net: page_pool: avoid false positive warning if NAPI was never added [almalinux-10.2.z] (JIRA:AlmaLinux-162140) * [AlmaLinux 10] Bonding reports unknown speed/duplex for tg3 interface [almalinux-10.2.z] (JIRA:AlmaLinux-182770) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: eventpoll: defer struct eventpoll free to RCU grace period (CVE-2026-43074) * kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276) * kernel: net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341) * kernel: smb/client: fix out-of-bounds read in smb2_compound_op() (CVE-2026-46155) * kernel: eventpoll: fix ep_remove struct eventpoll / struct file UAF (CVE-2026-46242) * kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259) Bug Fix(es) and Enhancement(s): * CNB103: net: page_pool: avoid false positive warning if NAPI was never added [almalinux-10.2.z] (JIRA:AlmaLinux-162140) * [AlmaLinux 10] Bonding reports unknown speed/duplex for tg3 interface [almalinux-10.2.z] (JIRA:AlmaLinux-182770) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:36541
- https://access.redhat.com/security/cve/CVE-2026-43074
- https://access.redhat.com/security/cve/CVE-2026-43276
- https://access.redhat.com/security/cve/CVE-2026-43341
- https://access.redhat.com/security/cve/CVE-2026-46155
- https://access.redhat.com/security/cve/CVE-2026-46242
- https://access.redhat.com/security/cve/CVE-2026-46259
- https://bugzilla.redhat.com/2467019
- https://bugzilla.redhat.com/2467113
- https://bugzilla.redhat.com/2468097
- https://bugzilla.redhat.com/2482660
- https://bugzilla.redhat.com/2483519
- https://bugzilla.redhat.com/2484477
- https://errata.almalinux.org/10/ALSA-2026-36541.html