Important: kernel security, bug fix, and enhancement update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: crypto: af_alg - zero initialize memory allocated via sock_kmalloc (CVE-2025-71113) * kernel: scsi: core: Wake up the error handler when final completions race against each other (CVE-2026-23110) * kernel: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (CVE-2026-46099) * kernel: fanotify: fix false positive on permission events (CVE-2026-46150) * kernel: drm: Set old handle to NULL before prime swap in change_handle (CVE-2026-46215) * kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071) Bug Fix(es) and Enhancement(s): * [AlmaLinux9] tools/lib/perf/Makefile: libperf includes appended after CFLAGS causes parallel build race, breaking kernel builds [almalinux-9.8.z] (JIRA:AlmaLinux-183980) * [AlmaLinux-9.8.z]: mlx5: include bug fixes (JIRA:AlmaLinux-188121) * dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() [almalinux-9.8.z] (JIRA:AlmaLinux-212061) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: crypto: af_alg - zero initialize memory allocated via sock_kmalloc (CVE-2025-71113) * kernel: scsi: core: Wake up the error handler when final completions race against each other (CVE-2026-23110) * kernel: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (CVE-2026-46099) * kernel: fanotify: fix false positive on permission events (CVE-2026-46150) * kernel: drm: Set old handle to NULL before prime swap in change_handle (CVE-2026-46215) * kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071) Bug Fix(es) and Enhancement(s): * [AlmaLinux9] tools/lib/perf/Makefile: libperf includes appended after CFLAGS causes parallel build race, breaking kernel builds [almalinux-9.8.z] (JIRA:AlmaLinux-183980) * [AlmaLinux-9.8.z]: mlx5: include bug fixes (JIRA:AlmaLinux-188121) * dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() [almalinux-9.8.z] (JIRA:AlmaLinux-212061) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:43307
- https://access.redhat.com/security/cve/CVE-2025-71113
- https://access.redhat.com/security/cve/CVE-2026-23110
- https://access.redhat.com/security/cve/CVE-2026-46150
- https://access.redhat.com/security/cve/CVE-2026-46215
- https://access.redhat.com/security/cve/CVE-2026-53071
- https://bugzilla.redhat.com/2429611
- https://bugzilla.redhat.com/2436755
- https://bugzilla.redhat.com/2481972
- https://bugzilla.redhat.com/2482612
- https://bugzilla.redhat.com/2482615
- https://bugzilla.redhat.com/2492458
- https://errata.almalinux.org/9/ALSA-2026-43307.html