Important: kernel security, bug fix, and enhancement update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: xfrm: Duplicate SPI Handling (CVE-2025-39797) * kernel: lib/buildid: use __kernel_read() for sleepable context (CVE-2026-23002) * kernel: futex: Drop CLONE_THREAD requirement for private default hash alloc (CVE-2026-52973) * kernel: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (CVE-2026-53281) * kernel: blk-mq: pop cached request if it is usable (CVE-2026-64017) Bug Fix(es) and Enhancement(s): * general protection fault during exportfs / nfsd4_revoke_states [almalinux-9.8.z] (JIRA:AlmaLinux-188257) * Enable Pretimeout Watchdog Panic Functionality on x86 [almalinux-9.8.z] (JIRA:AlmaLinux-193729) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: xfrm: Duplicate SPI Handling (CVE-2025-39797) * kernel: lib/buildid: use __kernel_read() for sleepable context (CVE-2026-23002) * kernel: futex: Drop CLONE_THREAD requirement for private default hash alloc (CVE-2026-52973) * kernel: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (CVE-2026-53281) * kernel: blk-mq: pop cached request if it is usable (CVE-2026-64017) Bug Fix(es) and Enhancement(s): * general protection fault during exportfs / nfsd4_revoke_states [almalinux-9.8.z] (JIRA:AlmaLinux-188257) * Enable Pretimeout Watchdog Panic Functionality on x86 [almalinux-9.8.z] (JIRA:AlmaLinux-193729) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:47040
- https://access.redhat.com/security/cve/CVE-2025-39797
- https://access.redhat.com/security/cve/CVE-2026-23002
- https://access.redhat.com/security/cve/CVE-2026-52973
- https://access.redhat.com/security/cve/CVE-2026-53281
- https://access.redhat.com/security/cve/CVE-2026-64017
- https://bugzilla.redhat.com/2400057
- https://bugzilla.redhat.com/2432666
- https://bugzilla.redhat.com/2492413
- https://bugzilla.redhat.com/2493728
- https://bugzilla.redhat.com/2502449
- https://errata.almalinux.org/9/ALSA-2026-47040.html