Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ipc: limit next_id allocation to the valid ID range (CVE-2026-52923) * kernel: tipc: fix double-free in tipc_buf_append() (CVE-2026-52993) * kernel: net: sched: UAF via missing handler for TC_ACT_CONSUMED in tcf_qevent_handle () * kernel: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (CVE-2026-64530) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ipc: limit next_id allocation to the valid ID range (CVE-2026-52923) * kernel: tipc: fix double-free in tipc_buf_append() (CVE-2026-52993) * kernel: net: sched: UAF via missing handler for TC_ACT_CONSUMED in tcf_qevent_handle () * kernel: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (CVE-2026-64530) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:49212
- https://access.redhat.com/security/cve/CVE-2026-52923
- https://access.redhat.com/security/cve/CVE-2026-52993
- https://access.redhat.com/security/cve/CVE-2026-64530
- https://bugzilla.redhat.com/2492094
- https://bugzilla.redhat.com/2492437
- https://bugzilla.redhat.com/2504052
- https://bugzilla.redhat.com/2507345
- https://errata.almalinux.org/9/ALSA-2026-49212.html