Moderate: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: Linux kernel: Use-After-Free vulnerability in ATM subsystem (CVE-2025-38180) * kernel: drm/sched: Fix potential double free in drm_sched_job_add_resv_dependencies (CVE-2025-40096) * kernel: Linux kernel: Local denial of service and memory leak in DAMON sysfs via setup failure (CVE-2026-23144) * kernel: Linux kernel: Use-after-free in bonding module can cause system crash or arbitrary code execution (CVE-2026-23171) * kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() (CVE-2026-23193) * kernel: macvlan: fix error recovery in macvlan_common_newlink() (CVE-2026-23209) * kernel: net/sched: cls_u32: use skb_header_pointer_careful() (CVE-2026-23204) * kernel: ALSA: aloop: Fix racy access at PCM trigger (CVE-2026-23191) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: Linux kernel: Use-After-Free vulnerability in ATM subsystem (CVE-2025-38180) * kernel: drm/sched: Fix potential double free in drm_sched_job_add_resv_dependencies (CVE-2025-40096) * kernel: Linux kernel: Local denial of service and memory leak in DAMON sysfs via setup failure (CVE-2026-23144) * kernel: Linux kernel: Use-after-free in bonding module can cause system crash or arbitrary code execution (CVE-2026-23171) * kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() (CVE-2026-23193) * kernel: macvlan: fix error recovery in macvlan_common_newlink() (CVE-2026-23209) * kernel: net/sched: cls_u32: use skb_header_pointer_careful() (CVE-2026-23204) * kernel: ALSA: aloop: Fix racy access at PCM trigger (CVE-2026-23191) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:6153
- https://access.redhat.com/security/cve/CVE-2025-38180
- https://access.redhat.com/security/cve/CVE-2025-40096
- https://access.redhat.com/security/cve/CVE-2026-23144
- https://access.redhat.com/security/cve/CVE-2026-23171
- https://access.redhat.com/security/cve/CVE-2026-23191
- https://access.redhat.com/security/cve/CVE-2026-23193
- https://access.redhat.com/security/cve/CVE-2026-23204
- https://access.redhat.com/security/cve/CVE-2026-23209
- https://bugzilla.redhat.com/2376376
- https://bugzilla.redhat.com/2407333
- https://bugzilla.redhat.com/2439872
- https://bugzilla.redhat.com/2439886
- https://bugzilla.redhat.com/2439887
- https://bugzilla.redhat.com/2439900
- https://bugzilla.redhat.com/2439931
- https://bugzilla.redhat.com/2439947
- https://errata.almalinux.org/9/ALSA-2026-6153.html