VORANT. Threat Intelligence Research Sign in Create a free account

CERT-FR Flags Red Hat Linux Kernel Flaws

high vulnerability technologyinfrastructure

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT-FR advisory lists dozens of Linux kernel vulnerabilities affecting Red Hat Enterprise Linux across multiple architectures and release streams.

CERT-FR has published an advisory consolidating multiple Red Hat security bulletins (RHSA) addressing vulnerabilities in the Linux kernel as shipped across Red Hat Enterprise Linux (RHEL) 6 through 10 and associated CodeReady Linux Builder packages, spanning x86_64, aarch64, ppc64le, and s390x architectures. The advisory references twelve separate RHSA bulletins issued between late September and early October 2026, covering a very large number of CVEs affecting the kernel across versions 6, 8, 9, and 10, including Extended Update Support, Extended Life Cycle, and SAP Solutions update streams.

The vulnerabilities collectively allow an attacker to achieve arbitrary code execution, privilege escalation, remote denial of service, data integrity and confidentiality compromise, and security policy bypass, depending on the specific flaw and kernel subsystem affected. No single CVE is highlighted as the primary driver; the bulletin aggregates a broad set of kernel fixes rather than describing a specific exploited flaw. CERT-FR provides no detail on exploitation status, exploit availability, or attack vectors beyond the generic risk categories, and defenders should consult the linked Red Hat RHSA bulletins for per-CVE technical details, affected package versions, and patch availability.

For defenders, the priority is identifying which RHEL major/minor versions and architectures are deployed in their environment and applying the corresponding RHSA kernel updates. Given the breadth of affected products (RHEL 6 through 10, multiple support tiers, and server variants including SAP and Real Time editions), organizations running Red Hat Enterprise Linux should treat this as a routine but broad patch management exercise and schedule kernel updates per their standard maintenance windows, prioritizing systems exposed to untrusted local users or network-facing services where remote DoS or privilege escalation vectors apply.

Mentioned in this report

Vulnerabilities CVE-2022-49670CVE-2024-57990CVE-2025-39964KEVCVE-2025-40323CVE-2026-31581CVE-2026-31663CVE-2026-43074CVE-2026-43493CVE-2026-43499CVE-2026-45856CVE-2026-45919CVE-2026-45942CVE-2026-46076CVE-2026-46199CVE-2026-46204CVE-2026-46230CVE-2026-46242CVE-2026-46317CVE-2026-46325CVE-2026-52924CVE-2026-52972CVE-2026-52993CVE-2026-53002CVE-2026-53059CVE-2026-53071CVE-2026-53091CVE-2026-53166CVE-2026-53185CVE-2026-53239CVE-2026-53266KEVCVE-2026-53341CVE-2026-63794CVE-2026-63823CVE-2026-63875CVE-2026-63917CVE-2026-63919CVE-2026-63921CVE-2026-64034CVE-2026-64102CVE-2026-64191

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1254

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,646 reports from 152 sources, 506 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs