# CERT-FR Flags Red Hat Linux Kernel Flaws

Published: 2026-10-02 · Severity: high · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/49f52a83-6896-5a1a-9ac3-ba308667d335/cert-fr-flags-red-hat-linux-kernel-flaws

> CERT-FR advisory lists dozens of Linux kernel vulnerabilities affecting Red Hat Enterprise Linux across multiple architectures and release streams.

CERT-FR has published an advisory consolidating multiple Red Hat security bulletins (RHSA) addressing vulnerabilities in the Linux kernel as shipped across Red Hat Enterprise Linux (RHEL) 6 through 10 and associated CodeReady Linux Builder packages, spanning x86_64, aarch64, ppc64le, and s390x architectures. The advisory references twelve separate RHSA bulletins issued between late September and early October 2026, covering a very large number of CVEs affecting the kernel across versions 6, 8, 9, and 10, including Extended Update Support, Extended Life Cycle, and SAP Solutions update streams.

The vulnerabilities collectively allow an attacker to achieve arbitrary code execution, privilege escalation, remote denial of service, data integrity and confidentiality compromise, and security policy bypass, depending on the specific flaw and kernel subsystem affected. No single CVE is highlighted as the primary driver; the bulletin aggregates a broad set of kernel fixes rather than describing a specific exploited flaw. CERT-FR provides no detail on exploitation status, exploit availability, or attack vectors beyond the generic risk categories, and defenders should consult the linked Red Hat RHSA bulletins for per-CVE technical details, affected package versions, and patch availability.

For defenders, the priority is identifying which RHEL major/minor versions and architectures are deployed in their environment and applying the corresponding RHSA kernel updates. Given the breadth of affected products (RHEL 6 through 10, multiple support tiers, and server variants including SAP and Real Time editions), organizations running Red Hat Enterprise Linux should treat this as a routine but broad patch management exercise and schedule kernel updates per their standard maintenance windows, prioritizing systems exposed to untrusted local users or network-facing services where remote DoS or privilege escalation vectors apply.

## Mentioned in this report

- Vulnerabilities: CVE-2022-49670, CVE-2024-57990, CVE-2025-39964 (KEV), CVE-2025-40323, CVE-2026-31581, CVE-2026-31663, CVE-2026-43074, CVE-2026-43493, CVE-2026-43499, CVE-2026-45856, CVE-2026-45919, CVE-2026-45942, CVE-2026-46076, CVE-2026-46199, CVE-2026-46204, CVE-2026-46230, CVE-2026-46242, CVE-2026-46317, CVE-2026-46325, CVE-2026-52924, CVE-2026-52972, CVE-2026-52993, CVE-2026-53002, CVE-2026-53059, CVE-2026-53071, CVE-2026-53091, CVE-2026-53166, CVE-2026-53185, CVE-2026-53239, CVE-2026-53266 (KEV), CVE-2026-53341, CVE-2026-63794, CVE-2026-63823, CVE-2026-63875, CVE-2026-63917, CVE-2026-63919, CVE-2026-63921, CVE-2026-64034, CVE-2026-64102, CVE-2026-64191

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1254

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/49f52a83-6896-5a1a-9ac3-ba308667d335/cert-fr-flags-red-hat-linux-kernel-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
