Red Hat patches dozens of Linux kernel flaws
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
CERT-FR advisory details numerous Linux kernel vulnerabilities in Red Hat Enterprise Linux allowing RCE, privilege escalation, and DoS; patches available.
CERT-FR has published an advisory (CERTFR-2026-AVI-1230) consolidating over two dozen Red Hat security bulletins (RHSA-2026) issued between September 21-25, 2026, covering multiple vulnerabilities in the Linux kernel shipped across the full range of Red Hat Enterprise Linux (RHEL) product lines and architectures, including versions 6 through 10, Extended Update Support (EUS), Extended Life Cycle (ELS), Update Services for SAP Solutions, Real Time kernels, and CodeReady Linux Builder variants across x86_64, aarch64, s390x (IBM z Systems), and ppc64le (IBM Power) platforms.
The vulnerabilities span a broad range of impact categories: remote code execution, local privilege escalation, remote denial of service, data integrity and confidentiality breaches, and security policy bypass. No single CVE is singled out as actively exploited in the wild in this advisory, and the vendor does not specify exploitation status for several entries. The advisory references approximately 80 CVEs spanning identifiers from 2023 through 2026, reflecting the routine cumulative kernel patching cycle typical of RHEL point releases.
Defenders running RHEL or RHEL-derived distributions (including Real Time and SAP Solutions variants) across any supported architecture should prioritize applying the referenced RHSA errata according to their patch management cadence. Given the breadth of affected product lines, organizations should inventory which specific RHEL versions and kernel packages are deployed and cross-reference against the RHSA bulletins to determine applicability, then schedule kernel updates and reboots as per standard change management.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1230
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,138 reports from 155 sources, 1,776 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs