# Red Hat patches dozens of Linux kernel flaws

Published: 2026-09-25 · Severity: high · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/69c1a5be-bf8e-5589-b3f8-ce7e843c6b26/red-hat-patches-dozens-of-linux-kernel-flaws

> CERT-FR advisory details numerous Linux kernel vulnerabilities in Red Hat Enterprise Linux allowing RCE, privilege escalation, and DoS; patches available.

CERT-FR has published an advisory (CERTFR-2026-AVI-1230) consolidating over two dozen Red Hat security bulletins (RHSA-2026) issued between September 21-25, 2026, covering multiple vulnerabilities in the Linux kernel shipped across the full range of Red Hat Enterprise Linux (RHEL) product lines and architectures, including versions 6 through 10, Extended Update Support (EUS), Extended Life Cycle (ELS), Update Services for SAP Solutions, Real Time kernels, and CodeReady Linux Builder variants across x86_64, aarch64, s390x (IBM z Systems), and ppc64le (IBM Power) platforms.

The vulnerabilities span a broad range of impact categories: remote code execution, local privilege escalation, remote denial of service, data integrity and confidentiality breaches, and security policy bypass. No single CVE is singled out as actively exploited in the wild in this advisory, and the vendor does not specify exploitation status for several entries. The advisory references approximately 80 CVEs spanning identifiers from 2023 through 2026, reflecting the routine cumulative kernel patching cycle typical of RHEL point releases.

Defenders running RHEL or RHEL-derived distributions (including Real Time and SAP Solutions variants) across any supported architecture should prioritize applying the referenced RHSA errata according to their patch management cadence. Given the breadth of affected product lines, organizations should inventory which specific RHEL versions and kernel packages are deployed and cross-reference against the RHSA bulletins to determine applicability, then schedule kernel updates and reboots as per standard change management.

## Mentioned in this report

- Vulnerabilities: CVE-2023-53781, CVE-2023-54120, CVE-2023-54214, CVE-2025-21826, CVE-2025-39964 (KEV), CVE-2025-40323, CVE-2025-71082, CVE-2026-23007, CVE-2026-31539, CVE-2026-31566, CVE-2026-31692, CVE-2026-43334, CVE-2026-43370, CVE-2026-45894, CVE-2026-45959, CVE-2026-46043, CVE-2026-46117, CVE-2026-46133, CVE-2026-46150, CVE-2026-46199, CVE-2026-46204, CVE-2026-46230, CVE-2026-46311, CVE-2026-52912, CVE-2026-52918, CVE-2026-52993, CVE-2026-53000, CVE-2026-53002, CVE-2026-53005, CVE-2026-53009, CVE-2026-53053, CVE-2026-53062, CVE-2026-53185, CVE-2026-53196, CVE-2026-53203, CVE-2026-53254, CVE-2026-53256, CVE-2026-53266 (KEV), CVE-2026-53290, CVE-2026-63802

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1230

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/69c1a5be-bf8e-5589-b3f8-ce7e843c6b26/red-hat-patches-dozens-of-linux-kernel-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
