VORANT. Threat Intelligence Sign in Get the full feed

Red Hat patches multiple Linux kernel flaws

routine vulnerability technology

CERT-FR advisory details numerous Red Hat Enterprise Linux kernel vulnerabilities enabling code execution, privilege escalation, and DoS; patches available.

CERT-FR has published an advisory (CERTFR-2026-AVI-1028) covering multiple vulnerabilities discovered in the Red Hat Enterprise Linux kernel, affecting a broad range of RHEL product lines and architectures including x86_64, ARM64, IBM z Systems, and Power little-endian, across versions 8 through 10.2 and various support tiers (EUS, ELS, AUS, TUS, SAP Solutions). The vulnerabilities collectively allow an attacker to compromise data integrity and confidentiality, bypass security policies, cause remote denial of service, execute arbitrary code, and escalate privileges.

Red Hat has released thirteen separate security errata (RHSA) between August 7 and August 13, 2026, addressing more than 20 distinct CVEs affecting kernel components. No specific exploitation details, proof-of-concept code, or in-the-wild attacks are mentioned in the advisory; it is a standard vendor patch notification distributed by the French national CERT. Organizations running affected RHEL versions should apply the referenced RHSA patches according to their standard patch management processes.

Given the breadth of affected systems and the kernel-level nature of the flaws (which can lead to privilege escalation and code execution), timely patching is recommended, though there is no indication of active exploitation at time of publication.

Mentioned in this report

Vulnerabilities CVE-2024-53143CVE-2025-10263CVE-2025-54518CVE-2025-71072CVE-2025-71131CVE-2026-23415CVE-2026-31488CVE-2026-31530CVE-2026-31787CVE-2026-43112CVE-2026-45991CVE-2026-46054CVE-2026-52923CVE-2026-52976CVE-2026-53009CVE-2026-53059CVE-2026-53202CVE-2026-53264CVE-2026-63887CVE-2026-64300CVE-2026-64368CVE-2026-64496CVE-2026-64531

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1028

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free