Red Hat patches multiple Linux kernel vulnerabilities enabling privilege escalation, data…
Red Hat patches multiple Linux kernel vulnerabilities enabling privilege escalation, data confidentiality breaches, and denial of service across RHEL 8 and 9.
The French CERT (CERT-FR) has issued an advisory regarding multiple vulnerabilities discovered in the Red Hat Enterprise Linux kernel affecting versions 8 and 9 across various architectures including x86_64, ARM64, IBM z Systems, and Power architectures. The vulnerabilities span various update channels including Extended Update Support, Extended Life Cycle, and standard release channels.
The vulnerabilities allow attackers to achieve privilege escalation, compromise data confidentiality and integrity, bypass security policies, and cause denial of service conditions. Red Hat has released patches via three separate security bulletins (RHSA-2026:21209, RHSA-2026:21706, and RHSA-2026:21745) issued on May 27-28, 2026. The advisory references 24 distinct CVE identifiers spanning from 2025 through 2026.
Organizations running Red Hat Enterprise Linux 8 or 9 on any supported architecture should prioritize patching, particularly for systems exposed to untrusted users or network traffic. The variety of impacts suggests multiple attack vectors within the kernel subsystems.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0665
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free