VORANT. Threat Intelligence Sign in Get the full feed

Red Hat patches multiple Linux kernel flaws

medium vulnerability technology

ANSSI advisory details numerous Red Hat Enterprise Linux kernel vulnerabilities enabling code execution, privilege escalation, and denial of service.

ANSSI (CERT-FR) issued advisory CERTFR-2026-AVI-0899 covering a large batch of vulnerabilities discovered in the Linux kernel as shipped by Red Hat across multiple product lines, including Red Hat Enterprise Linux (versions 8, 9, and 10) and CodeReady Linux Builder across ARM64, IBM z Systems, Power (ppc64le), and x86_64 architectures. The advisory aggregates over a dozen Red Hat Security Advisories (RHSAs) published between July 10 and July 17, 2026, and references approximately 30 CVEs affecting kernel components.

The vulnerabilities collectively enable a range of impacts including arbitrary code execution, privilege escalation, remote denial of service, data integrity and confidentiality breaches, and security policy bypass. No specific exploitation in the wild is mentioned in the advisory; it is a routine vendor patch notification. Red Hat has released fixes across all affected product editions, and administrators are directed to apply the corresponding RHSA patches referenced in the documentation.

Given the broad scope of affected Red Hat Enterprise Linux editions (spanning multiple architectures and long-term support variants including Extended Update Support and Extended Life Cycle), organizations running RHEL should prioritize patching per their asset criticality and exposure, particularly for systems exposed to untrusted local users or network-facing kernel-dependent services.

Mentioned in this report

Vulnerabilities CVE-2025-38653CVE-2025-68183CVE-2025-68724CVE-2025-71066CVE-2025-71089CVE-2026-31408CVE-2026-31411CVE-2026-31613CVE-2026-31684CVE-2026-43027CVE-2026-43074CVE-2026-43279CVE-2026-43330CVE-2026-43414CVE-2026-43499CVE-2026-45984CVE-2026-46086CVE-2026-46113CVE-2026-46116CVE-2026-46135CVE-2026-46152CVE-2026-46173CVE-2026-46189CVE-2026-46209CVE-2026-46242CVE-2026-46316CVE-2026-53016CVE-2026-53166CVE-2026-53266CVE-2026-53359

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0899

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free