VORANT. Threat Intelligence Sign in Get the full feed

Red Hat patches Linux kernel flaws

medium vulnerability

Red Hat released security updates addressing multiple Linux kernel vulnerabilities enabling remote code execution, privilege escalation, and denial of service across RHEL and OpenShift.

Red Hat has issued a comprehensive set of security advisories addressing multiple vulnerabilities in the Linux kernel affecting Red Hat Enterprise Linux (RHEL) versions 8, 9, and 10 across various architectures, as well as OpenShift Container Platform versions 4.12 and 4.13. The vulnerabilities pose risks including remote arbitrary code execution, privilege escalation, denial of service, data integrity compromise, data confidentiality breach, and security policy bypass.

The advisories, published between June 19-25, 2026, cover 35 distinct CVEs spanning from CVE-2026-4878 through CVE-2026-46331. The affected systems include RHEL deployments on ARM64, IBM z Systems (s390x), Power (ppc64le), and x86_64 architectures, with patches available for standard releases as well as extended update support and extended life cycle versions. OpenShift Container Platform users running versions 4.12 and 4.13 on RHEL 8 and 9 are also impacted.

Red Hat recommends applying the vendor-supplied patches immediately. Organizations running affected versions should consult the nineteen individual security bulletins referenced in the advisory and prioritize patching based on their deployment configuration and exposure profile.

Mentioned in this report

Vulnerabilities CVE-2026-31419CVE-2026-31474CVE-2026-31488CVE-2026-31636CVE-2026-31641CVE-2026-31669CVE-2026-31772CVE-2026-31786CVE-2026-31787CVE-2026-35385CVE-2026-39979CVE-2026-40164CVE-2026-41035CVE-2026-43037CVE-2026-43038CVE-2026-43056CVE-2026-43198CVE-2026-43260CVE-2026-43279CVE-2026-43284weaponizedCVE-2026-43330CVE-2026-43414CVE-2026-45898CVE-2026-45984CVE-2026-46054CVE-2026-46056CVE-2026-46090CVE-2026-46117CVE-2026-46125CVE-2026-46135CVE-2026-46145CVE-2026-46152CVE-2026-46166CVE-2026-46173CVE-2026-46331CVE-2026-4878

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0808

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free