VORANT. Threat Intelligence Sign in Get the full feed

Red Hat Linux kernel patches multiple CVEs

medium vulnerability

CERT-FR advisory details multiple Red Hat Enterprise Linux kernel vulnerabilities allowing RCE, privilege escalation, and denial of service.

CERT-FR has published an advisory (CERTFR-2026-AVI-0955) covering numerous vulnerabilities discovered in the Linux kernel as shipped in Red Hat Enterprise Linux and related products, including OpenShift Container Platform, CodeReady Linux Builder, and Real Time variants across multiple architectures (x86_64, aarch64, s390x, ppc64le). The affected products span current and extended-support releases from RHEL 7 through 10.2.

According to the advisory, some of these vulnerabilities could allow an attacker to achieve remote arbitrary code execution, privilege escalation, or remote denial of service, alongside risks to data confidentiality, data integrity, and security policy bypass. The advisory references thirteen Red Hat Security Advisories (RHSAs) issued between July 24 and July 30, 2026, and lists 28 associated CVEs spanning the kernel codebase. No indication of active exploitation is provided in the advisory.

Organizations running affected Red Hat Enterprise Linux versions or derivative products should apply the patches referenced in the corresponding RHSA bulletins as a priority, particularly for systems exposed to untrusted input or multi-tenant workloads where privilege escalation or RCE risks are most acute.

Mentioned in this report

Vulnerabilities CVE-2025-10263CVE-2025-38085CVE-2025-40026CVE-2025-68183CVE-2025-68724CVE-2026-12505CVE-2026-31488CVE-2026-31613CVE-2026-31684CVE-2026-31787CVE-2026-43027CVE-2026-43037CVE-2026-43279CVE-2026-43500weaponizedCVE-2026-46086CVE-2026-46116CVE-2026-46135CVE-2026-46189CVE-2026-46209CVE-2026-52923CVE-2026-52950CVE-2026-52976CVE-2026-52993CVE-2026-53006CVE-2026-53059CVE-2026-53281CVE-2026-57231CVE-2026-64530

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0955

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free