Red Hat patches dozens of Linux kernel flaws
Red Hat issued a batch of kernel security updates fixing dozens of CVEs across RHEL, OpenShift and CodeReady Builder that can enable RCE, privilege escalation or DoS.
CERT-FR relayed a Red Hat security advisory covering an extensive set of Linux kernel vulnerabilities affecting nearly all current and extended-support versions of Red Hat Enterprise Linux (8, 9, 10 and their AUS/EUS/ELS variants), Red Hat OpenShift Container Platform, and CodeReady Linux Builder across x86_64, ARM64, IBM Z (s390x) and Power (ppc64le) architectures. The flaws stem from the underlying Linux kernel and impact confidentiality, integrity, and availability, with some issues enabling remote code execution, privilege escalation, or remote denial of service, while others cause data integrity/confidentiality breaches or security policy bypass.
The advisory bundles more than 50 CVEs (2024-2026 range) addressed through roughly 20 separate RHSA errata published between July 1 and July 9, 2026. No indicators of compromise, threat actor attribution, or evidence of active exploitation were included in the bulletin — this is a routine vendor patch release requiring administrators to apply the referenced RHSA updates across affected RHEL and OpenShift deployments.
Given the breadth of affected product lines (core RHEL server, OpenShift Container Platform, SAP solution builds, real-time kernels), organizations running Red Hat infrastructure should prioritize patch deployment based on exposure, particularly for internet-facing or multi-tenant OpenShift clusters where privilege escalation or RCE vulnerabilities carry the greatest risk.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0863
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free