Details:
The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669)
kernel: RDMA/umem: Fix double dma_buf_unpin in failure path (CVE-2026-43128)
kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks (CVE-2026-43158)
kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198)
kernel: mm/page_alloc: clear page->private in free_pages_prepare() (CVE-2026-43303)
kernel: net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341)
kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329)
kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090)
kernel: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176)
kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166)
kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244)
Bug Fix(es) and Enhancement(s):
Backport "KVM: arm64: Hide ID_AA64MMFR2_EL1.NV from guest and userspace" [rhel-10.0.z] (JIRA:RHEL-134762)
Kernel panic while shutting down ice driver due to use-after-free [rhel-10.0.z] (JIRA:RHEL-177516)
crypto: testmgr - allow authenc(hmac(sha{256,384}),cts(cbc(aes))) in FIPS mode [rhel-10.0.z] (JIRA:RHEL-182536)
RHEL10.0 - s390/mm: Add missing secure storage access fixups [rhel-10.0.z] (JIRA:RHEL-183318)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
0:6.12.0-55.84.1.el10_00:6.12.0-55.84.1.el10_00:6.12.0-55.84.1.el10_00:6.12.0-55.84.1.el10_00:6.12.0-55.84.1.el10_00:6.12.0-55.84.1.el10_00:6.12.0-55.84.1.el10_00:6.12.0-55.84.1.el10_00:6.12.0-55.84.1.el10_00:6.12.0-55.84.1.el10_0Exploitability
AV:LAC:LPR:LUI:NScope
S:UImpact
C:HI:HA:H7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H