Details:
The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
kernel: eventpoll: defer struct eventpoll free to RCU grace period (CVE-2026-43074)
kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276)
kernel: net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341)
kernel: smb/client: fix out-of-bounds read in smb2_compound_op() (CVE-2026-46155)
kernel: eventpoll: fix ep_remove struct eventpoll / struct file UAF (CVE-2026-46242)
kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259)
Bug Fix(es) and Enhancement(s):
CNB103: net: page_pool: avoid false positive warning if NAPI was never added [rhel-10.2.z] (JIRA:RHEL-162140)
[RHEL 10] Bonding reports unknown speed/duplex for tg3 interface [rhel-10.2.z] (JIRA:RHEL-182770)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
0:6.12.0-211.31.1.el10_20:6.12.0-211.31.1.el10_20:6.12.0-211.31.1.el10_20:6.12.0-211.31.1.el10_20:6.12.0-211.31.1.el10_20:6.12.0-211.31.1.el10_20:6.12.0-211.31.1.el10_20:6.12.0-211.31.1.el10_20:6.12.0-211.31.1.el10_20:6.12.0-211.31.1.el10_2Exploitability
AV:LAC:LPR:LUI:NScope
S:UImpact
C:HI:LA:H7.3/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H