Issued at: 2026-09-16
Updated at: 2026-09-17
Advisory content derived from Red Hat RHSA-2026:67470, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Important: kernel security, bug fix, and enhancement update
Description
The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
* kernel: vhost: move vdpa group bound check to vhost_vdpa (CVE-2026-43248)
* kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)
* kernel: octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify (CVE-2026-63923)
* kernel: Linux kernel SLIP: Out-of-bounds write due to race condition during MTU change (CVE-2026-68143)
* kernel: net: qrtr: restrict socket creation to the initial network namespace (CVE-2026-68294)
* kernel: octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (CVE-2026-72045)
* kernel: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (CVE-2026-74556)
Bug Fix(es) and Enhancement(s):
* gfs2: bufdata leaks [rhel-9.8.z] (JIRA:Rocky Linux-178223)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.