Red Hat Product Errata RHSA-2026:8921 - Security Advisory Issued: 2026-04-20 Updated: 2026-04-20 RHSA-2026:8921 - Security Advisory Overview Updated Packages Synopsis Important: kernel security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for kernel is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): kernel: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit (CVE-2025-39766) kernel: scsi: qla2xxx: Fix improper freeing of purex item (CVE-2025-68741) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Fixes BZ - 2394648 - CVE-2025-39766 kernel: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit BZ - 2425046 - CVE-2025-68741 kernel: scsi: qla2xxx: Fix improper freeing of purex item CVEs CVE-2025-39766 CVE-2025-68741 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM kernel-5.14.0-611.49.1.el9_7.src.rpm SHA-256: 2f2d2906221d7fc0b3e458306e496cf31814a8892e2839700d271d93c11fd032 x86_64 kernel-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 29f3bd3f94fafb859731e43e28d3f258db1af50822afc418aac5a09cedcfbd5a kernel-abi-stablelists-5.14.0-611.49.1.el9_7.noarch.rpm SHA-256: 680aa4721da1f99d6a5a03b6bce1594fa2350d45d6566208d5fb1c3eb75b01d3 kernel-core-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 5b4f8f3e008ae121d135802da87d7bb32ec2373fbfc0ea42c8251b2ad6e2125f kernel-debug-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 73470543fff3663f47939d999623c816407c532c6407d069bcef99caf99ea437 kernel-debug-core-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 06aa5c63c362fa4e20858c84b26236108e28eadf3127180ece2edf0898a3ef5f kernel-debug-debuginfo-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 4fa32e3b883e9c4ad1272a0c8eeae338db8b9317d8e8194b556f35d98a3487c1 kernel-debug-debuginfo-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 4fa32e3b883e9c4ad1272a0c8eeae338db8b9317d8e8194b556f35d98a3487c1 kernel-debug-debuginfo-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 4fa32e3b883e9c4ad1272a0c8eeae338db8b9317d8e8194b556f35d98a3487c1 kernel-debug-debuginfo-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 4fa32e3b883e9c4ad1272a0c8eeae338db8b9317d8e8194b556f35d98a3487c1 kernel-debug-devel-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: a6b81e143ac28e81feeb823cb69bb21475f41b1f24194fa634f817b780c54ba4 kernel-debug-devel-matched-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: d08126c892f770b34972805e49158d3df5312cbaa4671e7e377c1461ca09e6c5 kernel-debug-modules-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 9243cf4d2d7a4e24d0ea9d41e5fe7c2223e4591c6062bb4a75d893f465eb049f kernel-debug-modules-core-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 0e027ede74b80354eeb468d2e0168d56d849d59ea55d3b35a5e1442f2ca3fbcd kernel-debug-modules-extra-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 8ed577e1f7df223b28309c8cd792f8a097bf3bd0476a9bd3bdb453fcff82a99c kernel-debug-uki-virt-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: d3fbf83cd007a9ce19e52bab6f20db3e0922376a6f5fe41e8099b261104d5c83 kernel-debuginfo-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 070807449a3e1b016be1665f60d85f5ed1540b73b64ab41116c594afef163117 kernel-debuginfo-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 070807449a3e1b016be1665f60d85f5ed1540b73b64ab41116c594afef163117 kernel-debuginfo-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 070807449a3e1b016be1665f60d85f5ed1540b73b64ab41116c594afef163117 kernel-debuginfo-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 070807449a3e1b016be1665f60d85f5ed1540b73b64ab41116c594afef163117 kernel-debuginfo-common-x86_64-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: fce9c34229e2d7dc158301fd2f7f749320e643c7aa5bbe931db4af55428179b5 kernel-debuginfo-common-x86_64-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: fce9c34229e2d7dc158301fd2f7f749320e643c7aa5bbe931db4af55428179b5 kernel-debuginfo-common-x86_64-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: fce9c34229e2d7dc158301fd2f7f749320e643c7aa5bbe931db4af55428179b5 kernel-debuginfo-common-x86_64-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: fce9c34229e2d7dc158301fd2f7f749320e643c7aa5bbe931db4af55428179b5 kernel-devel-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 64e410e8f1ca5bace415502ea4d291d8007ce433678f07c6a9fac634a22a241f kernel-devel-matched-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 9692f455923f8302053d6a57ceb2f7509576271204d9e12e692ebe78e46dcc80 kernel-doc-5.14.0-611.49.1.el9_7.noarch.rpm SHA-256: 4af7e14eeb1805c7ca0a47437cd70ea310cc7968cb13a4a67dccf452a38698d2 kernel-headers-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 9bbb4fc529d166ae0374f34820d1d8212ea25a0e8cc3a5b630c58f6e6be4a2d8 kernel-modules-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: ed36b7aabbe8c0d617a0d50b92b02e2a08014fbf383719c9c4a5fb2ad9acf9f6 kernel-modules-core-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: d3159475907b5ac50144b19236628345d0bb854525cd797f24062d77916e7397 kernel-modules-extra-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: fcafad0b732a435476f50db2451782bded4b1a792fcf85a127deb22975799ad4 kernel-rt-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: a1c07ea3d217d18fd1a66607422d791ad17a8c6a6144c50b838b86359c7d3689 kernel-rt-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: a1c07ea3d217d18fd1a66607422d791ad17a8c6a6144c50b838b86359c7d3689 kernel-rt-core-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: df8dc6b8243bdcad8e3e01bf29a66e986b82dfc2be4f551425d304e7563fcb60 kernel-rt-core-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: df8dc6b8243bdcad8e3e01bf29a66e986b82dfc2be4f551425d304e7563fcb60 kernel-rt-debug-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 3bece3f99930dfb88a83540913174303e121e486b6cc4e2318f40b647952580d kernel-rt-debug-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 3bece3f99930dfb88a83540913174303e121e486b6cc4e2318f40b647952580d kernel-rt-debug-core-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 4155e667053d9d4c391d1d4e39a75089d53d0414c1f0395bbf25249231f9c85c kernel-rt-debug-core-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 4155e667053d9d4c391d1d4e39a75089d53d0414c1f0395bbf25249231f9c85c kernel-rt-debug-debuginfo-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: d8ae59e24c68cec9be29d7cb5fcdbacfb7f539ddb51a32636fff28efa3d24512 kernel-rt-debug-debuginfo-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: d8ae59e24c68cec9be29d7cb5fcdbacfb7f539ddb51a32636fff28efa3d24512 kernel-rt-debug-debuginfo-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: d8ae59e24c68cec9be29d7cb5fcdbacfb7f539ddb51a32636fff28efa3d24512 kernel-rt-debug-debuginfo-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: d8ae59e24c68cec9be29d7cb5fcdbacfb7f539ddb51a32636fff28efa3d24512 kernel-rt-debug-devel-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 00769a722914d8d9e6431f76a85d4cae6a1e3dba3df1208dc045a0a72230906c kernel-rt-debug-devel-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 00769a722914d8d9e6431f76a85d4cae6a1e3dba3df1208dc045a0a72230906c kernel-rt-debug-modules-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 20b5cac3554cee07d1795cd74a098bb8fadc35dfde32b8f9a620ba8a549e4992 kernel-rt-debug-modules-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 20b5cac3554cee07d1795cd74a098bb8fadc35dfde32b8f9a620ba8a549e4992 kernel-rt-debug-modules-core-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: e6268806def829c7e4ee3f55d7c414b738b4bc4aa1e851475eb0d93c983d2ceb kernel-rt-debug-modules-core-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: e6268806def829c7e4ee3f55d7c414b738b4bc4aa1e851475eb0d93c983d2ceb kernel-rt-debug-modules-extra-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: d18fc443b9f9f55f96f1d884377ee49f55281dab8c1c72edd0b2ccb99edac37d kernel-rt-debug-modules-extra-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: d18fc443b9f9f55f96f1d884377ee49f55281dab8c1c72edd0b2ccb99edac37d kernel-rt-debuginfo-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: aee98d4b09426f758e8e48b4da46ea1e4b449e0deec8d7249995b6eaada3b3b6 kernel-rt-debuginfo-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: aee98d4b09426f758e8e48b4da46ea1e4b449e0deec8d7249995b6eaada3b3b6 kernel-rt-debuginfo-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: aee98d4b09426f758e8e48b4da46ea1e4b449e0deec8d7249995b6eaada3b3b6 kernel-rt-debuginfo-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: aee98d4b09426f758e8e48b4da46ea1e4b449e0deec8d7249995b6eaada3b3b6 kernel-rt-devel-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 9527061e9f56ba846b31166c1676db0ee4d40760c0965917326c68b4c841b3c6 kernel-rt-devel-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 9527061e9f56ba846b31166c1676db0ee4d40760c0965917326c68b4c841b3c6 kernel-rt-modules-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 7ec8c0b92449850b2190cd8c95f7d7c8107a6eb33cd1fcd14dd2b15c9717e836 kernel-rt-modules-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: 7ec8c0b92449850b2190cd8c95f7d7c8107a6eb33cd1fcd14dd2b15c9717e836 kernel-rt-modules-core-5.14.0-611.49.1.el9_7.x86_64.rpm SHA-256: b1e506291c7f8a452b17b5767a83631f687bb3f8397c90b67cf818f90c8d1808 kernel-rt-modules-core-5.14.0-611.49
This Red Hat security advisory addresses two Important-severity Linux kernel vulnerabilities: CVE-2025-39766, a high-severity (CVSS 7.8) issue in the CAKE network scheduler that could lead to resource exhaustion, and CVE-2025-68741, a flaw in the QLogic Fibre Channel driver. The vulnerabilities affect multiple kernel versions, specifically Linux kernels from 4.19 up to but not including 5.4.297, 5.5 up to 5.10.241, 5.11 up to 5.15.190, 5.16 up to 6.1.149, and 6.2 up to 6.6.103. The fix is provided in Red Hat Enterprise Linux 9 kernel update packages, such as kernel-5.14.0-611.49.1.el9_7, and requires a system reboot.