Red Hat Product Errata RHSA-2026:13566 - Security Advisory Issued: 2026-05-04 Updated: 2026-05-04 RHSA-2026:13566 - Security Advisory Overview Updated Packages Synopsis Important: kernel security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for kernel is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation (CVE-2026-23270) kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (CVE-2026-31402) kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service (CVE-2026-31419) kernel: crypto: algif_aead - Revert to operating out-of-place (CVE-2026-31431) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Fixes BZ - 2448745 - CVE-2026-23270 kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation BZ - 2454844 - CVE-2026-31402 kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache BZ - 2457829 - CVE-2026-31419 kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service BZ - 2460538 - CVE-2026-31431 kernel: crypto: algif_aead - Revert to operating out-of-place CVEs CVE-2026-23270 CVE-2026-31402 CVE-2026-31419 CVE-2026-31431 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM kernel-6.12.0-124.55.1.el10_1.src.rpm SHA-256: 764e9f44cfa362564f63472b2ab57ef8966c347a245cb07a3e86a491b2980e76 x86_64 kernel-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 6ceecb20cffb86be1728b2f215fc24b2ef5497e02b4ff22edf1a4fab14ba3283 kernel-abi-stablelists-6.12.0-124.55.1.el10_1.noarch.rpm SHA-256: 7a80c0a9ed3040bc0427254f7670e6f79a3002138d4a1785060fd8d94bebff5a kernel-core-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 7ac3e616e556bcf5719eda44961afa05dd722237212b135823e3f8ba0c83fc81 kernel-debug-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 0fd33d31665272c1540e9dcbf858da07c66eab37632eb31386710417863eb43c kernel-debug-core-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 6027d29908dcff15274dee29ce6d1af2bcd15e626e8b48bb794f7c8a2231ca95 kernel-debug-debuginfo-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 4fbbeecfd02e3e058ef57a68a20971d54f4d2c319a72492c96cc2bc89424b409 kernel-debug-debuginfo-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 4fbbeecfd02e3e058ef57a68a20971d54f4d2c319a72492c96cc2bc89424b409 kernel-debug-debuginfo-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 4fbbeecfd02e3e058ef57a68a20971d54f4d2c319a72492c96cc2bc89424b409 kernel-debug-debuginfo-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 4fbbeecfd02e3e058ef57a68a20971d54f4d2c319a72492c96cc2bc89424b409 kernel-debug-devel-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: fca59475c4b546405c6e7ebc31b468dd9f3b1fcc0e039715d5390e58eaf6bf0e kernel-debug-devel-matched-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: f3d424970ddeed6a4ca9b830539bf69761b5a289ff49a9f45788425b7a709a42 kernel-debug-modules-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: b164fc2f7e801705838373e3a030397ec55e08f30cae6bc2599ff3e54d60b6e8 kernel-debug-modules-core-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 3bff11c0f358e8cd6e509242284857e3c990efa570491840d8eacb72c163b3ee kernel-debug-modules-extra-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: adac3f24e1b3f12a93f44343c81d50997ac2a22d4880e94f5d26a2ac1ea1816a kernel-debug-uki-virt-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 9877e9216dba92f4fc512f3d15d10fc2ad8035d917d008546977cd5e1d6946c9 kernel-debuginfo-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: a189c12553b0d2c0379d26616b79bf265341ee4006e2d29d246d2ba7d47be6ff kernel-debuginfo-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: a189c12553b0d2c0379d26616b79bf265341ee4006e2d29d246d2ba7d47be6ff kernel-debuginfo-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: a189c12553b0d2c0379d26616b79bf265341ee4006e2d29d246d2ba7d47be6ff kernel-debuginfo-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: a189c12553b0d2c0379d26616b79bf265341ee4006e2d29d246d2ba7d47be6ff kernel-debuginfo-common-x86_64-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 1acb8763ef2a3e5350d403c84dd6f91415e1da9181daebdc5731a1730be990e8 kernel-debuginfo-common-x86_64-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 1acb8763ef2a3e5350d403c84dd6f91415e1da9181daebdc5731a1730be990e8 kernel-debuginfo-common-x86_64-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 1acb8763ef2a3e5350d403c84dd6f91415e1da9181daebdc5731a1730be990e8 kernel-debuginfo-common-x86_64-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 1acb8763ef2a3e5350d403c84dd6f91415e1da9181daebdc5731a1730be990e8 kernel-devel-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: d3d0a26b8dfe11c0d0680d5501efedf992ec1899479cc5b3d11d4e6292d3bcf0 kernel-devel-matched-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 0e0e12be34601fc7fb123993c980120dd42d5ea51d1401e4366e41eb7928b94c kernel-doc-6.12.0-124.55.1.el10_1.noarch.rpm SHA-256: c3e72d5bbb85171fd4324b9eb0323cdf843cb0fd91362f05b5fc389375c59692 kernel-headers-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 6c1cb328cdc39236d3cd98d57c5f7f4d6b8f59d6c7d047302cb000faca466eb9 kernel-modules-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 2feef7054b7c3a1b1305c3b2ceb5b09a79facef15689551ea1035da5ff3c5fc3 kernel-modules-core-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: ef5df013725221436a21680d3ffde0c7db53cfdf345b5d061fbf461be6155228 kernel-modules-extra-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: c49317200ae4ed6192ca24e6a23a24fc5f084d28c35503eff134530db23b42fb kernel-modules-extra-matched-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 85952300165c819e54c7fbb6b5554d5a8173f76e6bd6720b0e18c5bd98e3fef0 kernel-rt-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: bdd545ad41c18a1b8d923ecf7821b682ac7407b152b81cfd5be51710dcab0e29 kernel-rt-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: bdd545ad41c18a1b8d923ecf7821b682ac7407b152b81cfd5be51710dcab0e29 kernel-rt-core-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 111610852039bb65ac61750499e9e8fd744374d62d2bd0abc817e26ba0131443 kernel-rt-core-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 111610852039bb65ac61750499e9e8fd744374d62d2bd0abc817e26ba0131443 kernel-rt-debug-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 251a2cd57071db6a81e1b5bde17f60e4a5117f7bce0045207a8344fcc0b02321 kernel-rt-debug-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 251a2cd57071db6a81e1b5bde17f60e4a5117f7bce0045207a8344fcc0b02321 kernel-rt-debug-core-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 4e99e2a9abf214acc0ac8e49d31fb832628295edd59cf24525aa69c7bd2253b4 kernel-rt-debug-core-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 4e99e2a9abf214acc0ac8e49d31fb832628295edd59cf24525aa69c7bd2253b4 kernel-rt-debug-debuginfo-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 71fa76a2e22d300b377034271f52c131469a36f4cf7d4abf2235c7b4afcbeb4d kernel-rt-debug-debuginfo-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 71fa76a2e22d300b377034271f52c131469a36f4cf7d4abf2235c7b4afcbeb4d kernel-rt-debug-debuginfo-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 71fa76a2e22d300b377034271f52c131469a36f4cf7d4abf2235c7b4afcbeb4d kernel-rt-debug-debuginfo-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 71fa76a2e22d300b377034271f52c131469a36f4cf7d4abf2235c7b4afcbeb4d kernel-rt-debug-devel-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 909ec3b828d60d70da052b8ab886212540673cd544e9472edbde465ea9c0f022 kernel-rt-debug-devel-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 909ec3b828d60d70da052b8ab886212540673cd544e9472edbde465ea9c0f022 kernel-rt-debug-modules-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 7868d754317867b24acae2deb3f4b4468652314ce1e74dd6bffd9ead954fcf9e kernel-rt-debug-modules-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 7868d754317867b24acae2deb3f4b4468652314ce1e74dd6bffd9ead954fcf9e kernel-rt-debug-modules-core-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 196b40a28c656f3f4ad07d0b998e1c5524fbfe4e7e285a72f01590986d92d72f kernel-rt-debug-modules-core-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: 196b40a28c656f3f4ad07d0b998e1c5524fbfe4e7e285a72f01590986d92d72f kernel-rt-debug-modules-extra-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: ba9c01285a16134be94205fa036f3ef77077073e9f625e484036d6a4a71da708 kernel-rt-debug-modules-extra-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: ba9c01285a16134be94205fa036f3ef77077073e9f625e484036d6a4a71da708 kernel-rt-debuginfo-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: ab4b52ea3e653e907900d076fbe7e2f59b231715d7003fd4260886892fb9388f kernel-rt-debuginfo-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: ab4b52ea3e653e907900d076fbe7e2f59b231715d7003fd4260886892fb9388f kernel-rt-debuginfo-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: ab4b52ea3e653e907900d076fbe7e2f59b231715d7003fd4260886892fb9388f kernel-rt-debuginfo-6.12.0-124.55.1.el10_1.x86_64.rpm SHA-256: ab4b52ea3e653e907900d076f
This Red Hat kernel security update addresses four vulnerabilities, including a critical heap overflow in the NFSv4.0 LOCK replay cache (CVE-2026-31402, CVSS 9.8) and three high-severity use-after-free flaws in traffic control, bonding, and crypto subsystems that can lead to denial of service or privilege escalation. The update is rated Important and applies to all supported architectures of Red Hat Enterprise Linux 10. A system reboot is required after applying the patch to mitigate these risks.