Red Hat Product Errata RHSA-2026:16314 - Security Advisory Issued: 2026-05-12 Updated: 2026-05-12 RHSA-2026:16314 - Security Advisory Overview Updated Packages Synopsis Important: kernel security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for kernel is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): kernel: "Dirty Frag" is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel (CVE-2026-43284) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.0 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.0 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2467771 - CVE-2026-43284 kernel: "Dirty Frag" ESP XFRM variant is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel CVEs CVE-2026-43284 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM kernel-6.12.0-55.73.1.el10_0.src.rpm SHA-256: d2ab4075e6d31ca5999b0707e075a9a43bd9ee971aa1184b90dba278cb49b016 x86_64 kernel-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: b6365e8e690b03b5e041d44ebc34ef9938cd47b63bb9dda97ceae4adedc30058 kernel-abi-stablelists-6.12.0-55.73.1.el10_0.noarch.rpm SHA-256: c9cf141c2253685f5101cf8d13ee84eb49fcfaaabed61e288e4c4ad852a72519 kernel-core-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: b00b40ab9792cc6fdc66fa34aa9482b13d50ee9710552c8e678d88ab8966f112 kernel-debug-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 32996065222da45da60a89f4b1d05c1cb1cf2613ffd479c43d61a5a951e57ff4 kernel-debug-core-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 402c4e6133a683fca721784650e7187ca7706c6a9ea1254a680165c150888811 kernel-debug-debuginfo-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 7ed5e02749851e2e65f46f730699f7acb82614dcbcc6985cbc8cd450de1d96f2 kernel-debug-debuginfo-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 7ed5e02749851e2e65f46f730699f7acb82614dcbcc6985cbc8cd450de1d96f2 kernel-debug-debuginfo-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 7ed5e02749851e2e65f46f730699f7acb82614dcbcc6985cbc8cd450de1d96f2 kernel-debug-debuginfo-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 7ed5e02749851e2e65f46f730699f7acb82614dcbcc6985cbc8cd450de1d96f2 kernel-debug-devel-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 97216ee11aeb4b78833776bbf50751c360bbc9633e02b7ffb0aa93b0f9c75980 kernel-debug-devel-matched-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 16da4aff8f33b16f59edb49423665f2f64e515c6c84a5e02097bcf3b6473ea8d kernel-debug-modules-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: be05f1c2ae0c3002c04a782c4673b39a0b00313ea76e055f77608439dbe66b96 kernel-debug-modules-core-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 49ee4535105146dbce36eee285345e87f03b737bd0cfcd8d5591775ead4e5611 kernel-debug-modules-extra-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 23267bae242466d5686b07aa35cf42a4a080c9bfa7b622b45ee108d90448c88a kernel-debug-uki-virt-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: cfa2c6a7f3fed6955f13d9acecdf4c75745c8b9b46294c9683faadf527772a7b kernel-debuginfo-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 6183263ba1445291003bc7ab72f640b54e0a017e92e0a7b6cecfe5579fbe9800 kernel-debuginfo-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 6183263ba1445291003bc7ab72f640b54e0a017e92e0a7b6cecfe5579fbe9800 kernel-debuginfo-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 6183263ba1445291003bc7ab72f640b54e0a017e92e0a7b6cecfe5579fbe9800 kernel-debuginfo-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 6183263ba1445291003bc7ab72f640b54e0a017e92e0a7b6cecfe5579fbe9800 kernel-debuginfo-common-x86_64-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: de525709dbf7484b3f052a4f8c2e626362404c02aa0f7343668c1bf0b909f1fd kernel-debuginfo-common-x86_64-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: de525709dbf7484b3f052a4f8c2e626362404c02aa0f7343668c1bf0b909f1fd kernel-debuginfo-common-x86_64-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: de525709dbf7484b3f052a4f8c2e626362404c02aa0f7343668c1bf0b909f1fd kernel-debuginfo-common-x86_64-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: de525709dbf7484b3f052a4f8c2e626362404c02aa0f7343668c1bf0b909f1fd kernel-devel-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 754d695cf748432774b2ae86549d641605728f1d88f0df9ff1855ad6e6d6d4dd kernel-devel-matched-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 5decc7dca423e663eeb119b26e40d2439c3fc1937a3666841ac93909f20bdc27 kernel-doc-6.12.0-55.73.1.el10_0.noarch.rpm SHA-256: 700f61704033119548b3e4e7048246c06555b786d6bfeca5620148bdbb835129 kernel-headers-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 86b9d8aabf1e4307fbeffb39970f3d09f0f6fbdfc7728d6644d70f046f7bbc3e kernel-modules-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: ca048f08698deddbdf61457418fe2ab028ed79fd5a347ca13a3c2b08b01e3a97 kernel-modules-core-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: cc6300da588dc8a9b1d2e1ace797267f3bbfe85aaa16403466b6415b1f4327dc kernel-modules-extra-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 8560e71b0e458f6883591ed08c07ede6382fe11d0696a0f5ac68b3216be240ca kernel-rt-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 37d00f866f01b96355ca617b3e04240a1bebe99a9f0a3a6b8502c97592dfbc74 kernel-rt-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 37d00f866f01b96355ca617b3e04240a1bebe99a9f0a3a6b8502c97592dfbc74 kernel-rt-core-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 20e5ebd63283a6631f6588343280886ee6bf7bf88c9ba23049c494eab2b44116 kernel-rt-core-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 20e5ebd63283a6631f6588343280886ee6bf7bf88c9ba23049c494eab2b44116 kernel-rt-debug-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 275175ccfe27a482f46b8e6784a8f683133a158bd810ebaf136c1962acd0b944 kernel-rt-debug-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 275175ccfe27a482f46b8e6784a8f683133a158bd810ebaf136c1962acd0b944 kernel-rt-debug-core-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 662e3c1597b0270a4c7cd28768266a5fc06cc1f72359e02647f312801ddddda0 kernel-rt-debug-core-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 662e3c1597b0270a4c7cd28768266a5fc06cc1f72359e02647f312801ddddda0 kernel-rt-debug-debuginfo-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 8218b3e6778e4c5f8888234533a96caf4934074dc52dfb048c419c01f67528b3 kernel-rt-debug-debuginfo-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 8218b3e6778e4c5f8888234533a96caf4934074dc52dfb048c419c01f67528b3 kernel-rt-debug-debuginfo-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 8218b3e6778e4c5f8888234533a96caf4934074dc52dfb048c419c01f67528b3 kernel-rt-debug-debuginfo-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 8218b3e6778e4c5f8888234533a96caf4934074dc52dfb048c419c01f67528b3 kernel-rt-debug-devel-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: cd3488964f6a7124a2683dae6bcc32ac1b3c38ec2ab812e4f09f382d22d02e20 kernel-rt-debug-devel-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: cd3488964f6a7124a2683dae6bcc32ac1b3c38ec2ab812e4f09f382d22d02e20 kernel-rt-debug-kvm-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: e9497625171bceb7046293af0e991e0dd09c63cb7bafdd92172c6f5c01a08f60 kernel-rt-debug-modules-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 07c8c60ffd6342d14e649c47156425581c91962ed6c915aedee5df73339ff140 kernel-rt-debug-modules-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 07c8c60ffd6342d14e649c47156425581c91962ed6c915aedee5df73339ff140 kernel-rt-debug-modules-core-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 473ce01a2b1188f5cfdd6a6cc25d98d75ace6c15d92d101135bd30b7c2cff66d kernel-rt-debug-modules-core-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 473ce01a2b1188f5cfdd6a6cc25d98d75ace6c15d92d101135bd30b7c2cff66d kernel-rt-debug-modules-extra-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: bc1829e867a770a102d0e0dee3495d6c32f74b5e53f69e39e5b8675a5c0e719a kernel-rt-debug-modules-extra-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: bc1829e867a770a102d0e0dee3495d6c32f74b5e53f69e39e5b8675a5c0e719a kernel-rt-debuginfo-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 6c600407337dc98137d32da65d6359ba1c280c4ebcf38dcc21aacbfcad096de0 kernel-rt-debuginfo-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 6c600407337dc98137d32da65d6359ba1c280c4ebcf38dcc21aacbfcad096de0 kernel-rt-debuginfo-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 6c600407337dc98137d32da65d6359ba1c280c4ebcf38dcc21aacbfcad096de0 kernel-rt-debuginfo-6.12.0-55.73.1.el10_0.x86_64.rpm SHA-256: 6c600407337dc98137d32da65d6359ba1c280c4ebcf38dcc21aacbfcad096de0 kernel-rt-devel-6.12.0-55.73.1.el10_0.x86_64.rpm SHA
The "Dirty Frag" vulnerability (CVE-2026-43284, CVSS 8.8 High) is a universal Local Privilege Escalation (LPE) flaw in the Linux kernel's ESP XFRM subsystem. Affected versions include kernel 4.11 through 5.10.254, 5.12 through 5.15.204, 5.16 through 6.1.170, 6.2 through 6.6.137, and 6.7 through 6.12.86. The fix requires updating to specific patched kernel versions, such as 5.10.255, 5.15.205, 6.1.171, 6.6.138, or 6.12.87, followed by a system reboot.