Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:49033 - Security Advisory
Issued:
2026-07-31
Updated:
2026-07-31

RHSA-2026:49033 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: kernel security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for kernel is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)
  • kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (CVE-2026-46113)
  • kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263)
  • kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role (CVE-2026-53359)
  • kernel: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (CVE-2026-64530)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

The system must be rebooted for this update to take effect.

Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture.

Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available.

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.6 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.6 x86_64

Fixes

  • BZ - 2482523 - CVE-2026-46116 kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete
  • BZ - 2482587 - CVE-2026-46113 kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN
  • BZ - 2486958 - CVE-2025-10263 kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources
  • BZ - 2497033 - CVE-2026-53359 kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role
  • BZ - 2507345 - kernel: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle

CVEs

  • CVE-2025-10263
  • CVE-2026-46113
  • CVE-2026-46116
  • CVE-2026-53359
  • CVE-2026-64530

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.6

SRPM
kernel-4.18.0-372.204.1.el8_6.src.rpm SHA-256: fdcd74713c5ddbcc0035dd01e5941b4a505f2e7b37b407fcc2e5ca9cf8019cd4
x86_64
bpftool-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 7212c62654c0207d16e8eefcd4d40681ef47008851b0d6908b7cd15753dc80a5
bpftool-debuginfo-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: d467a518331f247c10c27b523b25a0b313072d20b7573d17437ae7d260f71b97
kernel-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 0e4ee90aef0d33105f6056087d4e45e732627759ef181afb226fe1956d6320a2
kernel-abi-stablelists-4.18.0-372.204.1.el8_6.noarch.rpm SHA-256: 8a7b0e0bc5c43ed3e72aac24941f5af37c9bdd0c172982e0a68b3ca9e9a2a204
kernel-core-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 0230e829b663e2353b93bac9b4fb44155e28f0c65a13bd2b7ee4154cdd5c4732
kernel-cross-headers-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 8430b30319d38949d75f09b706da667dd2d7c64baea3c6443249649b00e08722
kernel-debug-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: c7bbdedce5df3a6aa62c3d7ff7a55f76313818d664c5be85b3ef19b8096ca5ef
kernel-debug-core-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 4f06e0e17cf730667deaf511cf1d23ef8cca30c0a1d080e63250daf086d39376
kernel-debug-debuginfo-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: c8cd1254f6095d54b3b16c82b5788e74101918c45e10e45cb2316c9a2bd05747
kernel-debug-devel-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: a69c4b089e861425f32ee6f658048f9be4dae0bcb23914608300fa59aea56cc6
kernel-debug-modules-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 00c2e9fb951b1d79e60cb1eec7a044f8c2b3171580f1d6f8006ada271a5c19d7
kernel-debug-modules-extra-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 6a965ffe4646657d318db9dae3df9e550290756172b7a8ea73a642ea9e2eec06
kernel-debuginfo-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 3a1f742044fa5529b70ae430512dda3707b7d667147c132b3ac120802577ed72
kernel-debuginfo-common-x86_64-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 7685e5b14a37b9ca747a806840d4714b84b7433a0ccd182b76f8bd50e69a4a8b
kernel-devel-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: c762532c712d6d4bb15cbd5cb970529853dcb0290dfd69d16e94b45bf5b7fd6c
kernel-doc-4.18.0-372.204.1.el8_6.noarch.rpm SHA-256: 5ed756ebecbd58419feea45d9b6b2df93290fca6b8aad0248fad64ddf06d04a9
kernel-headers-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 2eac818c63d5b88a82b4bbc6967f776c04be699c98a162581fad14a486f10b0d
kernel-modules-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: d7673dfb547a3a24dd1fa33ea7b86f9493b435e60c7813aac7bdf825ba9cda27
kernel-modules-extra-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: afb1441b949cc39fce6f06aa2d30f74b3e190450b7057e84ca5538deef99e823
kernel-tools-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 2611df91e1c85571a9da117c13311343d3183fea488f454644a09153df4619df
kernel-tools-debuginfo-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 2c4fcf7d37d4afd86ef04a5fc29b0450154f55836448d6c8c901364475acf59b
kernel-tools-libs-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 6474e985592b8fab8b31d6049d41812d7d177eaba3701ae319c4ccd5ab74d9ea
perf-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 6ba418f4c3c3984d6e7ff3e941ea6f438d72d49c7bd710bc14fcbf85f6ef1845
perf-debuginfo-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 9d1dd6b9af7a83a101e447848586eae1045b825f8af66a3d52abacc3e5a364d7
python3-perf-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: ed836da3ee3f95ba84e18c8b5599677eebfb16ee8f32970cd40c4786e207376c
python3-perf-debuginfo-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 4533a3c7188af5cfab3ee618be8754397451c62d503bb3784f5b6f61578a1817

Red Hat Enterprise Linux Server - AUS 8.6

SRPM
kernel-4.18.0-372.204.1.el8_6.src.rpm SHA-256: fdcd74713c5ddbcc0035dd01e5941b4a505f2e7b37b407fcc2e5ca9cf8019cd4
x86_64
bpftool-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 7212c62654c0207d16e8eefcd4d40681ef47008851b0d6908b7cd15753dc80a5
bpftool-debuginfo-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: d467a518331f247c10c27b523b25a0b313072d20b7573d17437ae7d260f71b97
kernel-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 0e4ee90aef0d33105f6056087d4e45e732627759ef181afb226fe1956d6320a2
kernel-abi-stablelists-4.18.0-372.204.1.el8_6.noarch.rpm SHA-256: 8a7b0e0bc5c43ed3e72aac24941f5af37c9bdd0c172982e0a68b3ca9e9a2a204
kernel-core-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 0230e829b663e2353b93bac9b4fb44155e28f0c65a13bd2b7ee4154cdd5c4732
kernel-cross-headers-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 8430b30319d38949d75f09b706da667dd2d7c64baea3c6443249649b00e08722
kernel-debug-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: c7bbdedce5df3a6aa62c3d7ff7a55f76313818d664c5be85b3ef19b8096ca5ef
kernel-debug-core-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 4f06e0e17cf730667deaf511cf1d23ef8cca30c0a1d080e63250daf086d39376
kernel-debug-debuginfo-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: c8cd1254f6095d54b3b16c82b5788e74101918c45e10e45cb2316c9a2bd05747
kernel-debug-devel-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: a69c4b089e861425f32ee6f658048f9be4dae0bcb23914608300fa59aea56cc6
kernel-debug-modules-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 00c2e9fb951b1d79e60cb1eec7a044f8c2b3171580f1d6f8006ada271a5c19d7
kernel-debug-modules-extra-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 6a965ffe4646657d318db9dae3df9e550290756172b7a8ea73a642ea9e2eec06
kernel-debuginfo-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 3a1f742044fa5529b70ae430512dda3707b7d667147c132b3ac120802577ed72
kernel-debuginfo-common-x86_64-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 7685e5b14a37b9ca747a806840d4714b84b7433a0ccd182b76f8bd50e69a4a8b
kernel-devel-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: c762532c712d6d4bb15cbd5cb970529853dcb0290dfd69d16e94b45bf5b7fd6c
kernel-doc-4.18.0-372.204.1.el8_6.noarch.rpm SHA-256: 5ed756ebecbd58419feea45d9b6b2df93290fca6b8aad0248fad64ddf06d04a9
kernel-headers-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 2eac818c63d5b88a82b4bbc6967f776c04be699c98a162581fad14a486f10b0d
kernel-modules-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: d7673dfb547a3a24dd1fa33ea7b86f9493b435e60c7813aac7bdf825ba9cda27
kernel-modules-extra-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: afb1441b949cc39fce6f06aa2d30f74b3e190450b7057e84ca5538deef99e823
kernel-tools-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 2611df91e1c85571a9da117c13311343d3183fea488f454644a09153df4619df
kernel-tools-debuginfo-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 2c4fcf7d37d4afd86ef04a5fc29b0450154f55836448d6c8c901364475acf59b
kernel-tools-libs-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 6474e985592b8fab8b31d6049d41812d7d177eaba3701ae319c4ccd5ab74d9ea
perf-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 6ba418f4c3c3984d6e7ff3e941ea6f438d72d49c7bd710bc14fcbf85f6ef1845
perf-debuginfo-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 9d1dd6b9af7a83a101e447848586eae1045b825f8af66a3d52abacc3e5a364d7
python3-perf-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: ed836da3ee3f95ba84e18c8b5599677eebfb16ee8f32970cd40c4786e207376c
python3-perf-debuginfo-4.18.0-372.204.1.el8_6.x86_64.rpm SHA-256: 4533a3c7188af5cfab3ee618be8754397451c62d503bb3784f5b6f61578a1817

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility