Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:53989 - Security Advisory
Issued:
2026-08-12
Updated:
2026-08-12

RHSA-2026:53989 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: kernel security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for kernel is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787)
  • kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112)
  • kernel: md/bitmap: fix GPF in write_page caused by resize race (CVE-2026-43163)
  • kernel: xen: AMD Zen 2 Processors: Privilege escalation via improper CPU cache isolation (CVE-2025-54518)
  • kernel: dm log: fix out-of-bounds write due to region_count overflow (CVE-2026-53059)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

The system must be rebooted for this update to take effect.

Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture.

Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available.

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.6 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.6 x86_64

Fixes

  • BZ - 2464092 - CVE-2026-31787 kernel: xen/privcmd: fix double free via VMA splitting
  • BZ - 2467015 - CVE-2026-43112 kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath
  • BZ - 2467059 - CVE-2026-43163 kernel: md/bitmap: fix GPF in write_page caused by resize race
  • BZ - 2477784 - CVE-2025-54518 kernel: xen: AMD Zen 2 Processors: Privilege escalation via improper CPU cache isolation
  • BZ - 2492277 - CVE-2026-53059 kernel: dm log: fix out-of-bounds write due to region_count overflow

CVEs

  • CVE-2025-54518
  • CVE-2026-31787
  • CVE-2026-43112
  • CVE-2026-43163
  • CVE-2026-53059

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.6

SRPM
kernel-4.18.0-372.206.1.el8_6.src.rpm SHA-256: a7f5b65d307f85977c1b53116c32db4adf548209f36c6f7cd7dc082922f6d3a7
x86_64
bpftool-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: f395a0615fbd0f82389ef4fb1bca3bed6da07fb23566a5928248669552419da2
bpftool-debuginfo-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 74a97b040f1d3024ff0e5b075f42de86a57702678084e0463636bb8d8f7bd1ca
kernel-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: c9251e19b5742e2232239b6d09b61cc41723acd0f074fb3e0120bfd73149d505
kernel-abi-stablelists-4.18.0-372.206.1.el8_6.noarch.rpm SHA-256: 1b4a594f74fbdb098d99c11875059718200eed944d4ee0ec976b921d6e83e858
kernel-core-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 8c1e1bf37929b0135a8c014d200ea71ef81c044dc2c4549a3fc035957c0874a0
kernel-cross-headers-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: e4c798b25987623a504b73467603eafa803408b505566a4b16653282926f21d4
kernel-debug-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 9bbb40092484779613b57b3b71afcbe51fd2ffb39ceeba89f43aefe2cbdfaf29
kernel-debug-core-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 64bcb7e75ac8d879c640fa8e29572ad62a1f51c6b302c0246dd8b2e35f13eac2
kernel-debug-debuginfo-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: d1bd775e883643d1b4ae5b219bb7409981d6d7a5398680439b4bf86c4419f750
kernel-debug-devel-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 105e870f53384b54481d2cb65c5aa16e923756749c19acf5b07c4d1074b8bcf8
kernel-debug-modules-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 004536b1dc26ae2ccc0126c8d0e9818a86eebbced301c71917e5043120513d7e
kernel-debug-modules-extra-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: fdebd2b5f7cc24351adb6882dcba00ebed52b4d5a795eddcc9cf7f8e7a5821a2
kernel-debuginfo-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: d1fc08aaf496568c06abf263c1ccf02364579f2a64f71c294bd963226111d2ac
kernel-debuginfo-common-x86_64-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: f408b076af838dedfddeb187eba3fb5312c80c9389f429897b4621410440cf5c
kernel-devel-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 1ea3d1754cc06a9c0ada4691e1d7057f84d086b6d0b7b2857c9ae020d1574534
kernel-doc-4.18.0-372.206.1.el8_6.noarch.rpm SHA-256: 8de3b067a0f0805eeabbd0b4b723bbb9929b1ec2ddbc4193adda321a27a82ca3
kernel-headers-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: f4a6d6ee8ab515c5740d4496292efdd10609b88748ec7de9ac8337f4bb0842ba
kernel-modules-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: d1c6958bd67e417a17b02c48a2353d9c9340ff1a1af5bc7d196a1cc0662ee6e0
kernel-modules-extra-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 412246af36349c4225f13b3e5e29db8d1e93ef7d96137f115ebc18d6386c63f2
kernel-tools-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: db26f73bd3c3336d0942253ccd225b5485362a969dca5ec7abbed87a38d2610b
kernel-tools-debuginfo-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 2f156de10903fca02f5c9dd71800ec97a499c36b718f8ee8239eb1fd2ee45e21
kernel-tools-libs-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: f7cb991e140212f458306520ccd3b5fd504b049d1735fdb11ad1c1b0b11286f0
perf-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: a68a1538dcf1416286e368173d8129b15514ee9521100cd616913429d55859b5
perf-debuginfo-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 710820c0b8ffb50a4f90c64fda5383a3abd6a171b990d5b71bf234a44d94c540
python3-perf-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 3339b90e9dfbdd36a76f00b843cf67c57d76bbd2df6c1f48133d2038d846eadd
python3-perf-debuginfo-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 69b65656ee03d7b7e6e480dee838f5b387e18c82f35856439d4e0d4e09cc1208

Red Hat Enterprise Linux Server - AUS 8.6

SRPM
kernel-4.18.0-372.206.1.el8_6.src.rpm SHA-256: a7f5b65d307f85977c1b53116c32db4adf548209f36c6f7cd7dc082922f6d3a7
x86_64
bpftool-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: f395a0615fbd0f82389ef4fb1bca3bed6da07fb23566a5928248669552419da2
bpftool-debuginfo-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 74a97b040f1d3024ff0e5b075f42de86a57702678084e0463636bb8d8f7bd1ca
kernel-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: c9251e19b5742e2232239b6d09b61cc41723acd0f074fb3e0120bfd73149d505
kernel-abi-stablelists-4.18.0-372.206.1.el8_6.noarch.rpm SHA-256: 1b4a594f74fbdb098d99c11875059718200eed944d4ee0ec976b921d6e83e858
kernel-core-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 8c1e1bf37929b0135a8c014d200ea71ef81c044dc2c4549a3fc035957c0874a0
kernel-cross-headers-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: e4c798b25987623a504b73467603eafa803408b505566a4b16653282926f21d4
kernel-debug-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 9bbb40092484779613b57b3b71afcbe51fd2ffb39ceeba89f43aefe2cbdfaf29
kernel-debug-core-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 64bcb7e75ac8d879c640fa8e29572ad62a1f51c6b302c0246dd8b2e35f13eac2
kernel-debug-debuginfo-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: d1bd775e883643d1b4ae5b219bb7409981d6d7a5398680439b4bf86c4419f750
kernel-debug-devel-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 105e870f53384b54481d2cb65c5aa16e923756749c19acf5b07c4d1074b8bcf8
kernel-debug-modules-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 004536b1dc26ae2ccc0126c8d0e9818a86eebbced301c71917e5043120513d7e
kernel-debug-modules-extra-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: fdebd2b5f7cc24351adb6882dcba00ebed52b4d5a795eddcc9cf7f8e7a5821a2
kernel-debuginfo-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: d1fc08aaf496568c06abf263c1ccf02364579f2a64f71c294bd963226111d2ac
kernel-debuginfo-common-x86_64-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: f408b076af838dedfddeb187eba3fb5312c80c9389f429897b4621410440cf5c
kernel-devel-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 1ea3d1754cc06a9c0ada4691e1d7057f84d086b6d0b7b2857c9ae020d1574534
kernel-doc-4.18.0-372.206.1.el8_6.noarch.rpm SHA-256: 8de3b067a0f0805eeabbd0b4b723bbb9929b1ec2ddbc4193adda321a27a82ca3
kernel-headers-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: f4a6d6ee8ab515c5740d4496292efdd10609b88748ec7de9ac8337f4bb0842ba
kernel-modules-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: d1c6958bd67e417a17b02c48a2353d9c9340ff1a1af5bc7d196a1cc0662ee6e0
kernel-modules-extra-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 412246af36349c4225f13b3e5e29db8d1e93ef7d96137f115ebc18d6386c63f2
kernel-tools-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: db26f73bd3c3336d0942253ccd225b5485362a969dca5ec7abbed87a38d2610b
kernel-tools-debuginfo-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 2f156de10903fca02f5c9dd71800ec97a499c36b718f8ee8239eb1fd2ee45e21
kernel-tools-libs-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: f7cb991e140212f458306520ccd3b5fd504b049d1735fdb11ad1c1b0b11286f0
perf-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: a68a1538dcf1416286e368173d8129b15514ee9521100cd616913429d55859b5
perf-debuginfo-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 710820c0b8ffb50a4f90c64fda5383a3abd6a171b990d5b71bf234a44d94c540
python3-perf-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 3339b90e9dfbdd36a76f00b843cf67c57d76bbd2df6c1f48133d2038d846eadd
python3-perf-debuginfo-4.18.0-372.206.1.el8_6.x86_64.rpm SHA-256: 69b65656ee03d7b7e6e480dee838f5b387e18c82f35856439d4e0d4e09cc1208

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility