网安资讯详情 - SecLens 情报雷达

网安资讯,一网打尽。汇集权威漏洞通告与行业要闻,结合分组浏览、智能过滤、RSS订阅 和 Webhook 推送,多通道拓展您的安全情报视野。

(RHSA-2026:25533) Critical: kernel security update

来源: redhat_advisory · 发布时间 2026-06-13 03:41 (UTC+08:00) · 抓取时间 2026-06-13 03:50 (UTC+08:00)

原文链接

摘要

Critical: kernel security update

正文

Overview Updated Packages Critical: kernel security update Security Advisory: Critical Identify and remediate systems affected by this advisory. View affected systems An update for kernel is now available for Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On and Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): kernel: nvme: avoid double free special payload (CVE-2024-41073) kernel: sctp: fix a potential overflow in sctp_ifwdtsn_skip (CVE-2023-53372) kernel: net: use dst_dev_rcu() in sk_setup_caps() (CVE-2025-40170) kernel: ipv6: use RCU in ip6_xmit() (CVE-2025-40135) kernel: ipv6: use RCU in ip6_output() (CVE-2025-40158) kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366) kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724) kernel: iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089) kernel: macvlan: fix possible UAF in macvlan_forward_source() (CVE-2026-23001) kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() (CVE-2026-23216) kernel: can: raw: fix ro->uniq use-after-free in raw_rcv() (CVE-2026-31532) kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685) kernel: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (CVE-2026-43037) kernel: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038) kernel: wifi: brcmfmac: validate bsscfg indices in IF events (CVE-2026-43110) kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 x86_64 Red Hat Enterprise Linux Server - AUS 8.6 x86_64 BZ - 2301637 - CVE-2024-41073 kernel: nvme: avoid double free special payload BZ - 2396405 - CVE-2023-53372 kernel: sctp: fix a potential overflow in sctp_ifwdtsn_skip BZ - 2414506 - CVE-2025-40170 kernel: net: use dst_dev_rcu() in sk_setup_caps() BZ - 2414521 - CVE-2025-40135 kernel: ipv6: use RCU in ip6_xmit() BZ - 2414523 - CVE-2025-40158 kernel: ipv6: use RCU in ip6_output() BZ - 2424881 - CVE-2025-68366 kernel: nbd: defer config unlock in nbd_genl_connect BZ - 2424886 - CVE-2025-68724 kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id BZ - 2429104 - CVE-2025-71089 kernel: iommu: disable SVA when CONFIG_X86 is set BZ - 2432664 - CVE-2026-23001 kernel: macvlan: fix possible UAF in macvlan_forward_source() BZ - 2440630 - CVE-2026-23216 kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() BZ - 2461107 - CVE-2026-31532 kernel: can: raw: fix ro->uniq use-after-free in raw_rcv() BZ - 2461759 - CVE-2026-31685 kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets BZ - 2464351 - CVE-2026-43037 kernel: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() BZ - 2464397 - CVE-2026-43038 kernel: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() BZ - 2467014 - CVE-2026-43110 kernel: wifi: brcmfmac: validate bsscfg indices in IF events BZ - 2467064 - CVE-2026-43190 kernel: netfilter: xt_tcpmss: check remaining length before reading optlen CVE-2023-53372 CVE-2024-41073 CVE-2025-40135 CVE-2025-40158 CVE-2025-40170 CVE-2025-68366 CVE-2025-68724 CVE-2025-71089 CVE-2026-23001 CVE-2026-23216 CVE-2026-31532 CVE-2026-31685 CVE-2026-43037 CVE-2026-43038 CVE-2026-43110 CVE-2026-43190 https://access.redhat.com/security/updates/classification/#critical The Red Hat security contact is [email protected] . More contact details at https://access.redhat.com/security/team/contact/ .

标签

扩展字段

{
  "cves": [
    "CVE-2023-53372",
    "CVE-2024-41073",
    "CVE-2025-40135",
    "CVE-2025-40158",
    "CVE-2025-40170",
    "CVE-2025-68366",
    "CVE-2025-68724",
    "CVE-2025-71089",
    "CVE-2026-23001",
    "CVE-2026-23216",
    "CVE-2026-31532",
    "CVE-2026-31685",
    "CVE-2026-43037",
    "CVE-2026-43038",
    "CVE-2026-43110",
    "CVE-2026-43190"
  ],
  "product_names": [
    "Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension",
    "Red Hat Enterprise Linux Server - AUS"
  ],
  "update_date": [
    "2026-06-12T19:41:48Z"
  ]
}