RHEL 10 : kernel (RHSA-2026:64775)

high Nessus Plugin ID 343877

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

The remote Redhat Enterprise Linux 10 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2026:64775 advisory.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

* kernel: can: bcm: add locking for bcm_op runtime updates (CVE-2025-38004)

* kernel: ipv6: add NULL checks for idev in SRv6 paths (CVE-2026-23442)

* kernel: udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503)

* kernel: ipv6: prevent possible UaF in addrconf_permanent_addr() (CVE-2026-43339)

* kernel: tcp: call sk_data_ready() after listener migration (CVE-2026-46015)

* kernel: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (CVE-2026-46266)

* kernel: flow_dissector: do not dissect PPPoE PFC frames (CVE-2026-46306)

* kernel: io_uring/poll: fix signed comparison in io_poll_get_ownership() (CVE-2026-52933)

* kernel: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (CVE-2026-53075)

* kernel: KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (CVE-2026-53277)

* kernel: ipv6: sit: reload inner IPv6 header after GSO offloads (CVE-2026-53228)

* kernel: net: add pskb_may_pull() to skb_gro_receive_list() (CVE-2026-53235)

* kernel: net: guard timestamp cmsgs to real error queue skbs (CVE-2026-53223)

* kernel: ipv6: mcast: Fix use-after-free when processing MLD queries (CVE-2026-53275)

* kernel: ipv6: anycast: insert aca into global hash under idev->lock (CVE-2026-53259)

* kernel: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (CVE-2026-64002)

* kernel: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() (CVE-2026-63993)

* kernel: fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req (CVE-2026-64265)

* kernel: nvmet-auth: validate reply message payload bounds against transfer length (CVE-2026-64319)

* kernel: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (CVE-2026-64287)

* kernel: rhashtable: clear stale iter->p on table restart (CVE-2026-64563)

* kernel: smb: client: fix double-free in SMB2_close() replay (CVE-2026-64597)

Bug Fix(es) and Enhancement(s):

* Customer needs netfilter: nfnetlink_queue: optimize verdict lookup with hash table patch [RHEL 10.2] (JIRA:RHEL-132852)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://access.redhat.com/errata/RHSA-2026:64775

https://access.redhat.com/security/updates/classification/#important

https://bugzilla.redhat.com/show_bug.cgi?id=2370992

https://bugzilla.redhat.com/show_bug.cgi?id=2454807

https://bugzilla.redhat.com/show_bug.cgi?id=2460736

https://bugzilla.redhat.com/show_bug.cgi?id=2468102

https://bugzilla.redhat.com/show_bug.cgi?id=2481936

https://bugzilla.redhat.com/show_bug.cgi?id=2484456

https://bugzilla.redhat.com/show_bug.cgi?id=2486463

https://bugzilla.redhat.com/show_bug.cgi?id=2492097

https://bugzilla.redhat.com/show_bug.cgi?id=2492295

https://bugzilla.redhat.com/show_bug.cgi?id=2492725

https://bugzilla.redhat.com/show_bug.cgi?id=2492733

https://bugzilla.redhat.com/show_bug.cgi?id=2492745

https://bugzilla.redhat.com/show_bug.cgi?id=2492811

https://bugzilla.redhat.com/show_bug.cgi?id=2492841

https://bugzilla.redhat.com/show_bug.cgi?id=2492850

https://bugzilla.redhat.com/show_bug.cgi?id=2502363

https://bugzilla.redhat.com/show_bug.cgi?id=2502369

https://bugzilla.redhat.com/show_bug.cgi?id=2507041

https://bugzilla.redhat.com/show_bug.cgi?id=2507096

https://bugzilla.redhat.com/show_bug.cgi?id=2507129

https://bugzilla.redhat.com/show_bug.cgi?id=2510892

https://bugzilla.redhat.com/show_bug.cgi?id=2511932

https://issues.redhat.com/browse/RHEL-132852

http://www.nessus.org/u?91087fbe

Plugin Details

Severity: High

ID: 343877

File Name: redhat-RHSA-2026-64775.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/8/2026

Updated: 9/8/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.8

Percentile: 99.33

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Medium

Base Score: 6.2

Temporal Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:C

CVSS Score Source: CVE-2025-38004

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.4

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:redhat:enterprise_linux:10.2, p-cpe:/a:redhat:enterprise_linux:kernel-64k-core, p-cpe:/a:redhat:enterprise_linux:kernel-64k-debug-core, p-cpe:/a:redhat:enterprise_linux:kernel-64k-debug-devel-matched, p-cpe:/a:redhat:enterprise_linux:kernel-64k-debug-devel, p-cpe:/a:redhat:enterprise_linux:kernel-64k-debug-modules-core, p-cpe:/a:redhat:enterprise_linux:kernel-64k-debug-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-64k-debug-modules, p-cpe:/a:redhat:enterprise_linux:kernel-64k-debug, p-cpe:/a:redhat:enterprise_linux:kernel-64k-devel-matched, p-cpe:/a:redhat:enterprise_linux:kernel-64k-devel, p-cpe:/a:redhat:enterprise_linux:kernel-64k-modules-core, p-cpe:/a:redhat:enterprise_linux:kernel-64k-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-64k-modules, p-cpe:/a:redhat:enterprise_linux:kernel-64k, p-cpe:/a:redhat:enterprise_linux:kernel-core, p-cpe:/a:redhat:enterprise_linux:kernel-debug-core, p-cpe:/a:redhat:enterprise_linux:kernel-debug-devel-matched, p-cpe:/a:redhat:enterprise_linux:kernel-debug-devel, p-cpe:/a:redhat:enterprise_linux:kernel-debug-modules-core, p-cpe:/a:redhat:enterprise_linux:kernel-debug-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-debug-modules, p-cpe:/a:redhat:enterprise_linux:kernel-debug-uki-virt, p-cpe:/a:redhat:enterprise_linux:kernel-debug, p-cpe:/a:redhat:enterprise_linux:kernel-devel-matched, p-cpe:/a:redhat:enterprise_linux:kernel-devel, p-cpe:/a:redhat:enterprise_linux:kernel-modules-core, p-cpe:/a:redhat:enterprise_linux:kernel-modules-extra-matched, p-cpe:/a:redhat:enterprise_linux:kernel-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-modules, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-core, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-debug-core, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-debug-devel, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-debug-modules-core, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-debug-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-debug-modules, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-debug, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-devel, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-modules-core, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-modules, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k, p-cpe:/a:redhat:enterprise_linux:kernel-rt-core, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug-core, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug-devel, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug-modules-core, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug-modules, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug, p-cpe:/a:redhat:enterprise_linux:kernel-rt-devel, p-cpe:/a:redhat:enterprise_linux:kernel-rt-modules-core, p-cpe:/a:redhat:enterprise_linux:kernel-rt-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-rt-modules, p-cpe:/a:redhat:enterprise_linux:kernel-rt, p-cpe:/a:redhat:enterprise_linux:kernel-tools-libs-devel, p-cpe:/a:redhat:enterprise_linux:kernel-tools-libs, p-cpe:/a:redhat:enterprise_linux:kernel-tools, p-cpe:/a:redhat:enterprise_linux:kernel-uki-virt-addons, p-cpe:/a:redhat:enterprise_linux:kernel-uki-virt, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-core, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-devel-matched, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-devel, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-modules-core, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-modules, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump, p-cpe:/a:redhat:enterprise_linux:kernel, p-cpe:/a:redhat:enterprise_linux:libperf, p-cpe:/a:redhat:enterprise_linux:perf, p-cpe:/a:redhat:enterprise_linux:python3-perf, p-cpe:/a:redhat:enterprise_linux:rtla, p-cpe:/a:redhat:enterprise_linux:rv

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/8/2026

Vulnerability Publication Date: 6/8/2025

Reference Information

CVE: CVE-2025-38004, CVE-2026-23442, CVE-2026-31503, CVE-2026-43339, CVE-2026-46015, CVE-2026-46266, CVE-2026-46306, CVE-2026-52933, CVE-2026-53075, CVE-2026-53223, CVE-2026-53228, CVE-2026-53235, CVE-2026-53259, CVE-2026-53275, CVE-2026-53277, CVE-2026-63993, CVE-2026-64002, CVE-2026-64265, CVE-2026-64287, CVE-2026-64319, CVE-2026-64563, CVE-2026-64597

CWE: 1024, 125, 1287, 253, 266, 366, 415, 476, 805, 820, 821, 825, 843

RHSA: 2026:64775