RHEL 8 : kernel (RHSA-2026:70402)

high Nessus Plugin ID 349148

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

The remote Redhat Enterprise Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2026:70402 advisory.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)

* kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread (CVE-2023-54120)

* kernel: Bluetooth: L2CAP: Fix potential user-after-free (CVE-2023-54214)

* kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb (CVE-2025-71082)

* kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)

* kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)

* kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043)

* kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing (CVE-2026-46133)

* kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)

* kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)

* kernel: iommu/amd: Fix clone_alias() to use the original device's devid (CVE-2026-53053)

* kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)

* kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)

* kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)

* kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)

* kernel: Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CVE-2026-63947)

* kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (CVE-2026-64534)

* kernel: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (CVE-2026-64582)

* kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (CVE-2026-68293)

* kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios (CVE-2026-68188)

Bug Fix(es) and Enhancement(s):

* Intel IOMMU: possible circular locking dependency (JIRA:RHEL-243217)

* xfs: repeated xfs_trans_cancel called from xfs_iomap_write_direct (JIRA:RHEL-251578)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://access.redhat.com/errata/RHSA-2026:70402

https://access.redhat.com/security/updates/classification/#important

https://bugzilla.redhat.com/show_bug.cgi?id=2403545

https://bugzilla.redhat.com/show_bug.cgi?id=2425183

https://bugzilla.redhat.com/show_bug.cgi?id=2426069

https://bugzilla.redhat.com/show_bug.cgi?id=2429054

https://bugzilla.redhat.com/show_bug.cgi?id=2468050

https://bugzilla.redhat.com/show_bug.cgi?id=2481940

https://bugzilla.redhat.com/show_bug.cgi?id=2482127

https://bugzilla.redhat.com/show_bug.cgi?id=2482550

https://bugzilla.redhat.com/show_bug.cgi?id=2492092

https://bugzilla.redhat.com/show_bug.cgi?id=2492278

https://bugzilla.redhat.com/show_bug.cgi?id=2492310

https://bugzilla.redhat.com/show_bug.cgi?id=2492717

https://bugzilla.redhat.com/show_bug.cgi?id=2492795

https://bugzilla.redhat.com/show_bug.cgi?id=2502218

https://bugzilla.redhat.com/show_bug.cgi?id=2502346

https://bugzilla.redhat.com/show_bug.cgi?id=2502388

https://bugzilla.redhat.com/show_bug.cgi?id=2507399

https://bugzilla.redhat.com/show_bug.cgi?id=2511448

https://bugzilla.redhat.com/show_bug.cgi?id=2513150

https://bugzilla.redhat.com/show_bug.cgi?id=2513222

http://www.nessus.org/u?602c72f6

Plugin Details

Severity: High

ID: 349148

File Name: redhat-RHSA-2026-70402.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/23/2026

Updated: 9/23/2026

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.3

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-71082

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:redhat:enterprise_linux:8, cpe:/o:redhat:rhel_eus:8.10, p-cpe:/a:redhat:enterprise_linux:bpftool, p-cpe:/a:redhat:enterprise_linux:kernel-core, p-cpe:/a:redhat:enterprise_linux:kernel-debug-core, p-cpe:/a:redhat:enterprise_linux:kernel-debug-devel, p-cpe:/a:redhat:enterprise_linux:kernel-debug-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-debug-modules, p-cpe:/a:redhat:enterprise_linux:kernel-debug, p-cpe:/a:redhat:enterprise_linux:kernel-devel, p-cpe:/a:redhat:enterprise_linux:kernel-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-modules, p-cpe:/a:redhat:enterprise_linux:kernel-tools-libs-devel, p-cpe:/a:redhat:enterprise_linux:kernel-tools-libs, p-cpe:/a:redhat:enterprise_linux:kernel-tools, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-core, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-devel, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-modules, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump, p-cpe:/a:redhat:enterprise_linux:kernel, p-cpe:/a:redhat:enterprise_linux:perf, p-cpe:/a:redhat:enterprise_linux:python3-perf

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/22/2026

Vulnerability Publication Date: 7/21/2021

CISA Known Exploited Vulnerability Due Dates: 9/21/2026

Reference Information

CVE: CVE-2023-54120, CVE-2023-54214, CVE-2025-39964, CVE-2025-71082, CVE-2026-43334, CVE-2026-45894, CVE-2026-46043, CVE-2026-46133, CVE-2026-52918, CVE-2026-53053, CVE-2026-53062, CVE-2026-53254, CVE-2026-53256, CVE-2026-63823, CVE-2026-63947, CVE-2026-63975, CVE-2026-64534, CVE-2026-64582, CVE-2026-68188, CVE-2026-68293

CWE: 120, 125, 1284, 191, 322, 364, 366, 367, 414, 416, 694, 820, 825, 826, 911

RHSA: 2026:70402