RHEL 8 : kernel (RHSA-2026:75747)

high Nessus Plugin ID 362970

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

The remote Redhat Enterprise Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2026:75747 advisory.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

* kernel: Linux kernel: Use-after-free in xc5000 tuner driver due to race condition (CVE-2025-39994)

* kernel: gfs2: Fix unlikely race in gdlm_put_lock (CVE-2025-40242)

* kernel: Linux kernel: Denial of Service in RDMA/bnxt_re driver due to race condition during QP destruction (CVE-2023-54048)

* kernel: nvme-pci: fix mempool alloc size (CVE-2022-50756)

* kernel: Linux kernel: Denial of Service in QFQ scheduler via child qlen manipulation (CVE-2026-23105)

* kernel: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856)

* kernel: gfs2: Fix slab-use-after-free in qd_put (CVE-2026-45861)

* kernel: net/sched: act_ct: Only release RCU read lock after ct_ft (CVE-2026-46319)

* kernel: gfs2: add some missing log locking (CVE-2026-53049)

* kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 (CVE-2026-52972)

* kernel: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (CVE-2026-53230)

* kernel: ipvs: clear the svc scheduler ptr early on edit (CVE-2026-53270)

* kernel: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-63829)

* kernel: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (CVE-2026-63794)

* kernel: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (CVE-2026-63992)

* kernel: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() (CVE-2026-63994)

* kernel: vxlan: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-68432)

* kernel: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-72052)

* kernel: netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst (CVE-2026-72255)

* kernel: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (CVE-2026-74516)

* kernel: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (CVE-2026-74569)

* kernel: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (CVE-2026-74669)

* kernel: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev (CVE-2026-74744)

* kernel: netfilter: flowtable: publish GC-visible tuple last (CVE-2026-74746)

* kernel: KVM: s390: vsie: zero stale crypto bits (CVE-2026-80921)

* kernel: nvme-tcp: fix host memory disclosure on R2T for a read command (CVE-2026-89481)

* kernel: nvme: add missing SRCU grace period in error path (CVE-2026-89972)

* kernel: nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() (CVE-2026-90227)

* kernel: netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() (CVE-2026-97417)

Bug Fix(es) and Enhancement(s):

* RHEL8.10 - s390/vfio_ccw: Error path cleanups (JIRA:RHEL-252194)

* RHEL8.10 - s390/topology: Use zero-based numbering (JIRA:RHEL-252199)

* [nfs rhel8.10] Disable async copy on nfsd side (JIRA:RHEL-266661)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://access.redhat.com/errata/RHSA-2026:75747

https://access.redhat.com/security/updates/classification/#important

https://bugzilla.redhat.com/show_bug.cgi?id=2404123

https://bugzilla.redhat.com/show_bug.cgi?id=2418819

https://bugzilla.redhat.com/show_bug.cgi?id=2425013

https://bugzilla.redhat.com/show_bug.cgi?id=2425209

https://bugzilla.redhat.com/show_bug.cgi?id=2436789

https://bugzilla.redhat.com/show_bug.cgi?id=2482129

https://bugzilla.redhat.com/show_bug.cgi?id=2482143

https://bugzilla.redhat.com/show_bug.cgi?id=2486979

https://bugzilla.redhat.com/show_bug.cgi?id=2492276

https://bugzilla.redhat.com/show_bug.cgi?id=2492364

https://bugzilla.redhat.com/show_bug.cgi?id=2492728

https://bugzilla.redhat.com/show_bug.cgi?id=2492853

https://bugzilla.redhat.com/show_bug.cgi?id=2502230

https://bugzilla.redhat.com/show_bug.cgi?id=2502241

https://bugzilla.redhat.com/show_bug.cgi?id=2502431

https://bugzilla.redhat.com/show_bug.cgi?id=2502444

https://bugzilla.redhat.com/show_bug.cgi?id=2514441

https://bugzilla.redhat.com/show_bug.cgi?id=2516306

https://bugzilla.redhat.com/show_bug.cgi?id=2516717

https://bugzilla.redhat.com/show_bug.cgi?id=2516998

https://bugzilla.redhat.com/show_bug.cgi?id=2517052

https://bugzilla.redhat.com/show_bug.cgi?id=2521375

https://bugzilla.redhat.com/show_bug.cgi?id=2524431

https://bugzilla.redhat.com/show_bug.cgi?id=2524483

https://bugzilla.redhat.com/show_bug.cgi?id=2531066

https://bugzilla.redhat.com/show_bug.cgi?id=2532184

https://bugzilla.redhat.com/show_bug.cgi?id=2535140

https://bugzilla.redhat.com/show_bug.cgi?id=2536346

https://bugzilla.redhat.com/show_bug.cgi?id=2540479

http://www.nessus.org/u?0954ab8e

Plugin Details

Severity: High

ID: 362970

File Name: redhat-RHSA-2026-75747.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/5/2026

Updated: 10/5/2026

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7

Percentile: 98.06

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-63794

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:redhat:enterprise_linux:8, cpe:/o:redhat:rhel_eus:8.10, p-cpe:/a:redhat:enterprise_linux:bpftool, p-cpe:/a:redhat:enterprise_linux:kernel-core, p-cpe:/a:redhat:enterprise_linux:kernel-debug-core, p-cpe:/a:redhat:enterprise_linux:kernel-debug-devel, p-cpe:/a:redhat:enterprise_linux:kernel-debug-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-debug-modules, p-cpe:/a:redhat:enterprise_linux:kernel-debug, p-cpe:/a:redhat:enterprise_linux:kernel-devel, p-cpe:/a:redhat:enterprise_linux:kernel-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-modules, p-cpe:/a:redhat:enterprise_linux:kernel-tools-libs-devel, p-cpe:/a:redhat:enterprise_linux:kernel-tools-libs, p-cpe:/a:redhat:enterprise_linux:kernel-tools, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-core, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-devel, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-modules, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump, p-cpe:/a:redhat:enterprise_linux:kernel, p-cpe:/a:redhat:enterprise_linux:perf, p-cpe:/a:redhat:enterprise_linux:python3-perf

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 10/5/2026

Vulnerability Publication Date: 7/21/2021

Reference Information

CVE: CVE-2022-50756, CVE-2023-54048, CVE-2025-39994, CVE-2025-40242, CVE-2026-23105, CVE-2026-45856, CVE-2026-45861, CVE-2026-46319, CVE-2026-52972, CVE-2026-53049, CVE-2026-53230, CVE-2026-53270, CVE-2026-63794, CVE-2026-63829, CVE-2026-63992, CVE-2026-63994, CVE-2026-68432, CVE-2026-72052, CVE-2026-72255, CVE-2026-74516, CVE-2026-74569, CVE-2026-74669, CVE-2026-74744, CVE-2026-74746, CVE-2026-80921, CVE-2026-89481, CVE-2026-89972, CVE-2026-90227, CVE-2026-97417

CWE: 119, 124, 125, 1284, 190, 201, 266, 366, 414, 416, 662, 664, 787, 805, 825, 826, 843, 908, 911

RHSA: 2026:75747