Skip to Content.
Sympa Menu

linux-announce - Re: [[Linux-announce] ] next kernel vulnerabilities for gaining root access

linux-announce AT lists.psi.ch

Subject: Linux Mailing List

List archive

Re: [[Linux-announce] ] next kernel vulnerabilities for gaining root access


Chronological Thread  
  • From: "Konrad Bucheli (PSI)" <konrad.bucheli AT psi.ch>
  • To: linux-announce AT lists.psi.ch
  • Subject: Re: [[Linux-announce] ] next kernel vulnerabilities for gaining root access
  • Date: Wed, 15 Jul 2026 09:24:23 +0200
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=psi.ch; dmarc=pass action=none header.from=psi.ch; dkim=pass header.d=psi.ch; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=r/gSVc6L0AD9du4NJ2W9f2FXdBzkNeuCHCqwE66Qku8=; b=YayrcW1o1lHxlV7wMTAj9TgMDVNlxYa2gWPZ3RO1ZrcUvNTAPhTh5mS8h60tpclpxrakI5w68ISJuXNqEU2E6EGqgxZ3uhqeksj4bTblz8dQm4nQtr7R+HmuN69u4e3+U1UoAVZcjjy4ThTvZU8oeSFS0s8zEEtR+NumS5+wLHLhvqste63r+ZRGS0HI8fqC2bn0rktisytoNcry0LuI35r4Qcp1adtU/AO6JIhT4m9TFuLr4vt6KEkulszlkZLH2FUP+B4pgFfynzZzWCknNtEPWS4k/PFaix5/mtuo08N8qG5Rmp/YmE1KlijgLuiiQxvHmnhPiCuM3P2/h2XhOA==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=PzkVy8kfphbAD10/AZWEtSZPSpL5JT7ZZzDF5bHBMCNOB8ZEUlM4Up5Pizgk3iaqR/XBadEy2dGlE/uBb93nqS00ssgvqmJdfUOpMTf1ctwAaN0QghfmEvybgohOXrLkLS/dv3M+G5Emmvo2mlmtEdJ8DOGVDMe88z/z+31j/O0JspUusVc9h2lC7uqiO7ULjja2f0QA6yjdj4DTWibX6pwcA8XbMB9XZ96eGu/sZ4zSxJk1jW9uJLoa5m/ZY1z676HT5uwh9LGXaURUDehqsqM88NIgwQQe+MitWr44dCAUwnRqRwG6eX1er1Mw2796ZYp3N2CEAADSdaFs+Q7+5A==
  • Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=psi.ch;

Corrigendum: the RHEL8 kernel is not yet available internally. It is still waiting for a corresponding AFS driver to be released.
I will update you as soon as it is here.

On 14.07.2026 16:32, "Konrad Bucheli (PSI)" wrote:
Hi

Two vulnerabilities allowing for local privilege escalation* have been reported:

   Bad Epoll - CVE-2026-46242 [1,2]
   GhostLock - CVE-2026-43499 [3,4]

RedHat released new kernels with fixes:

    RHEL8: kernel-4.18.0-553.143.1.el8_10
    RHEL9: kkernel-5.14.0-687.25.1.el9_8

so you may update and reboot. There is no other mitigation possible.
You can do this e.g. by running:

    dnf clean all
    dnf update -y kernel
    # or better "dnf update -y" for full update
    puppet agent -t
    reboot


*
How severe is a local privilege escalation vulnerability?
It allows any user/process (in this two cases also from within containers) to break out and get root permissions on the full machine.
If you trust all users and all software running on the system, you do not need to hurry very much updating.
If you deal with unknown users, or you load run or let run some random software or containers, then you should update and reboot rather soon.


[1] https://thehackernews.com/2026/07/new-bad-epoll-linux-kernel-flaw- lets.html
[2] https://access.redhat.com/security/cve/cve-2026-46242
[3] https://nebusec.ai/research/ionstack-part-2/
[4] https://access.redhat.com/security/cve/cve-2026-43499

Kind regards
Konrad





Archive powered by MHonArc 2.6.24.

Top of Page