Skip to Content.
Sympa Menu

linux-announce - Re: [[Linux-announce] ] next kernel vulnerabilities for gaining root access

linux-announce AT lists.psi.ch

Subject: Linux Mailing List

List archive

Re: [[Linux-announce] ] next kernel vulnerabilities for gaining root access


Chronological Thread  
  • From: "Konrad Bucheli (PSI)" <konrad.bucheli AT psi.ch>
  • To: linux-announce AT lists.psi.ch
  • Subject: Re: [[Linux-announce] ] next kernel vulnerabilities for gaining root access
  • Date: Thu, 16 Jul 2026 08:09:29 +0200
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=psi.ch; dmarc=pass action=none header.from=psi.ch; dkim=pass header.d=psi.ch; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=xThulKcnNYW1bHzcScjyQcq0jJNbZFyNq4z9XzpYkNk=; b=EVhzyWKjgaWdpvCLU6DHpbT15uSlNnyQtC8Xq6nTg8XAWaz1mjgfHu1+AwB4qBMPXUKdwlGtqrUA0jREx2Nxal/Gu+rJphk2AQbpAOc/9qtL88xtwVqY/zopPqfzWOgaIkhtAZZpReImiws+DavRkrmfC+U/i+qsg+G0Jf7QdfUmw6+tzY2sdWwIeqDlJBlS0pBrjdoNdqFOw0XKZwMEu4TrFPQPgI90b2hJYkQWXUYGTbDHNRG0uTG9LQtTfXDPlmWj1VfBUDjeRfIDYFdMT6QrQc3QfVHKki4bxyuZ5gs+YLd3zFZKNtdDjCgemRkCBtzvStQU7IU0VVCiMHdnzw==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=aVAhP8vc6e5npOzCNUqb3srwP8an9rq01Jtdy+K59s1f4lqk35yZH0f2CBzSsaNYX1+PD8+RYpCaaok2YFyZRRXQJbEOG9K2o68xwo6j++Ls5ThECUHGf+MwrcCSnTSi2WgjlsfMkt4ATMH+YzLQQoBaUI8I1DhmunMLBHmrLwRC3SKZFgbsFPUGkI0ycLGMA+zdRRfqJy8DxE7S7vCXRL1m0bYeA6MRtDzcYaQMwpt8G6yngfZ/E9YUXnZxoquyCufeOb5R0qdHPcNxmN1tQ81/TECObMEz4S+joTcf4MTMoSlbEFTXsABNhr/SqE0WfrB4BsUPqSFP/Ijs9SiJ0g==
  • Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=psi.ch;

Dear Linux Admins

The RHEL8 kernel including the fix is now also available for updating.

Kind regards
Konrad

On 15.07.26 09:24, Konrad Bucheli (PSI) wrote:
Corrigendum: the RHEL8 kernel is not yet available internally. It is still waiting for a corresponding AFS driver to be released.
I will update you as soon as it is here.

On 14.07.2026 16:32, "Konrad Bucheli (PSI)" wrote:
Hi

Two vulnerabilities allowing for local privilege escalation* have been reported:

    Bad Epoll - CVE-2026-46242 [1,2]
    GhostLock - CVE-2026-43499 [3,4]

RedHat released new kernels with fixes:

     RHEL8: kernel-4.18.0-553.143.1.el8_10
     RHEL9: kkernel-5.14.0-687.25.1.el9_8

so you may update and reboot. There is no other mitigation possible.
You can do this e.g. by running:

     dnf clean all
     dnf update -y kernel
     # or better "dnf update -y" for full update
     puppet agent -t
     reboot


*
How severe is a local privilege escalation vulnerability?
It allows any user/process (in this two cases also from within containers) to break out and get root permissions on the full machine.
If you trust all users and all software running on the system, you do not need to hurry very much updating.
If you deal with unknown users, or you load run or let run some random software or containers, then you should update and reboot rather soon.


[1] https://thehackernews.com/2026/07/new-bad-epoll-linux-kernel-flaw- lets.html
[2] https://access.redhat.com/security/cve/cve-2026-46242
[3] https://nebusec.ai/research/ionstack-part-2/
[4] https://access.redhat.com/security/cve/cve-2026-43499

Kind regards
Konrad



--
Paul Scherrer Institut
Konrad Bucheli
Linux Systems Engineer
Core Linux Research Services
Science IT Infrastructure and Services department (AWI)
OBBA/230
Forschungstrasse 111
5232 Villigen PSI
Switzerland

Phone: +41 56 310 27 24
konrad.bucheli AT psi.ch
www.psi.ch




Archive powered by MHonArc 2.6.24.

Top of Page