linux-announce AT lists.psi.ch
Subject: Linux Mailing List
List archive
- From: "Konrad Bucheli (PSI)" <konrad.bucheli AT psi.ch>
- To: linux-announce AT lists.psi.ch
- Subject: Re: [[Linux-announce] ] next kernel vulnerabilities for gaining root access
- Date: Thu, 16 Jul 2026 08:09:29 +0200
- Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=psi.ch; dmarc=pass action=none header.from=psi.ch; dkim=pass header.d=psi.ch; arc=none
- Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=xThulKcnNYW1bHzcScjyQcq0jJNbZFyNq4z9XzpYkNk=; b=EVhzyWKjgaWdpvCLU6DHpbT15uSlNnyQtC8Xq6nTg8XAWaz1mjgfHu1+AwB4qBMPXUKdwlGtqrUA0jREx2Nxal/Gu+rJphk2AQbpAOc/9qtL88xtwVqY/zopPqfzWOgaIkhtAZZpReImiws+DavRkrmfC+U/i+qsg+G0Jf7QdfUmw6+tzY2sdWwIeqDlJBlS0pBrjdoNdqFOw0XKZwMEu4TrFPQPgI90b2hJYkQWXUYGTbDHNRG0uTG9LQtTfXDPlmWj1VfBUDjeRfIDYFdMT6QrQc3QfVHKki4bxyuZ5gs+YLd3zFZKNtdDjCgemRkCBtzvStQU7IU0VVCiMHdnzw==
- Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=aVAhP8vc6e5npOzCNUqb3srwP8an9rq01Jtdy+K59s1f4lqk35yZH0f2CBzSsaNYX1+PD8+RYpCaaok2YFyZRRXQJbEOG9K2o68xwo6j++Ls5ThECUHGf+MwrcCSnTSi2WgjlsfMkt4ATMH+YzLQQoBaUI8I1DhmunMLBHmrLwRC3SKZFgbsFPUGkI0ycLGMA+zdRRfqJy8DxE7S7vCXRL1m0bYeA6MRtDzcYaQMwpt8G6yngfZ/E9YUXnZxoquyCufeOb5R0qdHPcNxmN1tQ81/TECObMEz4S+joTcf4MTMoSlbEFTXsABNhr/SqE0WfrB4BsUPqSFP/Ijs9SiJ0g==
- Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=psi.ch;
Dear Linux Admins
The RHEL8 kernel including the fix is now also available for updating.
Kind regards
Konrad
On 15.07.26 09:24, Konrad Bucheli (PSI) wrote:
Corrigendum: the RHEL8 kernel is not yet available internally. It is still waiting for a corresponding AFS driver to be released.
I will update you as soon as it is here.
On 14.07.2026 16:32, "Konrad Bucheli (PSI)" wrote:
Hi
Two vulnerabilities allowing for local privilege escalation* have been reported:
Bad Epoll - CVE-2026-46242 [1,2]
GhostLock - CVE-2026-43499 [3,4]
RedHat released new kernels with fixes:
RHEL8: kernel-4.18.0-553.143.1.el8_10
RHEL9: kkernel-5.14.0-687.25.1.el9_8
so you may update and reboot. There is no other mitigation possible.
You can do this e.g. by running:
dnf clean all
dnf update -y kernel
# or better "dnf update -y" for full update
puppet agent -t
reboot
*
How severe is a local privilege escalation vulnerability?
It allows any user/process (in this two cases also from within containers) to break out and get root permissions on the full machine.
If you trust all users and all software running on the system, you do not need to hurry very much updating.
If you deal with unknown users, or you load run or let run some random software or containers, then you should update and reboot rather soon.
[1] https://thehackernews.com/2026/07/new-bad-epoll-linux-kernel-flaw- lets.html
[2] https://access.redhat.com/security/cve/cve-2026-46242
[3] https://nebusec.ai/research/ionstack-part-2/
[4] https://access.redhat.com/security/cve/cve-2026-43499
Kind regards
Konrad
--
Paul Scherrer Institut
Konrad Bucheli
Linux Systems Engineer
Core Linux Research Services
Science IT Infrastructure and Services department (AWI)
OBBA/230
Forschungstrasse 111
5232 Villigen PSI
Switzerland
Phone: +41 56 310 27 24
konrad.bucheli AT psi.ch
www.psi.ch
-
[[Linux-announce] ] next kernel vulnerabilities for gaining root access,
Konrad Bucheli (PSI), 07/14/2026
-
Re: [[Linux-announce] ] next kernel vulnerabilities for gaining root access,
Konrad Bucheli (PSI), 07/15/2026
- Re: [[Linux-announce] ] next kernel vulnerabilities for gaining root access, Konrad Bucheli (PSI), 07/16/2026
-
Re: [[Linux-announce] ] next kernel vulnerabilities for gaining root access,
Konrad Bucheli (PSI), 07/15/2026
Archive powered by MHonArc 2.6.24.