Changeflow GovPing Data Privacy & Cybersecurity Red Hat Linux Kernel Vulnerabilities
Priority review Notice Added Final

Red Hat Linux Kernel Vulnerabilities

Favicon for www.cert.ssi.gouv.fr CERT-FR Security Advisories
Published March 20th, 2026
Detected March 20th, 2026
Email

Summary

CERT-FR has issued a notice regarding multiple vulnerabilities discovered in the Red Hat Linux kernel. These vulnerabilities could allow attackers to achieve arbitrary code execution, privilege escalation, and data confidentiality breaches. Affected systems require patching as detailed in Red Hat's security bulletin.

What changed

CERT-FR, the French national cybersecurity agency, has published a notice (CERTFR-2026-AVI-0330) detailing multiple critical vulnerabilities found in the Red Hat Linux kernel. These flaws, referenced by various CVEs including CVE-2025-38106 and CVE-2026-23001, pose significant risks such as arbitrary code execution, privilege escalation, and data breaches. The advisory specifically lists affected Red Hat Enterprise Linux and CodeReady Linux Builder versions across multiple architectures.

Organizations utilizing the affected Red Hat Linux distributions must urgently consult Red Hat's security bulletin (RHSA-2026:4012) for specific patch information and apply the necessary updates. Failure to do so could expose systems to severe security compromises, leading to potential data loss, service disruption, and policy violations. This notice serves as an alert to implement immediate remediation actions to mitigate these risks.

What to do next

  1. Consult Red Hat security bulletin RHSA-2026:4012 for patch details
  2. Apply necessary security patches to affected Red Hat Linux systems
  3. Review system logs for any signs of compromise related to these vulnerabilities

Source document (simplified)

Premier Ministre S.G.D.S.N

Agence nationale
de la sécurité des
systèmes d'information

Paris, le 20 mars 2026 N° CERTFR-2026-AVI-0330 Affaire suivie par: CERT-FR

Avis du CERT-FR

Objet: Multiples vulnérabilités dans le noyau Linux de Red Hat

Gestion du document

| Référence | CERTFR-2026-AVI-0330 |
| Titre | Multiples vulnérabilités dans le noyau Linux de Red Hat |
| Date de la première version | 20 mars 2026 |
| Date de la dernière version | 20 mars 2026 |
| Source(s) | Bulletin de sécurité Red Hat RHSA-2026:4012 du 09 mars 2026 |
Une gestion de version détaillée se trouve à la fin de ce document.


Risques

  • Atteinte à la confidentialité des données
  • Contournement de la politique de sécurité
  • Déni de service
  • Exécution de code arbitraire
  • Élévation de privilèges

Systèmes affectés

  • Red Hat CodeReady Linux Builder for ARM 64 10 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x
  • Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le
  • Red Hat CodeReady Linux Builder for x8664 10 x8664
  • Red Hat Enterprise Linux for ARM 64 10 aarch64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for x8664 10 x8664

Résumé

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et une atteinte à la confidentialité des données.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Documentation


Gestion détaillée du document

  1. le 20 mars 2026 Version initiale

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-FR
Published
March 20th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
CERTFR-2026-AVI-0330

Who this affects

Applies to
Employers Technology companies
Industry sector
5112 Software & Technology
Activity scope
Vulnerability Management System Patching
Geographic scope
France FR

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Vulnerability Management Operating Systems

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-FR Security Advisories publishes new changes.

Free. Unsubscribe anytime.