CVE-2026-31402
The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
- kernel: nvme: avoid double free special payload (CVE-2024-41073)
- kernel: net: qlogic/qede: fix potential out-of-bounds read in qedetpacont() and qedetpaend() (CVE-2025-40252)
- kernel: crypto: asymmetrickeys - prevent overflow in asymmetrickeygenerateid (CVE-2025-68724)
- kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (CVE-2026-31402)
- kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling (CVE-2026-23401)
- kernel: crypto: algif_aead - Revert to operating out-of-place (CVE-2026-31431)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://access.redhat.com/errata/RHSA-2026:13577, https://access.redhat.com/security/cve/CVE-2024-41073, https://access.redhat.com/security/cve/CVE-2025-40252, https://access.redhat.com/security/cve/CVE-2025-68724, https://access.redhat.com/security/cve/CVE-2026-23401, https://access.redhat.com/security/cve/CVE-2026-31402, https://access.redhat.com/security/cve/CVE-2026-31431, https://access.redhat.com/security/cve/CVE-2026-43077
