Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:21745 - Security Advisory
Issued:
2026-05-28
Updated:
2026-05-28

RHSA-2026:21745 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: kernel-rt security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for kernel-rt is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

Security Fix(es):

  • kernel: Bluetooth: MGMT: Fix possible UAFs (CVE-2025-39981)
  • kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)
  • kernel: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events (CVE-2025-68347)
  • kernel: libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116)
  • kernel: Linux kernel: Denial of service and memory corruption in RDMA umad (CVE-2026-23243)
  • kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation (CVE-2026-23270)
  • kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)
  • kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)
  • kernel: can: raw: fix ro->uniq use-after-free in raw_rcv() (CVE-2026-31532)
  • kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)
  • kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)
  • kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)
  • kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)
  • kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)
  • kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)
  • kernel: md/bitmap: fix GPF in write_page caused by resize race (CVE-2026-43163)
  • kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190)
  • kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks (CVE-2026-43158)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

The system must be rebooted for this update to take effect.

Affected Products

  • Red Hat Enterprise Linux for Real Time 8 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV 8 x86_64
  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64

Fixes

  • BZ - 2404105 - CVE-2025-39981 kernel: Bluetooth: MGMT: Fix possible UAFs
  • BZ - 2422699 - CVE-2025-68183 kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr
  • BZ - 2424879 - CVE-2025-68347 kernel: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events
  • BZ - 2429602 - CVE-2025-71116 kernel: libceph: make decode_pool() more resilient against corrupted osdmaps
  • BZ - 2448594 - CVE-2026-23243 kernel: Linux kernel: Denial of service and memory corruption in RDMA umad
  • BZ - 2448745 - CVE-2026-23270 kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation
  • BZ - 2454810 - CVE-2026-23455 kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()
  • BZ - 2455334 - CVE-2026-31408 kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold
  • BZ - 2461107 - CVE-2026-31532 kernel: can: raw: fix ro->uniq use-after-free in raw_rcv()
  • BZ - 2461757 - CVE-2026-31684 kernel: net: sched: act_csum: validate nested VLAN headers
  • BZ - 2461759 - CVE-2026-31685 kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets
  • BZ - 2464369 - CVE-2026-43027 kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup
  • BZ - 2464455 - CVE-2026-43020 kernel: Bluetooth: MGMT: validate LTK enc_size on load
  • BZ - 2464462 - CVE-2026-43051 kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq
  • BZ - 2464476 - CVE-2026-31709 kernel: smb: client: validate the whole DACL before rewriting it in cifsacl
  • BZ - 2467059 - CVE-2026-43163 kernel: md/bitmap: fix GPF in write_page caused by resize race
  • BZ - 2467064 - CVE-2026-43190 kernel: netfilter: xt_tcpmss: check remaining length before reading optlen
  • BZ - 2467210 - CVE-2026-43158 kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks

CVEs

  • CVE-2025-39981
  • CVE-2025-68183
  • CVE-2025-68347
  • CVE-2025-71116
  • CVE-2026-23243
  • CVE-2026-23270
  • CVE-2026-23455
  • CVE-2026-31408
  • CVE-2026-31532
  • CVE-2026-31684
  • CVE-2026-31685
  • CVE-2026-31709
  • CVE-2026-43020
  • CVE-2026-43027
  • CVE-2026-43051
  • CVE-2026-43158
  • CVE-2026-43163
  • CVE-2026-43190

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for Real Time 8

SRPM
kernel-rt-4.18.0-553.126.1.rt7.467.el8_10.src.rpm SHA-256: c137ae3c279e208ff473de49dc7bf9b949b8b2173ec78e979df494a58ac12103
x86_64
kernel-rt-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 6f4bc461a31ff1ff0f70ec1c83fa702874137c1eed7605e63782736a0abd07ff
kernel-rt-core-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: ab5b904c83cfa28c7f967ece07a86d47e5dc13ea6f75e70c702c67e0c0204a90
kernel-rt-debug-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 4d29c2fc27a76d22a07741299d6efa0d8327578eec34439e0986873d904d2784
kernel-rt-debug-core-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: bd00e93d7e3a3e6b7595cfe05fc259d8a40629cf55ce445d210e0446485d3921
kernel-rt-debug-debuginfo-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 70f767812674f4307c49b6c0bec5d8bae3242f2a0be4d3991a7e6d4833015ba8
kernel-rt-debug-devel-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 1bedcf408a63072b0a51d9724c85fcec2f3501a90a4f11108543263d8c802098
kernel-rt-debug-modules-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 69b301ad83b4b13504c7353e3979a1a58740d37fb07e8722946e177f719a2885
kernel-rt-debug-modules-extra-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 24c7de6db825bba461ea87c9f9393b9d95926a8e5b3315508790d418313b4718
kernel-rt-debuginfo-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 136b7213318dcaa325a78d8b18e583a71c3f2af78a963e32975aea28271b0106
kernel-rt-debuginfo-common-x86_64-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: bbab8e46b5f63792080884a3ab3fb0b6d9900a27b2493bda55abfe6d649371d1
kernel-rt-devel-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 1a7385dacaca45b59969ee5ebe2b77e725d80eb48b540c13fb70c0caa1e258d6
kernel-rt-modules-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 6339f69da0343821c857ec2e50d2ae51ba01770eca3627534095b232b699696c
kernel-rt-modules-extra-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 159503884a61262f77b18d2a10031f6cda5f6e658328c4fc08719a2ab393c06d

Red Hat Enterprise Linux for Real Time for NFV 8

SRPM
kernel-rt-4.18.0-553.126.1.rt7.467.el8_10.src.rpm SHA-256: c137ae3c279e208ff473de49dc7bf9b949b8b2173ec78e979df494a58ac12103
x86_64
kernel-rt-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 6f4bc461a31ff1ff0f70ec1c83fa702874137c1eed7605e63782736a0abd07ff
kernel-rt-core-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: ab5b904c83cfa28c7f967ece07a86d47e5dc13ea6f75e70c702c67e0c0204a90
kernel-rt-debug-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 4d29c2fc27a76d22a07741299d6efa0d8327578eec34439e0986873d904d2784
kernel-rt-debug-core-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: bd00e93d7e3a3e6b7595cfe05fc259d8a40629cf55ce445d210e0446485d3921
kernel-rt-debug-debuginfo-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 70f767812674f4307c49b6c0bec5d8bae3242f2a0be4d3991a7e6d4833015ba8
kernel-rt-debug-devel-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 1bedcf408a63072b0a51d9724c85fcec2f3501a90a4f11108543263d8c802098
kernel-rt-debug-kvm-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 976b48f2ba96968636daf6318a28e6fbeabea79c097ecd8717c7f81674308f64
kernel-rt-debug-modules-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 69b301ad83b4b13504c7353e3979a1a58740d37fb07e8722946e177f719a2885
kernel-rt-debug-modules-extra-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 24c7de6db825bba461ea87c9f9393b9d95926a8e5b3315508790d418313b4718
kernel-rt-debuginfo-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 136b7213318dcaa325a78d8b18e583a71c3f2af78a963e32975aea28271b0106
kernel-rt-debuginfo-common-x86_64-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: bbab8e46b5f63792080884a3ab3fb0b6d9900a27b2493bda55abfe6d649371d1
kernel-rt-devel-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 1a7385dacaca45b59969ee5ebe2b77e725d80eb48b540c13fb70c0caa1e258d6
kernel-rt-kvm-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: b9e4eb5c7adf4052ac9e3bdb99423a79e43c5cb2d51bf63d1d4addf6fe9f14f6
kernel-rt-modules-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 6339f69da0343821c857ec2e50d2ae51ba01770eca3627534095b232b699696c
kernel-rt-modules-extra-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 159503884a61262f77b18d2a10031f6cda5f6e658328c4fc08719a2ab393c06d

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10

SRPM
kernel-rt-4.18.0-553.126.1.rt7.467.el8_10.src.rpm SHA-256: c137ae3c279e208ff473de49dc7bf9b949b8b2173ec78e979df494a58ac12103
x86_64
kernel-rt-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 6f4bc461a31ff1ff0f70ec1c83fa702874137c1eed7605e63782736a0abd07ff
kernel-rt-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 6f4bc461a31ff1ff0f70ec1c83fa702874137c1eed7605e63782736a0abd07ff
kernel-rt-core-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: ab5b904c83cfa28c7f967ece07a86d47e5dc13ea6f75e70c702c67e0c0204a90
kernel-rt-core-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: ab5b904c83cfa28c7f967ece07a86d47e5dc13ea6f75e70c702c67e0c0204a90
kernel-rt-debug-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 4d29c2fc27a76d22a07741299d6efa0d8327578eec34439e0986873d904d2784
kernel-rt-debug-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 4d29c2fc27a76d22a07741299d6efa0d8327578eec34439e0986873d904d2784
kernel-rt-debug-core-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: bd00e93d7e3a3e6b7595cfe05fc259d8a40629cf55ce445d210e0446485d3921
kernel-rt-debug-core-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: bd00e93d7e3a3e6b7595cfe05fc259d8a40629cf55ce445d210e0446485d3921
kernel-rt-debug-debuginfo-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 70f767812674f4307c49b6c0bec5d8bae3242f2a0be4d3991a7e6d4833015ba8
kernel-rt-debug-debuginfo-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 70f767812674f4307c49b6c0bec5d8bae3242f2a0be4d3991a7e6d4833015ba8
kernel-rt-debug-devel-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 1bedcf408a63072b0a51d9724c85fcec2f3501a90a4f11108543263d8c802098
kernel-rt-debug-devel-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 1bedcf408a63072b0a51d9724c85fcec2f3501a90a4f11108543263d8c802098
kernel-rt-debug-kvm-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 976b48f2ba96968636daf6318a28e6fbeabea79c097ecd8717c7f81674308f64
kernel-rt-debug-modules-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 69b301ad83b4b13504c7353e3979a1a58740d37fb07e8722946e177f719a2885
kernel-rt-debug-modules-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 69b301ad83b4b13504c7353e3979a1a58740d37fb07e8722946e177f719a2885
kernel-rt-debug-modules-extra-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 24c7de6db825bba461ea87c9f9393b9d95926a8e5b3315508790d418313b4718
kernel-rt-debug-modules-extra-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 24c7de6db825bba461ea87c9f9393b9d95926a8e5b3315508790d418313b4718
kernel-rt-debuginfo-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 136b7213318dcaa325a78d8b18e583a71c3f2af78a963e32975aea28271b0106
kernel-rt-debuginfo-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 136b7213318dcaa325a78d8b18e583a71c3f2af78a963e32975aea28271b0106
kernel-rt-debuginfo-common-x86_64-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: bbab8e46b5f63792080884a3ab3fb0b6d9900a27b2493bda55abfe6d649371d1
kernel-rt-debuginfo-common-x86_64-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: bbab8e46b5f63792080884a3ab3fb0b6d9900a27b2493bda55abfe6d649371d1
kernel-rt-devel-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 1a7385dacaca45b59969ee5ebe2b77e725d80eb48b540c13fb70c0caa1e258d6
kernel-rt-devel-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 1a7385dacaca45b59969ee5ebe2b77e725d80eb48b540c13fb70c0caa1e258d6
kernel-rt-kvm-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: b9e4eb5c7adf4052ac9e3bdb99423a79e43c5cb2d51bf63d1d4addf6fe9f14f6
kernel-rt-modules-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 6339f69da0343821c857ec2e50d2ae51ba01770eca3627534095b232b699696c
kernel-rt-modules-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 6339f69da0343821c857ec2e50d2ae51ba01770eca3627534095b232b699696c
kernel-rt-modules-extra-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 159503884a61262f77b18d2a10031f6cda5f6e658328c4fc08719a2ab393c06d
kernel-rt-modules-extra-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm SHA-256: 159503884a61262f77b18d2a10031f6cda5f6e658328c4fc08719a2ab393c06d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility