Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:5690 - Security Advisory
Issued:
2026-03-25
Updated:
2026-03-25

RHSA-2026:5690 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: kernel-rt security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for kernel-rt is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

Security Fix(es):

  • kernel: page_pool: Fix use-after-free in page_pool_recycle_in_ring (CVE-2025-38129)
  • kernel: Linux kernel: Use-after-free in BPF sockmap can lead to denial of service and privilege escalation (CVE-2025-38154)
  • kernel: sctp: avoid NULL dereference when chunk data buffer is missing (CVE-2025-40240)
  • kernel: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (CVE-2025-71085)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

The system must be rebooted for this update to take effect.

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64

Fixes

  • BZ - 2376034 - CVE-2025-38129 kernel: page_pool: Fix use-after-free in page_pool_recycle_in_ring
  • BZ - 2376056 - CVE-2025-38154 kernel: Linux kernel: Use-after-free in BPF sockmap can lead to denial of service and privilege escalation
  • BZ - 2418832 - CVE-2025-40240 kernel: sctp: avoid NULL dereference when chunk data buffer is missing
  • BZ - 2429026 - CVE-2025-71085 kernel: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr()

CVEs

  • CVE-2025-38129
  • CVE-2025-38154
  • CVE-2025-40240
  • CVE-2025-71085

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
kernel-rt-5.14.0-284.161.1.rt14.446.el9_2.src.rpm SHA-256: ec933d3eb9e934c7e49d8c3a2dbc59ad68b54c92b79737e5d4b50d2a0e8ca20a
x86_64
kernel-rt-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: e59365299f6ff3a9e6c246d04c810a95b7f3a8b29c5f181dae4580dff2812189
kernel-rt-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: e59365299f6ff3a9e6c246d04c810a95b7f3a8b29c5f181dae4580dff2812189
kernel-rt-core-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: a696c8285de32396817151104f75c6188a4a246a4bfdd74c12016a827eee4e77
kernel-rt-core-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: a696c8285de32396817151104f75c6188a4a246a4bfdd74c12016a827eee4e77
kernel-rt-debug-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: 2327036d12ab03d61f5599c180c9522fb7c739a342d87a7c776a42bb67e5af64
kernel-rt-debug-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: 2327036d12ab03d61f5599c180c9522fb7c739a342d87a7c776a42bb67e5af64
kernel-rt-debug-core-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: 8ccccf62a49f865f3864de0047b0fdb9f24da486cdde89e7f65d3c9aa78190b0
kernel-rt-debug-core-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: 8ccccf62a49f865f3864de0047b0fdb9f24da486cdde89e7f65d3c9aa78190b0
kernel-rt-debug-debuginfo-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: f7f08a2d34358156e6e35ded79bd614c7ae96bc787ab23040afc4a2876bfc7af
kernel-rt-debug-debuginfo-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: f7f08a2d34358156e6e35ded79bd614c7ae96bc787ab23040afc4a2876bfc7af
kernel-rt-debug-devel-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: 9ceb7f49792d46c93a44615c306b8bd585c599f62832d6313b9ca6352b9319cb
kernel-rt-debug-devel-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: 9ceb7f49792d46c93a44615c306b8bd585c599f62832d6313b9ca6352b9319cb
kernel-rt-debug-kvm-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: 6b08332e753df72da9e5f18125b47a021c17d5ba8724b06416735d79a1d6774b
kernel-rt-debug-modules-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: ce829d1c5e8c7f726bb29d8d4a974a600700f32ca776bd260b0a11bb89672eeb
kernel-rt-debug-modules-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: ce829d1c5e8c7f726bb29d8d4a974a600700f32ca776bd260b0a11bb89672eeb
kernel-rt-debug-modules-core-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: e5eec4f06ab49276856655fa2d73563ac9b96f26a0cf7e9aaee5b45a3127b0d7
kernel-rt-debug-modules-core-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: e5eec4f06ab49276856655fa2d73563ac9b96f26a0cf7e9aaee5b45a3127b0d7
kernel-rt-debug-modules-extra-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: ba92f0eadc3297f3c436a2bdaf6e5d65a345b37630ca12f4e26085a99149501f
kernel-rt-debug-modules-extra-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: ba92f0eadc3297f3c436a2bdaf6e5d65a345b37630ca12f4e26085a99149501f
kernel-rt-debuginfo-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: 045d474dc7aeaad8e251fcd076d81b62e8c315316ab7fdd459cfa7b1618d9461
kernel-rt-debuginfo-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: 045d474dc7aeaad8e251fcd076d81b62e8c315316ab7fdd459cfa7b1618d9461
kernel-rt-debuginfo-common-x86_64-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: b731b82c2e079ca611d78a4f549c979f8161ed6675692fda458aad1082e7633a
kernel-rt-debuginfo-common-x86_64-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: b731b82c2e079ca611d78a4f549c979f8161ed6675692fda458aad1082e7633a
kernel-rt-devel-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: a82ef8829902e2d08c26b8493d58024ffe8ebaa6530ac43e8591d4674fb3118e
kernel-rt-devel-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: a82ef8829902e2d08c26b8493d58024ffe8ebaa6530ac43e8591d4674fb3118e
kernel-rt-kvm-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: cd85623f69250e61e51ad2ad504a41cd04c7ebbdb31573ef499f644ffc09a195
kernel-rt-modules-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: 1f0f9c6c8914acd73922069d4afb4d98ae9ce7273e61e1c8698844daba55797e
kernel-rt-modules-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: 1f0f9c6c8914acd73922069d4afb4d98ae9ce7273e61e1c8698844daba55797e
kernel-rt-modules-core-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: a9636674315ee40f4aeb2ba85ad99dabbaa58f15dab04904a21fd6a9f579a48d
kernel-rt-modules-core-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: a9636674315ee40f4aeb2ba85ad99dabbaa58f15dab04904a21fd6a9f579a48d
kernel-rt-modules-extra-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: ecf47440d20a3b5524706e845c7749b6499d86ed94a4dcacabc163dc7c436ac9
kernel-rt-modules-extra-5.14.0-284.161.1.rt14.446.el9_2.x86_64.rpm SHA-256: ecf47440d20a3b5524706e845c7749b6499d86ed94a4dcacabc163dc7c436ac9

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility