[ALSA-2026:21745] Important: kernel-rt security update
Type:
security
Severity:
important
Release date:
2026-05-28
Description:
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: Bluetooth: MGMT: Fix possible UAFs (CVE-2025-39981) * kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183) * kernel: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events (CVE-2025-68347) * kernel: libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116) * kernel: Linux kernel: Denial of service and memory corruption in RDMA umad (CVE-2026-23243) * kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation (CVE-2026-23270) * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455) * kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408) * kernel: can: raw: fix ro->uniq use-after-free in raw_rcv() (CVE-2026-31532) * kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684) * kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685) * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027) * kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020) * kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051) * kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709) * kernel: md/bitmap: fix GPF in write_page caused by resize race (CVE-2026-43163) * kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190) * kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks (CVE-2026-43158) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
x86_64 kernel-rt-core-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm 02e57ed002d50fd2287960ba4b6ceab67e8212b44ad2123b8625cd7f10ebf4fe
x86_64 kernel-rt-debug-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm 2f0dc31dc87dab053047abdccef189cdf11da46d7a4d43f2514d40b72150f2d3
x86_64 kernel-rt-debug-devel-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm 337559ce43d6b9d63b111473bbd2963aa85897c0f72b418e18d8ab26aef796cb
x86_64 kernel-rt-devel-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm 338ae8b19e2513feb495c1c381b657f7fce85f7e1f880174ff207fc1ee2297a4
x86_64 kernel-rt-modules-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm 58f078f9b98eab51fbed662ea945d800ed4d4e74d4feb88ae3a16b990d96b98a
x86_64 kernel-rt-debug-modules-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm 68a126d16ff36cf1a1b06c34d51e4d23716c09bf82b7adf87625d2ea99d5acf9
x86_64 kernel-rt-debug-core-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm 9f951ad2e3058c757eb3315b54e62d744e297ee69a15f54cb07454a675598663
x86_64 kernel-rt-modules-extra-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm a69f448706f38725d431f3b38b253902def85ecc0d5399cf90f96ad9cbee9c27
x86_64 kernel-rt-debug-modules-extra-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm e30538db10fcc993cb1b00791f37f280128edea8878d1c3aab634816035bddb8
x86_64 kernel-rt-4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm fb07d08d3ae4860bfc92172d747e55fa032961bd5b1121520ef792c69734a4f3
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.