[ALSA-2026:75746] Important: kernel-rt security, bug fix, and enhancement update
Type:
security
Severity:
important
Release date:
2026-10-06
Description:
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: Linux kernel: Use-after-free in xc5000 tuner driver due to race condition (CVE-2025-39994) * kernel: gfs2: Fix unlikely race in gdlm_put_lock (CVE-2025-40242) * kernel: Linux kernel: Denial of Service in RDMA/bnxt_re driver due to race condition during QP destruction (CVE-2023-54048) * kernel: nvme-pci: fix mempool alloc size (CVE-2022-50756) * kernel: Linux kernel: Denial of Service in QFQ scheduler via child qlen manipulation (CVE-2026-23105) * kernel: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856) * kernel: gfs2: Fix slab-use-after-free in qd_put (CVE-2026-45861) * kernel: net/sched: act_ct: Only release RCU read lock after ct_ft (CVE-2026-46319) * kernel: gfs2: add some missing log locking (CVE-2026-53049) * kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 (CVE-2026-52972) * kernel: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (CVE-2026-53230) * kernel: ipvs: clear the svc scheduler ptr early on edit (CVE-2026-53270) * kernel: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-63829) * kernel: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (CVE-2026-63794) * kernel: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (CVE-2026-63992) * kernel: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() (CVE-2026-63994) * kernel: vxlan: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-68432) * kernel: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-72052) * kernel: netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst (CVE-2026-72255) * kernel: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (CVE-2026-74516) * kernel: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (CVE-2026-74569) * kernel: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (CVE-2026-74669) * kernel: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev (CVE-2026-74744) * kernel: netfilter: flowtable: publish GC-visible tuple last (CVE-2026-74746) * kernel: KVM: s390: vsie: zero stale crypto bits (CVE-2026-80921) * kernel: nvme-tcp: fix host memory disclosure on R2T for a read command (CVE-2026-89481) * kernel: nvme: add missing SRCU grace period in error path (CVE-2026-89972) * kernel: nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() (CVE-2026-90227) * kernel: netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() (CVE-2026-97417) Bug Fix(es) and Enhancement(s): * AlmaLinux8.10 - s390/vfio_ccw: Error path cleanups (JIRA:AlmaLinux-252194) * AlmaLinux8.10 - s390/topology: Use zero-based numbering (JIRA:AlmaLinux-252199) * [nfs rhel8.10] Disable async copy on nfsd side (JIRA:AlmaLinux-266661) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
x86_64 kernel-rt-debug-core-4.18.0-553.171.1.rt7.512.el8_10.x86_64.rpm 001d23caebadbae2ea32dc8374b44fd47e45ec0beb746dd8c03b3fc3d9b2a7b8
x86_64 kernel-rt-4.18.0-553.171.1.rt7.512.el8_10.x86_64.rpm 004509baf5c2f2a223030e688cfcdbef4459e85aab585340d56409175b588624
x86_64 kernel-rt-modules-4.18.0-553.171.1.rt7.512.el8_10.x86_64.rpm 08dd6d279f091183972316d3e688419516b8cf8db5b2eee905a8476cd68bd8d9
x86_64 kernel-rt-debug-modules-4.18.0-553.171.1.rt7.512.el8_10.x86_64.rpm 15ff8e41027944d0f26b5ea6b82584d55d59d24bc467acb3cb81b165412c0427
x86_64 kernel-rt-debug-4.18.0-553.171.1.rt7.512.el8_10.x86_64.rpm 3900e3da5ce119a6377bd5550207843e871e530c529b11a509bfa963964aebf8
x86_64 kernel-rt-debug-modules-extra-4.18.0-553.171.1.rt7.512.el8_10.x86_64.rpm 7cb737a756b1c7abe111979be7653a54ea590059eb3aaa5ad382d6d015ed58c7
x86_64 kernel-rt-modules-extra-4.18.0-553.171.1.rt7.512.el8_10.x86_64.rpm 90a83dc7a3fa2d7e637115118027d1ab244d7073fa75c76e5e1ce89b3453308d
x86_64 kernel-rt-core-4.18.0-553.171.1.rt7.512.el8_10.x86_64.rpm bdee397bedf5e7eb3d21830943e2b73608149caa54dd67380bc02150dc368166
x86_64 kernel-rt-debug-devel-4.18.0-553.171.1.rt7.512.el8_10.x86_64.rpm cf4fd3a2f6223bf907f4deb3d9fff8671aa08074a27f6b4f38376ebc40517591
x86_64 kernel-rt-devel-4.18.0-553.171.1.rt7.512.el8_10.x86_64.rpm e73171f572e3ad7d5eb29f27c735ba6c55253e65e32c0dabcbcbf4fb39af7274
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.