Red Hat Security Advisory: kernel-rt security update
🔗 CVE IDs covered (12)
📋 Description
CVE-2022-50673 — kernel: ext4: fix use-after-free in ext4_orphan_cleanup CVE-2023-53192 — kernel: Linux kernel: Out-of-bounds write in VXLAN due to incorrect nexthop hash size leading to denial of service CVE-2023-53762 — kernel: Linux kernel Bluetooth: Denial of Service due to use-after-free in connection handling CVE-2023-53821 — kernel: ip6_vti: fix slab-use-after-free in decode_session6 CVE-2025-37861 — kernel: scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue CVE-2025-37882 — kernel: Linux kernel: xHCI driver isochronous event handling race condition leading to data loss or UAF CVE-2025-38415 — kernel: Linux kernel: Memory corruption in Squashfs due to incorrect block size calculation CVE-2025-39760 — kernel: Linux kernel: Denial of Service via out-of-bounds read in USB configuration parsing CVE-2025-39933 — kernel: smb: client: let recv_done verify data_offset, data_length and remaining_data_length CVE-2025-40269 — kernel: Linux kernel ALSA USB audio driver: Buffer overflow leading to information disclosure and denial of service CVE-2025-40271 — kernel: Linux kernel: Use-after-free in proc_readdir_de() can lead to privilege escalation or denial of service. CVE-2025-68349 — kernel: NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid
🎯 Affected products36
- Red Hat Enterprise Linux Real Time E4S (v.9.2)
- Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
- kernel-rt-0:5.14.0-284.158.1.rt14.443.el9_2.src as a component of Red Hat Enterprise Linux Real Time E4S (v.9.2)
- kernel-rt-0:5.14.0-284.158.1.rt14.443.el9_2.src as a component of Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
- kernel-rt-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time E4S (v.9.2)
- kernel-rt-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
- kernel-rt-core-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time E4S (v.9.2)
- kernel-rt-core-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
- kernel-rt-debug-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time E4S (v.9.2)
- kernel-rt-debug-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
- kernel-rt-debug-core-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time E4S (v.9.2)
- kernel-rt-debug-core-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
- kernel-rt-debug-debuginfo-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time E4S (v.9.2)
- kernel-rt-debug-debuginfo-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
- kernel-rt-debug-devel-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time E4S (v.9.2)
- kernel-rt-debug-devel-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
- kernel-rt-debug-kvm-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
- kernel-rt-debug-modules-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time E4S (v.9.2)
- kernel-rt-debug-modules-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
- kernel-rt-debug-modules-core-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time E4S (v.9.2)
- kernel-rt-debug-modules-core-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
- kernel-rt-debug-modules-extra-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time E4S (v.9.2)
- kernel-rt-debug-modules-extra-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
- kernel-rt-debuginfo-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time E4S (v.9.2)
- kernel-rt-debuginfo-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
- kernel-rt-debuginfo-common-x86_64-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time E4S (v.9.2)
- kernel-rt-debuginfo-common-x86_64-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
- kernel-rt-devel-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time E4S (v.9.2)
- kernel-rt-devel-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
- kernel-rt-kvm-0:5.14.0-284.158.1.rt14.443.el9_2.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)
- +6 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, prevent the `snd_usb_audio` kernel module from loading if USB audio functionality is not required. Create a file `/etc/modprobe.d/disable-snd-usb-audio.conf` with the following content: `install snd_usb_audio /bin/true` After creating the file, a system reboot is required for the changes to take effect. This action will disable all USB audio device functionality. Workaround: If NFS service not being used, then disable it to prevent possibility of triggering this bug (and usually it is disabled by default): sudo systemctl stop nfs-server sudo systemctl disable nfs-server
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2026:3358
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2365250
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2365256
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2383404
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2394601
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2395232
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2401432
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2419837
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2419838
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2419919
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2420329
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2420347
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2424880
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3358.json