Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update
🔗 CVE IDs covered (15)
📋 Description
CVE-2025-68745 — kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset CVE-2026-46149 — kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() CVE-2026-52917 — kernel: sctp: diag: reject stale associations in dump_one path CVE-2026-52942 — kernel: netfilter: nf_log: validate MAC header was set before dumping it CVE-2026-52986 — kernel: netfilter: nf_conntrack_sip: don't use simple_strtoul CVE-2026-53091 — kernel: net: pull headers in qdisc_pkt_len_segs_init() CVE-2026-53246 — kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing CVE-2026-63801 — kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done CVE-2026-63971 — kernel: sctp: fix race between sctp_wait_for_connect and peeloff CVE-2026-64015 — kernel: security/keys: fix missed RCU read section on lookup CVE-2026-64113 — kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning CVE-2026-68117 — kernel: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() CVE-2026-68300 — kernel: sctp: auth: verify auth requirement when auth_chunk is NULL CVE-2026-68315 — kernel: sctp: validate stream count in sctp_process_strreset_inreq() CVE-2026-68376 — kernel: sctp: fix auth_hmacs array size in struct sctp_cookie
🎯 Affected products32
- Red Hat Enterprise Linux NFV (v. 8)
- Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-0:4.18.0-553.162.1.rt7.503.el8_10.src as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-0:4.18.0-553.162.1.rt7.503.el8_10.src as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-core-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-core-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-core-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-core-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-devel-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-devel-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-kvm-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debuginfo-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debuginfo-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-devel-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-devel-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-kvm-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-modules-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-modules-0:4.18.0-553.162.1.rt7.503.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- +2 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture. Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available. Workaround: To mitigate this issue, if the `qla2xxx` SCSI driver is not required, it can be prevented from loading by blacklisting the module. This can be achieved by creating a modprobe configuration file. 1. Create a file named `/etc/modprobe.d/blacklist-qla2xxx.conf` with the following content: ``` blacklist qla2xxx install qla2xxx /bin/true ``` 2. Rebuild the initial ramdisk: ```bash dracut -f -v ``` 3. Reboot the system for the changes to take effect. This mitigation will prevent the `qla2xxx` module from loading, which may impact systems relying on QLogic Fibre Channel HBAs. A system reboot is required for the changes to take full effect. Workaround: To mitigate this issue, prevent module sctp from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2026:66324
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2425039
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2482566
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492091
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492115
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492270
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492397
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492771
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2502254
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2502331
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2502380
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2502541
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2513253
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2513397
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2513408
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2513474
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_66324.json