RHSA-2026:70403HighCVSS 7.8

Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update

Published
September 22, 2026
Last Modified
September 24, 2026

🔗 CVE IDs covered (20)

📋 Description

CVE-2023-54120 — kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread CVE-2023-54214 — kernel: Bluetooth: L2CAP: Fix potential user-after-free CVE-2025-39964 — kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg CVE-2025-71082 — kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb CVE-2026-43334 — kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response CVE-2026-45894 — kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry CVE-2026-46043 — kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv CVE-2026-46133 — kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing CVE-2026-52918 — kernel: Bluetooth: serialize accept_q access CVE-2026-53053 — kernel: iommu/amd: Fix clone_alias() to use the original device's devid CVE-2026-53062 — kernel: dm cache policy smq: fix missing locks in invalidating cache blocks CVE-2026-53254 — kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers CVE-2026-53256 — kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() CVE-2026-63823 — kernel: keys: Pin request_key_auth payload in instantiate paths CVE-2026-63947 — kernel: Bluetooth: HIDP: fix missing length checks in hidp_input_report() CVE-2026-63975 — kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp CVE-2026-64534 — kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path CVE-2026-64582 — kernel: RDMA/rxe: Fix a use-after-free problem in rxe_mmap CVE-2026-68188 — kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios CVE-2026-68293 — kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads

🎯 Affected products32

  • Red Hat Enterprise Linux NFV (v. 8)
  • Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-0:4.18.0-553.166.1.rt7.507.el8_10.src as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-0:4.18.0-553.166.1.rt7.507.el8_10.src as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-core-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-core-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-core-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-core-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-debuginfo-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-debuginfo-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-devel-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-devel-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-kvm-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-modules-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-modules-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-modules-extra-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-modules-extra-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debuginfo-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debuginfo-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-devel-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-devel-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-kvm-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-modules-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-modules-0:4.18.0-553.166.1.rt7.507.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • +2 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture. Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available. Workaround: To mitigate this issue, disable the Bluetooth service if it is not required. This can be achieved by stopping and disabling the `bluetooth` service and preventing the `bluetooth` kernel module from loading. To stop and disable the Bluetooth service: ```bash sudo systemctl stop bluetooth sudo systemctl disable bluetooth ``` To prevent the `bluetooth` kernel module from loading at boot, create a modprobe configuration file: ```bash echo "blacklist bluetooth" | sudo tee /etc/modprobe.d/blacklist-bluetooth.conf ``` A system reboot is required for the kernel module change to take full effect. Disabling Bluetooth will impact any functionality that relies on Bluetooth connectivity. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, prevent the `rxe` kernel module from loading. This can be achieved by blacklisting the module. Create a file named `/etc/modprobe.d/blacklist-rxe.conf` with the following content: ``` blacklist rxe ``` After creating the file, regenerate the initramfs and reboot the system for the changes to take effect. This mitigation may impact functionality that relies on the RDMA/rxe module. Workaround: To prevent the `rfcomm` kernel module from loading, create a modprobe configuration file. Add the following lines to `/etc/modprobe.d/disable-rfcomm.conf`: ``` install rfcomm /bin/true blacklist rfcomm ``` After saving the file, regenerate the initramfs and reboot the system for the changes to take effect. This action will disable Bluetooth RFCOMM functionality. If the module is currently loaded, unload it with `rmmod rfcomm`; however, a system reboot is recommended to ensure the module is not loaded.

🔗 References (23)