Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update
🔗 CVE IDs covered (7)
📋 Description
CVE-2026-43370 — kernel: drm/amdgpu: Fix use-after-free race in VM acquire CVE-2026-63831 — kernel: mac802154: llsec: add skb_cow_data() before in-place crypto CVE-2026-64564 — kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing CVE-2026-72261 — kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control CVE-2026-80844 — kernel: xfrm: ah6: validate routing header segments_left CVE-2026-81000 — kernel: net: tun: bound receive headroom CVE-2026-89846 — kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read
🎯 Affected products32
- Red Hat Enterprise Linux NFV (v. 8)
- Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-0:4.18.0-553.167.1.rt7.508.el8_10.src as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-0:4.18.0-553.167.1.rt7.508.el8_10.src as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-core-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-core-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-core-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-core-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-devel-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-devel-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-kvm-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debuginfo-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debuginfo-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-devel-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-devel-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-kvm-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-modules-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-modules-0:4.18.0-553.167.1.rt7.508.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- +2 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture. Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available. Workaround: To mitigate this issue, prevent the `sctp` kernel module from loading. Create a file named `/etc/modprobe.d/disable-sctp.conf` with the following content: ``` install sctp /bin/true blacklist sctp ``` After creating the file, regenerate the initramfs and reboot the system for the changes to take effect. Applications or services that rely on the SCTP protocol cannot use this mitigation and should prioritize applying the fix. Workaround: See the security bulletin for a detailed mitigation procedure. Workaround: If QLogic Fibre Channel HBAs are not in use, the 'qla2xxx' kernel module can be blacklisted to prevent it from loading. This can be achieved by creating a modprobe configuration file. To blacklist the module: 1. Create a file named `/etc/modprobe.d/blacklist-qla2xxx.conf` with the following content: `blacklist qla2xxx` 2. Regenerate the initramfs to ensure the blacklist is applied during boot: `sudo dracut -f -v` (for RHEL 7/8/9) `sudo mkinitcpio -P` (for Arch-based systems, if applicable) 3. Reboot the system for the changes to take effect. Warning: Blacklisting this module will disable functionality for QLogic Fibre Channel HBAs. Ensure that this hardware is not required before applying this mitigation. A system reboot is required for the changes to take effect.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:71016
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2468244
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2502243
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510890
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2516527
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2528676
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2532176
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2535391
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_71016.json