Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update
🔗 CVE IDs covered (29)
📋 Description
CVE-2022-50756 — kernel: nvme-pci: fix mempool alloc size CVE-2023-54048 — kernel: Linux kernel: Denial of Service in RDMA/bnxt_re driver due to race condition during QP destruction CVE-2025-39994 — kernel: Linux kernel: Use-after-free in xc5000 tuner driver due to race condition CVE-2025-40242 — kernel: gfs2: Fix unlikely race in gdlm_put_lock CVE-2026-23105 — kernel: Linux kernel: Denial of Service in QFQ scheduler via child qlen manipulation CVE-2026-45856 — kernel: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send CVE-2026-45861 — kernel: gfs2: Fix slab-use-after-free in qd_put CVE-2026-46319 — kernel: net/sched: act_ct: Only release RCU read lock after ct_ft CVE-2026-52972 — kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 CVE-2026-53049 — kernel: gfs2: add some missing log locking CVE-2026-53230 — kernel: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list CVE-2026-53270 — kernel: ipvs: clear the svc scheduler ptr early on edit CVE-2026-63794 — kernel: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path CVE-2026-63829 — kernel: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink CVE-2026-63992 — kernel: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() CVE-2026-63994 — kernel: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmpv6 CVE-2026-68432 — kernel: vxlan: require CAP_NET_ADMIN in the device netns for changelink CVE-2026-72052 — kernel: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink CVE-2026-72255 — kernel: netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst CVE-2026-74516 — kernel: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active CVE-2026-74569 — kernel: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() CVE-2026-74669 — kernel: ipvs: clear IPv4 options after rebasing tunnel ICMP errors CVE-2026-74744 — kernel: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev CVE-2026-74746 — kernel: netfilter: flowtable: publish GC-visible tuple last CVE-2026-80921 — kernel: KVM: s390: vsie: zero stale crypto bits CVE-2026-89481 — kernel: nvme-tcp: fix host memory disclosure on R2T for a read command CVE-2026-89972 — kernel: nvme: add missing SRCU grace period in error path CVE-2026-90227 — kernel: nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() CVE-2026-97417 — kernel: netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack()
🎯 Affected products32
- Red Hat Enterprise Linux NFV (v. 8)
- Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-0:4.18.0-553.171.1.rt7.512.el8_10.src as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-0:4.18.0-553.171.1.rt7.512.el8_10.src as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-core-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-core-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-core-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-core-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-debuginfo-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-devel-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-devel-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-kvm-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debug-modules-extra-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debuginfo-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debuginfo-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-devel-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-devel-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- kernel-rt-kvm-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-modules-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
- kernel-rt-modules-0:4.18.0-553.171.1.rt7.512.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
- +2 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Red Hat recommends treating all kernel errata as security-relevant. Given the kernel's fundamental role, any bug has a higher chance of impacting system security, even if that impact only becomes clear after a fix is published. Therefore, Red Hat prioritizes delivering fixes that improve our customers' overall security posture. Because of this proactive approach, a patch may be associated with a CVE assignment at a future date. Retroactive CVE assignments are always documented in the corresponding errata and on Red Hat's CVE pages. We strongly advise against delaying updates, as doing so may leave your system exposed when protections are already available. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent the `bnxt_re` kernel module from loading if RDMA functionality with Broadcom NetXtreme-E hardware is not required. Create a blacklist file: ``` echo "blacklist bnxt_re" > /etc/modprobe.d/bnxt_re.conf ``` After creating the file, regenerate the initramfs and reboot the system for the changes to take effect. This may impact systems relying on the `bnxt_re` driver for RDMA operations. Workaround: To mitigate this issue, prevent the `xc5000` kernel module from loading. Create a file `/etc/modprobe.d/blacklist-xc5000.conf` with `blacklist xc5000`. Regenerate the initramfs using `dracut -f -v` and reboot the system. This may impact functionality if `xc5000` tuner hardware is in use. Workaround: To mitigate this issue, prevent module act_ct from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: If IPv6 GRE or IP-ERSpan tunnels are not in use, their respective kernel modules (`ip6_gre` and `ip6erspan`) can be blacklisted to prevent exploitation. Create a file such as `/etc/modprobe.d/disable-ip6gre.conf` with the following content: ``` install ip6_gre /bin/true install ip6erspan /bin/true ``` After creating the file, regenerate the initramfs and reboot the system for the changes to take effect. This mitigation may impact network functionality if these tunnel types are actively used. Workaround: To mitigate this issue, prevent the `ip_vs` kernel module from loading. This can be achieved by creating a blacklist rule. 1. Unload the module if currently loaded: `sudo modprobe -r ip_vs` 2. Create a blacklist configuration file: `echo "blacklist ip_vs" | sudo tee /etc/modprobe.d/disable-ip_vs.conf` 3. Rebuild the initial RAM disk to ensure the module is not loaded at boot: `sudo dracut -f` A system reboot is required for the changes to take full effect. Disabling this module will prevent the use of IP Virtual Server (IPVS) functionality. Workaround: Prevent the nvme-tcp kernel module from loading if NVMe over TCP storage is not required on the system. 1. Add an entry to /etc/modprobe.d to prevent the module from loading: # echo "install nvme-tcp /bin/true" >> /etc/modprobe.d/disable-nvme-tcp.conf 2. If the module is currently loaded and not in use by any storage target, unload it: # modprobe -r nvme-tcp Caveats: Disabling this module prevents the system from connecting to NVMe over TCP block storage devices. Warning: Do not attempt to unload this module if active NVMe over TCP storage is mounted or in use, as doing so will cause I/O failure and potential data loss. If the module cannot be cleanly unloaded, a system restart is required for the change to take full effect. Additionally, restrict NVMe-oF connections to verified, trusted storage targets over isolated or encrypted network fabrics. Workaround: Systems that do not require stateful firewall, NAT, or connection tracking can eliminate exposure by unloading the nf_conntrack kernel module. On systems where conntrack is required, exposure can be reduced by applying NOTRACK rules in the raw table to bypass connection tracking on untrusted or internet-facing interfaces, ensuring the vulnerable TCP SACK parsing code path in tcp_sack() is not reached for attacker-controlled traffic.
🔗 References (32)
- selfhttps://access.redhat.com/errata/RHSA-2026:75746
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2404123
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2418819
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2425013
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2425209
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2436789
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2482129
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2482143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2486979
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492276
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492364
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492728
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492853
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2502230
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2502241
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2502431
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2502444
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2514441
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2516306
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2516717
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2516998
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2517052
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2521375
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2524431
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2524483
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2531066
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2532184
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2535140
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2536346
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2540479
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_75746.json