[Apollo] Advisories Statistics light light Login

RLSA-2026:21745

Security Mirrored from RHSA-2026:21745
Issued at: 2026-05-31
Updated at: 2026-05-31

Synopsis

Important: kernel-rt security update



Description

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

Security Fix(es):

* kernel: Bluetooth: MGMT: Fix possible UAFs (CVE-2025-39981)

* kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)

* kernel: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events (CVE-2025-68347)

* kernel: libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116)

* kernel: Linux kernel: Denial of service and memory corruption in RDMA umad (CVE-2026-23243)

* kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation (CVE-2026-23270)

* kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)

* kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)

* kernel: can: raw: fix ro->uniq use-after-free in raw_rcv() (CVE-2026-31532)

* kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)

* kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)

* kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)

* kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)

* kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)

* kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)

* kernel: md/bitmap: fix GPF in write_page caused by resize race (CVE-2026-43163)

* kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190)

* kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks (CVE-2026-43158)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 8 x86_64

Fixes

2404105 2422699 2424879 2429602 2448594 2448745 2454810 2455334 2461107 2461757 2461759 2464369 2464455 2464462 2464476 2467059 2467064 2467210

CVEs

CVE-2025-39981 CVE-2025-68183 CVE-2025-68347 CVE-2025-71116 CVE-2026-23243 CVE-2026-23270 CVE-2026-23455 CVE-2026-31408 CVE-2026-31532 CVE-2026-31684 CVE-2026-31685 CVE-2026-31709 CVE-2026-43020 CVE-2026-43027 CVE-2026-43051 CVE-2026-43158 CVE-2026-43163 CVE-2026-43190

Affected packages

Rocky Linux 8 x86_64 - NFV

kernel-rt-0:4.18.0-553.126.1.rt7.467.el8_10.src.rpm kernel-rt-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-core-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-debug-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-debug-core-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-debug-debuginfo-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-debug-devel-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-debuginfo-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-debug-kvm-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-debug-modules-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-debug-modules-extra-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-devel-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-kvm-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-modules-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-modules-extra-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm

Rocky Linux 8 x86_64 - RT

kernel-rt-0:4.18.0-553.126.1.rt7.467.el8_10.src.rpm kernel-rt-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-core-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-debug-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-debug-core-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-debug-debuginfo-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-debug-devel-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-debuginfo-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-debug-modules-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-debug-modules-extra-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-devel-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-kvm-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-modules-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm kernel-rt-modules-extra-0:4.18.0-553.126.1.rt7.467.el8_10.x86_64.rpm