Issued at: 2026-09-16
Updated at: 2026-09-16
Advisory content derived from Red Hat RHSA-2026:67469, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Important: kernel-rt security update
Description
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.
Security Fix(es):
* kernel: EDAC/bluefield: Fix potential integer overflow (CVE-2024-53161)
* kernel: wifi: mac80211: Discard Beacon frames to non-broadcast address (CVE-2025-71127)
* kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133)
* kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (CVE-2026-52947)
* kernel: wifi: nl80211: reject oversized EMA RNR lists (CVE-2026-53182)
* kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() (CVE-2026-63802)
* kernel: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (CVE-2026-63889)
* kernel: wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb (CVE-2026-64117)
* kernel: Linux kernel: ath9k Wi-Fi driver use-after-free vulnerability leading to system crash (CVE-2026-68363)
* kernel: net: qrtr: restrict socket creation to the initial network namespace (CVE-2026-68294)
* kernel: dm-verity: fix buffer overflow in FEC calculation (CVE-2026-72098)
* kernel: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (CVE-2026-74556)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.