Issued at: 2026-10-06
Updated at: 2026-10-06
Advisory content derived from Red Hat RHSA-2026:75746, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Important: kernel-rt security, bug fix, and enhancement update
Description
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.
Security Fix(es):
* kernel: Linux kernel: Use-after-free in xc5000 tuner driver due to race condition (CVE-2025-39994)
* kernel: gfs2: Fix unlikely race in gdlm_put_lock (CVE-2025-40242)
* kernel: Linux kernel: Denial of Service in RDMA/bnxt_re driver due to race condition during QP destruction (CVE-2023-54048)
* kernel: nvme-pci: fix mempool alloc size (CVE-2022-50756)
* kernel: Linux kernel: Denial of Service in QFQ scheduler via child qlen manipulation (CVE-2026-23105)
* kernel: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856)
* kernel: gfs2: Fix slab-use-after-free in qd_put (CVE-2026-45861)
* kernel: net/sched: act_ct: Only release RCU read lock after ct_ft (CVE-2026-46319)
* kernel: gfs2: add some missing log locking (CVE-2026-53049)
* kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 (CVE-2026-52972)
* kernel: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (CVE-2026-53230)
* kernel: ipvs: clear the svc scheduler ptr early on edit (CVE-2026-53270)
* kernel: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-63829)
* kernel: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (CVE-2026-63794)
* kernel: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (CVE-2026-63992)
* kernel: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() (CVE-2026-63994)
* kernel: vxlan: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-68432)
* kernel: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-72052)
* kernel: netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst (CVE-2026-72255)
* kernel: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (CVE-2026-74516)
* kernel: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (CVE-2026-74569)
* kernel: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (CVE-2026-74669)
* kernel: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev (CVE-2026-74744)
* kernel: netfilter: flowtable: publish GC-visible tuple last (CVE-2026-74746)
* kernel: KVM: s390: vsie: zero stale crypto bits (CVE-2026-80921)
* kernel: nvme-tcp: fix host memory disclosure on R2T for a read command (CVE-2026-89481)
* kernel: nvme: add missing SRCU grace period in error path (CVE-2026-89972)
* kernel: nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() (CVE-2026-90227)
* kernel: netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() (CVE-2026-97417)
Bug Fix(es) and Enhancement(s):
* Rocky Linux8.10 - s390/vfio_ccw: Error path cleanups (JIRA:Rocky Linux-252194)
* Rocky Linux8.10 - s390/topology: Use zero-based numbering (JIRA:Rocky Linux-252199)
* [nfs rhel8.10] Disable async copy on nfsd side (JIRA:Rocky Linux-266661)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.