FlawAtlas
Search the atlas
ALSA-2026:13578 Not scored

Important: kernel-rt security update

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: nvme: avoid double free special payload (CVE-2024-41073) * kernel: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end() (CVE-2025-40252) * kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724) * kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (CVE-2026-31402) * kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling (CVE-2026-23401) * kernel: crypto: algif_aead - Revert to operating out-of-place (CVE-2026-31431) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Exploit probability Not scored
Published May 5, 2026
Required by Not available
Last source change May 6, 2026

02 / AFFECTED SOFTWARE

Affected packages

AlmaLinux:8 kernel-rt
AlmaLinux:8 kernel-rt-core
AlmaLinux:8 kernel-rt-debug
AlmaLinux:8 kernel-rt-debug-core
AlmaLinux:8 kernel-rt-debug-devel
AlmaLinux:8 kernel-rt-debug-modules
AlmaLinux:8 kernel-rt-debug-modules-extra
AlmaLinux:8 kernel-rt-devel
AlmaLinux:8 kernel-rt-modules
AlmaLinux:8 kernel-rt-modules-extra

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities ALSA-2026:13578

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: nvme: avoid double free special payload (CVE-2024-41073) * kernel: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end() (CVE-2025-40252) * kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724) * kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (CVE-2026-31402) * kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling (CVE-2026-23401) * kernel: crypto: algif_aead - Revert to operating out-of-place (CVE-2026-31431) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

View original source

05 / REFERENCES

Further evidence