Important: kernel-rt security update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: Bluetooth: MGMT: Fix possible UAFs (CVE-2025-39981) * kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183) * kernel: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events (CVE-2025-68347) * kernel: libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116) * kernel: Linux kernel: Denial of service and memory corruption in RDMA umad (CVE-2026-23243) * kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation (CVE-2026-23270) * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455) * kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408) * kernel: can: raw: fix ro->uniq use-after-free in raw_rcv() (CVE-2026-31532) * kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684) * kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685) * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027) * kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020) * kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051) * kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709) * kernel: md/bitmap: fix GPF in write_page caused by resize race (CVE-2026-43163) * kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190) * kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks (CVE-2026-43158) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: Bluetooth: MGMT: Fix possible UAFs (CVE-2025-39981) * kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183) * kernel: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events (CVE-2025-68347) * kernel: libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116) * kernel: Linux kernel: Denial of service and memory corruption in RDMA umad (CVE-2026-23243) * kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation (CVE-2026-23270) * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455) * kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408) * kernel: can: raw: fix ro->uniq use-after-free in raw_rcv() (CVE-2026-31532) * kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684) * kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685) * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027) * kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020) * kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051) * kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709) * kernel: md/bitmap: fix GPF in write_page caused by resize race (CVE-2026-43163) * kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190) * kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks (CVE-2026-43158) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:21745
- https://access.redhat.com/security/cve/CVE-2025-39981
- https://access.redhat.com/security/cve/CVE-2025-68183
- https://access.redhat.com/security/cve/CVE-2025-68347
- https://access.redhat.com/security/cve/CVE-2025-71116
- https://access.redhat.com/security/cve/CVE-2026-23243
- https://access.redhat.com/security/cve/CVE-2026-23270
- https://access.redhat.com/security/cve/CVE-2026-23455
- https://access.redhat.com/security/cve/CVE-2026-31408
- https://access.redhat.com/security/cve/CVE-2026-31532
- https://access.redhat.com/security/cve/CVE-2026-31684
- https://access.redhat.com/security/cve/CVE-2026-31685
- https://access.redhat.com/security/cve/CVE-2026-31709
- https://access.redhat.com/security/cve/CVE-2026-43020
- https://access.redhat.com/security/cve/CVE-2026-43027
- https://access.redhat.com/security/cve/CVE-2026-43051
- https://access.redhat.com/security/cve/CVE-2026-43158
- https://access.redhat.com/security/cve/CVE-2026-43163
- https://access.redhat.com/security/cve/CVE-2026-43190
- https://bugzilla.redhat.com/2404105
- https://bugzilla.redhat.com/2422699
- https://bugzilla.redhat.com/2424879
- https://bugzilla.redhat.com/2429602
- https://bugzilla.redhat.com/2448594
- https://bugzilla.redhat.com/2448745
- https://bugzilla.redhat.com/2454810
- https://bugzilla.redhat.com/2455334
- https://bugzilla.redhat.com/2461107
- https://bugzilla.redhat.com/2461757
- https://bugzilla.redhat.com/2461759
- https://bugzilla.redhat.com/2464369
- https://bugzilla.redhat.com/2464455
- https://bugzilla.redhat.com/2464462
- https://bugzilla.redhat.com/2464476
- https://bugzilla.redhat.com/2467059
- https://bugzilla.redhat.com/2467064
- https://bugzilla.redhat.com/2467210
- https://errata.almalinux.org/8/ALSA-2026-21745.html