Critical: kernel-rt security update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: geneve: Fix use-after-free in geneve_find_dev(). (CVE-2025-21858) * kernel: smc: Fix use-after-free in tcp_write_timer_handler() (CVE-2023-53781) * kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366) * kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() (CVE-2026-22984) * kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (CVE-2026-22990) * kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392) * kernel: ALSA: 6fire: fix use-after-free on disconnect (CVE-2026-31581) * kernel: smb: client: fix OOB reads parsing symlink error response (CVE-2026-31613) * kernel: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (CVE-2026-43037) * kernel: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038) * kernel: dlm: validate length in dlm_search_rsb_tree (CVE-2026-43125) * kernel: RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852) * kernel: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: geneve: Fix use-after-free in geneve_find_dev(). (CVE-2025-21858) * kernel: smc: Fix use-after-free in tcp_write_timer_handler() (CVE-2023-53781) * kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366) * kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() (CVE-2026-22984) * kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (CVE-2026-22990) * kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392) * kernel: ALSA: 6fire: fix use-after-free on disconnect (CVE-2026-31581) * kernel: smb: client: fix OOB reads parsing symlink error response (CVE-2026-31613) * kernel: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (CVE-2026-43037) * kernel: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038) * kernel: dlm: validate length in dlm_search_rsb_tree (CVE-2026-43125) * kernel: RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852) * kernel: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:25120
- https://access.redhat.com/security/cve/CVE-2023-53781
- https://access.redhat.com/security/cve/CVE-2025-21858
- https://access.redhat.com/security/cve/CVE-2025-68366
- https://access.redhat.com/security/cve/CVE-2026-22984
- https://access.redhat.com/security/cve/CVE-2026-22990
- https://access.redhat.com/security/cve/CVE-2026-23392
- https://access.redhat.com/security/cve/CVE-2026-31581
- https://access.redhat.com/security/cve/CVE-2026-31613
- https://access.redhat.com/security/cve/CVE-2026-43037
- https://access.redhat.com/security/cve/CVE-2026-43038
- https://access.redhat.com/security/cve/CVE-2026-43125
- https://access.redhat.com/security/cve/CVE-2026-45852
- https://access.redhat.com/security/cve/CVE-2026-46181
- https://bugzilla.redhat.com/2351619
- https://bugzilla.redhat.com/2420279
- https://bugzilla.redhat.com/2424881
- https://bugzilla.redhat.com/2432389
- https://bugzilla.redhat.com/2432400
- https://bugzilla.redhat.com/2451218
- https://bugzilla.redhat.com/2461471
- https://bugzilla.redhat.com/2461480
- https://bugzilla.redhat.com/2464351
- https://bugzilla.redhat.com/2464397
- https://bugzilla.redhat.com/2467234
- https://bugzilla.redhat.com/2482166
- https://bugzilla.redhat.com/2482532
- https://errata.almalinux.org/8/ALSA-2026-25120.html