Important: kernel-rt security, bug fix, and enhancement update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198) * kernel: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (CVE-2026-43450) * kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227) * kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209) * kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259) * kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263) Bug Fix(es) and Enhancement(s): * kernel panic at trailing_symlink while the task wdavdaemon runs even after 4c4f7c19b3c7 (JIRA:AlmaLinux-152759) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198) * kernel: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (CVE-2026-43450) * kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227) * kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209) * kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259) * kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263) Bug Fix(es) and Enhancement(s): * kernel panic at trailing_symlink while the task wdavdaemon runs even after 4c4f7c19b3c7 (JIRA:AlmaLinux-152759) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:36348
- https://access.redhat.com/security/cve/CVE-2025-10263
- https://access.redhat.com/security/cve/CVE-2026-43198
- https://access.redhat.com/security/cve/CVE-2026-43450
- https://access.redhat.com/security/cve/CVE-2026-46209
- https://access.redhat.com/security/cve/CVE-2026-46227
- https://access.redhat.com/security/cve/CVE-2026-46259
- https://bugzilla.redhat.com/2467228
- https://bugzilla.redhat.com/2468228
- https://bugzilla.redhat.com/2482564
- https://bugzilla.redhat.com/2482636
- https://bugzilla.redhat.com/2484477
- https://bugzilla.redhat.com/2486958
- https://errata.almalinux.org/8/ALSA-2026-36348.html