RHSA-2026:57254: Important: kernel-rt security, bug fix, and enhancement update
Important: kernel-rt security, bug fix, and enhancement update
Other sources
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: net: ieee802154: do not leave a dangling sk pointer in ieee802154create() (CVE-2024-56602) kernel: ip6gre: Use cached t->net in ip6erspanchangelink() (CVE-2026-46120) kernel: sched/psi: fix race between file release and pressure write (CVE-2026-52991) kernel: mm/hugememory: update file PMD counter before folioput() (CVE-2026-53189) kernel: scsi: target: iscsi: Fix CRC overread and double-free in iscsithandletextcmd() (CVE-2026-63888) kernel: scsi: target: iscsi: Bound iscsiencodetextoutput() appends to rspbuf (CVE-2026-63887) kernel: net/smc: reject CHID-0 ACCEPT that matches an empty ismdev slot (CVE-2026-64048) kernel: smb: client: mask server-provided mode to 07777 in modefromsid (CVE-2026-64379) kernel: smb/client: handle overlapping allocated ranges in fallocate (CVE-2026-68388) Bug Fix(es) and Enhancement(s): sfc: TX queue stalls and NIC resets caused by GFPATOMIC allocation failures after RHEL 8.10 kernel update (JIRA:RHEL-219767) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 4.18.0-553.157.1.rt7.498.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-coreto a version that resolves this vulnerability.Fixed in 4.18.0-553.157.1.rt7.498.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-debugto a version that resolves this vulnerability.Fixed in 4.18.0-553.157.1.rt7.498.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-553.157.1.rt7.498.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-553.157.1.rt7.498.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-553.157.1.rt7.498.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-553.157.1.rt7.498.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-553.157.1.rt7.498.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-553.157.1.rt7.498.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-develto a version that resolves this vulnerability.Fixed in 4.18.0-553.157.1.rt7.498.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-553.157.1.rt7.498.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-553.157.1.rt7.498.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-debug-kvmto a version that resolves this vulnerability.Fixed in 4.18.0-553.157.1.rt7.498.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-kvmto a version that resolves this vulnerability.Fixed in 4.18.0-553.157.1.rt7.498.el8_10 - Upgrade
Upgrade
kernel-rtto a version that resolves this vulnerability.Patch RHEL-219767 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch JIRA:RHEL-219767 - Upgrade
Upgrade
kernelto a version that resolves this vulnerability.Patch CVE-2024-56602 - Compensating control
Reboot the system after applying the kernel-rt update so the changes described in the advisory take effect.
Event History
Frequently Asked Questions
Which systems should be prioritized for this update?
Prioritize systems running Red Hat kernel-rt packages, including Red Hat Enterprise Linux for Real Time, Real Time for NFV, and the listed x86_64 Extended Life Cycle offering. The affected package set includes kernel-rt, kernel-rt-core, and the debug variants.
Are there operational fixes in addition to the security fixes?
Yes. The update addresses sfc TX queue stalls and NIC resets caused by GFP_ATOMIC allocation failures after a RHEL 8.10 kernel update.