RHSA-2026:59663: Important: kernel-rt security, bug fix, and enhancement update
Important: kernel-rt security, bug fix, and enhancement update
Other sources
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: net: atm: fix crash due to unvalidated vcc pointer in sigdsend() (CVE-2026-31411) kernel: fs/smb/client: fix out-of-bounds read in cifssanitizeprepath (CVE-2026-43112) kernel: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (CVE-2026-46099) kernel: dm log: fix out-of-bounds write due to regioncount overflow (CVE-2026-53059) Bug Fix(es) and Enhancement(s): [RHEL 9] Bonding reports unknown speed/duplex for tg3 interface (JIRA:RHEL-182765) vhost: reset the vring metadata cache on vring reconfiguration (JIRA:RHEL-224546) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 5.14.0-284.188.1.rt14.473.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-coreto a version that resolves this vulnerability.Fixed in 5.14.0-284.188.1.rt14.473.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debugto a version that resolves this vulnerability.Fixed in 5.14.0-284.188.1.rt14.473.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debug-coreto a version that resolves this vulnerability.Fixed in 5.14.0-284.188.1.rt14.473.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debug-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-284.188.1.rt14.473.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debug-develto a version that resolves this vulnerability.Fixed in 5.14.0-284.188.1.rt14.473.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debug-kvmto a version that resolves this vulnerability.Fixed in 5.14.0-284.188.1.rt14.473.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debug-modulesto a version that resolves this vulnerability.Fixed in 5.14.0-284.188.1.rt14.473.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debug-modules-coreto a version that resolves this vulnerability.Fixed in 5.14.0-284.188.1.rt14.473.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debug-modules-extrato a version that resolves this vulnerability.Fixed in 5.14.0-284.188.1.rt14.473.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-284.188.1.rt14.473.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-develto a version that resolves this vulnerability.Fixed in 5.14.0-284.188.1.rt14.473.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-kvmto a version that resolves this vulnerability.Fixed in 5.14.0-284.188.1.rt14.473.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-modulesto a version that resolves this vulnerability.Fixed in 5.14.0-284.188.1.rt14.473.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-modules-coreto a version that resolves this vulnerability.Fixed in 5.14.0-284.188.1.rt14.473.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-modules-extrato a version that resolves this vulnerability.Fixed in 5.14.0-284.188.1.rt14.473.el9_2 - Upgrade
Upgrade
kernel-rtto a version that resolves this vulnerability.Patch CVE-2026-53059 - Upgrade
Upgrade
kernel-rtto a version that resolves this vulnerability.Patch CVE-2026-43112 - Upgrade
Upgrade
kernel-rtto a version that resolves this vulnerability.Patch CVE-2026-46099 - Upgrade
Upgrade
kernel-rtto a version that resolves this vulnerability.Patch CVE-2026-31411 - Configuration
Reset the vring metadata cache on vring reconfiguration (JIRA:RHEL-224546).
vhost vring metadata cache = reset on vring reconfiguration - Operational
Reboot the system to ensure the kernel-rt update takes effect.
Event History
Frequently Asked Questions
Which systems should prioritize this update?
Systems running the Red Hat kernel-rt packages should prioritize it, especially Real Time Linux deployments used for workloads requiring extremely high determinism. The listed affected package set includes kernel-rt, kernel-rt-core, and kernel-rt-debug variants.
What types of kernel flaws are addressed?
The update fixes a crash involving an unvalidated ATM VCC pointer, an out-of-bounds read in the SMB client, an IPv6 NOREF destination use issue in seg6 and RPL lwtunnels, and an out-of-bounds write caused by device-mapper log region_count overflow.
Are non-security fixes included in this update?
Yes. It includes a RHEL 9 fix for bonding reporting unknown speed or duplex on tg3 interfaces, and a vhost fix that resets vring metadata cache during vring reconfiguration.