RHSA-2026:59737: Important: kernel-rt security, bug fix, and enhancement update
Important: kernel-rt security, bug fix, and enhancement update
Other sources
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: sctp: purge outqueue on stale COOKIE-ECHO handling (CVE-2026-52924) kernel: scsi: target: iscsi: Validate CHAPR length before base64 decode (CVE-2026-63886) kernel: netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check (CVE-2026-63913) kernel: i2c: stub: Reject I2C block transfers with invalid length (CVE-2026-64191) kernel: netfilter: ipset: fix race between dump and ipsetlist resize (CVE-2026-64189) kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (CVE-2026-64320) kernel: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (CVE-2026-64277) kernel: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (CVE-2026-64276) Bug Fix(es) and Enhancement(s): [RHEL-RT] usbhubwq items may run on isolated+nohzfull cores (JIRA:RHEL-178088) SELinux TCP/MPTCP connect check bypass via TCP Fast Open [rhel-8.10.z] (JIRA:RHEL-222800) ss core dumped when there is an SCTP session [rhel-8.10.z] (JIRA:RHEL-212400) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 4.18.0-553.158.1.rt7.499.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-coreto a version that resolves this vulnerability.Fixed in 4.18.0-553.158.1.rt7.499.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-debugto a version that resolves this vulnerability.Fixed in 4.18.0-553.158.1.rt7.499.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-debug-coreto a version that resolves this vulnerability.Fixed in 4.18.0-553.158.1.rt7.499.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-debug-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-553.158.1.rt7.499.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-debug-develto a version that resolves this vulnerability.Fixed in 4.18.0-553.158.1.rt7.499.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-debug-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-553.158.1.rt7.499.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-debug-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-553.158.1.rt7.499.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-debuginfoto a version that resolves this vulnerability.Fixed in 4.18.0-553.158.1.rt7.499.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-develto a version that resolves this vulnerability.Fixed in 4.18.0-553.158.1.rt7.499.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-modulesto a version that resolves this vulnerability.Fixed in 4.18.0-553.158.1.rt7.499.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-modules-extrato a version that resolves this vulnerability.Fixed in 4.18.0-553.158.1.rt7.499.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-debug-kvmto a version that resolves this vulnerability.Fixed in 4.18.0-553.158.1.rt7.499.el8_10 - Upgrade
Upgrade
redhat/kernel-rt-kvmto a version that resolves this vulnerability.Fixed in 4.18.0-553.158.1.rt7.499.el8_10
Event History
Frequently Asked Questions
Which systems should be prioritized for this update?
Prioritize systems running the kernel-rt packages, particularly Red Hat Enterprise Linux for Real Time, Real Time for NFV, and the listed x86_64 Extended Life Cycle offering. The affected package set includes kernel-rt, kernel-rt-core, and kernel-rt debug packages.
Is any issue identified as reachable before authentication?
Yes. CVE-2026-64320 is described as a pre-auth out-of-bounds heap read in the NVMe target Discovery Get Log Page handling. Systems exposing NVMe target discovery functionality should be assessed for this condition.
Which network-facing kernel features are included in the security fixes?
The update includes fixes involving SCTP stale COOKIE-ECHO handling, iSCSI target CHAP_R validation, netfilter conntrack TCP RST handling, and netfilter ipset dump/list resizing. It also includes the pre-auth NVMe target discovery issue.
Does the advisory contain changes beyond the listed CVEs?
Yes. It also contains bug fixes and enhancements, including a fix for SELinux TCP/MPTCP connect-check bypass via TCP Fast Open and a real-time scheduling-related USB hub workqueue fix.