RHSA-2026:60438: Important: kernel-rt security update
Important: kernel-rt security update
Other sources
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.Security Fix(es): kernel: net: ipv6: use-after-free in fib6rulesuppress due to stale res->rt6 pointer (CVE-2026-74581) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 5.14.0-284.189.1.rt14.474.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-coreto a version that resolves this vulnerability.Fixed in 5.14.0-284.189.1.rt14.474.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debugto a version that resolves this vulnerability.Fixed in 5.14.0-284.189.1.rt14.474.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debug-coreto a version that resolves this vulnerability.Fixed in 5.14.0-284.189.1.rt14.474.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debug-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-284.189.1.rt14.474.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debug-develto a version that resolves this vulnerability.Fixed in 5.14.0-284.189.1.rt14.474.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debug-kvmto a version that resolves this vulnerability.Fixed in 5.14.0-284.189.1.rt14.474.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debug-modulesto a version that resolves this vulnerability.Fixed in 5.14.0-284.189.1.rt14.474.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debug-modules-coreto a version that resolves this vulnerability.Fixed in 5.14.0-284.189.1.rt14.474.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debug-modules-extrato a version that resolves this vulnerability.Fixed in 5.14.0-284.189.1.rt14.474.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-debuginfoto a version that resolves this vulnerability.Fixed in 5.14.0-284.189.1.rt14.474.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-develto a version that resolves this vulnerability.Fixed in 5.14.0-284.189.1.rt14.474.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-kvmto a version that resolves this vulnerability.Fixed in 5.14.0-284.189.1.rt14.474.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-modulesto a version that resolves this vulnerability.Fixed in 5.14.0-284.189.1.rt14.474.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-modules-coreto a version that resolves this vulnerability.Fixed in 5.14.0-284.189.1.rt14.474.el9_2 - Upgrade
Upgrade
redhat/kernel-rt-modules-extrato a version that resolves this vulnerability.Fixed in 5.14.0-284.189.1.rt14.474.el9_2
Event History
Frequently Asked Questions
Which systems are covered by this update?
The advisory applies to Red Hat kernel-rt packages, including kernel-rt-core and kernel-rt-debug variants, for Red Hat Enterprise Linux x86_64 Update Services for SAP Solutions and Extended Life Cycle offerings.
What vulnerability class is addressed?
The update fixes CVE-2026-74581, a use-after-free issue in the IPv6 networking code involving fib6_rule_suppress and a stale res->rt6 pointer.