RHSA-2026:75746: Important: kernel-rt security, bug fix, and enhancement update
Reporting by Red Hat Security AdvisoriesRead the original at access.redhat.com
Executive Summary
A security advisory for kernel-rt was issued on October 5, 2026, detailing numerous security fixes and enhancements affecting Red Hat Enterprise Linux systems. The update addresses vulnerabilities across various kernel components, including the Linux kernel, gfs2, RDMA/bnxtre driver, nvme-pci, QFQ scheduler, and various networking subsystems like ipvs, netfilter, and tunnels. The list includes numerous CVEs spanning from 2022 to 2026, indicating a broad scope of required remediation for the Real Time Linux Kernel components.
The fixes involve addressing issues such as use-after-free bugs, race conditions, denial of service vulnerabilities, and memory disclosure flaws across drivers and scheduling mechanisms. Specific vulnerabilities identified include issues in the xc5000 tuner driver, gdlmputlock, RDMA/bnxtre QP destruction, and various netfilter and KVM related operations. The advisory mandates a system reboot for the update to take effect.
The advisory emphasizes that kernel errata should be treated as security-relevant due to the kernel's foundational role in system security. Red Hat stresses the importance of timely updates to maintain system security posture, noting that proactive patching minimizes exposure even for future, unassigned CVEs.
Facts Only
* The advisory was issued on 2026-10-05 and updated on 2026-10-05.
* The update concerns the kernel-rt packages for Red Hat Enterprise Linux 8.
* Security impact is rated as Important.
* Specific security fixes target vulnerabilities in kernel components such as the Linux kernel, gfs2, and various drivers.
* Identified vulnerabilities include CVEs ranging from CVE-2025-39994 to CVE-2026-97417.
* Fixes address issues like use-after-free in the xc5000 tuner driver (CVE-2025-39994) and Denial of Service in RDMA/bnxtre (CVE-2023-54048).
* Other fixed vulnerabilities include issues in nvme-pci, QFQ scheduler, network protocols (ipvs, netfilter), and KVM virtualization.
* The affected products include Red Hat Enterprise Linux for Real Time 8 x8664 and related NFV packages.
* Specific fixes involve kernel components like `net/sched`, `crypto`, `netfilter`, and various device drivers.
* The solution requires a system reboot to apply the update.
Full Take
The pattern emerging here is the tight coupling between low-level kernel components—specifically those managing real-time performance and hardware interaction (like RDMA, NVMe, and KVM)—and complex network/virtualization features. The sheer volume and novelty of CVEs involving race conditions and memory management across these subsystems suggest a systematic complexity where fine-grained resource handling introduces significant attack surfaces. The pattern is one of layered exposure: even in critical components like the Real Time Linux Kernel, subtle errors compound into significant security risks, demanding meticulous attention from the kernel development process to avoid systemic vulnerabilities.
The implication for agency is that true cognitive sovereignty requires understanding not just the high-level policy, but the intricate mechanics of the underlying infrastructure. When a vendor issues numerous, interconnected fixes across diverse subsystems, it forces the user to engage in deep scrutiny of system integrity rather than passive acceptance of updates. The focus on proactive patching highlights a tension: administrators must balance operational stability with immediate security remediation, recognizing that delays create exposure against a backdrop of rapidly evolving, deeply technical threats.
The attack playbook for an actor leveraging this information would likely focus on exploiting the complex interplay between these kernel subsystems, potentially by triggering specific race conditions within the Real Time Linux environment to achieve privilege escalation or denial of service on specialized hardware interfaces. The pattern is not just about patching individual bugs but understanding the emergent properties of system interactions. What are the implicit assumptions being made about the security and determinism guarantees offered by the `kernel-rt` layer, and who bears the true cost when these highly specific race conditions are exploited?
From the original · Red Hat Security Advisories
- Issued: - 2026-10-05 - Updated: - 2026-10-05 RHSA-2026:75746 - Security Advisory Synopsis Important: kernel-rt security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. Topic An update for kernel-rt is now available for Red Hat Enterprise Linux 8.Read the full story at access.redhat.com
