RHSA-2026:6572MediumCVSS 7.5

Red Hat Security Advisory: kernel-rt security update

Published
April 6, 2026
Last Modified
September 11, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2024-26984 — kernel: nouveau: fix instmem race condition around ptr stores CVE-2025-71238 — kernel: Linux kernel (qla2xxx): Double free vulnerability leads to denial of service and potential privilege escalation. CVE-2026-23193 — kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() CVE-2026-23231 — kernel: kernel: Privilege escalation or denial of service via use-after-free in nf_tables_addchain()

🎯 Affected products32

  • Red Hat Enterprise Linux NFV (v. 8)
  • Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-0:4.18.0-553.117.1.rt7.458.el8_10.src as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-0:4.18.0-553.117.1.rt7.458.el8_10.src as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-core-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-core-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-core-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-core-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-debuginfo-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-debuginfo-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-devel-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-devel-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-kvm-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-modules-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-modules-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debug-modules-extra-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debug-modules-extra-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debuginfo-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debuginfo-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-devel-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-devel-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • kernel-rt-kvm-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-modules-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux NFV (v. 8)
  • kernel-rt-modules-0:4.18.0-553.117.1.rt7.458.el8_10.x86_64 as a component of Red Hat Enterprise Linux RT (v. 8)
  • +2 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent module qla2xxx from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module iscsi_target_mod from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: In order to trigger the issue, it requires the ability to create user/net namespaces. On non-containerized deployments of Red Hat Enterprise Linux 7.4 and later, it is recommended to disable user namespaces by setting user.max_user_namespaces to 0: # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf On containerized deployments, such as Red Hat OpenShift Container Platform, do not use this mitigation as the functionality is needed to be enabled.

🔗 References (7)