Red Hat Product Errata RHSA-2026:14301 - Security Advisory Issued: 2026-05-06 Updated: 2026-05-06 RHSA-2026:14301 - Security Advisory Overview Updated Packages Synopsis Important: kernel-rt security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for kernel-rt is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): kernel: nvme: avoid double free special payload (CVE-2024-41073) kernel: Linux kernel: Denial of Service due to a deadlock in hugetlb folio migration (CVE-2026-23097) kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() (CVE-2026-23193) kernel: ALSA: aloop: Fix racy access at PCM trigger (CVE-2026-23191) kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (CVE-2026-31402) kernel: crypto: algif_aead - Revert to operating out-of-place (CVE-2026-31431) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Affected Products Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Fixes BZ - 2301637 - CVE-2024-41073 kernel: nvme: avoid double free special payload BZ - 2436802 - CVE-2026-23097 kernel: Linux kernel: Denial of Service due to a deadlock in hugetlb folio migration BZ - 2439887 - CVE-2026-23193 kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() BZ - 2439947 - CVE-2026-23191 kernel: ALSA: aloop: Fix racy access at PCM trigger BZ - 2454844 - CVE-2026-31402 kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache BZ - 2460538 - CVE-2026-31431 kernel: crypto: algif_aead - Revert to operating out-of-place CVEs CVE-2024-41073 CVE-2026-23097 CVE-2026-23191 CVE-2026-23193 CVE-2026-31402 CVE-2026-31431 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 SRPM kernel-rt-5.14.0-284.169.1.rt14.454.el9_2.src.rpm SHA-256: a74db84683ff132128f1ebe5ac4aa3c17492e32352abc48774b050bddd603f2b x86_64 kernel-rt-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: b37fdd0ac6cd776f22af181d7ee9f8b549a10cd011c7817be074cb90346ffb19 kernel-rt-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: b37fdd0ac6cd776f22af181d7ee9f8b549a10cd011c7817be074cb90346ffb19 kernel-rt-core-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 59ae30aa26dc8fe3f53321290a2344993cecffb97653ec8ebe341f638dc95f21 kernel-rt-core-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 59ae30aa26dc8fe3f53321290a2344993cecffb97653ec8ebe341f638dc95f21 kernel-rt-debug-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: e6ac3af8ba88c0f088e832c97fc1ae69253100836137556922d840b2adc71749 kernel-rt-debug-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: e6ac3af8ba88c0f088e832c97fc1ae69253100836137556922d840b2adc71749 kernel-rt-debug-core-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 7232a549902d87b8fba0bc921771024d9030bebb6f6a4716eb9426ff4fdc85db kernel-rt-debug-core-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 7232a549902d87b8fba0bc921771024d9030bebb6f6a4716eb9426ff4fdc85db kernel-rt-debug-debuginfo-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 02584228b68a59cc88c183b01173414d40ee81a38ee3a1ee325fffd5c6bd98e2 kernel-rt-debug-debuginfo-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 02584228b68a59cc88c183b01173414d40ee81a38ee3a1ee325fffd5c6bd98e2 kernel-rt-debug-devel-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 3edff7e478743cd90d36d45f26e147f2fbb7dbd0e340a9c0de29e7ec181a9b2f kernel-rt-debug-devel-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 3edff7e478743cd90d36d45f26e147f2fbb7dbd0e340a9c0de29e7ec181a9b2f kernel-rt-debug-kvm-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: a2232a6230f0258234f5716bf40c4237c8c8a2abfd321dd1bf7abdc4a9746c66 kernel-rt-debug-modules-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: ace19d9242317147eb03c31b61b7ae85a2a54039f86f5bedf2539f8e9163056e kernel-rt-debug-modules-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: ace19d9242317147eb03c31b61b7ae85a2a54039f86f5bedf2539f8e9163056e kernel-rt-debug-modules-core-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 6df6482e6f687305fc24becd70da83b8fd12e9af23fbc3ea247b5f0a9f13c277 kernel-rt-debug-modules-core-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 6df6482e6f687305fc24becd70da83b8fd12e9af23fbc3ea247b5f0a9f13c277 kernel-rt-debug-modules-extra-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: c256eaed245e97f1e3828edabe4897398c56b314e358fe04962f16618dd726f8 kernel-rt-debug-modules-extra-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: c256eaed245e97f1e3828edabe4897398c56b314e358fe04962f16618dd726f8 kernel-rt-debuginfo-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 23c95e16bd5b32604ca52fb16c8d1207628c68355dc1468cb986b6ad8764f4e9 kernel-rt-debuginfo-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 23c95e16bd5b32604ca52fb16c8d1207628c68355dc1468cb986b6ad8764f4e9 kernel-rt-debuginfo-common-x86_64-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 04f5045254b207896f8ec88adcc248facdc1a819e587884fd646bff6c88334a6 kernel-rt-debuginfo-common-x86_64-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 04f5045254b207896f8ec88adcc248facdc1a819e587884fd646bff6c88334a6 kernel-rt-devel-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 792d3f738438716d0f92532ac04357bb2b7e558c7fca251609be99b5d4d42da2 kernel-rt-devel-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 792d3f738438716d0f92532ac04357bb2b7e558c7fca251609be99b5d4d42da2 kernel-rt-kvm-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 11bdfb91365c0b88bcb05987fc8bed9396787dc6f4aabe40454a9095f05f9838 kernel-rt-modules-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 3bfa411a5f1704cf3410c8f8502dff7144b175ed6eb339a139e5b5d2f53b0e3e kernel-rt-modules-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 3bfa411a5f1704cf3410c8f8502dff7144b175ed6eb339a139e5b5d2f53b0e3e kernel-rt-modules-core-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 2c0027e65d1d1ef1c7c6b125698754ad66ed25bb996a50a95882bf077266b878 kernel-rt-modules-core-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 2c0027e65d1d1ef1c7c6b125698754ad66ed25bb996a50a95882bf077266b878 kernel-rt-modules-extra-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 17ccc36f64d7bd9c8151beb3bee989f31eeb9fd021e400f75df5ba9fc6394ad3 kernel-rt-modules-extra-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 17ccc36f64d7bd9c8151beb3bee989f31eeb9fd021e400f75df5ba9fc6394ad3 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 SRPM kernel-rt-5.14.0-284.169.1.rt14.454.el9_2.src.rpm SHA-256: a74db84683ff132128f1ebe5ac4aa3c17492e32352abc48774b050bddd603f2b x86_64 kernel-rt-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: b37fdd0ac6cd776f22af181d7ee9f8b549a10cd011c7817be074cb90346ffb19 kernel-rt-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: b37fdd0ac6cd776f22af181d7ee9f8b549a10cd011c7817be074cb90346ffb19 kernel-rt-core-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 59ae30aa26dc8fe3f53321290a2344993cecffb97653ec8ebe341f638dc95f21 kernel-rt-core-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 59ae30aa26dc8fe3f53321290a2344993cecffb97653ec8ebe341f638dc95f21 kernel-rt-debug-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: e6ac3af8ba88c0f088e832c97fc1ae69253100836137556922d840b2adc71749 kernel-rt-debug-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: e6ac3af8ba88c0f088e832c97fc1ae69253100836137556922d840b2adc71749 kernel-rt-debug-core-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 7232a549902d87b8fba0bc921771024d9030bebb6f6a4716eb9426ff4fdc85db kernel-rt-debug-core-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 7232a549902d87b8fba0bc921771024d9030bebb6f6a4716eb9426ff4fdc85db kernel-rt-debug-debuginfo-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 02584228b68a59cc88c183b01173414d40ee81a38ee3a1ee325fffd5c6bd98e2 kernel-rt-debug-debuginfo-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 02584228b68a59cc88c183b01173414d40ee81a38ee3a1ee325fffd5c6bd98e2 kernel-rt-debug-devel-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 3edff7e478743cd90d36d45f26e147f2fbb7dbd0e340a9c0de29e7ec181a9b2f kernel-rt-debug-devel-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 3edff7e478743cd90d36d45f26e147f2fbb7dbd0e340a9c0de29e7ec181a9b2f kernel-rt-debug-kvm-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: a2232a6230f0258234f5716bf40c4237c8c8a2abfd321dd1bf7abdc4a9746c66 kernel-rt-debug-modules-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: ace19d9242317147eb03c31b61b7ae85a2a54039f86f5bedf2539f8e9163056e kernel-rt-debug-modules-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: ace19d9242317147eb03c31b61b7ae85a2a54039f86f5bedf2539f8e9163056e kernel-rt-debug-modules-core-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 6df6482e6f687305fc24becd70da83b8fd12e9af23fbc3ea247b5f0a9f13c277 kernel-rt-debug-modules-core-5.14.0-284.169.1.rt14.454.el9_2.x86_64.rpm SHA-256: 6df6482e6f687305fc24becd70da83b8fd12e9af2
This Red Hat security advisory addresses six vulnerabilities in the kernel-rt package for RHEL 9.2 Update Services for SAP Solutions, including a high-severity use-after-free in iSCSI target code (CVE-2026-23193, CVSS 8.8), a high-severity double-free in NVMe (CVE-2024-41073, CVSS 7.8), a heap overflow in NFSv4.0, and a denial-of-service deadlock in hugetlb folio migration. The specific affected and fixed kernel versions are detailed in the provided NVD data for each CVE. A system reboot is required after applying the update.