Red Hat Product Errata RHSA-2026:16254 - Security Advisory Issued: 2026-05-12 Updated: 2026-05-12 RHSA-2026:16254 - Security Advisory Overview Updated Packages Synopsis Important: kernel-rt security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for kernel-rt is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): kernel: "Dirty Frag" is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel (CVE-2026-43284) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Affected Products Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Fixes BZ - 2467771 - CVE-2026-43284 kernel: "Dirty Frag" ESP XFRM variant is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel CVEs CVE-2026-43284 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 SRPM kernel-rt-5.14.0-284.170.1.rt14.455.el9_2.src.rpm SHA-256: 5cfbafb760af5c920c84cefacc18cf507ab29ab2812c4e5e39d96523e99c8f40 x86_64 kernel-rt-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: ae47bd306f163526bdce636edffce71e51cfbec8e78eaa169101745f5d7805b5 kernel-rt-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: ae47bd306f163526bdce636edffce71e51cfbec8e78eaa169101745f5d7805b5 kernel-rt-core-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 9c473a99a9341c48d2ba6d741d875b9a005483430a443df6264a506b3e490606 kernel-rt-core-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 9c473a99a9341c48d2ba6d741d875b9a005483430a443df6264a506b3e490606 kernel-rt-debug-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: cb7f02108b768c13fb2c586d8442d532cd9e8a4448272424f4345567aa3d6e05 kernel-rt-debug-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: cb7f02108b768c13fb2c586d8442d532cd9e8a4448272424f4345567aa3d6e05 kernel-rt-debug-core-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: a18967b0aaa0e9b429abe09567736b2b37de5cdaa944cff73941968df1714e60 kernel-rt-debug-core-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: a18967b0aaa0e9b429abe09567736b2b37de5cdaa944cff73941968df1714e60 kernel-rt-debug-debuginfo-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 82072a44ed8a4ea3ba5310c2e5e96b4b8910ca1ef09574b957903c8d6d56ed92 kernel-rt-debug-debuginfo-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 82072a44ed8a4ea3ba5310c2e5e96b4b8910ca1ef09574b957903c8d6d56ed92 kernel-rt-debug-devel-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 6807b54c3025a18e3efd0a2c2b1e76148be73bde69c77e182a27a3a97d3021ad kernel-rt-debug-devel-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 6807b54c3025a18e3efd0a2c2b1e76148be73bde69c77e182a27a3a97d3021ad kernel-rt-debug-kvm-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: ccd1ab4c63c094523e669e850ba12099ea012bf0f840fce6b6bc7b9a2b0cacc7 kernel-rt-debug-modules-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 91252f8e84f5d7362122d9468faf1b7cd051fc3afdf2c50521eaa063677fa728 kernel-rt-debug-modules-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 91252f8e84f5d7362122d9468faf1b7cd051fc3afdf2c50521eaa063677fa728 kernel-rt-debug-modules-core-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 820ef89935287d680b93b5c5c5fbe342f6a13a4a9575a88933b1fe102f143ff8 kernel-rt-debug-modules-core-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 820ef89935287d680b93b5c5c5fbe342f6a13a4a9575a88933b1fe102f143ff8 kernel-rt-debug-modules-extra-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: db53a3f45c5fd182058bfb0905bb6d108db91d8ff743b3ca5d23ea14cf775710 kernel-rt-debug-modules-extra-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: db53a3f45c5fd182058bfb0905bb6d108db91d8ff743b3ca5d23ea14cf775710 kernel-rt-debuginfo-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 2544635421c340dba95d19935e77b27df3f9dcc6393592ba0b91424dc96a0cd2 kernel-rt-debuginfo-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 2544635421c340dba95d19935e77b27df3f9dcc6393592ba0b91424dc96a0cd2 kernel-rt-debuginfo-common-x86_64-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 522d319f958f83e052ab64418b15464ae514764484a56e3918a6276203b91b62 kernel-rt-debuginfo-common-x86_64-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 522d319f958f83e052ab64418b15464ae514764484a56e3918a6276203b91b62 kernel-rt-devel-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 0ce47e26cc770499a4861f282e40358bfc42c5e1cdc79b0358f6ca08bf0ac1ff kernel-rt-devel-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 0ce47e26cc770499a4861f282e40358bfc42c5e1cdc79b0358f6ca08bf0ac1ff kernel-rt-kvm-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 3e0903d75393a55ee542284e70c0ee266b57f30c2b9a7e03c5fc15e7531ed099 kernel-rt-modules-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 9846411cadbdeae2dc526f47f8309686c1597226a355af89d84c070c6200eebb kernel-rt-modules-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 9846411cadbdeae2dc526f47f8309686c1597226a355af89d84c070c6200eebb kernel-rt-modules-core-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: b7fa09dfec5eb79bb3158f184140d9a8b87d920c9d48ae427f25d69049cee1e3 kernel-rt-modules-core-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: b7fa09dfec5eb79bb3158f184140d9a8b87d920c9d48ae427f25d69049cee1e3 kernel-rt-modules-extra-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 906d6bdd037c8fc7b4b148a249f73e5f57febb2ead9dc5d1f786312e95f639e6 kernel-rt-modules-extra-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 906d6bdd037c8fc7b4b148a249f73e5f57febb2ead9dc5d1f786312e95f639e6 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 SRPM kernel-rt-5.14.0-284.170.1.rt14.455.el9_2.src.rpm SHA-256: 5cfbafb760af5c920c84cefacc18cf507ab29ab2812c4e5e39d96523e99c8f40 x86_64 kernel-rt-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: ae47bd306f163526bdce636edffce71e51cfbec8e78eaa169101745f5d7805b5 kernel-rt-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: ae47bd306f163526bdce636edffce71e51cfbec8e78eaa169101745f5d7805b5 kernel-rt-core-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 9c473a99a9341c48d2ba6d741d875b9a005483430a443df6264a506b3e490606 kernel-rt-core-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 9c473a99a9341c48d2ba6d741d875b9a005483430a443df6264a506b3e490606 kernel-rt-debug-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: cb7f02108b768c13fb2c586d8442d532cd9e8a4448272424f4345567aa3d6e05 kernel-rt-debug-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: cb7f02108b768c13fb2c586d8442d532cd9e8a4448272424f4345567aa3d6e05 kernel-rt-debug-core-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: a18967b0aaa0e9b429abe09567736b2b37de5cdaa944cff73941968df1714e60 kernel-rt-debug-core-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: a18967b0aaa0e9b429abe09567736b2b37de5cdaa944cff73941968df1714e60 kernel-rt-debug-debuginfo-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 82072a44ed8a4ea3ba5310c2e5e96b4b8910ca1ef09574b957903c8d6d56ed92 kernel-rt-debug-debuginfo-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 82072a44ed8a4ea3ba5310c2e5e96b4b8910ca1ef09574b957903c8d6d56ed92 kernel-rt-debug-devel-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 6807b54c3025a18e3efd0a2c2b1e76148be73bde69c77e182a27a3a97d3021ad kernel-rt-debug-devel-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 6807b54c3025a18e3efd0a2c2b1e76148be73bde69c77e182a27a3a97d3021ad kernel-rt-debug-kvm-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: ccd1ab4c63c094523e669e850ba12099ea012bf0f840fce6b6bc7b9a2b0cacc7 kernel-rt-debug-modules-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 91252f8e84f5d7362122d9468faf1b7cd051fc3afdf2c50521eaa063677fa728 kernel-rt-debug-modules-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 91252f8e84f5d7362122d9468faf1b7cd051fc3afdf2c50521eaa063677fa728 kernel-rt-debug-modules-core-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 820ef89935287d680b93b5c5c5fbe342f6a13a4a9575a88933b1fe102f143ff8 kernel-rt-debug-modules-core-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 820ef89935287d680b93b5c5c5fbe342f6a13a4a9575a88933b1fe102f143ff8 kernel-rt-debug-modules-extra-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: db53a3f45c5fd182058bfb0905bb6d108db91d8ff743b3ca5d23ea14cf775710 kernel-rt-debug-modules-extra-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: db53a3f45c5fd182058bfb0905bb6d108db91d8ff743b3ca5d23ea14cf775710 kernel-rt-debuginfo-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 2544635421c340dba95d19935e77b27df3f9dcc6393592ba0b91424dc96a0cd2 kernel-rt-debuginfo-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 2544635421c340dba95d19935e77b27df3f9dcc6393592ba0b91424dc96a0cd2 kernel-rt-debuginfo-common-x86_64-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 522d319f958f83e052ab64418b15464ae514764484a56e3918a6276203b91b62 kernel-rt-debuginfo-common-x86_64-5.14.0-284.170.1.rt14.455.el9_2.x86_64.rpm SHA-256: 522d319f958f83e052ab64418b15464ae5
The vulnerability is CVE-2026-43284 ("Dirty Frag"), a universal Local Privilege Escalation (LPE) flaw in the Linux kernel's ESP XFRM component, with a CVSS 3.1 score of 8.8 (High). Affected kernel versions are from 4.11 up to but not including 5.10.255, from 5.12 up to but not including 5.15.205, from 5.16 up to but not including 6.1.171, from 6.2 up to but not including 6.6.138, and from 6.7 up to but not including 6.12.87. The fix requires applying the specific kernel-rt update provided in the Red Hat advisory and rebooting the system.