RHEL 8 : kernel-rt (RHSA-2026:70403)

high Nessus Plugin ID 349105

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

The remote Redhat Enterprise Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2026:70403 advisory.

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

Security Fix(es):

* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)

* kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread (CVE-2023-54120)

* kernel: Bluetooth: L2CAP: Fix potential user-after-free (CVE-2023-54214)

* kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb (CVE-2025-71082)

* kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)

* kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)

* kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043)

* kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing (CVE-2026-46133)

* kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)

* kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)

* kernel: iommu/amd: Fix clone_alias() to use the original device's devid (CVE-2026-53053)

* kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)

* kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)

* kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)

* kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)

* kernel: Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CVE-2026-63947)

* kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (CVE-2026-64534)

* kernel: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (CVE-2026-64582)

* kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (CVE-2026-68293)

* kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios (CVE-2026-68188)

Bug Fix(es) and Enhancement(s):

* Intel IOMMU: possible circular locking dependency (JIRA:RHEL-243217)

* xfs: repeated xfs_trans_cancel called from xfs_iomap_write_direct (JIRA:RHEL-251578)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://access.redhat.com/errata/RHSA-2026:70403

https://access.redhat.com/security/updates/classification/#important

https://bugzilla.redhat.com/show_bug.cgi?id=2403545

https://bugzilla.redhat.com/show_bug.cgi?id=2425183

https://bugzilla.redhat.com/show_bug.cgi?id=2426069

https://bugzilla.redhat.com/show_bug.cgi?id=2429054

https://bugzilla.redhat.com/show_bug.cgi?id=2468050

https://bugzilla.redhat.com/show_bug.cgi?id=2481940

https://bugzilla.redhat.com/show_bug.cgi?id=2482127

https://bugzilla.redhat.com/show_bug.cgi?id=2482550

https://bugzilla.redhat.com/show_bug.cgi?id=2492092

https://bugzilla.redhat.com/show_bug.cgi?id=2492278

https://bugzilla.redhat.com/show_bug.cgi?id=2492310

https://bugzilla.redhat.com/show_bug.cgi?id=2492717

https://bugzilla.redhat.com/show_bug.cgi?id=2492795

https://bugzilla.redhat.com/show_bug.cgi?id=2502218

https://bugzilla.redhat.com/show_bug.cgi?id=2502346

https://bugzilla.redhat.com/show_bug.cgi?id=2502388

https://bugzilla.redhat.com/show_bug.cgi?id=2507399

https://bugzilla.redhat.com/show_bug.cgi?id=2511448

https://bugzilla.redhat.com/show_bug.cgi?id=2513150

https://bugzilla.redhat.com/show_bug.cgi?id=2513222

http://www.nessus.org/u?84ab50c1

Plugin Details

Severity: High

ID: 349105

File Name: redhat-RHSA-2026-70403.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/22/2026

Updated: 9/22/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.3

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-71082

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:redhat:enterprise_linux:8, cpe:/o:redhat:rhel_eus:8.10, p-cpe:/a:redhat:enterprise_linux:kernel-rt-core, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug-core, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug-devel, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug-kvm, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug-modules, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug, p-cpe:/a:redhat:enterprise_linux:kernel-rt-devel, p-cpe:/a:redhat:enterprise_linux:kernel-rt-kvm, p-cpe:/a:redhat:enterprise_linux:kernel-rt-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-rt-modules, p-cpe:/a:redhat:enterprise_linux:kernel-rt

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/22/2026

Vulnerability Publication Date: 7/21/2021

CISA Known Exploited Vulnerability Due Dates: 9/21/2026

Reference Information

CVE: CVE-2023-54120, CVE-2023-54214, CVE-2025-39964, CVE-2025-71082, CVE-2026-43334, CVE-2026-45894, CVE-2026-46043, CVE-2026-46133, CVE-2026-52918, CVE-2026-53053, CVE-2026-53062, CVE-2026-53254, CVE-2026-53256, CVE-2026-63823, CVE-2026-63947, CVE-2026-63975, CVE-2026-64534, CVE-2026-64582, CVE-2026-68188, CVE-2026-68293

CWE: 120, 125, 1284, 191, 322, 364, 366, 367, 414, 416, 694, 820, 825, 826, 911

RHSA: 2026:70403