<?xml version="1.0" ?>
<rss version="2.0">
  <channel>
    <title>Rocky Linux 8 x86_64 RT</title>
    <link>https://rockylinux.org</link>
    <description>Recently updated packages for Rocky Linux 8 x86_64 RT</description>
    <pubDate>Mon, 14 Sep 2026 05:31:29 AM GMT</pubDate>
    <generator>DNF</generator>
    <item>
      <title>kernel-rt-debug-modules-4.18.0-553.162.1.rt7.503.el8_10.x86_64</title>
      <pubDate>Thu, 10 Sep 2026 02:22:01 PM GMT</pubDate>
      <guid isPermaLink="false">6c3e41713305114b8f8814d3bf59a70d9023184c6fdf38687d9ea20c2dfae4ad</guid>
      <link>https://dl.rockylinux.org/pub/rocky/8/RT/x86_64/os/Packages/k/kernel-rt-debug-modules-4.18.0-553.162.1.rt7.503.el8_10.x86_64.rpm</link>
      <description><p><strong>kernel-rt-debug-modules</strong> - kernel modules to match the debug-core kernel&lt;br /&gt;</p>

<p>This package provides commonly used kernel modules for the debug-core kernel package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 4.18.0-553.162.1.rt7.503
- Adding prod certs and changed cert date to 20210620 (Sherif Nagy)
- Adding Rocky secure boot certs (Sherif Nagy)
- Fixing vmlinuz removal (Sherif Nagy)
- Fixing UEFI CA path (Sherif Nagy)
- Porting to 8.10/8.10, debranding and Rocky branding (Louis Abel)
- Fixing pesign_key_name values (Sherif Nagy)
- Debrand the kernel (Louis Abel)

Wed, 09 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.162.1.rt7.503.el8_10]
- scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (Laurence Oberman) [RHEL-194117]
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Xin Long) [RHEL-228877] {CVE-2026-63801}
- tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (Xin Long) [RHEL-238050] {CVE-2026-68117}
- sctp: fix race between sctp_wait_for_connect and peeloff (Xin Long) [RHEL-229464] {CVE-2026-63971}
- sctp: diag: reject stale associations in dump_one path (Xin Long) [RHEL-231561] {CVE-2026-52917}
- sctp: validate stream count in sctp_process_strreset_inreq() (Xin Long) [RHEL-236135] {CVE-2026-68315}
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [RHEL-237394] {CVE-2026-68376}
- sctp: auth: verify auth requirement when auth_chunk is NULL (Xin Long) [RHEL-237088] {CVE-2026-68300}
- gfs2: harden gfs2_glock_hold (Andreas Gruenbacher) [RHEL-240340]
- gfs2: gfs2_glock_hold cleanup (Andreas Gruenbacher) [RHEL-240340]
- sctp: validate embedded INIT chunk and address list lengths in cookie (Xin Long) [RHEL-190202]
- sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (Xin Long) [RHEL-190202] {CVE-2026-53246}
- netfilter: nf_log: validate MAC header was set before dumping it (CKI Backport Bot) [RHEL-232055] {CVE-2026-52942}
- netfilter: nf_conntrack_sip: don't use simple_strtoul (CKI Backport Bot) [RHEL-232024] {CVE-2026-52986}
- scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-230822] {CVE-2025-68745}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225791] {CVE-2026-46149}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.161.1.rt7.502.el8_10]
- security/keys: fix missed RCU read section on lookup (Bruno Meneguele) [RHEL-225679] {CVE-2026-64015}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227760] {CVE-2026-64113}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: use qdisc_pkt_len_segs_init() in sch_handle_ingress() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: add more sanity checks to qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- sch_cake: do not use skb_mac_header() in cake_overhead() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: do not use skb_mac_header() in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: Skip GSO length estimation if transport header is not set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-rt-core-4.18.0-553.162.1.rt7.503.el8_10.x86_64</title>
      <pubDate>Thu, 10 Sep 2026 02:22:01 PM GMT</pubDate>
      <guid isPermaLink="false">8a1c14e71e9e555e35f6a803714d50a61b3dfb14f5fc080e40c6f13a5110c5aa</guid>
      <link>https://dl.rockylinux.org/pub/rocky/8/RT/x86_64/os/Packages/k/kernel-rt-core-4.18.0-553.162.1.rt7.503.el8_10.x86_64.rpm</link>
      <description><p><strong>kernel-rt-core</strong> - The Linux kernel&lt;br /&gt;</p>

<p>The kernel package contains the Linux kernel (vmlinuz), the core of any&lt;br /&gt;
Linux operating system.  The kernel handles the basic functions&lt;br /&gt;
of the operating system: memory allocation, process allocation, device&lt;br /&gt;
input and output, etc.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 4.18.0-553.162.1.rt7.503
- Adding prod certs and changed cert date to 20210620 (Sherif Nagy)
- Adding Rocky secure boot certs (Sherif Nagy)
- Fixing vmlinuz removal (Sherif Nagy)
- Fixing UEFI CA path (Sherif Nagy)
- Porting to 8.10/8.10, debranding and Rocky branding (Louis Abel)
- Fixing pesign_key_name values (Sherif Nagy)
- Debrand the kernel (Louis Abel)

Wed, 09 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.162.1.rt7.503.el8_10]
- scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (Laurence Oberman) [RHEL-194117]
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Xin Long) [RHEL-228877] {CVE-2026-63801}
- tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (Xin Long) [RHEL-238050] {CVE-2026-68117}
- sctp: fix race between sctp_wait_for_connect and peeloff (Xin Long) [RHEL-229464] {CVE-2026-63971}
- sctp: diag: reject stale associations in dump_one path (Xin Long) [RHEL-231561] {CVE-2026-52917}
- sctp: validate stream count in sctp_process_strreset_inreq() (Xin Long) [RHEL-236135] {CVE-2026-68315}
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [RHEL-237394] {CVE-2026-68376}
- sctp: auth: verify auth requirement when auth_chunk is NULL (Xin Long) [RHEL-237088] {CVE-2026-68300}
- gfs2: harden gfs2_glock_hold (Andreas Gruenbacher) [RHEL-240340]
- gfs2: gfs2_glock_hold cleanup (Andreas Gruenbacher) [RHEL-240340]
- sctp: validate embedded INIT chunk and address list lengths in cookie (Xin Long) [RHEL-190202]
- sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (Xin Long) [RHEL-190202] {CVE-2026-53246}
- netfilter: nf_log: validate MAC header was set before dumping it (CKI Backport Bot) [RHEL-232055] {CVE-2026-52942}
- netfilter: nf_conntrack_sip: don't use simple_strtoul (CKI Backport Bot) [RHEL-232024] {CVE-2026-52986}
- scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-230822] {CVE-2025-68745}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225791] {CVE-2026-46149}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.161.1.rt7.502.el8_10]
- security/keys: fix missed RCU read section on lookup (Bruno Meneguele) [RHEL-225679] {CVE-2026-64015}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227760] {CVE-2026-64113}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: use qdisc_pkt_len_segs_init() in sch_handle_ingress() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: add more sanity checks to qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- sch_cake: do not use skb_mac_header() in cake_overhead() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: do not use skb_mac_header() in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: Skip GSO length estimation if transport header is not set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-rt-kvm-4.18.0-553.162.1.rt7.503.el8_10.x86_64</title>
      <pubDate>Thu, 10 Sep 2026 02:22:01 PM GMT</pubDate>
      <guid isPermaLink="false">fd5883de25a501d844a7a45f1464eda5ae6544c851e9174a54f28b4bd3d6f7b6</guid>
      <link>https://dl.rockylinux.org/pub/rocky/8/RT/x86_64/os/Packages/k/kernel-rt-kvm-4.18.0-553.162.1.rt7.503.el8_10.x86_64.rpm</link>
      <description><p><strong>kernel-rt-kvm</strong> - KVM modules for package kernel-rt&lt;br /&gt;</p>

<p>This package provides KVM modules for package kernel-rt.&lt;br /&gt;
 }</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 4.18.0-553.162.1.rt7.503
- Adding prod certs and changed cert date to 20210620 (Sherif Nagy)
- Adding Rocky secure boot certs (Sherif Nagy)
- Fixing vmlinuz removal (Sherif Nagy)
- Fixing UEFI CA path (Sherif Nagy)
- Porting to 8.10/8.10, debranding and Rocky branding (Louis Abel)
- Fixing pesign_key_name values (Sherif Nagy)
- Debrand the kernel (Louis Abel)

Wed, 09 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.162.1.rt7.503.el8_10]
- scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (Laurence Oberman) [RHEL-194117]
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Xin Long) [RHEL-228877] {CVE-2026-63801}
- tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (Xin Long) [RHEL-238050] {CVE-2026-68117}
- sctp: fix race between sctp_wait_for_connect and peeloff (Xin Long) [RHEL-229464] {CVE-2026-63971}
- sctp: diag: reject stale associations in dump_one path (Xin Long) [RHEL-231561] {CVE-2026-52917}
- sctp: validate stream count in sctp_process_strreset_inreq() (Xin Long) [RHEL-236135] {CVE-2026-68315}
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [RHEL-237394] {CVE-2026-68376}
- sctp: auth: verify auth requirement when auth_chunk is NULL (Xin Long) [RHEL-237088] {CVE-2026-68300}
- gfs2: harden gfs2_glock_hold (Andreas Gruenbacher) [RHEL-240340]
- gfs2: gfs2_glock_hold cleanup (Andreas Gruenbacher) [RHEL-240340]
- sctp: validate embedded INIT chunk and address list lengths in cookie (Xin Long) [RHEL-190202]
- sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (Xin Long) [RHEL-190202] {CVE-2026-53246}
- netfilter: nf_log: validate MAC header was set before dumping it (CKI Backport Bot) [RHEL-232055] {CVE-2026-52942}
- netfilter: nf_conntrack_sip: don't use simple_strtoul (CKI Backport Bot) [RHEL-232024] {CVE-2026-52986}
- scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-230822] {CVE-2025-68745}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225791] {CVE-2026-46149}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.161.1.rt7.502.el8_10]
- security/keys: fix missed RCU read section on lookup (Bruno Meneguele) [RHEL-225679] {CVE-2026-64015}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227760] {CVE-2026-64113}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: use qdisc_pkt_len_segs_init() in sch_handle_ingress() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: add more sanity checks to qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- sch_cake: do not use skb_mac_header() in cake_overhead() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: do not use skb_mac_header() in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: Skip GSO length estimation if transport header is not set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-rt-debug-devel-4.18.0-553.162.1.rt7.503.el8_10.x86_64</title>
      <pubDate>Thu, 10 Sep 2026 02:22:01 PM GMT</pubDate>
      <guid isPermaLink="false">5571acd64d7043687b3464f9d81a2503158d7de2fc12fb3235fca0f54717776d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/8/RT/x86_64/os/Packages/k/kernel-rt-debug-devel-4.18.0-553.162.1.rt7.503.el8_10.x86_64.rpm</link>
      <description><p><strong>kernel-rt-debug-devel</strong> - Development package for building kernel modules to match the debug kernel&lt;br /&gt;</p>

<p>This package provides kernel headers and makefiles sufficient to build modules&lt;br /&gt;
against the debug kernel package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 4.18.0-553.162.1.rt7.503
- Adding prod certs and changed cert date to 20210620 (Sherif Nagy)
- Adding Rocky secure boot certs (Sherif Nagy)
- Fixing vmlinuz removal (Sherif Nagy)
- Fixing UEFI CA path (Sherif Nagy)
- Porting to 8.10/8.10, debranding and Rocky branding (Louis Abel)
- Fixing pesign_key_name values (Sherif Nagy)
- Debrand the kernel (Louis Abel)

Wed, 09 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.162.1.rt7.503.el8_10]
- scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (Laurence Oberman) [RHEL-194117]
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Xin Long) [RHEL-228877] {CVE-2026-63801}
- tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (Xin Long) [RHEL-238050] {CVE-2026-68117}
- sctp: fix race between sctp_wait_for_connect and peeloff (Xin Long) [RHEL-229464] {CVE-2026-63971}
- sctp: diag: reject stale associations in dump_one path (Xin Long) [RHEL-231561] {CVE-2026-52917}
- sctp: validate stream count in sctp_process_strreset_inreq() (Xin Long) [RHEL-236135] {CVE-2026-68315}
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [RHEL-237394] {CVE-2026-68376}
- sctp: auth: verify auth requirement when auth_chunk is NULL (Xin Long) [RHEL-237088] {CVE-2026-68300}
- gfs2: harden gfs2_glock_hold (Andreas Gruenbacher) [RHEL-240340]
- gfs2: gfs2_glock_hold cleanup (Andreas Gruenbacher) [RHEL-240340]
- sctp: validate embedded INIT chunk and address list lengths in cookie (Xin Long) [RHEL-190202]
- sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (Xin Long) [RHEL-190202] {CVE-2026-53246}
- netfilter: nf_log: validate MAC header was set before dumping it (CKI Backport Bot) [RHEL-232055] {CVE-2026-52942}
- netfilter: nf_conntrack_sip: don't use simple_strtoul (CKI Backport Bot) [RHEL-232024] {CVE-2026-52986}
- scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-230822] {CVE-2025-68745}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225791] {CVE-2026-46149}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.161.1.rt7.502.el8_10]
- security/keys: fix missed RCU read section on lookup (Bruno Meneguele) [RHEL-225679] {CVE-2026-64015}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227760] {CVE-2026-64113}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: use qdisc_pkt_len_segs_init() in sch_handle_ingress() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: add more sanity checks to qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- sch_cake: do not use skb_mac_header() in cake_overhead() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: do not use skb_mac_header() in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: Skip GSO length estimation if transport header is not set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-rt-4.18.0-553.162.1.rt7.503.el8_10.x86_64</title>
      <pubDate>Thu, 10 Sep 2026 02:22:01 PM GMT</pubDate>
      <guid isPermaLink="false">518a6c6c1fe3cc4e4ca649d818556cd3cf4196cf44e9f121c5a891f5b66519c7</guid>
      <link>https://dl.rockylinux.org/pub/rocky/8/RT/x86_64/os/Packages/k/kernel-rt-4.18.0-553.162.1.rt7.503.el8_10.x86_64.rpm</link>
      <description><p><strong>kernel-rt</strong> - The Linux kernel, based on version 4.18.0, heavily modified with backports&lt;br /&gt;</p>

<p>This is the package which provides the Linux kernel-rt for Rocky&lt;br /&gt;
Linux. It is based on upstream Linux at version 4.18.0 and maintains kABI&lt;br /&gt;
compatibility of a set of approved symbols, however it is heavily modified with&lt;br /&gt;
backports and fixes pulled from newer upstream Linux kernel-rt releases. This means&lt;br /&gt;
this is not a 4.18.0 kernel anymore: it includes several components which come&lt;br /&gt;
from newer upstream linux versions, while maintaining a well tested and stable&lt;br /&gt;
core. Some of the components/backports that may be pulled in are: changes like&lt;br /&gt;
updates to the core kernel (eg.: scheduler, cgroups, memory management, security&lt;br /&gt;
fixes and features), updates to block layer, supported filesystems, major driver&lt;br /&gt;
updates for supported hardware in Rocky Linux, enhancements for&lt;br /&gt;
enterprise customers, etc.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 4.18.0-553.162.1.rt7.503
- Adding prod certs and changed cert date to 20210620 (Sherif Nagy)
- Adding Rocky secure boot certs (Sherif Nagy)
- Fixing vmlinuz removal (Sherif Nagy)
- Fixing UEFI CA path (Sherif Nagy)
- Porting to 8.10/8.10, debranding and Rocky branding (Louis Abel)
- Fixing pesign_key_name values (Sherif Nagy)
- Debrand the kernel (Louis Abel)

Wed, 09 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.162.1.rt7.503.el8_10]
- scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (Laurence Oberman) [RHEL-194117]
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Xin Long) [RHEL-228877] {CVE-2026-63801}
- tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (Xin Long) [RHEL-238050] {CVE-2026-68117}
- sctp: fix race between sctp_wait_for_connect and peeloff (Xin Long) [RHEL-229464] {CVE-2026-63971}
- sctp: diag: reject stale associations in dump_one path (Xin Long) [RHEL-231561] {CVE-2026-52917}
- sctp: validate stream count in sctp_process_strreset_inreq() (Xin Long) [RHEL-236135] {CVE-2026-68315}
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [RHEL-237394] {CVE-2026-68376}
- sctp: auth: verify auth requirement when auth_chunk is NULL (Xin Long) [RHEL-237088] {CVE-2026-68300}
- gfs2: harden gfs2_glock_hold (Andreas Gruenbacher) [RHEL-240340]
- gfs2: gfs2_glock_hold cleanup (Andreas Gruenbacher) [RHEL-240340]
- sctp: validate embedded INIT chunk and address list lengths in cookie (Xin Long) [RHEL-190202]
- sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (Xin Long) [RHEL-190202] {CVE-2026-53246}
- netfilter: nf_log: validate MAC header was set before dumping it (CKI Backport Bot) [RHEL-232055] {CVE-2026-52942}
- netfilter: nf_conntrack_sip: don't use simple_strtoul (CKI Backport Bot) [RHEL-232024] {CVE-2026-52986}
- scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-230822] {CVE-2025-68745}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225791] {CVE-2026-46149}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.161.1.rt7.502.el8_10]
- security/keys: fix missed RCU read section on lookup (Bruno Meneguele) [RHEL-225679] {CVE-2026-64015}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227760] {CVE-2026-64113}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: use qdisc_pkt_len_segs_init() in sch_handle_ingress() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: add more sanity checks to qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- sch_cake: do not use skb_mac_header() in cake_overhead() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: do not use skb_mac_header() in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: Skip GSO length estimation if transport header is not set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-rt-devel-4.18.0-553.162.1.rt7.503.el8_10.x86_64</title>
      <pubDate>Thu, 10 Sep 2026 02:22:01 PM GMT</pubDate>
      <guid isPermaLink="false">bee749627d1c56b8104abaf8c9cf733164e748e09f7a479eb067e93d87d056a9</guid>
      <link>https://dl.rockylinux.org/pub/rocky/8/RT/x86_64/os/Packages/k/kernel-rt-devel-4.18.0-553.162.1.rt7.503.el8_10.x86_64.rpm</link>
      <description><p><strong>kernel-rt-devel</strong> - Development package for building kernel modules to match the kernel&lt;br /&gt;</p>

<p>This package provides kernel headers and makefiles sufficient to build modules&lt;br /&gt;
against the kernel package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 4.18.0-553.162.1.rt7.503
- Adding prod certs and changed cert date to 20210620 (Sherif Nagy)
- Adding Rocky secure boot certs (Sherif Nagy)
- Fixing vmlinuz removal (Sherif Nagy)
- Fixing UEFI CA path (Sherif Nagy)
- Porting to 8.10/8.10, debranding and Rocky branding (Louis Abel)
- Fixing pesign_key_name values (Sherif Nagy)
- Debrand the kernel (Louis Abel)

Wed, 09 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.162.1.rt7.503.el8_10]
- scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (Laurence Oberman) [RHEL-194117]
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Xin Long) [RHEL-228877] {CVE-2026-63801}
- tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (Xin Long) [RHEL-238050] {CVE-2026-68117}
- sctp: fix race between sctp_wait_for_connect and peeloff (Xin Long) [RHEL-229464] {CVE-2026-63971}
- sctp: diag: reject stale associations in dump_one path (Xin Long) [RHEL-231561] {CVE-2026-52917}
- sctp: validate stream count in sctp_process_strreset_inreq() (Xin Long) [RHEL-236135] {CVE-2026-68315}
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [RHEL-237394] {CVE-2026-68376}
- sctp: auth: verify auth requirement when auth_chunk is NULL (Xin Long) [RHEL-237088] {CVE-2026-68300}
- gfs2: harden gfs2_glock_hold (Andreas Gruenbacher) [RHEL-240340]
- gfs2: gfs2_glock_hold cleanup (Andreas Gruenbacher) [RHEL-240340]
- sctp: validate embedded INIT chunk and address list lengths in cookie (Xin Long) [RHEL-190202]
- sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (Xin Long) [RHEL-190202] {CVE-2026-53246}
- netfilter: nf_log: validate MAC header was set before dumping it (CKI Backport Bot) [RHEL-232055] {CVE-2026-52942}
- netfilter: nf_conntrack_sip: don't use simple_strtoul (CKI Backport Bot) [RHEL-232024] {CVE-2026-52986}
- scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-230822] {CVE-2025-68745}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225791] {CVE-2026-46149}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.161.1.rt7.502.el8_10]
- security/keys: fix missed RCU read section on lookup (Bruno Meneguele) [RHEL-225679] {CVE-2026-64015}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227760] {CVE-2026-64113}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: use qdisc_pkt_len_segs_init() in sch_handle_ingress() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: add more sanity checks to qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- sch_cake: do not use skb_mac_header() in cake_overhead() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: do not use skb_mac_header() in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: Skip GSO length estimation if transport header is not set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-rt-debug-core-4.18.0-553.162.1.rt7.503.el8_10.x86_64</title>
      <pubDate>Thu, 10 Sep 2026 02:22:01 PM GMT</pubDate>
      <guid isPermaLink="false">fd6a3d4827e9154e8f1b9f04f27c5656d41cab74185be8b803b5cd6f44837027</guid>
      <link>https://dl.rockylinux.org/pub/rocky/8/RT/x86_64/os/Packages/k/kernel-rt-debug-core-4.18.0-553.162.1.rt7.503.el8_10.x86_64.rpm</link>
      <description><p><strong>kernel-rt-debug-core</strong> - The Linux kernel compiled with extra debugging enabled&lt;br /&gt;</p>

<p>The kernel package contains the Linux kernel (vmlinuz), the core of any&lt;br /&gt;
Linux operating system.  The kernel handles the basic functions&lt;br /&gt;
of the operating system:  memory allocation, process allocation, device&lt;br /&gt;
input and output, etc.&lt;br /&gt;
&lt;br /&gt;
This variant of the kernel has numerous debugging options enabled.&lt;br /&gt;
It should only be installed when trying to gather additional information&lt;br /&gt;
on kernel bugs, as some of these options impact performance noticably.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 4.18.0-553.162.1.rt7.503
- Adding prod certs and changed cert date to 20210620 (Sherif Nagy)
- Adding Rocky secure boot certs (Sherif Nagy)
- Fixing vmlinuz removal (Sherif Nagy)
- Fixing UEFI CA path (Sherif Nagy)
- Porting to 8.10/8.10, debranding and Rocky branding (Louis Abel)
- Fixing pesign_key_name values (Sherif Nagy)
- Debrand the kernel (Louis Abel)

Wed, 09 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.162.1.rt7.503.el8_10]
- scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (Laurence Oberman) [RHEL-194117]
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Xin Long) [RHEL-228877] {CVE-2026-63801}
- tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (Xin Long) [RHEL-238050] {CVE-2026-68117}
- sctp: fix race between sctp_wait_for_connect and peeloff (Xin Long) [RHEL-229464] {CVE-2026-63971}
- sctp: diag: reject stale associations in dump_one path (Xin Long) [RHEL-231561] {CVE-2026-52917}
- sctp: validate stream count in sctp_process_strreset_inreq() (Xin Long) [RHEL-236135] {CVE-2026-68315}
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [RHEL-237394] {CVE-2026-68376}
- sctp: auth: verify auth requirement when auth_chunk is NULL (Xin Long) [RHEL-237088] {CVE-2026-68300}
- gfs2: harden gfs2_glock_hold (Andreas Gruenbacher) [RHEL-240340]
- gfs2: gfs2_glock_hold cleanup (Andreas Gruenbacher) [RHEL-240340]
- sctp: validate embedded INIT chunk and address list lengths in cookie (Xin Long) [RHEL-190202]
- sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (Xin Long) [RHEL-190202] {CVE-2026-53246}
- netfilter: nf_log: validate MAC header was set before dumping it (CKI Backport Bot) [RHEL-232055] {CVE-2026-52942}
- netfilter: nf_conntrack_sip: don't use simple_strtoul (CKI Backport Bot) [RHEL-232024] {CVE-2026-52986}
- scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-230822] {CVE-2025-68745}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225791] {CVE-2026-46149}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.161.1.rt7.502.el8_10]
- security/keys: fix missed RCU read section on lookup (Bruno Meneguele) [RHEL-225679] {CVE-2026-64015}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227760] {CVE-2026-64113}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: use qdisc_pkt_len_segs_init() in sch_handle_ingress() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: add more sanity checks to qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- sch_cake: do not use skb_mac_header() in cake_overhead() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: do not use skb_mac_header() in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: Skip GSO length estimation if transport header is not set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-rt-modules-extra-4.18.0-553.162.1.rt7.503.el8_10.x86_64</title>
      <pubDate>Thu, 10 Sep 2026 02:22:01 PM GMT</pubDate>
      <guid isPermaLink="false">33635982c10385ea0ed11018ff66f2e3aa12a17d3f915a8e4051a139e704fbec</guid>
      <link>https://dl.rockylinux.org/pub/rocky/8/RT/x86_64/os/Packages/k/kernel-rt-modules-extra-4.18.0-553.162.1.rt7.503.el8_10.x86_64.rpm</link>
      <description><p><strong>kernel-rt-modules-extra</strong> - Extra kernel modules to match the kernel&lt;br /&gt;</p>

<p>This package provides less commonly used kernel modules for the kernel package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 4.18.0-553.162.1.rt7.503
- Adding prod certs and changed cert date to 20210620 (Sherif Nagy)
- Adding Rocky secure boot certs (Sherif Nagy)
- Fixing vmlinuz removal (Sherif Nagy)
- Fixing UEFI CA path (Sherif Nagy)
- Porting to 8.10/8.10, debranding and Rocky branding (Louis Abel)
- Fixing pesign_key_name values (Sherif Nagy)
- Debrand the kernel (Louis Abel)

Wed, 09 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.162.1.rt7.503.el8_10]
- scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (Laurence Oberman) [RHEL-194117]
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Xin Long) [RHEL-228877] {CVE-2026-63801}
- tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (Xin Long) [RHEL-238050] {CVE-2026-68117}
- sctp: fix race between sctp_wait_for_connect and peeloff (Xin Long) [RHEL-229464] {CVE-2026-63971}
- sctp: diag: reject stale associations in dump_one path (Xin Long) [RHEL-231561] {CVE-2026-52917}
- sctp: validate stream count in sctp_process_strreset_inreq() (Xin Long) [RHEL-236135] {CVE-2026-68315}
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [RHEL-237394] {CVE-2026-68376}
- sctp: auth: verify auth requirement when auth_chunk is NULL (Xin Long) [RHEL-237088] {CVE-2026-68300}
- gfs2: harden gfs2_glock_hold (Andreas Gruenbacher) [RHEL-240340]
- gfs2: gfs2_glock_hold cleanup (Andreas Gruenbacher) [RHEL-240340]
- sctp: validate embedded INIT chunk and address list lengths in cookie (Xin Long) [RHEL-190202]
- sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (Xin Long) [RHEL-190202] {CVE-2026-53246}
- netfilter: nf_log: validate MAC header was set before dumping it (CKI Backport Bot) [RHEL-232055] {CVE-2026-52942}
- netfilter: nf_conntrack_sip: don't use simple_strtoul (CKI Backport Bot) [RHEL-232024] {CVE-2026-52986}
- scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-230822] {CVE-2025-68745}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225791] {CVE-2026-46149}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.161.1.rt7.502.el8_10]
- security/keys: fix missed RCU read section on lookup (Bruno Meneguele) [RHEL-225679] {CVE-2026-64015}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227760] {CVE-2026-64113}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: use qdisc_pkt_len_segs_init() in sch_handle_ingress() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: add more sanity checks to qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- sch_cake: do not use skb_mac_header() in cake_overhead() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: do not use skb_mac_header() in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: Skip GSO length estimation if transport header is not set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-rt-debug-modules-extra-4.18.0-553.162.1.rt7.503.el8_10.x86_64</title>
      <pubDate>Thu, 10 Sep 2026 02:22:01 PM GMT</pubDate>
      <guid isPermaLink="false">7e7cdde1bef1dbd950f9c01e3883e4022d4fc497357923b7a74791a1faf09122</guid>
      <link>https://dl.rockylinux.org/pub/rocky/8/RT/x86_64/os/Packages/k/kernel-rt-debug-modules-extra-4.18.0-553.162.1.rt7.503.el8_10.x86_64.rpm</link>
      <description><p><strong>kernel-rt-debug-modules-extra</strong> - Extra kernel modules to match the debug kernel&lt;br /&gt;</p>

<p>This package provides less commonly used kernel modules for the debug kernel package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 4.18.0-553.162.1.rt7.503
- Adding prod certs and changed cert date to 20210620 (Sherif Nagy)
- Adding Rocky secure boot certs (Sherif Nagy)
- Fixing vmlinuz removal (Sherif Nagy)
- Fixing UEFI CA path (Sherif Nagy)
- Porting to 8.10/8.10, debranding and Rocky branding (Louis Abel)
- Fixing pesign_key_name values (Sherif Nagy)
- Debrand the kernel (Louis Abel)

Wed, 09 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.162.1.rt7.503.el8_10]
- scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (Laurence Oberman) [RHEL-194117]
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Xin Long) [RHEL-228877] {CVE-2026-63801}
- tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (Xin Long) [RHEL-238050] {CVE-2026-68117}
- sctp: fix race between sctp_wait_for_connect and peeloff (Xin Long) [RHEL-229464] {CVE-2026-63971}
- sctp: diag: reject stale associations in dump_one path (Xin Long) [RHEL-231561] {CVE-2026-52917}
- sctp: validate stream count in sctp_process_strreset_inreq() (Xin Long) [RHEL-236135] {CVE-2026-68315}
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [RHEL-237394] {CVE-2026-68376}
- sctp: auth: verify auth requirement when auth_chunk is NULL (Xin Long) [RHEL-237088] {CVE-2026-68300}
- gfs2: harden gfs2_glock_hold (Andreas Gruenbacher) [RHEL-240340]
- gfs2: gfs2_glock_hold cleanup (Andreas Gruenbacher) [RHEL-240340]
- sctp: validate embedded INIT chunk and address list lengths in cookie (Xin Long) [RHEL-190202]
- sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (Xin Long) [RHEL-190202] {CVE-2026-53246}
- netfilter: nf_log: validate MAC header was set before dumping it (CKI Backport Bot) [RHEL-232055] {CVE-2026-52942}
- netfilter: nf_conntrack_sip: don't use simple_strtoul (CKI Backport Bot) [RHEL-232024] {CVE-2026-52986}
- scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-230822] {CVE-2025-68745}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225791] {CVE-2026-46149}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.161.1.rt7.502.el8_10]
- security/keys: fix missed RCU read section on lookup (Bruno Meneguele) [RHEL-225679] {CVE-2026-64015}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227760] {CVE-2026-64113}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: use qdisc_pkt_len_segs_init() in sch_handle_ingress() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: add more sanity checks to qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- sch_cake: do not use skb_mac_header() in cake_overhead() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: do not use skb_mac_header() in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: Skip GSO length estimation if transport header is not set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-rt-debug-4.18.0-553.162.1.rt7.503.el8_10.x86_64</title>
      <pubDate>Thu, 10 Sep 2026 02:22:01 PM GMT</pubDate>
      <guid isPermaLink="false">dcf6da5be19c46830ed4516e074f7dc90f1a88399fd0a7dcfc8bc89b843e626d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/8/RT/x86_64/os/Packages/k/kernel-rt-debug-4.18.0-553.162.1.rt7.503.el8_10.x86_64.rpm</link>
      <description><p><strong>kernel-rt-debug</strong> - kernel meta-package for the debug kernel&lt;br /&gt;</p>

<p>The meta-package for the debug kernel</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 4.18.0-553.162.1.rt7.503
- Adding prod certs and changed cert date to 20210620 (Sherif Nagy)
- Adding Rocky secure boot certs (Sherif Nagy)
- Fixing vmlinuz removal (Sherif Nagy)
- Fixing UEFI CA path (Sherif Nagy)
- Porting to 8.10/8.10, debranding and Rocky branding (Louis Abel)
- Fixing pesign_key_name values (Sherif Nagy)
- Debrand the kernel (Louis Abel)

Wed, 09 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.162.1.rt7.503.el8_10]
- scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (Laurence Oberman) [RHEL-194117]
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Xin Long) [RHEL-228877] {CVE-2026-63801}
- tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (Xin Long) [RHEL-238050] {CVE-2026-68117}
- sctp: fix race between sctp_wait_for_connect and peeloff (Xin Long) [RHEL-229464] {CVE-2026-63971}
- sctp: diag: reject stale associations in dump_one path (Xin Long) [RHEL-231561] {CVE-2026-52917}
- sctp: validate stream count in sctp_process_strreset_inreq() (Xin Long) [RHEL-236135] {CVE-2026-68315}
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [RHEL-237394] {CVE-2026-68376}
- sctp: auth: verify auth requirement when auth_chunk is NULL (Xin Long) [RHEL-237088] {CVE-2026-68300}
- gfs2: harden gfs2_glock_hold (Andreas Gruenbacher) [RHEL-240340]
- gfs2: gfs2_glock_hold cleanup (Andreas Gruenbacher) [RHEL-240340]
- sctp: validate embedded INIT chunk and address list lengths in cookie (Xin Long) [RHEL-190202]
- sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (Xin Long) [RHEL-190202] {CVE-2026-53246}
- netfilter: nf_log: validate MAC header was set before dumping it (CKI Backport Bot) [RHEL-232055] {CVE-2026-52942}
- netfilter: nf_conntrack_sip: don't use simple_strtoul (CKI Backport Bot) [RHEL-232024] {CVE-2026-52986}
- scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-230822] {CVE-2025-68745}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225791] {CVE-2026-46149}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.161.1.rt7.502.el8_10]
- security/keys: fix missed RCU read section on lookup (Bruno Meneguele) [RHEL-225679] {CVE-2026-64015}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227760] {CVE-2026-64113}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: use qdisc_pkt_len_segs_init() in sch_handle_ingress() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: add more sanity checks to qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- sch_cake: do not use skb_mac_header() in cake_overhead() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: do not use skb_mac_header() in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: Skip GSO length estimation if transport header is not set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-rt-modules-4.18.0-553.162.1.rt7.503.el8_10.x86_64</title>
      <pubDate>Thu, 10 Sep 2026 02:22:01 PM GMT</pubDate>
      <guid isPermaLink="false">9391e66b60752c237fc8bb0428c11e40964d548f7a553ba339667677673ee5cc</guid>
      <link>https://dl.rockylinux.org/pub/rocky/8/RT/x86_64/os/Packages/k/kernel-rt-modules-4.18.0-553.162.1.rt7.503.el8_10.x86_64.rpm</link>
      <description><p><strong>kernel-rt-modules</strong> - kernel modules to match the core kernel&lt;br /&gt;</p>

<p>This package provides commonly used kernel modules for the core kernel package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 4.18.0-553.162.1.rt7.503
- Adding prod certs and changed cert date to 20210620 (Sherif Nagy)
- Adding Rocky secure boot certs (Sherif Nagy)
- Fixing vmlinuz removal (Sherif Nagy)
- Fixing UEFI CA path (Sherif Nagy)
- Porting to 8.10/8.10, debranding and Rocky branding (Louis Abel)
- Fixing pesign_key_name values (Sherif Nagy)
- Debrand the kernel (Louis Abel)

Wed, 09 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.162.1.rt7.503.el8_10]
- scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (Laurence Oberman) [RHEL-194117]
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Xin Long) [RHEL-228877] {CVE-2026-63801}
- tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (Xin Long) [RHEL-238050] {CVE-2026-68117}
- sctp: fix race between sctp_wait_for_connect and peeloff (Xin Long) [RHEL-229464] {CVE-2026-63971}
- sctp: diag: reject stale associations in dump_one path (Xin Long) [RHEL-231561] {CVE-2026-52917}
- sctp: validate stream count in sctp_process_strreset_inreq() (Xin Long) [RHEL-236135] {CVE-2026-68315}
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [RHEL-237394] {CVE-2026-68376}
- sctp: auth: verify auth requirement when auth_chunk is NULL (Xin Long) [RHEL-237088] {CVE-2026-68300}
- gfs2: harden gfs2_glock_hold (Andreas Gruenbacher) [RHEL-240340]
- gfs2: gfs2_glock_hold cleanup (Andreas Gruenbacher) [RHEL-240340]
- sctp: validate embedded INIT chunk and address list lengths in cookie (Xin Long) [RHEL-190202]
- sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (Xin Long) [RHEL-190202] {CVE-2026-53246}
- netfilter: nf_log: validate MAC header was set before dumping it (CKI Backport Bot) [RHEL-232055] {CVE-2026-52942}
- netfilter: nf_conntrack_sip: don't use simple_strtoul (CKI Backport Bot) [RHEL-232024] {CVE-2026-52986}
- scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-230822] {CVE-2025-68745}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225791] {CVE-2026-46149}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [4.18.0-553.161.1.rt7.502.el8_10]
- security/keys: fix missed RCU read section on lookup (Bruno Meneguele) [RHEL-225679] {CVE-2026-64015}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227760] {CVE-2026-64113}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: use qdisc_pkt_len_segs_init() in sch_handle_ingress() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: add more sanity checks to qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- sch_cake: do not use skb_mac_header() in cake_overhead() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: do not use skb_mac_header() in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: Skip GSO length estimation if transport header is not set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>tuned-profiles-realtime-2.22.1-7.el8_10.noarch</title>
      <pubDate>Tue, 25 Aug 2026 10:52:05 PM GMT</pubDate>
      <guid isPermaLink="false">e25282c381bccf3938a9a13a5ec760ede137c98721e05e45e57ba685b93cf00f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/8/RT/x86_64/os/Packages/t/tuned-profiles-realtime-2.22.1-7.el8_10.noarch.rpm</link>
      <description><p><strong>tuned-profiles-realtime</strong> - Additional tuned profile(s) targeted to realtime&lt;br /&gt;</p>

<p>Additional tuned profile(s) targeted to realtime.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 29 Jun 2026 GMT - Jaroslav Škarvada &amp;lt;jskarvad@redhat.com&amp;gt; - 2.22.1-7
- sap-hana forced latency to 70 us
  Resolves: RHEL-184274

Mon, 06 Jan 2025 GMT - Pavol Žáčik &amp;lt;pzacik@redhat.com&amp;gt; - 2.22.1-6
- Make hdparm device checks lazy
  Resolves: RHEL-71457
- Disable the amd.scheduler plug-in instance in the postgresql profile
  Resolves: RHEL-70470

Mon, 18 Nov 2024 GMT - Jaroslav Škarvada &amp;lt;jskarvad@redhat.com&amp;gt; - 2.22.1-5
- Added sanity checks for API methods parameters, (CVE-2024-52337)
  Resolves: RHEL-66614

...&lt;/pre&gt;</description>
    </item>
  </channel>
</rss>
