Red Hat RHEL 7 ELS Kernel Updates Fix CVE-2025-40026
Quick Answer
Red Hat published RHSA-2026:78843 and RHSA-2026:78844 for RHEL 7 Extended Lifecycle Support standard and real-time kernel packages. Inventory the exact affected scope, apply kernel 3.10.0-1160.165.1.el7 and kernel-rt 3.10.0-1160.165.1.rt56.1317.el7 with the matching advisory-listed packages, followed by a controlled reboot, validate dependent operations, and preserve change evidence.
Validate kernel Scope And Apply The Supported Fix
What to do now: Inventory RHEL 7 Extended Lifecycle Support standard and real-time kernel packages, match versions and enabled features to the authority's scope, apply supported remediation, validate representative operations, and document exceptions.
Last verified: 2026-10-08 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | RHEL 7 Extended Lifecycle Support standard and real-time kernel packages |
|---|---|
| Advisory | RHSA-2026:78843 / RHSA-2026:78844 |
| CVE | CVE-2025-40026 |
| Authoritative release date | 2026-10-08 06:54:43 UTC |
| Authority revision date | 2026-10-08 12:01:16 UTC |
| Affected versions | The exact entitled RHEL 7 Extended Lifecycle Support standard and real-time kernel packages branches and package or image relationships identified by RHSA-2026:78843 and RHSA-2026:78844; compare installed NEVRAs or digests with the fixed content. |
| Fixed version | kernel 3.10.0-1160.165.1.el7 and kernel-rt 3.10.0-1160.165.1.rt56.1317.el7 with the matching advisory-listed packages, followed by a controlled reboot |
| CVSS base score | 5.5 (CVSS v3.1) |
| CVSS severity | Medium |
| Exploitation status | Not stated by the authority; no exploitation claim is inferred. |
What Changed
Red Hat published authority-rated Moderate kernel security content with branch-specific fixed packages or images for the listed CVEs.
What To Validate Now
- Inventory. Locate RHEL 7 Extended Lifecycle Support standard and real-time kernel packages; record versions, enabled features, exposure paths, owners, dependencies, support channels, and maintenance groups.
- Establish applicability. Compare every deployment with the authority's affected statement: The exact entitled RHEL 7 Extended Lifecycle Support standard and real-time kernel packages branches and package or image relationships identified by RHSA-2026:78843 and RHSA-2026:78844; compare installed NEVRAs or digests with the fixed content. Do not infer applicability from product family, CVSS, or Internet reachability alone.
- Remediate. Apply kernel 3.10.0-1160.165.1.el7 and kernel-rt 3.10.0-1160.165.1.rt56.1317.el7 with the matching advisory-listed packages, followed by a controlled reboot through the authority-supported channel and follow the current advisory.
- Validate. Confirm the resulting kernel build or managed state, exercise representative services and recovery paths, monitor for regressions, and retain the result.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Retain the prior boot entry, rebuild external modules where required, reboot in a controlled window, and validate workload and recovery behavior. Preserve pre-change state, installation output, logs, validation evidence, and rollback decisions.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

