RHSA-2026:28738: Critical: kpatch-patch-5_14_0-427_100_1, kpatch-patch-5_14_0-427_113_1, kpatch-patch-5_14_0-427_126_1, kpatch-patch-5_14_0-427_68_2, and kpatch-patch-5_14_0-427_84_1 security update
Critical: kpatch-patch-5140-4271001, kpatch-patch-5140-4271131, kpatch-patch-5140-4271261, kpatch-patch-5140-427682, and kpatch-patch-5140-427841 security update
Other sources
This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-5.14.0-427.68.2.el94.Security Fix(es): kernel: ip6tunnel: clear skb2->cb[] in ip4ip6err() (CVE-2026-43037) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_100_1-1-6.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_113_1-1-4.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_126_1-1-1.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_68_2-1-13.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_84_1-1-8.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_100_1-debuginfo-1-6.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_100_1-debugsource-1-6.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_113_1-debuginfo-1-4.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_113_1-debugsource-1-4.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_126_1-debuginfo-1-1.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_126_1-debugsource-1-1.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_68_2-debuginfo-1-13.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_68_2-debugsource-1-13.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_84_1-debuginfo-1-8.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_84_1-debugsource-1-8.el9_4
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:28738?
The severity of RHSA-2026:28738 is classified as critical with a score of 9.
How do I fix RHSA-2026:28738?
To fix RHSA-2026:28738, you should apply the security update for the affected kpatch versions.
What products are affected by RHSA-2026:28738?
RHSA-2026:28738 affects various versions of Red Hat Enterprise Linux, including server and SAP solutions.
What is the purpose of the kpatch in RHSA-2026:28738?
The kpatch in RHSA-2026:28738 is a kernel live patch module that allows for the modification of running kernel code.
When was RHSA-2026:28738 published?
RHSA-2026:28738 was published on June 24, 2026.