RHSA-2026:28740: Critical: kpatch-patch-5_14_0-570_116_1, kpatch-patch-5_14_0-570_17_1, kpatch-patch-5_14_0-570_39_1, kpatch-patch-5_14_0-570_66_1, and kpatch-patch-5_14_0-570_94_1 security update
Critical: kpatch-patch-5140-5701161, kpatch-patch-5140-570171, kpatch-patch-5140-570391, kpatch-patch-5140-570661, and kpatch-patch-5140-570941 security update
Other sources
This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-5.14.0-570.17.1.el96.Security Fix(es): kernel: ip6tunnel: clear skb2->cb[] in ip4ip6err() (CVE-2026-43037) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_116_1-1-1.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_17_1-1-16.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_39_1-1-7.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_66_1-1-6.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_94_1-1-4.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_116_1-debuginfo-1-1.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_116_1-debugsource-1-1.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_17_1-debuginfo-1-16.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_17_1-debugsource-1-16.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_39_1-debuginfo-1-7.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_39_1-debugsource-1-7.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_66_1-debuginfo-1-6.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_66_1-debugsource-1-6.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_94_1-debuginfo-1-4.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_94_1-debugsource-1-4.el9_6
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:28740?
The severity of RHSA-2026:28740 is critical with a score of 9.
How do I fix RHSA-2026:28740?
To fix RHSA-2026:28740, you need to apply the latest kpatch updates for the affected kernel versions.
What software is affected by RHSA-2026:28740?
RHSA-2026:28740 affects multiple Red Hat Enterprise Linux versions running on different architectures.
What is the purpose of the kpatch in RHSA-2026:28740?
The kpatch in RHSA-2026:28740 is designed to allow live patching of the Linux kernel without needing a reboot.
When was RHSA-2026:28740 published?
RHSA-2026:28740 was published on June 24, 2026.