RHSA-2026:36531: Important: kpatch-patch-4_18_0-477_107_1, kpatch-patch-4_18_0-477_120_1, kpatch-patch-4_18_0-477_130_1, and kpatch-patch-4_18_0-477_97_1 security update
Important: kpatch-patch-4180-4771071, kpatch-patch-4180-4771201, kpatch-patch-4180-4771301, and kpatch-patch-4180-477971 security update
Other sources
This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-4.18.0-477.97.1.el88.Security Fix(es): kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling (CVE-2026-23401) kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (CVE-2026-31402) kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service (CVE-2026-31419) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-477_107_1-1-9.el8_8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-477_120_1-1-8.el8_8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-477_130_1-1-6.el8_8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-477_97_1-1-13.el8_8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-477_107_1-debuginfo-1-9.el8_8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-477_107_1-debugsource-1-9.el8_8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-477_120_1-debuginfo-1-8.el8_8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-477_120_1-debugsource-1-8.el8_8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-477_130_1-debuginfo-1-6.el8_8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-477_130_1-debugsource-1-6.el8_8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-477_97_1-debuginfo-1-13.el8_8 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-477_97_1-debugsource-1-13.el8_8 - Upgrade
Upgrade
Linux kernel (kernel-4.18.0-477.97.1.el8_8) kpatch live patch moduleto a version that resolves this vulnerability.Patch kpatch-patch-4_18_0-477_97_1 - Upgrade
Upgrade
Linux kernel (kernel-4.18.0-477.97.1.el8_8) kpatch live patch moduleto a version that resolves this vulnerability.Patch kpatch-patch-4_18_0-477_107_1 - Upgrade
Upgrade
Linux kernel (kernel-4.18.0-477.97.1.el8_8) kpatch live patch moduleto a version that resolves this vulnerability.Patch kpatch-patch-4_18_0-477_120_1 - Upgrade
Upgrade
Linux kernel (kernel-4.18.0-477.97.1.el8_8) kpatch live patch moduleto a version that resolves this vulnerability.Patch kpatch-patch-4_18_0-477_130_1 - Compensating control
If you cannot apply the kpatch security update immediately, use the vendor advisory (referenced in the material) for the recommended mitigations for the listed CVEs (CVE-2026-31419, CVE-2026-31402, CVE-2026-23401) until the live patch module is loaded.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:36531?
The severity of RHSA-2026:36531 is high with a score of 7.
How do I fix RHSA-2026:36531?
To fix RHSA-2026:36531, apply the latest kpatch-patch updates provided by Red Hat.
What software is affected by RHSA-2026:36531?
RHSA-2026:36531 affects Red Hat Enterprise Linux for x86_64 and Power LE systems.
What vulnerability type is described in RHSA-2026:36531?
RHSA-2026:36531 describes a Use After Free vulnerability.
When was RHSA-2026:36531 published?
RHSA-2026:36531 was published on July 8, 2026.