RHSA-2026:56224: Important: kpatch-patch-5_14_0-427_100_1, kpatch-patch-5_14_0-427_113_1, kpatch-patch-5_14_0-427_126_1, kpatch-patch-5_14_0-427_68_2, and kpatch-patch-5_14_0-427_84_1 security update
Important: kpatch-patch-5140-4271001, kpatch-patch-5140-4271131, kpatch-patch-5140-4271261, kpatch-patch-5140-427682, and kpatch-patch-5140-427841 security update
Other sources
This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-5.14.0-427.68.2.el94.Security Fix(es): kernel: ipv6: icmp: clear skb2->cb[] in ip6errgenicmpv6unreach() (CVE-2026-43038) kernel: dlm: validate length in dlmsearchrsbtree (CVE-2026-43125) kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) kernel: net: sched: UAF via missing handler for TCACTCONSUMED in tcfqeventhandle (CVE-2026-64530) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_100_1-1-12.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_113_1-1-10.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_126_1-1-7.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_68_2-1-19.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_84_1-1-14.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_100_1-debuginfo-1-12.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_100_1-debugsource-1-12.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_113_1-debuginfo-1-10.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_113_1-debugsource-1-10.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_126_1-debuginfo-1-7.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_126_1-debugsource-1-7.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_68_2-debuginfo-1-19.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_68_2-debugsource-1-19.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_84_1-debuginfo-1-14.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_84_1-debugsource-1-14.el9_4 - Upgrade
Upgrade
kernel-5.14.0-427.68.2.el9_4to a version that resolves this vulnerability.Patch kpatch-patch-5_14_0-427_100_1 - Upgrade
Upgrade
kernel-5.14.0-427.68.2.el9_4to a version that resolves this vulnerability.Patch kpatch-patch-5_14_0-427_113_1 - Upgrade
Upgrade
kernel-5.14.0-427.68.2.el9_4to a version that resolves this vulnerability.Patch kpatch-patch-5_14_0-427_126_1 - Upgrade
Upgrade
kernel-5.14.0-427.68.2.el9_4to a version that resolves this vulnerability.Patch kpatch-patch-5_14_0-427_68_2 - Upgrade
Upgrade
kernel-5.14.0-427.68.2.el9_4to a version that resolves this vulnerability.Patch kpatch-patch-5_14_0-427_84_1
Event History
Frequently Asked Questions
How can I determine whether this live patch module applies to a system?
This live patch module is targeted for the running kernel kernel-5.14.0-427.68.2.el9_4. Systems running that kernel should be assessed for applicability of this module.
Is there a remediation option that does not require immediately replacing the running kernel?
The module can be loaded with the kpatch command-line utility to modify code in a running kernel. This provides a way to apply the live patch without replacing the running kernel at that time.
Which platform families are identified by the advisory?
The advisory lists Red Hat Enterprise Linux offerings for x86_64 and Power little-endian, including Extended Life Cycle, AUS, and Update Services for SAP Solutions. Applicability also depends on the targeted kernel release.