RHSA-2026:56225: Important: kpatch-patch-5_14_0-570_116_1, kpatch-patch-5_14_0-570_17_1, kpatch-patch-5_14_0-570_39_1, kpatch-patch-5_14_0-570_66_1, and kpatch-patch-5_14_0-570_94_1 security update
Important: kpatch-patch-5140-5701161, kpatch-patch-5140-570171, kpatch-patch-5140-570391, kpatch-patch-5140-570661, and kpatch-patch-5140-570941 security update
Other sources
This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-5.14.0-570.17.1.el96.Security Fix(es): kernel: ipv6: icmp: clear skb2->cb[] in ip6errgenicmpv6unreach() (CVE-2026-43038) kernel: dlm: validate length in dlmsearchrsbtree (CVE-2026-43125) kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) kernel: netfilter: nftinner: Fix IPv6 innerthoff desync (CVE-2026-46244) kernel: net: sched: UAF via missing handler for TCACTCONSUMED in tcfqeventhandle (CVE-2026-64530) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_116_1-1-7.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_17_1-1-22.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_39_1-1-13.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_66_1-1-12.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_94_1-1-10.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_116_1-debuginfo-1-7.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_116_1-debugsource-1-7.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_17_1-debuginfo-1-22.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_17_1-debugsource-1-22.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_39_1-debuginfo-1-13.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_39_1-debugsource-1-13.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_66_1-debuginfo-1-12.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_66_1-debugsource-1-12.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_94_1-debuginfo-1-10.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_94_1-debugsource-1-10.el9_6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in kernel-5.14.0-570.17.1.el9_6.<Patch kpatch-patch-5_14_0-570_17_1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch kpatch-patch-5_14_0-570_116_1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch kpatch-patch-5_14_0-570_39_1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch kpatch-patch-5_14_0-570_66_1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch kpatch-patch-5_14_0-570_94_1
Event History
Frequently Asked Questions
Which systems are in scope for this update?
The live patch module is targeted for kernel-5.14.0-570.17.1.el9_6. The advisory lists Red Hat Enterprise Linux x86_64 and Power little-endian offerings, including AUS, Extended Life Cycle, Extended Update Support, and Update Services for SAP Solutions.
Can the fixes be loaded into a running system?
It is a kernel live patch module that the kpatch command-line utility can load to modify code in a running kernel. The advisory does not provide other deployment or mitigation instructions.
How can I determine whether this advisory applies to a host?
The advisory identifies kernel-5.14.0-570.17.1.el9_6 as the target kernel. It does not provide vulnerable-version ranges or configuration-based indicators for determining exposure beyond that target information.