RHSA-2026:59145: Important: kpatch-patch-5_14_0-427_100_1, kpatch-patch-5_14_0-427_113_1, kpatch-patch-5_14_0-427_126_1, kpatch-patch-5_14_0-427_68_2, and kpatch-patch-5_14_0-427_84_1 security update
Important: kpatch-patch-5140-4271001, kpatch-patch-5140-4271131, kpatch-patch-5140-4271261, kpatch-patch-5140-427682, and kpatch-patch-5140-427841 security update
Other sources
This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-5.14.0-427.68.2.el94.Security Fix(es): kernel: rtmutex: Use waiter::task instead of current in removewaiter() (CVE-2026-43499) kernel: gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984) kernel: xfrm: defensively unhash xfrmstate lists in xfrmstatedelete (CVE-2026-46116) kernel: sctp: revalidate list cursor after sctpsendmsgtoasoc() in SCTPSENDALL (CVE-2026-46227) kernel: net: openvswitch: reject oversized nested action attrs (CVE-2026-64531) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_100_1-1-13.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_113_1-1-11.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_126_1-1-8.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_68_2-1-20.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_84_1-1-15.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_100_1-debuginfo-1-13.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_100_1-debugsource-1-13.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_113_1-debuginfo-1-11.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_113_1-debugsource-1-11.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_126_1-debuginfo-1-8.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_126_1-debugsource-1-8.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_68_2-debuginfo-1-20.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_68_2-debugsource-1-20.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_84_1-debuginfo-1-15.el9_4 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-427_84_1-debugsource-1-15.el9_4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch kpatch-patch-5_14_0-427_100_1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch kpatch-patch-5_14_0-427_113_1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch kpatch-patch-5_14_0-427_126_1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch kpatch-patch-5_14_0-427_68_2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch kpatch-patch-5_14_0-427_84_1