RHSA-2026:59148: Important: kpatch-patch-5_14_0-570_116_1, kpatch-patch-5_14_0-570_17_1, kpatch-patch-5_14_0-570_39_1, kpatch-patch-5_14_0-570_66_1, and kpatch-patch-5_14_0-570_94_1 security update
Important: kpatch-patch-5140-5701161, kpatch-patch-5140-570171, kpatch-patch-5140-570391, kpatch-patch-5140-570661, and kpatch-patch-5140-570941 security update
Other sources
This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-5.14.0-570.17.1.el96.Security Fix(es): kernel: rtmutex: Use waiter::task instead of current in removewaiter() (CVE-2026-43499) kernel: gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984) kernel: xfrm: defensively unhash xfrmstate lists in xfrmstatedelete (CVE-2026-46116) kernel: sctp: revalidate list cursor after sctpsendmsgtoasoc() in SCTPSENDALL (CVE-2026-46227) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_116_1-1-8.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_17_1-1-23.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_39_1-1-14.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_66_1-1-13.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_94_1-1-11.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_116_1-debuginfo-1-8.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_116_1-debugsource-1-8.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_17_1-debuginfo-1-23.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_17_1-debugsource-1-23.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_39_1-debuginfo-1-14.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_39_1-debugsource-1-14.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_66_1-debuginfo-1-13.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_66_1-debugsource-1-13.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_94_1-debuginfo-1-11.el9_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 5_14_0-570_94_1-debugsource-1-11.el9_6 - Upgrade
Upgrade
kernel live patch module kpatch-patch-5_14_0-570_116_1to a version that resolves this vulnerability.Fixed in 5.14.0-570.17.1.el9_6Patch kpatch-patch-5_14_0-570_116_1 - Upgrade
Upgrade
kernel live patch module kpatch-patch-5_14_0-570_17_1to a version that resolves this vulnerability.Fixed in 5.14.0-570.17.1.el9_6Patch kpatch-patch-5_14_0-570_17_1 - Upgrade
Upgrade
kernel live patch module kpatch-patch-5_14_0-570_39_1to a version that resolves this vulnerability.Fixed in 5.14.0-570.17.1.el9_6Patch kpatch-patch-5_14_0-570_39_1 - Upgrade
Upgrade
kernel live patch module kpatch-patch-5_14_0-570_66_1to a version that resolves this vulnerability.Fixed in 5.14.0-570.17.1.el9_6Patch kpatch-patch-5_14_0-570_66_1 - Upgrade
Upgrade
kernel live patch module kpatch-patch-5_14_0-570_94_1to a version that resolves this vulnerability.Fixed in 5.14.0-570.17.1.el9_6Patch kpatch-patch-5_14_0-570_94_1