Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:36534: Important: kpatch-patch-5_14_0-570_116_1, kpatch-patch-5_14_0-570_17_1, kpatch-patch-5_14_0-570_39_1, kpatch-patch-5_14_0-570_66_1, and kpatch-patch-5_14_0-570_94_1 security update

This Red Hat security advisory addresses three vulnerabilities in the Linux kernel for RHEL 9.6 EUS, requiring live patching via kpatch modules. The vulnerabilities include a KVM shadow page table flaw (CVE-2026-23401, CVSS 5.5 MEDIUM) allowing privilege escalation/DoS, a critical heap overflow in NFSv4.0 LOCK replay (CVE-2026-31402, CVSS 9.8 CRITICAL), and a use-after-free in the bonding driver (CVE-2026-31419, CVSS 7.8 HIGH) leading to DoS. The provided kpatch-patch modules target kernel version 5.14.0-570.17.1.el9_6 to mitigate these issues without a full reboot.
Read Full Article →

Red Hat Product Errata RHSA-2026:36534 - Security Advisory Issued: 2026-07-08 Updated: 2026-07-08 RHSA-2026:36534 - Security Advisory Overview Updated Packages Synopsis Important: kpatch-patch-5_14_0-570_116_1, kpatch-patch-5_14_0-570_17_1, kpatch-patch-5_14_0-570_39_1, kpatch-patch-5_14_0-570_66_1, and kpatch-patch-5_14_0-570_94_1 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for multiple packages is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-5.14.0-570.17.1.el9_6. Security Fix(es): kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling (CVE-2026-23401) kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (CVE-2026-31402) kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service (CVE-2026-31419) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Fixes BZ - 2453803 - CVE-2026-23401 kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling BZ - 2454844 - CVE-2026-31402 kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache BZ - 2457829 - CVE-2026-31419 kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service CVEs CVE-2026-23401 CVE-2026-31402 CVE-2026-31419 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM kpatch-patch-5_14_0-570_116_1-1-3.el9_6.src.rpm SHA-256: 7e6192c929e1f446389cb1927bf817d953ebfcdcbf9e89d9e356d07c02c2098e kpatch-patch-5_14_0-570_17_1-1-18.el9_6.src.rpm SHA-256: e04f38955319908f46bfbc32144df34a4753a45676cf3f562791346872ff5602 kpatch-patch-5_14_0-570_39_1-1-9.el9_6.src.rpm SHA-256: fc5bae6c951c2436cd37b52cdb8f4f3aeec59f045b6d06f32716bfa4033d9c95 kpatch-patch-5_14_0-570_66_1-1-8.el9_6.src.rpm SHA-256: d6e050fc45de57e92c1a2cc7898e9cd0bc64e65e079b7bc65ba82140c65f5b3c kpatch-patch-5_14_0-570_94_1-1-6.el9_6.src.rpm SHA-256: 09131b310af0612f4fc84e7f93d61a29dc3e56cc4efeeb2b318d045c66f40fac x86_64 kpatch-patch-5_14_0-570_116_1-1-3.el9_6.x86_64.rpm SHA-256: 622d19888f734e34ef8b69497dde274cbfcd8e873cd2cf4bac9803c7eaa5b6d0 kpatch-patch-5_14_0-570_116_1-debuginfo-1-3.el9_6.x86_64.rpm SHA-256: a4006e658c051cc800485249c5fffc95bd3e3c641771b8448eb4d1d4c1eaaeea kpatch-patch-5_14_0-570_116_1-debugsource-1-3.el9_6.x86_64.rpm SHA-256: 3b017d6dd198b53ce0064fabbbd61372c48f2acbeacbe8d9788ac9a3607ed8c6 kpatch-patch-5_14_0-570_17_1-1-18.el9_6.x86_64.rpm SHA-256: 9b9a9e786d278d98d6f0a6aeb625eda3736ff5f3cab161291370854014c2615f kpatch-patch-5_14_0-570_17_1-debuginfo-1-18.el9_6.x86_64.rpm SHA-256: d30c7ea067b000836dda194457f3a18d564677bac4df7118b45210ba541ed8cc kpatch-patch-5_14_0-570_17_1-debugsource-1-18.el9_6.x86_64.rpm SHA-256: 5611c31247afeb3f88e8b3ad7dc0773fcc4286cab7fbdc5172d9068ac9ce6260 kpatch-patch-5_14_0-570_39_1-1-9.el9_6.x86_64.rpm SHA-256: dae3158c0cd2107f51aab8d32a025c016a084264cac9dc4015353987d1bdb2ff kpatch-patch-5_14_0-570_39_1-debuginfo-1-9.el9_6.x86_64.rpm SHA-256: cda8bc86fdd411d1ffe881fbaa155590cb366af2737ca90531773b6d732db733 kpatch-patch-5_14_0-570_39_1-debugsource-1-9.el9_6.x86_64.rpm SHA-256: 8f130c73cd20ed80dc03425c01932479311f2f8a11d309e992a322f3c5d57adb kpatch-patch-5_14_0-570_66_1-1-8.el9_6.x86_64.rpm SHA-256: 2c02369fd435d3b88783a8a148e655269a6d4e2d2fff3da4dabcf10cd147e843 kpatch-patch-5_14_0-570_66_1-debuginfo-1-8.el9_6.x86_64.rpm SHA-256: 132bd77234783adee3660ea171a6c152b4e2c7fd2dcf941f3167a84d10bf2972 kpatch-patch-5_14_0-570_66_1-debugsource-1-8.el9_6.x86_64.rpm SHA-256: a6078c19b4f820417d488c722123cc7a128b4f9b670e71dc6470fa7f8e12f3bf kpatch-patch-5_14_0-570_94_1-1-6.el9_6.x86_64.rpm SHA-256: a9a3e7e838189cc9d36e4180e1d63a869ccd15596152ec71c483dcb7767765d3 kpatch-patch-5_14_0-570_94_1-debuginfo-1-6.el9_6.x86_64.rpm SHA-256: 633b9b442f44c0b282c144da2db62b2fcb3d35b1703831661b3102dc94aae404 kpatch-patch-5_14_0-570_94_1-debugsource-1-6.el9_6.x86_64.rpm SHA-256: 66133056d442a157f8765a1b73790a17b60afc19d68fcf2f54b903f77db1bbac Red Hat Enterprise Linux Server - AUS 9.6 SRPM kpatch-patch-5_14_0-570_116_1-1-3.el9_6.src.rpm SHA-256: 7e6192c929e1f446389cb1927bf817d953ebfcdcbf9e89d9e356d07c02c2098e kpatch-patch-5_14_0-570_17_1-1-18.el9_6.src.rpm SHA-256: e04f38955319908f46bfbc32144df34a4753a45676cf3f562791346872ff5602 kpatch-patch-5_14_0-570_39_1-1-9.el9_6.src.rpm SHA-256: fc5bae6c951c2436cd37b52cdb8f4f3aeec59f045b6d06f32716bfa4033d9c95 kpatch-patch-5_14_0-570_66_1-1-8.el9_6.src.rpm SHA-256: d6e050fc45de57e92c1a2cc7898e9cd0bc64e65e079b7bc65ba82140c65f5b3c kpatch-patch-5_14_0-570_94_1-1-6.el9_6.src.rpm SHA-256: 09131b310af0612f4fc84e7f93d61a29dc3e56cc4efeeb2b318d045c66f40fac x86_64 kpatch-patch-5_14_0-570_116_1-1-3.el9_6.x86_64.rpm SHA-256: 622d19888f734e34ef8b69497dde274cbfcd8e873cd2cf4bac9803c7eaa5b6d0 kpatch-patch-5_14_0-570_116_1-debuginfo-1-3.el9_6.x86_64.rpm SHA-256: a4006e658c051cc800485249c5fffc95bd3e3c641771b8448eb4d1d4c1eaaeea kpatch-patch-5_14_0-570_116_1-debugsource-1-3.el9_6.x86_64.rpm SHA-256: 3b017d6dd198b53ce0064fabbbd61372c48f2acbeacbe8d9788ac9a3607ed8c6 kpatch-patch-5_14_0-570_17_1-1-18.el9_6.x86_64.rpm SHA-256: 9b9a9e786d278d98d6f0a6aeb625eda3736ff5f3cab161291370854014c2615f kpatch-patch-5_14_0-570_17_1-debuginfo-1-18.el9_6.x86_64.rpm SHA-256: d30c7ea067b000836dda194457f3a18d564677bac4df7118b45210ba541ed8cc kpatch-patch-5_14_0-570_17_1-debugsource-1-18.el9_6.x86_64.rpm SHA-256: 5611c31247afeb3f88e8b3ad7dc0773fcc4286cab7fbdc5172d9068ac9ce6260 kpatch-patch-5_14_0-570_39_1-1-9.el9_6.x86_64.rpm SHA-256: dae3158c0cd2107f51aab8d32a025c016a084264cac9dc4015353987d1bdb2ff kpatch-patch-5_14_0-570_39_1-debuginfo-1-9.el9_6.x86_64.rpm SHA-256: cda8bc86fdd411d1ffe881fbaa155590cb366af2737ca90531773b6d732db733 kpatch-patch-5_14_0-570_39_1-debugsource-1-9.el9_6.x86_64.rpm SHA-256: 8f130c73cd20ed80dc03425c01932479311f2f8a11d309e992a322f3c5d57adb kpatch-patch-5_14_0-570_66_1-1-8.el9_6.x86_64.rpm SHA-256: 2c02369fd435d3b88783a8a148e655269a6d4e2d2fff3da4dabcf10cd147e843 kpatch-patch-5_14_0-570_66_1-debuginfo-1-8.el9_6.x86_64.rpm SHA-256: 132bd77234783adee3660ea171a6c152b4e2c7fd2dcf941f3167a84d10bf2972 kpatch-patch-5_14_0-570_66_1-debugsource-1-8.el9_6.x86_64.rpm SHA-256: a6078c19b4f820417d488c722123cc7a128b4f9b670e71dc6470fa7f8e12f3bf kpatch-patch-5_14_0-570_94_1-1-6.el9_6.x86_64.rpm SHA-256: a9a3e7e838189cc9d36e4180e1d63a869ccd15596152ec71c483dcb7767765d3 kpatch-patch-5_14_0-570_94_1-debuginfo-1-6.el9_6.x86_64.rpm SHA-256: 633b9b442f44c0b282c144da2db62b2fcb3d35b1703831661b3102dc94aae404 kpatch-patch-5_14_0-570_94_1-debugsource-1-6.el9_6.x86_64.rpm SHA-256: 66133056d442a157f8765a1b73790a17b60afc19d68fcf2f54b903f77db1bbac Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 SRPM kpatch-patch-5_14_0-570_116_1-1-3.el9_6.src.rpm SHA-256: 7e6192c929e1f446389cb1927bf817d953ebfcdcbf9e89d9e356d07c02c2098e kpatch-patch-5_14_0-570_17_1-1-18.el9_6.src.rpm SHA-256: e04f38955319908f46bfbc32144df34a4753a45676cf3f562791346872ff5602 kpatch-patch-5_14_0-570_39_1-1-9.el9_6.src.rpm SHA-256: fc5bae6c951c2436cd37b52cdb8f4f3aeec59f045b6d06f32716bfa4033d9c95 kpatch-patch-5_14_0-570_66_1-1-8.el9_6.src.rpm SHA-256: d6e050fc45de57e92c1a2cc7898e9cd0bc64e65e079b7bc65ba82140c65f5b3c kpatch-patch-5_14_0-570_94_1-1-6.el9_6.src.rpm SHA-256: 09131b310af0612f4fc84e7f93d61a29dc3e56cc4efeeb2b318d045c66f40fac ppc64le kpatch-patch-5_14_0-570_116_1-1-3.el9_6.ppc64le.rpm SHA-256: 13a762c84ee28770692efbf6bb2473f4eb1a01fe5946aa494979f12678ecd503 kpatch-patch-5_14_0-570_116_1-debuginfo-1-3.el9_6.ppc64le.rpm SHA-256: c62df4fd1b565fc8191852f3b2e410015e8da61498843ffce25eebef53cdfc4f kpatch-patch-5_14_0-570_116_1-debugsource-1-3.el9_6.ppc64le.rpm SHA-256: 9a3632513b68c4ae964cbdfdacd2ee195cccbe700e3869469ede35b8268faa2d kpatch-patch-5_14_0-570_17_1-1-18.el9_6.ppc64le.rpm SHA-256: a52be04309e649c3035feb59fc5cc13d50a7d8b58474a6d7e3fc10f7d528ed9f kpatch-patch-5_14_0-570_17_1-debuginfo-1-18.el9_6.ppc64le.rpm SHA-256: b45366b7d72f2c8491fe67b499db563f49255aae3cf29c0fc979e9068624f0f2 kpatch-patch-5_14_0-570_17_1-debugsource-1-18.el9_6.ppc64le.rpm SHA-256: 652435a1687629c176e358025c3317f0ccacc1a9b3652cd43cfcacb1bd5de74c kpatch-patch-5_14_0-570_39_1-1-9.el9_6.ppc64le.rpm SHA-256: aaf41b4e0cfce43cdfd6a7296ed9b249b7f410aa3c0fdd4f5236ff0ee1f516aa kpatch-patch-5_14_0-570_39_1-debuginfo-1-9.el9_6.ppc64le.rpm SHA-256: 77a85af52c1928e8ede384aed68d748a8a4ea0b511fc4100b4b4785e21fab498 kpatch-patch-5_14_0-570_39_

Share this article