Red Hat Product Errata RHSA-2026:55762 - Security Advisory Issued: 2026-08-17 Updated: 2026-08-17 RHSA-2026:55762 - Security Advisory Overview Updated Packages Synopsis Important: kpatch-patch-4_18_0-553_109_1, kpatch-patch-4_18_0-553_125_1, kpatch-patch-4_18_0-553_53_1, kpatch-patch-4_18_0-553_72_1, and kpatch-patch-4_18_0-553_85_1 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for multiple packages is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-4.18.0-553.53.1.el8_10. Security Fix(es): kernel: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038) kernel: dlm: validate length in dlm_search_rsb_tree (CVE-2026-43125) kernel: netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329) kernel: net: sched: UAF via missing handler for TC_ACT_CONSUMED in tcf_qevent_handle (CVE-2026-64530) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Fixes BZ - 2464397 - CVE-2026-43038 kernel: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() BZ - 2467234 - CVE-2026-43125 kernel: dlm: validate length in dlm_search_rsb_tree BZ - 2468124 - CVE-2026-43329 kernel: netfilter: flowtable: strictly check for maximum number of actions BZ - 2504052 - CVE-2026-64530 kernel: net: sched: UAF via missing handler for TC_ACT_CONSUMED in tcf_qevent_handle CVEs CVE-2026-43038 CVE-2026-43125 CVE-2026-43329 CVE-2026-64530 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM kpatch-patch-4_18_0-553_109_1-1-9.el8_10.src.rpm SHA-256: afac2f863b6459d1f2a1d178af6ec7f04de883b690d9df2f9622dfdb9d8ac5fd kpatch-patch-4_18_0-553_125_1-1-6.el8_10.src.rpm SHA-256: c50778b5618b6ac2f17dbe5aacd408b9b961d316f4cc546bf065f2f16a44a947 kpatch-patch-4_18_0-553_53_1-1-16.el8_10.src.rpm SHA-256: b956d0c030ca7d9415562e0d91185f9f9471e3d5adcde3903641d23f3be4fe3f kpatch-patch-4_18_0-553_72_1-1-13.el8_10.src.rpm SHA-256: 293f4b47c5f961ca4ce868e7c47b87e57b749e23facb7dd65de85b8d2dbf523c kpatch-patch-4_18_0-553_85_1-1-11.el8_10.src.rpm SHA-256: bb86b04c266baf23cc4a7c5a30e6a57e639095e24d57e40e24357c1a8ca699cc x86_64 kpatch-patch-4_18_0-553_109_1-1-9.el8_10.x86_64.rpm SHA-256: a76048f69bb291aa94f20c77726b128cc526b0a9ec7a1c7066965088cd03c5f4 kpatch-patch-4_18_0-553_109_1-debuginfo-1-9.el8_10.x86_64.rpm SHA-256: 9f4152856473233f58267aa2d26302c3b7e586587b45d827a4bbd13797c16f25 kpatch-patch-4_18_0-553_109_1-debugsource-1-9.el8_10.x86_64.rpm SHA-256: bf85b11323fdfa7cad7f5c92527bbbe6a6b50f11a31ec0a1c3f8542f36d95c0f kpatch-patch-4_18_0-553_125_1-1-6.el8_10.x86_64.rpm SHA-256: 3d4e8183835b3ca0b724b23b1943487228773a6902bc741b95b823d62dc78bbf kpatch-patch-4_18_0-553_125_1-debuginfo-1-6.el8_10.x86_64.rpm SHA-256: 35386c45df3c99972cd335bb6541c9aaab317c2e781c521f48255f3d07390396 kpatch-patch-4_18_0-553_125_1-debugsource-1-6.el8_10.x86_64.rpm SHA-256: 75b2211e21e997b493acc084f520c5c72e79b596b73a08f542fa22c8a390afe1 kpatch-patch-4_18_0-553_53_1-1-16.el8_10.x86_64.rpm SHA-256: 16c90e9a9c20aa0eba7f50e0ca3a7b2bdf0c7355e732c771b8ef36db8f0320a1 kpatch-patch-4_18_0-553_53_1-debuginfo-1-16.el8_10.x86_64.rpm SHA-256: 74986af4b91b7063b0df510d177d50f0cc5951eb551f04df0b5ad0dd530d22ed kpatch-patch-4_18_0-553_53_1-debugsource-1-16.el8_10.x86_64.rpm SHA-256: 3756107f3e60966a8e13c1adf5b5340a4cc83706b53e4950b3c341ceb17943b9 kpatch-patch-4_18_0-553_72_1-1-13.el8_10.x86_64.rpm SHA-256: 56eb6a6e183401df45e0d2392bbeabe5aec7976a1bc1088582bfad97908a0949 kpatch-patch-4_18_0-553_72_1-debuginfo-1-13.el8_10.x86_64.rpm SHA-256: aea7b06130227f802560d22ea1cb990e7fc68ff67a4d43473555c3e9b6037be5 kpatch-patch-4_18_0-553_72_1-debugsource-1-13.el8_10.x86_64.rpm SHA-256: 25cf337f06f3c6aa2315c0f36d25d74b29c33cf3769e6c5e64adcf59daadd05a kpatch-patch-4_18_0-553_85_1-1-11.el8_10.x86_64.rpm SHA-256: bc41d657a26d76e115b973c157d983f8b861afbab39739c8e72f5db8680bd996 kpatch-patch-4_18_0-553_85_1-debuginfo-1-11.el8_10.x86_64.rpm SHA-256: f359d6e1533ec5ea37ecc4cbf6657be444b43162de7a1b93a8c061d168621163 kpatch-patch-4_18_0-553_85_1-debugsource-1-11.el8_10.x86_64.rpm SHA-256: 9ff47e2e2c3b06fd6569daaf49c77492bc91e49623fef11af616972837219f02 Red Hat Enterprise Linux for Power, little endian 8 SRPM kpatch-patch-4_18_0-553_109_1-1-9.el8_10.src.rpm SHA-256: afac2f863b6459d1f2a1d178af6ec7f04de883b690d9df2f9622dfdb9d8ac5fd kpatch-patch-4_18_0-553_125_1-1-6.el8_10.src.rpm SHA-256: c50778b5618b6ac2f17dbe5aacd408b9b961d316f4cc546bf065f2f16a44a947 kpatch-patch-4_18_0-553_53_1-1-16.el8_10.src.rpm SHA-256: b956d0c030ca7d9415562e0d91185f9f9471e3d5adcde3903641d23f3be4fe3f kpatch-patch-4_18_0-553_72_1-1-13.el8_10.src.rpm SHA-256: 293f4b47c5f961ca4ce868e7c47b87e57b749e23facb7dd65de85b8d2dbf523c kpatch-patch-4_18_0-553_85_1-1-11.el8_10.src.rpm SHA-256: bb86b04c266baf23cc4a7c5a30e6a57e639095e24d57e40e24357c1a8ca699cc ppc64le kpatch-patch-4_18_0-553_109_1-1-9.el8_10.ppc64le.rpm SHA-256: 7656392343c6a4c7d67578ae654122ab513d2f6ffeed6945de6bfb39c3465ea9 kpatch-patch-4_18_0-553_109_1-debuginfo-1-9.el8_10.ppc64le.rpm SHA-256: 16c919aaedad81d5fda60528c9cccd755d6b13103d51ad3a05c43bab6e1827cf kpatch-patch-4_18_0-553_109_1-debugsource-1-9.el8_10.ppc64le.rpm SHA-256: c9f075fa9c597765ad894b60873216d6da176e19e7f9cf360f6257c7430b357f kpatch-patch-4_18_0-553_125_1-1-6.el8_10.ppc64le.rpm SHA-256: a90dd6a02933ef33840a17690cbe9061e39d1030e01d6d858fff64ac96df3e39 kpatch-patch-4_18_0-553_125_1-debuginfo-1-6.el8_10.ppc64le.rpm SHA-256: a43c4612289c1b9e3271384cd0f81f1e32ea2cc3b1e075a9304d64a0d420aa84 kpatch-patch-4_18_0-553_125_1-debugsource-1-6.el8_10.ppc64le.rpm SHA-256: 7d253ed9389f5b115abe58759b5d42c3ef8915e4e6ec0a3bbf2fcf3742c6e0ec kpatch-patch-4_18_0-553_53_1-1-16.el8_10.ppc64le.rpm SHA-256: 6178eafd6943678ffe994b49583046634da076802684b43f34aa15c041749eef kpatch-patch-4_18_0-553_53_1-debuginfo-1-16.el8_10.ppc64le.rpm SHA-256: eb8109a671b264b71f95ef60c2791455a571e64a26bbf3caa992b6a85892873e kpatch-patch-4_18_0-553_53_1-debugsource-1-16.el8_10.ppc64le.rpm SHA-256: d9e704b38be92f49e6f76bdb2e77468f9e99467cfa506f73e7b9994e845010f9 kpatch-patch-4_18_0-553_72_1-1-13.el8_10.ppc64le.rpm SHA-256: 4a457ce3ef2db4ef533492a7924efa5b06c3f885f3cdb0c957cd157189960d29 kpatch-patch-4_18_0-553_72_1-debuginfo-1-13.el8_10.ppc64le.rpm SHA-256: c553141e239f044856c71006720aac0ff124666f5d05977b69933142f95e6f43 kpatch-patch-4_18_0-553_72_1-debugsource-1-13.el8_10.ppc64le.rpm SHA-256: 449418040c698e3847fdc990b2014c6d23ba39ec5cd3668f5c0f76f98e5bd76d kpatch-patch-4_18_0-553_85_1-1-11.el8_10.ppc64le.rpm SHA-256: f659911f23543d5ff886f4d5299128cad292edb150436c47926bd1a540d81207 kpatch-patch-4_18_0-553_85_1-debuginfo-1-11.el8_10.ppc64le.rpm SHA-256: a50c40694654601a5972a9b11cf92abb52efb240090f7b5d1f247c095b3b79c1 kpatch-patch-4_18_0-553_85_1-debugsource-1-11.el8_10.ppc64le.rpm SHA-256: b9484869f95c3a4e301eeea3db64f923d2e29e1e70581914b3f8f95cac6d823c Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 SRPM kpatch-patch-4_18_0-553_109_1-1-9.el8_10.src.rpm SHA-256: afac2f863b6459d1f2a1d178af6ec7f04de883b690d9df2f9622dfdb9d8ac5fd kpatch-patch-4_18_0-553_125_1-1-6.el8_10.src.rpm SHA-256: c50778b5618b6ac2f17dbe5aacd408b9b961d316f4cc546bf065f2f16a44a947 kpatch-patch-4_18_0-553_53_1-1-16.el8_10.src.rpm SHA-256: b956d0c030ca7d9415562e0d91185f9f9471e3d5adcde3903641d23f3be4fe3f kpatch-patch-4_18_0-553_72_1-1-13.el8_10.src.rpm SHA-256: 293f4b47c5f961ca4ce868e7c47b87e57b749e23facb7dd65de85b8d2dbf523c kpatch-patch-4_18_0-553_85_1-1-11.el8_10.src.rpm SHA-256: bb86b04c266baf23cc4a7c5a30e6a57e639095e24d57e40e24357c1a8ca699cc x86_64 kpatch-patch-4_18_0-553_109_1-1-9.el8_10.x86_64.rpm SHA-256: a76048f69bb291aa94f20c77726b128cc526b0a9ec7a1c7066965088cd03c5f4 kpatch-patch-4_18_0-553_109_1-debuginfo-1-9.el8_10.x86_64.rpm SHA-256: 9f4152856473233f58267aa2d26302c3b7e586587b45d827a4bbd13797c16f25 kpatch-patch-4_18_0-553_109_1-debugsource-1-9.el8_10.x86_64.rpm SHA-256: bf85b11323fdfa7cad7f5c92527bbbe6a6b50f11a31ec0a1c3f8542f36d95c0f kpatch-patch-4_18_0-553_125_1-1-6.el8_10.x86_64.rpm SHA-256: 3d4e8183835b3ca0b724b23b1943487228773a6902bc741b95b823d62dc78bbf kpatch-patch-4_18_0-553_125_1-debuginfo-1-6.el8_10.x86_64.rpm SHA-256: 35386c45df3c99972cd335bb6541c9aaab317c2e781c521f48255f3d07390396 kpatch-patch-4_18_0-553_125_1-debugsource-1-6.el8_10.x86_64.rpm SHA-256: 75b2211e21e997b493acc084f520c5c72e79b596b73a08f542fa22c8a390afe1 kpatch-patch-4_18_0-553_53_1-1-16.el8_10.x86_64.rpm SHA-256: 16c90e9a9c20aa0eba7f50e0ca3a7b2bdf0c7355e732c771b8ef36db8f0320a1 kpatch-patch-4_18_0-553_53_1-debuginfo-1-16.el8_10.x86_64.rpm SHA-256: 74986af4b91b7063b0df510d177d50f0cc5951eb551f04df0b5ad0dd530d22ed kpatch-patch-4_18_0-553_53_1-debugsource-1-16.el8_10.x86_64.rpm SHA-256: 3756107f3e60966a8e13c1adf5b5340a4cc83706b53e4950b3c341ceb17943b9 kpatch-patch-4_18_0-553_72_1-1-13.
This Red Hat security advisory addresses four critical and high-severity kernel vulnerabilities (CVE-2026-43038, CVE-2026-43125, CVE-2026-43329, CVE-2026-64530) affecting the Linux kernel, including issues in IPv6 ICMP handling, DLM, netfilter flowtable, and traffic control that can lead to use-after-free and other memory corruption flaws. The provided kpatch live patches are for the 4.18.0-553 kernel stream on RHEL 8, but the underlying CVEs affect a wide range of mainline kernel versions, for example, CVE-2026-43038 affects versions prior to 5.10.253, 5.15.203, 6.1.168, 6.6.134, 6.12.81, 6.18.22, and 6.19.12. Administrators should apply the provided kpatch updates immediately to affected RHEL 8 systems to mitigate these remote and local attack vectors.