- What: Security update for multiple kpatch-patch packages
- Impact: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions users
Red Hat Product Errata RHSA-2026:62639 - Security Advisory Issued: 2026-09-02 Updated: 2026-09-02 RHSA-2026:62639 - Security Advisory Overview Updated Packages Synopsis Important: kpatch-patch-5_14_0-427_100_1, kpatch-patch-5_14_0-427_113_1, kpatch-patch-5_14_0-427_126_1, kpatch-patch-5_14_0-427_68_2, and kpatch-patch-5_14_0-427_84_1 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for multiple packages is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-5.14.0-427.68.2.el9_4. Security Fix(es): kernel: Kernel: Privilege escalation or denial of service in nf_tables via inverted element activity check (CVE-2026-23111) kernel: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (CVE-2026-43114) kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112) kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323) kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle (CVE-2026-53264) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le Fixes BZ - 2439687 - CVE-2026-23111 kernel: Kernel: Privilege escalation or denial of service in nf_tables via inverted element activity check BZ - 2466994 - CVE-2026-43114 kernel: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry BZ - 2467015 - CVE-2026-43112 kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath BZ - 2479832 - CVE-2026-46323 kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs BZ - 2492851 - CVE-2026-53264 kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle CVEs CVE-2026-23111 CVE-2026-43112 CVE-2026-43114 CVE-2026-46323 CVE-2026-53264 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.4 SRPM kpatch-patch-5_14_0-427_100_1-1-14.el9_4.src.rpm SHA-256: 837ee9ee1c0ff551a1f958f2fa9af0a6f5528eddd2f6f84a4bb30b1dc7b764b5 kpatch-patch-5_14_0-427_113_1-1-12.el9_4.src.rpm SHA-256: c862440a92c426375f5a6e67f00f7f2b7274776ae73391bce3aa9f2f8869dab9 kpatch-patch-5_14_0-427_126_1-1-9.el9_4.src.rpm SHA-256: ff3afc27317aa652b90c9770082bb7f3fcf1595f3a98502b02ec672bf2177403 kpatch-patch-5_14_0-427_68_2-1-21.el9_4.src.rpm SHA-256: 6084bd848c3fd576735bdf16993499f6623f7fedfc7dc1b91561950af9fe3da3 kpatch-patch-5_14_0-427_84_1-1-16.el9_4.src.rpm SHA-256: d1e4e0e3a6f7a6c08637e105f68288f508b7753d263f28992accf47071047b45 x86_64 kpatch-patch-5_14_0-427_100_1-1-14.el9_4.x86_64.rpm SHA-256: 5d4f55f2cc9eb9f9a93aeabd90510cb7f0801cb1b6e874f7d0d374184de7bd54 kpatch-patch-5_14_0-427_100_1-debuginfo-1-14.el9_4.x86_64.rpm SHA-256: 34242b4144d997df09074fed8ef3ba68234da5dfb876c434ecd9ad0482e655f6 kpatch-patch-5_14_0-427_100_1-debugsource-1-14.el9_4.x86_64.rpm SHA-256: 9e581bf05703d13b3ac2ff91a04af42449cd5897d78aea46b0e01df3b0c8a3da kpatch-patch-5_14_0-427_113_1-1-12.el9_4.x86_64.rpm SHA-256: 4ebc5e66fdb70013df01bffcdb4f95428e2a35d4a7c2627007e4c0b2ccaaecab kpatch-patch-5_14_0-427_113_1-debuginfo-1-12.el9_4.x86_64.rpm SHA-256: 76ceeabf5b59808993f112a1b269ce3a90ade457293ec25aa33f33e4806fe785 kpatch-patch-5_14_0-427_113_1-debugsource-1-12.el9_4.x86_64.rpm SHA-256: 7cf7a13a9b873220fbe6c6d51d9f2462958731d78ac2178839c931ed36b30d0f kpatch-patch-5_14_0-427_126_1-1-9.el9_4.x86_64.rpm SHA-256: 71e07c3bf7594454d3c1df83f57eefab96384e4323e0c1636161b04a18de68c5 kpatch-patch-5_14_0-427_126_1-debuginfo-1-9.el9_4.x86_64.rpm SHA-256: 6014422741b48afa2631b35d7acd1e23d9febda78410798d81b6ebb3b2ca7274 kpatch-patch-5_14_0-427_126_1-debugsource-1-9.el9_4.x86_64.rpm SHA-256: 0cfa02a67c1e87ca44be29e33167d046b0a6a5bf3c30e3dfcbc8cc4e8256c4cd kpatch-patch-5_14_0-427_68_2-1-21.el9_4.x86_64.rpm SHA-256: 1d9fe3537f3aa9d6f0409bc9413ef4fcc6b9c633155eecb11807f21a6397e770 kpatch-patch-5_14_0-427_68_2-debuginfo-1-21.el9_4.x86_64.rpm SHA-256: 38e7a873ae607fac4f2da420fc7654b069b1b32e03f797fe6daff477554db3c4 kpatch-patch-5_14_0-427_68_2-debugsource-1-21.el9_4.x86_64.rpm SHA-256: 6ee54574af278702914c1aacd83da6b9e43a255a1ec727d927d4b1f1c3d91c61 kpatch-patch-5_14_0-427_84_1-1-16.el9_4.x86_64.rpm SHA-256: 562bb3d3315123e287d16598b23b75fbd9434c6730311064997cb0e0d3cd160e kpatch-patch-5_14_0-427_84_1-debuginfo-1-16.el9_4.x86_64.rpm SHA-256: 3f8f1b18a4fb3a65f518b5a180900f0dc36eabbf26babb8f692899422153f150 kpatch-patch-5_14_0-427_84_1-debugsource-1-16.el9_4.x86_64.rpm SHA-256: 4c4326cbcb39d45640f3f3a7bb419364e34374dafa16f117ff68bbea02413c8f Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 SRPM kpatch-patch-5_14_0-427_100_1-1-14.el9_4.src.rpm SHA-256: 837ee9ee1c0ff551a1f958f2fa9af0a6f5528eddd2f6f84a4bb30b1dc7b764b5 kpatch-patch-5_14_0-427_113_1-1-12.el9_4.src.rpm SHA-256: c862440a92c426375f5a6e67f00f7f2b7274776ae73391bce3aa9f2f8869dab9 kpatch-patch-5_14_0-427_126_1-1-9.el9_4.src.rpm SHA-256: ff3afc27317aa652b90c9770082bb7f3fcf1595f3a98502b02ec672bf2177403 kpatch-patch-5_14_0-427_68_2-1-21.el9_4.src.rpm SHA-256: 6084bd848c3fd576735bdf16993499f6623f7fedfc7dc1b91561950af9fe3da3 kpatch-patch-5_14_0-427_84_1-1-16.el9_4.src.rpm SHA-256: d1e4e0e3a6f7a6c08637e105f68288f508b7753d263f28992accf47071047b45 ppc64le kpatch-patch-5_14_0-427_100_1-1-14.el9_4.ppc64le.rpm SHA-256: 95324bcb2e792a7ad0bd008947ef72911d632a810e230ab1608dbb13a157b9a0 kpatch-patch-5_14_0-427_100_1-debuginfo-1-14.el9_4.ppc64le.rpm SHA-256: df78675a7a2f71a6d4b12130874f62afe8d5b66b9e24dc570ba06063d452091c kpatch-patch-5_14_0-427_100_1-debugsource-1-14.el9_4.ppc64le.rpm SHA-256: 4e9ec0bce000eb0f8a998acb2dc9170209918f03935ca708f048b9d8b8945739 kpatch-patch-5_14_0-427_113_1-1-12.el9_4.ppc64le.rpm SHA-256: 1212a6d43a4c5c17684f62e9a0951e4bb1c824e24cd75a255cc1877415fa79e3 kpatch-patch-5_14_0-427_113_1-debuginfo-1-12.el9_4.ppc64le.rpm SHA-256: 3241b21d06e9909649f22ce79bc52d4a2ea8f097ce60c315923190efc6723018 kpatch-patch-5_14_0-427_113_1-debugsource-1-12.el9_4.ppc64le.rpm SHA-256: 727d70f9e575ba3cb86108fd93dbdf7dfbe4cbd13de95de63f7b01243020ac84 kpatch-patch-5_14_0-427_126_1-1-9.el9_4.ppc64le.rpm SHA-256: fe76452872bef275e78d5bc5bec5278688817011cf6e45aa41c0f57b972ec79f kpatch-patch-5_14_0-427_126_1-debuginfo-1-9.el9_4.ppc64le.rpm SHA-256: b5b3214a61929520094960cd9f28d2a0ec401570d3d691f9e44ac1512327a7c7 kpatch-patch-5_14_0-427_126_1-debugsource-1-9.el9_4.ppc64le.rpm SHA-256: 7c5f59769ad2086f2b5f460c68571331939b575b4d173bee0acc21f9474983a9 kpatch-patch-5_14_0-427_68_2-1-21.el9_4.ppc64le.rpm SHA-256: ff0d1f294ecf52fe8f9947e532585641568e762f7cb3939dabb2f8756029e5c2 kpatch-patch-5_14_0-427_68_2-debuginfo-1-21.el9_4.ppc64le.rpm SHA-256: 0ec76238ab169e9b26b5e2e0a63499325f851457c050c19131bedf1f482c48a4 kpatch-patch-5_14_0-427_68_2-debugsource-1-21.el9_4.ppc64le.rpm SHA-256: 049052972975502bd967bbbe625503fd99e3ec8e22f3fdde94e5d70bbea98beb kpatch-patch-5_14_0-427_84_1-1-16.el9_4.ppc64le.rpm SHA-256: d67eaf4fa5e73c29bf8b80c8577adeae783d64018677bf651f94c7f0bb31b0c6 kpatch-patch-5_14_0-427_84_1-debuginfo-1-16.el9_4.ppc64le.rpm SHA-256: daa008f3e1c005840d6d7c6dedb90cb38dfa133ea54b27065ace0cf28f0faef3 kpatch-patch-5_14_0-427_84_1-debugsource-1-16.el9_4.ppc64le.rpm SHA-256: b435c6a5e5f637fdb0ccf69ae69a30ba087a2972a48e486d4c9d039d4a9083e3 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 SRPM kpatch-patch-5_14_0-427_100_1-1-14.el9_4.src.rpm SHA-256: 837ee9ee1c0ff551a1f958f2fa9af0a6f5528eddd2f6f84a4bb30b1dc7b764b5 kpatch-patch-5_14_0-427_113_1-1-12.el9_4.src.rpm SHA-256: c862440a92c426375f5a6e67f00f7f2b7274776ae73391bce3aa9f2f8869dab9 kpatch-patch-5_14_0-427_126_1-1-9.el9_4.src.rpm SHA-256: ff3afc27317aa652b90c9770082bb7f3fcf1595f3a98502b02ec672bf2177403 kpatch-patch-5_14_0-427_68_2-1-21.el9_4.src.rpm SHA-256: 6084bd848c3fd576735bdf16993499f6623f7fedfc7dc1b91561950af9fe3da3 kpatch-patch-5_14_0-427_84_1-1-16.el9_4.src.rpm SHA-256: d1e4e0e3a6f7a6c08637e105f68288f508b7753d263f28992accf47071047b45 x86_64 kpatch-patch-5_14_0-427_100_1-1-14.el9_4.x86_64.rpm SHA-256: 5d4f55f2cc9eb9f9a93aeabd90510cb7f0801cb1b6e874f7d0d374184de7bd54 kpatch-patch-5_14_0-427_100_1-debuginfo-1-14.el9_4.x86_64.rpm SHA-256: 34242b4144d997df09074fed8ef3ba68234da5dfb876c434ecd9ad0482e655f6 kpatch-patch-5_14_0-427_100_1-debugsource-1-14.el9_4.x86_64.rpm SHA-256: 9e581bf05703d13b3ac2ff91a04af42449cd5897d78aea46b0e01df3b0c8a3da kpatch-patch-5_14_0-427_113_1-1-12.el9_4.x86_64.rpm SHA-256: 4ebc5e66fdb70013df01bffcdb4f95428e2a35d4a7c2627007e4c0b2ccaaecab kpatch-patch-5_14_0-427_113_1-debuginfo-1-12.el9_4.x86_64.rpm SHA-256: 76ceeabf5b59808993f112a1b269ce3a90ade457293ec25aa33f33e4806fe785 kpatch-patch-5_14_0-427_113_1-debugso