RHSA-2026:62640HighCVSS 8.1

Red Hat Security Advisory: kpatch-patch-5_14_0-687_10_1 security update

Published
September 2, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2026-43112 — kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath CVE-2026-43114 — kernel: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry CVE-2026-46323 — kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs CVE-2026-52973 — kernel: futex: Drop CLONE_THREAD requirement for private default hash alloc CVE-2026-53264 — kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle

🎯 Affected products8

  • Red Hat Enterprise Linux BaseOS (v. 9)
  • kpatch-patch-5_14_0-687_10_1-0:1-8.el9_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kpatch-patch-5_14_0-687_10_1-0:1-8.el9_8.src as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kpatch-patch-5_14_0-687_10_1-0:1-8.el9_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kpatch-patch-5_14_0-687_10_1-debuginfo-0:1-8.el9_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kpatch-patch-5_14_0-687_10_1-debuginfo-0:1-8.el9_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kpatch-patch-5_14_0-687_10_1-debugsource-0:1-8.el9_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • kpatch-patch-5_14_0-687_10_1-debugsource-0:1-8.el9_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (8)