Red Hat Product Errata RHSA-2026:28748 - Security Advisory Issued: 2026-06-24 Updated: 2026-06-24 RHSA-2026:28748 - Security Advisory Overview Updated Packages Synopsis Critical: kpatch-patch-4_18_0-477_107_1, kpatch-patch-4_18_0-477_120_1, kpatch-patch-4_18_0-477_130_1, kpatch-patch-4_18_0-477_143_1, and kpatch-patch-4_18_0-477_97_1 security update Type/Severity Security Advisory: Critical Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for multiple packages is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-4.18.0-477.97.1.el8_8. Security Fix(es): kernel: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (CVE-2026-43037) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2464351 - CVE-2026-43037 kernel: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() CVEs CVE-2026-43037 References https://access.redhat.com/security/updates/classification/#critical Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 SRPM kpatch-patch-4_18_0-477_107_1-1-7.el8_8.src.rpm SHA-256: 3c269d0ba2f42e3f6fd813eae6b507e303893aba332c107fb6accded48e162a5 kpatch-patch-4_18_0-477_120_1-1-6.el8_8.src.rpm SHA-256: 5eb8a33f1bf81c52a3163c767a03dd3587b2d4d1873bc2a560c7657f1fa15b62 kpatch-patch-4_18_0-477_130_1-1-4.el8_8.src.rpm SHA-256: 51e5459a4a6c10e3b26f406219b3ec809b4b8d6ef8b168cee7b52d5c20caa1c7 kpatch-patch-4_18_0-477_143_1-1-1.el8_8.src.rpm SHA-256: 7a54e1edf326557ec5c8c0839ec41d7afb5b1effc41f025a908dc4dc4db22f3f kpatch-patch-4_18_0-477_97_1-1-11.el8_8.src.rpm SHA-256: 11fd9934c7f35659acf599e60eb588d461603adb2c72530767b9ffa26532ec03 x86_64 kpatch-patch-4_18_0-477_107_1-1-7.el8_8.x86_64.rpm SHA-256: bedb39b79b4c35a28df8d1b9e46d6fd906f577a68d009de1d6c6cd9e5e4b0762 kpatch-patch-4_18_0-477_107_1-debuginfo-1-7.el8_8.x86_64.rpm SHA-256: 1335fe8c9a74137a2698ee978209f3e223a56985842dd7f558552e3e72c5c033 kpatch-patch-4_18_0-477_107_1-debugsource-1-7.el8_8.x86_64.rpm SHA-256: f35c531a4d0f5dafd808feeb45b1965fbcb4ef35ee644a23289f1021f580187c kpatch-patch-4_18_0-477_120_1-1-6.el8_8.x86_64.rpm SHA-256: 047a0bc209ca8dc8a84930f672227bfe869d2f01e517818a424e8cb1da899eef kpatch-patch-4_18_0-477_120_1-debuginfo-1-6.el8_8.x86_64.rpm SHA-256: 9015c7f96f727666e1fcfc6e25ad8ba5edef2a00c3297ca302a8175d16a8a1c9 kpatch-patch-4_18_0-477_120_1-debugsource-1-6.el8_8.x86_64.rpm SHA-256: f2eb9be62c963be64a6b3e224c8e6855f542aecaec65c333fa3b6dba9500218e kpatch-patch-4_18_0-477_130_1-1-4.el8_8.x86_64.rpm SHA-256: c8e50ebd20631a7d5e2fe1198cdf9b49c267ca9f29d5a175e666e87604e4f8a6 kpatch-patch-4_18_0-477_130_1-debuginfo-1-4.el8_8.x86_64.rpm SHA-256: 2d3fb72f678dd1aee33bd1268da2aff6dd9f7114914c5da11d53fd2d145ac06a kpatch-patch-4_18_0-477_130_1-debugsource-1-4.el8_8.x86_64.rpm SHA-256: 5c8bfef68d20392b260c377ed39f79aa3a2a0729fb3c296b6904f9519efe1491 kpatch-patch-4_18_0-477_143_1-1-1.el8_8.x86_64.rpm SHA-256: fa4ad7ecaa167c570b60949502729e178030b9ecaf2f64e617aec117bdf00239 kpatch-patch-4_18_0-477_143_1-debuginfo-1-1.el8_8.x86_64.rpm SHA-256: 33cd03a5fcc9ecdc31e70cf65e3394ac3e32c1927f2a1d3b78acc340d7bd47bd kpatch-patch-4_18_0-477_143_1-debugsource-1-1.el8_8.x86_64.rpm SHA-256: a53ebffa77b5753b297ea6ca254184c907532d0d1a2ca91599a35dcfd0e81e12 kpatch-patch-4_18_0-477_97_1-1-11.el8_8.x86_64.rpm SHA-256: 2fc6b1101aadb6ae020ff8691b11812e4cb2e1514e185f2d8d5383c4ed3f12a6 kpatch-patch-4_18_0-477_97_1-debuginfo-1-11.el8_8.x86_64.rpm SHA-256: 41f3185bd4f34c87b5ce4a4527b713594a2d9e756209b6aa1d14dd818ade7def kpatch-patch-4_18_0-477_97_1-debugsource-1-11.el8_8.x86_64.rpm SHA-256: eb57eb964c51e6cee8a8b0b2aae237f43eea502f2bbc7d1ce92e7abbe4fb25b3 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 SRPM kpatch-patch-4_18_0-477_107_1-1-7.el8_8.src.rpm SHA-256: 3c269d0ba2f42e3f6fd813eae6b507e303893aba332c107fb6accded48e162a5 kpatch-patch-4_18_0-477_120_1-1-6.el8_8.src.rpm SHA-256: 5eb8a33f1bf81c52a3163c767a03dd3587b2d4d1873bc2a560c7657f1fa15b62 kpatch-patch-4_18_0-477_130_1-1-4.el8_8.src.rpm SHA-256: 51e5459a4a6c10e3b26f406219b3ec809b4b8d6ef8b168cee7b52d5c20caa1c7 kpatch-patch-4_18_0-477_143_1-1-1.el8_8.src.rpm SHA-256: 7a54e1edf326557ec5c8c0839ec41d7afb5b1effc41f025a908dc4dc4db22f3f kpatch-patch-4_18_0-477_97_1-1-11.el8_8.src.rpm SHA-256: 11fd9934c7f35659acf599e60eb588d461603adb2c72530767b9ffa26532ec03 ppc64le kpatch-patch-4_18_0-477_107_1-1-7.el8_8.ppc64le.rpm SHA-256: 215fa76364c25279f97d9b9e90e2cddb301fe6b7bcf5d3da6ae8edb58e5fe7e9 kpatch-patch-4_18_0-477_107_1-debuginfo-1-7.el8_8.ppc64le.rpm SHA-256: 240c2fdd38b6c91674e6e8c86608d2b3a1e13361a75ab648c18392eed635e374 kpatch-patch-4_18_0-477_107_1-debugsource-1-7.el8_8.ppc64le.rpm SHA-256: e86a8819261f3b420afa91ee9b87e5b6cafbfd66ce1c7b6d18b0dabc6e5fa9e7 kpatch-patch-4_18_0-477_120_1-1-6.el8_8.ppc64le.rpm SHA-256: 9e323543f0177c7a9b2bc2aa1c93ec2d29ee81e3509237d961d2bdb2c7ed4cc8 kpatch-patch-4_18_0-477_120_1-debuginfo-1-6.el8_8.ppc64le.rpm SHA-256: a68fda7ff313e202cf2cae19bc468dab5e847f4594482a0d655032811acc4e34 kpatch-patch-4_18_0-477_120_1-debugsource-1-6.el8_8.ppc64le.rpm SHA-256: 4e6b9f5ea428d9fa811153b574b1ba2b5e2bf9f7c5a5ceff6110e2fc06ae9435 kpatch-patch-4_18_0-477_130_1-1-4.el8_8.ppc64le.rpm SHA-256: 58984ad679ac8791f17240846e7d51b93cf97bb34910ae7fb46b90c946ee1a92 kpatch-patch-4_18_0-477_130_1-debuginfo-1-4.el8_8.ppc64le.rpm SHA-256: 427475b662184ac8f0cb4b5ba0180c20057ce5cca16b8485a34c42bbf760a74e kpatch-patch-4_18_0-477_130_1-debugsource-1-4.el8_8.ppc64le.rpm SHA-256: 05eed9aa85fb63754a31a13516f0c17921106a69513526a510f211e91c3d3443 kpatch-patch-4_18_0-477_143_1-1-1.el8_8.ppc64le.rpm SHA-256: 47d1b75a3c6bb0ac8583524b7d88fa363db65a25f166c9785647981b5c3ed056 kpatch-patch-4_18_0-477_143_1-debuginfo-1-1.el8_8.ppc64le.rpm SHA-256: 529a5de967f2d7466ee827cb53d1b9a2402f56a1b730a211d7a0370b38548d29 kpatch-patch-4_18_0-477_143_1-debugsource-1-1.el8_8.ppc64le.rpm SHA-256: 5f8f8fb395255860a6acba61140a4c61e9ea7f24a1055391637c6bc692fc5657 kpatch-patch-4_18_0-477_97_1-1-11.el8_8.ppc64le.rpm SHA-256: de506c6c838979991a2abd5b3b1887b51d634a1632c7974df55718696f7f2b69 kpatch-patch-4_18_0-477_97_1-debuginfo-1-11.el8_8.ppc64le.rpm SHA-256: 86ae32d88b53d89601bbd774a9b006839c9387a726d89fbe54a78847b7fd1d87 kpatch-patch-4_18_0-477_97_1-debugsource-1-11.el8_8.ppc64le.rpm SHA-256: 39e4aa04b29572192daf920a4068495a757d4f26c7263924d5f7f2cbb52ce55e Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 SRPM kpatch-patch-4_18_0-477_107_1-1-7.el8_8.src.rpm SHA-256: 3c269d0ba2f42e3f6fd813eae6b507e303893aba332c107fb6accded48e162a5 kpatch-patch-4_18_0-477_120_1-1-6.el8_8.src.rpm SHA-256: 5eb8a33f1bf81c52a3163c767a03dd3587b2d4d1873bc2a560c7657f1fa15b62 kpatch-patch-4_18_0-477_130_1-1-4.el8_8.src.rpm SHA-256: 51e5459a4a6c10e3b26f406219b3ec809b4b8d6ef8b168cee7b52d5c20caa1c7 kpatch-patch-4_18_0-477_143_1-1-1.el8_8.src.rpm SHA-256: 7a54e1edf326557ec5c8c0839ec41d7afb5b1effc41f025a908dc4dc4db22f3f kpatch-patch-4_18_0-477_97_1-1-11.el8_8.src.rpm SHA-256: 11fd9934c7f35659acf599e60eb588d461603adb2c72530767b9ffa26532ec03 x86_64 kpatch-patch-4_18_0-477_107_1-1-7.el8_8.x86_64.rpm SHA-256: bedb39b79b4c35a28df8d1b9e46d6fd906f577a68d009de1d6c6cd9e5e4b0762 kpatch-patch-4_18_0-477_107_1-debuginfo-1-7.el8_8.x86_64.rpm SHA-256: 1335fe8c9a74137a2698ee978209f3e223a56985842dd7f558552e3e72c5c033 kpatch-patch-4_18_0-477_107_1-debugsource-1-7.el8_8.x86_64.rpm SHA-256: f35c531a4d0f5dafd808feeb45b1965fbcb4ef35ee644a23289f1021f580187c kpatch-patch-4_18_0-477_120_1-1-6.el8_8.x86_64.rpm SHA-256: 047a0bc209ca8dc8a84930f672227bfe869d2f01e517818a424e8cb1da899eef kpatch-patch-4_18_0-477_120_1-debuginfo-1-6.el8_8.x86_64.rpm SHA-256: 9015c7f96f727666e1fcfc6e25ad8ba5edef2a00c3297ca302a8175d16a8a1c9 kpatch-patch-4_18_0-477_120_1-debugsource-1-6.el8_8.x86_64.rpm SHA-256: f2eb9be62c963be64a6b3e224c8e6855f542aecaec65c333fa3b6dba9500218e kpatch-patch-4_18_0-477_130_1-1-4.el8_8.x86_64.rpm SHA-256: c8e50ebd20631a7d5e2fe1198cdf9b49c267ca9f29d5a175e666e87604e4f8a6 kpatch-patch-4_18_0-477_130_1-debuginfo-1-4.el8_8.x86_64.rpm SHA-256: 2d3fb72f678dd1aee33bd1268da2aff6dd9f7114914c5da11d53fd2d145ac06a kpatch-patch-4_18_0-477_130_1-debugsource-1-4.el8_8.x86_64.rpm SHA-256: 5c8bfef68d20392b260c377ed39f79aa3a2a0729fb3c296b6904f9519efe1491 kpatch-patch-4_18_0-477_143_1-1-1.el8_8.x86_64.rpm SHA-256: fa4ad7ecaa167c570b60949502729e178030b9ecaf2f64e617aec117bdf00239 kpatch-patch-4_18_0-477_143_1-debuginfo-1-1.el8_8.x86_64.rpm SHA-256: 33cd03a5fcc9ecdc31e70cf65e3394ac3e32c1927f2a1d3b78acc340d7bd47bd kpatch-patch-4_18_0-477_143_1-debugsource-1-1.el8_8.x86_64.rpm SHA-256: a53ebffa77b5753b297ea6ca254184c907532d0d1a2ca91599a35dcfd0e81e12 kpatch-patch-4_18_0-477_97_1-1-11.el8_8.x86_64.rpm SHA-256: 2fc6b1101aadb6ae020ff8691b11812e4cb2e1514e185f2d8d5383c4ed3f12a6 kpatch-patch-4_18_0-477_97_1-debuginfo-1-11.el8_8.x86_64.rpm SHA-256: 41f3185bd4f34c87b5ce4a
A critical vulnerability (CVE-2026-43037, CVSS 9.8) in the Linux kernel's `ip6_tunnel` module, where failing to clear the `skb2->cb[]` buffer in `ip4ip6_err()` could allow for privilege escalation or other impacts. Affected kernel versions range from 2.6.22 up to but excluding 5.10.253, from 5.11 up to but excluding 5.15.203, from 5.16 up to but excluding 6.1.168, from 6.2 up to but excluding 6.6.134, and from 6.7 up to but excluding 6.12.81. Red Hat has released critical live patch (`kpatch`) modules for the 4.18.0-477 kernel stream on RHEL 8.8 Update Services for SAP Solutions to address this flaw without a full reboot.