Security News

Cybersecurity news aggregator

🔄
CRITICAL Updates Red Hat Errata

RHSA-2026:28741: Critical: kpatch-patch-5_14_0-687_10_1 security update

A critical vulnerability (CVE-2026-43037, CVSS 9.8) in the Linux kernel's `ip6_tunnel` module allows exploitation via a failure to clear the `skb->cb[]` buffer in the `ip4ip6_err()` function. Affected kernel versions range from 2.6.22 up to but excluding 5.10.253, from 5.11 up to 5.15.203, from 5.16 up to 6.1.168, from 6.2 up to 6.6.134, and from 6.7 up to 6.12.81. The fix is provided via a Red Hat kpatch live patch module for kernel-5.14.0-687.10.1.el9_8, and the underlying vulnerability is fixed in upstream kernel versions 5.10.253, 5.15.203, 6.1.168, 6.6.134, 6.12.81, 6.18.22, and 6.19.12.
Read Full Article →

Red Hat Product Errata RHSA-2026:28741 - Security Advisory Issued: 2026-06-24 Updated: 2026-06-24 RHSA-2026:28741 - Security Advisory Overview Updated Packages Synopsis Critical: kpatch-patch-5_14_0-687_10_1 security update Type/Severity Security Advisory: Critical Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for kpatch-patch-5_14_0-687_10_1 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-5.14.0-687.10.1.el9_8. Security Fix(es): kernel: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (CVE-2026-43037) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Fixes BZ - 2464351 - CVE-2026-43037 kernel: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() CVEs CVE-2026-43037 References https://access.redhat.com/security/updates/classification/#critical Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM kpatch-patch-5_14_0-687_10_1-1-1.el9_8.src.rpm SHA-256: 33f45ed2a3ea49b8ec37d9ed361ccc3a67d2259063a8b6f080c888e00e02ece9 x86_64 kpatch-patch-5_14_0-687_10_1-1-1.el9_8.x86_64.rpm SHA-256: ced8281444dc9ea7957a76e952babef511bde7e4ab62a4d2df449c29d2d0fa3b kpatch-patch-5_14_0-687_10_1-debuginfo-1-1.el9_8.x86_64.rpm SHA-256: 79a73529190cff3800ed98b126056fda0479511c18af524d2be118f44d8d33b1 kpatch-patch-5_14_0-687_10_1-debugsource-1-1.el9_8.x86_64.rpm SHA-256: 9e97c05af7ce611b852f02cb94a3951ce5c338b16611d8c41fae3a81db1036a4 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM kpatch-patch-5_14_0-687_10_1-1-1.el9_8.src.rpm SHA-256: 33f45ed2a3ea49b8ec37d9ed361ccc3a67d2259063a8b6f080c888e00e02ece9 x86_64 kpatch-patch-5_14_0-687_10_1-1-1.el9_8.x86_64.rpm SHA-256: ced8281444dc9ea7957a76e952babef511bde7e4ab62a4d2df449c29d2d0fa3b kpatch-patch-5_14_0-687_10_1-debuginfo-1-1.el9_8.x86_64.rpm SHA-256: 79a73529190cff3800ed98b126056fda0479511c18af524d2be118f44d8d33b1 kpatch-patch-5_14_0-687_10_1-debugsource-1-1.el9_8.x86_64.rpm SHA-256: 9e97c05af7ce611b852f02cb94a3951ce5c338b16611d8c41fae3a81db1036a4 Red Hat Enterprise Linux for Power, little endian 9 SRPM kpatch-patch-5_14_0-687_10_1-1-1.el9_8.src.rpm SHA-256: 33f45ed2a3ea49b8ec37d9ed361ccc3a67d2259063a8b6f080c888e00e02ece9 ppc64le kpatch-patch-5_14_0-687_10_1-1-1.el9_8.ppc64le.rpm SHA-256: aa21ea600541e5f46a43b6f83440194f5e60e62f46935eb208c78ee096af79dd kpatch-patch-5_14_0-687_10_1-debuginfo-1-1.el9_8.ppc64le.rpm SHA-256: 0321969e4f8da5d412fd5ea4a02772afec1fb3ff894cade84f0b613a47794319 kpatch-patch-5_14_0-687_10_1-debugsource-1-1.el9_8.ppc64le.rpm SHA-256: a0816bd242633cbce9475bce6d57f6357db9f8f03097505087c4a350c60aa0e9 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 SRPM kpatch-patch-5_14_0-687_10_1-1-1.el9_8.src.rpm SHA-256: 33f45ed2a3ea49b8ec37d9ed361ccc3a67d2259063a8b6f080c888e00e02ece9 ppc64le kpatch-patch-5_14_0-687_10_1-1-1.el9_8.ppc64le.rpm SHA-256: aa21ea600541e5f46a43b6f83440194f5e60e62f46935eb208c78ee096af79dd kpatch-patch-5_14_0-687_10_1-debuginfo-1-1.el9_8.ppc64le.rpm SHA-256: 0321969e4f8da5d412fd5ea4a02772afec1fb3ff894cade84f0b613a47794319 kpatch-patch-5_14_0-687_10_1-debugsource-1-1.el9_8.ppc64le.rpm SHA-256: a0816bd242633cbce9475bce6d57f6357db9f8f03097505087c4a350c60aa0e9 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 SRPM kpatch-patch-5_14_0-687_10_1-1-1.el9_8.src.rpm SHA-256: 33f45ed2a3ea49b8ec37d9ed361ccc3a67d2259063a8b6f080c888e00e02ece9 ppc64le kpatch-patch-5_14_0-687_10_1-1-1.el9_8.ppc64le.rpm SHA-256: aa21ea600541e5f46a43b6f83440194f5e60e62f46935eb208c78ee096af79dd kpatch-patch-5_14_0-687_10_1-debuginfo-1-1.el9_8.ppc64le.rpm SHA-256: 0321969e4f8da5d412fd5ea4a02772afec1fb3ff894cade84f0b613a47794319 kpatch-patch-5_14_0-687_10_1-debugsource-1-1.el9_8.ppc64le.rpm SHA-256: a0816bd242633cbce9475bce6d57f6357db9f8f03097505087c4a350c60aa0e9 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 SRPM kpatch-patch-5_14_0-687_10_1-1-1.el9_8.src.rpm SHA-256: 33f45ed2a3ea49b8ec37d9ed361ccc3a67d2259063a8b6f080c888e00e02ece9 x86_64 kpatch-patch-5_14_0-687_10_1-1-1.el9_8.x86_64.rpm SHA-256: ced8281444dc9ea7957a76e952babef511bde7e4ab62a4d2df449c29d2d0fa3b kpatch-patch-5_14_0-687_10_1-debuginfo-1-1.el9_8.x86_64.rpm SHA-256: 79a73529190cff3800ed98b126056fda0479511c18af524d2be118f44d8d33b1 kpatch-patch-5_14_0-687_10_1-debugsource-1-1.el9_8.x86_64.rpm SHA-256: 9e97c05af7ce611b852f02cb94a3951ce5c338b16611d8c41fae3a81db1036a4 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 SRPM kpatch-patch-5_14_0-687_10_1-1-1.el9_8.src.rpm SHA-256: 33f45ed2a3ea49b8ec37d9ed361ccc3a67d2259063a8b6f080c888e00e02ece9 x86_64 kpatch-patch-5_14_0-687_10_1-1-1.el9_8.x86_64.rpm SHA-256: ced8281444dc9ea7957a76e952babef511bde7e4ab62a4d2df449c29d2d0fa3b kpatch-patch-5_14_0-687_10_1-debuginfo-1-1.el9_8.x86_64.rpm SHA-256: 79a73529190cff3800ed98b126056fda0479511c18af524d2be118f44d8d33b1 kpatch-patch-5_14_0-687_10_1-debugsource-1-1.el9_8.x86_64.rpm SHA-256: 9e97c05af7ce611b852f02cb94a3951ce5c338b16611d8c41fae3a81db1036a4 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 SRPM kpatch-patch-5_14_0-687_10_1-1-1.el9_8.src.rpm SHA-256: 33f45ed2a3ea49b8ec37d9ed361ccc3a67d2259063a8b6f080c888e00e02ece9 ppc64le kpatch-patch-5_14_0-687_10_1-1-1.el9_8.ppc64le.rpm SHA-256: aa21ea600541e5f46a43b6f83440194f5e60e62f46935eb208c78ee096af79dd kpatch-patch-5_14_0-687_10_1-debuginfo-1-1.el9_8.ppc64le.rpm SHA-256: 0321969e4f8da5d412fd5ea4a02772afec1fb3ff894cade84f0b613a47794319 kpatch-patch-5_14_0-687_10_1-debugsource-1-1.el9_8.ppc64le.rpm SHA-256: a0816bd242633cbce9475bce6d57f6357db9f8f03097505087c4a350c60aa0e9 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article