- What: Security update for Red Hat Enterprise Linux kernel modules
- Impact: Systems running RHEL 9.4 Update Services for SAP Solutions
Red Hat Product Errata RHSA-2026:36533 - Security Advisory Issued: 2026-07-08 Updated: 2026-07-08 RHSA-2026:36533 - Security Advisory Overview Updated Packages Synopsis Important: kpatch-patch-5_14_0-427_100_1, kpatch-patch-5_14_0-427_113_1, kpatch-patch-5_14_0-427_126_1, kpatch-patch-5_14_0-427_68_2, and kpatch-patch-5_14_0-427_84_1 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for multiple packages is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-5.14.0-427.68.2.el9_4. Security Fix(es): kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling (CVE-2026-23401) kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (CVE-2026-31402) kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service (CVE-2026-31419) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le Fixes BZ - 2453803 - CVE-2026-23401 kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling BZ - 2454844 - CVE-2026-31402 kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache BZ - 2457829 - CVE-2026-31419 kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service CVEs CVE-2026-23401 CVE-2026-31402 CVE-2026-31419 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.4 SRPM kpatch-patch-5_14_0-427_100_1-1-8.el9_4.src.rpm SHA-256: a19772e04a063b327836fd5e7d0afc294d4aa18ea91fb1f626a9fdc77b5b2f95 kpatch-patch-5_14_0-427_113_1-1-6.el9_4.src.rpm SHA-256: 7e0cafe5d0ce448a2be92956cce2be5c830f784dbbd801acbdaf35c08a0695d9 kpatch-patch-5_14_0-427_126_1-1-3.el9_4.src.rpm SHA-256: 96f00766c4fa04a0fcfc9bdce989ccf6f289bc37c7259aceefd634f2bc284d56 kpatch-patch-5_14_0-427_68_2-1-15.el9_4.src.rpm SHA-256: 237e21265f606900a23d6b0eb4a21209ab0755add43ac90de1fc3496a300aa0a kpatch-patch-5_14_0-427_84_1-1-10.el9_4.src.rpm SHA-256: 2218f8641953333ffa90e17913e0239f2530de4bc43d83eb6386af2fe30feff8 x86_64 kpatch-patch-5_14_0-427_100_1-1-8.el9_4.x86_64.rpm SHA-256: 970ce6db2ba07c98b382115cdfe30644795de0d7219e0e4f540824a35ede121a kpatch-patch-5_14_0-427_100_1-debuginfo-1-8.el9_4.x86_64.rpm SHA-256: 78d2a4fb4bdb4ad92dec41c0770aa183454cb44f4850079a7de433ec5d530168 kpatch-patch-5_14_0-427_100_1-debugsource-1-8.el9_4.x86_64.rpm SHA-256: 551569e286ba871bce15d49160df4995c649dd6df98afdab334c1608587055b9 kpatch-patch-5_14_0-427_113_1-1-6.el9_4.x86_64.rpm SHA-256: 394bec1457e5d7cf4cee371d5ee57fb21d370fb0092f607f2bca1432d9129cd9 kpatch-patch-5_14_0-427_113_1-debuginfo-1-6.el9_4.x86_64.rpm SHA-256: d35f534e2b3db3b8ade4c289dac8873938e8b0345224cc0c4a8855d3f3073b71 kpatch-patch-5_14_0-427_113_1-debugsource-1-6.el9_4.x86_64.rpm SHA-256: d32a3d5573acef33026fd073155b3ddaf09ae842fa0108a72bf177914f96dd96 kpatch-patch-5_14_0-427_126_1-1-3.el9_4.x86_64.rpm SHA-256: 8aae78a03601343ac772c049c36a975f6f65c8ef4c536f5a6dfa9e22e0a628c0 kpatch-patch-5_14_0-427_126_1-debuginfo-1-3.el9_4.x86_64.rpm SHA-256: 10b233d663a17ab40698f02bbd0e8512635dda390b1fa5fa273f71fdb4d7b324 kpatch-patch-5_14_0-427_126_1-debugsource-1-3.el9_4.x86_64.rpm SHA-256: 80c749881c3ffc159598fac88f6c0569d6076169ee94ecd4a61c868957097020 kpatch-patch-5_14_0-427_68_2-1-15.el9_4.x86_64.rpm SHA-256: 8cd9cceb1e37fac849e81a5049c8dde9b19cea808fe13491713da89b63670bb3 kpatch-patch-5_14_0-427_68_2-debuginfo-1-15.el9_4.x86_64.rpm SHA-256: 87e50a69c7970d8b1ff9a927ee16884d0397007bf0aae55b131a9f947628c9e7 kpatch-patch-5_14_0-427_68_2-debugsource-1-15.el9_4.x86_64.rpm SHA-256: 74fbfb74ff0102fe5ece3cb83306dab66de274f36c7476ac2762ce6a684db0fa kpatch-patch-5_14_0-427_84_1-1-10.el9_4.x86_64.rpm SHA-256: 05ca1e3aeef1393ac7725ade4ee78ce6af39db3a33dd927ce04460ba9a572256 kpatch-patch-5_14_0-427_84_1-debuginfo-1-10.el9_4.x86_64.rpm SHA-256: 390c40fe536715c9c1614488168375134ca72cac455a7304ece01a8aff0e4679 kpatch-patch-5_14_0-427_84_1-debugsource-1-10.el9_4.x86_64.rpm SHA-256: 2db75c0da63acaf93851a32c1a9e267f8c39aab40d52fe54fabeeb5433b8b1ac Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 SRPM kpatch-patch-5_14_0-427_100_1-1-8.el9_4.src.rpm SHA-256: a19772e04a063b327836fd5e7d0afc294d4aa18ea91fb1f626a9fdc77b5b2f95 kpatch-patch-5_14_0-427_113_1-1-6.el9_4.src.rpm SHA-256: 7e0cafe5d0ce448a2be92956cce2be5c830f784dbbd801acbdaf35c08a0695d9 kpatch-patch-5_14_0-427_126_1-1-3.el9_4.src.rpm SHA-256: 96f00766c4fa04a0fcfc9bdce989ccf6f289bc37c7259aceefd634f2bc284d56 kpatch-patch-5_14_0-427_68_2-1-15.el9_4.src.rpm SHA-256: 237e21265f606900a23d6b0eb4a21209ab0755add43ac90de1fc3496a300aa0a kpatch-patch-5_14_0-427_84_1-1-10.el9_4.src.rpm SHA-256: 2218f8641953333ffa90e17913e0239f2530de4bc43d83eb6386af2fe30feff8 ppc64le kpatch-patch-5_14_0-427_100_1-1-8.el9_4.ppc64le.rpm SHA-256: 11bb85bc321bb3ccb3e6f002a8611b79e5e2203601be1df43432708ffb3c7076 kpatch-patch-5_14_0-427_100_1-debuginfo-1-8.el9_4.ppc64le.rpm SHA-256: d8da367a5c93ae403abd109e85fbc74beed749f41ff688bb151accb19b859664 kpatch-patch-5_14_0-427_100_1-debugsource-1-8.el9_4.ppc64le.rpm SHA-256: 75c3e8dbb82fb02f89b827e2f77a9c363130301f8f589bd8f9807c5688f366e7 kpatch-patch-5_14_0-427_113_1-1-6.el9_4.ppc64le.rpm SHA-256: 92f68873b84bbc72e64e3f3027583a76c4e68be7326c408936f809455e01e012 kpatch-patch-5_14_0-427_113_1-debuginfo-1-6.el9_4.ppc64le.rpm SHA-256: 05e92d040630b7b7ced2ce46f0bf20aa761802c5ffc9f49c433708c378d4ee22 kpatch-patch-5_14_0-427_113_1-debugsource-1-6.el9_4.ppc64le.rpm SHA-256: 6a9f83ec91ec468ad9f8f312c315c3a89dd090ad3ca939295e331cac3481ae24 kpatch-patch-5_14_0-427_126_1-1-3.el9_4.ppc64le.rpm SHA-256: cddcf33d2a4a2e6d1456e5532e7c0de949b0fb816af714af468badaaa021a6a1 kpatch-patch-5_14_0-427_126_1-debuginfo-1-3.el9_4.ppc64le.rpm SHA-256: 5c919eb77909f9783517c7959d1e1a14c10eb026fb6fd1db95b21ad4d1a5d941 kpatch-patch-5_14_0-427_126_1-debugsource-1-3.el9_4.ppc64le.rpm SHA-256: 91951de2fd0e20f647c7be48654d08c8676f60ec9a2fcfd9416ce582498f8c2c kpatch-patch-5_14_0-427_68_2-1-15.el9_4.ppc64le.rpm SHA-256: 419bf4d5b678c87d3a894c41013440eaf0d94e8d28a13883127f02861cd93f88 kpatch-patch-5_14_0-427_68_2-debuginfo-1-15.el9_4.ppc64le.rpm SHA-256: e8bf0dfc02a1b4a8cc26bba787778fe55111b695bba83098c3445d7bd5cf5906 kpatch-patch-5_14_0-427_68_2-debugsource-1-15.el9_4.ppc64le.rpm SHA-256: 23f8e55cc50c045767715e971783b44f91c71bbf27aa37a5f85d11d2f35b3adb kpatch-patch-5_14_0-427_84_1-1-10.el9_4.ppc64le.rpm SHA-256: 6b299f2a59c5a6190b1eb7e8880492becd3070b49e4d2f177729cef3f6ae8ad4 kpatch-patch-5_14_0-427_84_1-debuginfo-1-10.el9_4.ppc64le.rpm SHA-256: 46726203facc3fa4045e3cc5cf7914c772fd85f6dd62ed6193a2f6097c3dde77 kpatch-patch-5_14_0-427_84_1-debugsource-1-10.el9_4.ppc64le.rpm SHA-256: 3740c54178141c61e77453b0b40446b75e7417aff1b284c8969b9d6a686d6d2b Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 SRPM kpatch-patch-5_14_0-427_100_1-1-8.el9_4.src.rpm SHA-256: a19772e04a063b327836fd5e7d0afc294d4aa18ea91fb1f626a9fdc77b5b2f95 kpatch-patch-5_14_0-427_113_1-1-6.el9_4.src.rpm SHA-256: 7e0cafe5d0ce448a2be92956cce2be5c830f784dbbd801acbdaf35c08a0695d9 kpatch-patch-5_14_0-427_126_1-1-3.el9_4.src.rpm SHA-256: 96f00766c4fa04a0fcfc9bdce989ccf6f289bc37c7259aceefd634f2bc284d56 kpatch-patch-5_14_0-427_68_2-1-15.el9_4.src.rpm SHA-256: 237e21265f606900a23d6b0eb4a21209ab0755add43ac90de1fc3496a300aa0a kpatch-patch-5_14_0-427_84_1-1-10.el9_4.src.rpm SHA-256: 2218f8641953333ffa90e17913e0239f2530de4bc43d83eb6386af2fe30feff8 x86_64 kpatch-patch-5_14_0-427_100_1-1-8.el9_4.x86_64.rpm SHA-256: 970ce6db2ba07c98b382115cdfe30644795de0d7219e0e4f540824a35ede121a kpatch-patch-5_14_0-427_100_1-debuginfo-1-8.el9_4.x86_64.rpm SHA-256: 78d2a4fb4bdb4ad92dec41c0770aa183454cb44f4850079a7de433ec5d530168 kpatch-patch-5_14_0-427_100_1-debugsource-1-8.el9_4.x86_64.rpm SHA-256: 551569e286ba871bce15d49160df4995c649dd6df98afdab334c1608587055b9 kpatch-patch-5_14_0-427_113_1-1-6.el9_4.x86_64.rpm SHA-256: 394bec1457e5d7cf4cee371d5ee57fb21d370fb0092f607f2bca1432d9129cd9 kpatch-patch-5_14_0-427_113_1-debuginfo-1-6.el9_4.x86_64.rpm SHA-256: d35f534e2b3db3b8ade4c289dac8873938e8b0345224cc0c4a8855d3f3073b71 kpatch-patch-5_14_0-427_113_1-debugsource-1-6.el9_4.x86_64.rpm SHA-256: d32a3d5573acef33026fd073155b3ddaf09ae842fa0108a72bf177914f96dd96 kpatch-patch-5_14_0-427_126_1-1-3.el9_4.x86_64.rpm SHA-256: 8aae78a03601343ac772c049c36a975f6f65c8ef4c536f5a6dfa9e22e0a628c0 kpatch-patch-5_14_0-427_126_1-debuginfo-1-3.el9_4.x86_64.rpm SHA-256: 10b233d663a17ab40698f02bbd0e8512635dda390b1fa5fa273f71fdb4d7b324 kpatch-patch-5_14_0-427_126_1-debugsource-1-3.el9_4.x86_64.rpm SHA-256: 80c749881c3ffc159598fac88f6c0569d6076169ee94ecd4a61c8