Red Hat Product Errata RHSA-2026:44007 - Security Advisory Issued: 2026-07-22 Updated: 2026-07-22 RHSA-2026:44007 - Security Advisory Overview Updated Packages Synopsis Important: kpatch-patch-5_14_0-570_116_1, kpatch-patch-5_14_0-570_17_1, kpatch-patch-5_14_0-570_39_1, kpatch-patch-5_14_0-570_66_1, and kpatch-patch-5_14_0-570_94_1 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for multiple packages is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-5.14.0-570.17.1.el9_6. Security Fix(es): kernel: eventpoll: fix ep_remove struct eventpoll / struct file UAF (CVE-2026-46242) kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role (CVE-2026-53359) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Fixes BZ - 2483519 - CVE-2026-46242 kernel: eventpoll: fix ep_remove struct eventpoll / struct file UAF BZ - 2497033 - CVE-2026-53359 kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role CVEs CVE-2026-46242 CVE-2026-53359 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM kpatch-patch-5_14_0-570_116_1-1-5.el9_6.src.rpm SHA-256: 8e7cdd5cfde7c5c25c2ac00db1979ee0986c5c9dcf3e498be940107e17ec977f kpatch-patch-5_14_0-570_17_1-1-20.el9_6.src.rpm SHA-256: 3a65dcbb80f5fe099811a59b1df4e2a261694263b28b5f2db2c5a23ab341e162 kpatch-patch-5_14_0-570_39_1-1-11.el9_6.src.rpm SHA-256: e87d034ecca6c2fc64974c4ba6c7556358c84352319c37f4352158f56c06f839 kpatch-patch-5_14_0-570_66_1-1-10.el9_6.src.rpm SHA-256: a902758c69eacc7e544075aaf20ff0fdde826531b8096ac776023798cf7db405 kpatch-patch-5_14_0-570_94_1-1-8.el9_6.src.rpm SHA-256: e3375fe34dba2ff6b8bc5a1a7d2b6f7210b2ad3fac138d160354da990802d221 x86_64 kpatch-patch-5_14_0-570_116_1-1-5.el9_6.x86_64.rpm SHA-256: f3932c06a089ce1f25e4cd15b11e41de757a6b888460d057c041dcdc657c1bb1 kpatch-patch-5_14_0-570_116_1-debuginfo-1-5.el9_6.x86_64.rpm SHA-256: c553ff07fbf875f2e0e922f7aba33aa581b9c49881d62642cd06b526aec99eee kpatch-patch-5_14_0-570_116_1-debugsource-1-5.el9_6.x86_64.rpm SHA-256: 65e0de56c5d59bae22288fdaca04e444b2cc79482249f6c3e5df957f72ebf200 kpatch-patch-5_14_0-570_17_1-1-20.el9_6.x86_64.rpm SHA-256: 446a16fa6d6d03b45bca0e4eacf95977158e1669093e970c97cdbe47734c1bb6 kpatch-patch-5_14_0-570_17_1-debuginfo-1-20.el9_6.x86_64.rpm SHA-256: 28d29db650570952359509e42fd18e68147c8861c7dc901ca6a7fa76d3c83341 kpatch-patch-5_14_0-570_17_1-debugsource-1-20.el9_6.x86_64.rpm SHA-256: bbb113826d1e31ba2b0faebb8f0f3e26064dc4544f9d59eb9aefaeab8afa3490 kpatch-patch-5_14_0-570_39_1-1-11.el9_6.x86_64.rpm SHA-256: ea026a33275a7de1bf8fe7af1cb359388cded4742cfd5041640fa4e7848b3a73 kpatch-patch-5_14_0-570_39_1-debuginfo-1-11.el9_6.x86_64.rpm SHA-256: ef076f49af39d9635db1448ce60dc45f5db93ed0faf6f568fc933441b419b975 kpatch-patch-5_14_0-570_39_1-debugsource-1-11.el9_6.x86_64.rpm SHA-256: 48eebae18b0d7422d1a36de097ced061e58f8aad8b75e59f23f762851875ff14 kpatch-patch-5_14_0-570_66_1-1-10.el9_6.x86_64.rpm SHA-256: 824b26c2f9c8e6859d76d93be2c26019993eb35c8165eec0748805533449ab24 kpatch-patch-5_14_0-570_66_1-debuginfo-1-10.el9_6.x86_64.rpm SHA-256: 2505129d98a61df82a81c71eef853fb5b825e6010c4613f49bc3591f1db7b9e6 kpatch-patch-5_14_0-570_66_1-debugsource-1-10.el9_6.x86_64.rpm SHA-256: 52de1b5026017a2d91c4e0041a67af690c05a966092a0b2c06a53c686abf0876 kpatch-patch-5_14_0-570_94_1-1-8.el9_6.x86_64.rpm SHA-256: 2ab0267a004857fd8ef32f8ae1e2b8d323b9339a1f18b943fef20a624137f2dc kpatch-patch-5_14_0-570_94_1-debuginfo-1-8.el9_6.x86_64.rpm SHA-256: ba6c6a00d3bca4c2fc3833feb7ea3c0daa822bc461479735b05609796f1c958a kpatch-patch-5_14_0-570_94_1-debugsource-1-8.el9_6.x86_64.rpm SHA-256: 45a4cf159a5fc44bfb1cf605863aa6ac975250dd2dff53ac34893c99d961b8dd Red Hat Enterprise Linux Server - AUS 9.6 SRPM kpatch-patch-5_14_0-570_116_1-1-5.el9_6.src.rpm SHA-256: 8e7cdd5cfde7c5c25c2ac00db1979ee0986c5c9dcf3e498be940107e17ec977f kpatch-patch-5_14_0-570_17_1-1-20.el9_6.src.rpm SHA-256: 3a65dcbb80f5fe099811a59b1df4e2a261694263b28b5f2db2c5a23ab341e162 kpatch-patch-5_14_0-570_39_1-1-11.el9_6.src.rpm SHA-256: e87d034ecca6c2fc64974c4ba6c7556358c84352319c37f4352158f56c06f839 kpatch-patch-5_14_0-570_66_1-1-10.el9_6.src.rpm SHA-256: a902758c69eacc7e544075aaf20ff0fdde826531b8096ac776023798cf7db405 kpatch-patch-5_14_0-570_94_1-1-8.el9_6.src.rpm SHA-256: e3375fe34dba2ff6b8bc5a1a7d2b6f7210b2ad3fac138d160354da990802d221 x86_64 kpatch-patch-5_14_0-570_116_1-1-5.el9_6.x86_64.rpm SHA-256: f3932c06a089ce1f25e4cd15b11e41de757a6b888460d057c041dcdc657c1bb1 kpatch-patch-5_14_0-570_116_1-debuginfo-1-5.el9_6.x86_64.rpm SHA-256: c553ff07fbf875f2e0e922f7aba33aa581b9c49881d62642cd06b526aec99eee kpatch-patch-5_14_0-570_116_1-debugsource-1-5.el9_6.x86_64.rpm SHA-256: 65e0de56c5d59bae22288fdaca04e444b2cc79482249f6c3e5df957f72ebf200 kpatch-patch-5_14_0-570_17_1-1-20.el9_6.x86_64.rpm SHA-256: 446a16fa6d6d03b45bca0e4eacf95977158e1669093e970c97cdbe47734c1bb6 kpatch-patch-5_14_0-570_17_1-debuginfo-1-20.el9_6.x86_64.rpm SHA-256: 28d29db650570952359509e42fd18e68147c8861c7dc901ca6a7fa76d3c83341 kpatch-patch-5_14_0-570_17_1-debugsource-1-20.el9_6.x86_64.rpm SHA-256: bbb113826d1e31ba2b0faebb8f0f3e26064dc4544f9d59eb9aefaeab8afa3490 kpatch-patch-5_14_0-570_39_1-1-11.el9_6.x86_64.rpm SHA-256: ea026a33275a7de1bf8fe7af1cb359388cded4742cfd5041640fa4e7848b3a73 kpatch-patch-5_14_0-570_39_1-debuginfo-1-11.el9_6.x86_64.rpm SHA-256: ef076f49af39d9635db1448ce60dc45f5db93ed0faf6f568fc933441b419b975 kpatch-patch-5_14_0-570_39_1-debugsource-1-11.el9_6.x86_64.rpm SHA-256: 48eebae18b0d7422d1a36de097ced061e58f8aad8b75e59f23f762851875ff14 kpatch-patch-5_14_0-570_66_1-1-10.el9_6.x86_64.rpm SHA-256: 824b26c2f9c8e6859d76d93be2c26019993eb35c8165eec0748805533449ab24 kpatch-patch-5_14_0-570_66_1-debuginfo-1-10.el9_6.x86_64.rpm SHA-256: 2505129d98a61df82a81c71eef853fb5b825e6010c4613f49bc3591f1db7b9e6 kpatch-patch-5_14_0-570_66_1-debugsource-1-10.el9_6.x86_64.rpm SHA-256: 52de1b5026017a2d91c4e0041a67af690c05a966092a0b2c06a53c686abf0876 kpatch-patch-5_14_0-570_94_1-1-8.el9_6.x86_64.rpm SHA-256: 2ab0267a004857fd8ef32f8ae1e2b8d323b9339a1f18b943fef20a624137f2dc kpatch-patch-5_14_0-570_94_1-debuginfo-1-8.el9_6.x86_64.rpm SHA-256: ba6c6a00d3bca4c2fc3833feb7ea3c0daa822bc461479735b05609796f1c958a kpatch-patch-5_14_0-570_94_1-debugsource-1-8.el9_6.x86_64.rpm SHA-256: 45a4cf159a5fc44bfb1cf605863aa6ac975250dd2dff53ac34893c99d961b8dd Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 SRPM kpatch-patch-5_14_0-570_116_1-1-5.el9_6.src.rpm SHA-256: 8e7cdd5cfde7c5c25c2ac00db1979ee0986c5c9dcf3e498be940107e17ec977f kpatch-patch-5_14_0-570_17_1-1-20.el9_6.src.rpm SHA-256: 3a65dcbb80f5fe099811a59b1df4e2a261694263b28b5f2db2c5a23ab341e162 kpatch-patch-5_14_0-570_39_1-1-11.el9_6.src.rpm SHA-256: e87d034ecca6c2fc64974c4ba6c7556358c84352319c37f4352158f56c06f839 kpatch-patch-5_14_0-570_66_1-1-10.el9_6.src.rpm SHA-256: a902758c69eacc7e544075aaf20ff0fdde826531b8096ac776023798cf7db405 kpatch-patch-5_14_0-570_94_1-1-8.el9_6.src.rpm SHA-256: e3375fe34dba2ff6b8bc5a1a7d2b6f7210b2ad3fac138d160354da990802d221 ppc64le kpatch-patch-5_14_0-570_116_1-1-5.el9_6.ppc64le.rpm SHA-256: 5408c0ccc9229ef396f1176ec82a647946a9360f0c33e6d65942cc508de06298 kpatch-patch-5_14_0-570_116_1-debuginfo-1-5.el9_6.ppc64le.rpm SHA-256: c46a3bf84351feecaa4528e3c91b765f10b6fb5155802b500c5f1f3c44ec6936 kpatch-patch-5_14_0-570_116_1-debugsource-1-5.el9_6.ppc64le.rpm SHA-256: 50cdcb0f5fae69a75480b603d61ced3513ad8acdcaac30feb5bf691d00ede704 kpatch-patch-5_14_0-570_17_1-1-20.el9_6.ppc64le.rpm SHA-256: 17e9278395ff36ce3b968549a1c02c823ec468cfade850c56e87a2b34c1a43c8 kpatch-patch-5_14_0-570_17_1-debuginfo-1-20.el9_6.ppc64le.rpm SHA-256: 60678c6c967661446fbd9153f57d616650a7b3b505f806af013ad8224e0f5227 kpatch-patch-5_14_0-570_17_1-debugsource-1-20.el9_6.ppc64le.rpm SHA-256: 284cee2af6e4ccbab558aa8ca6d12d92ed88f7f3746d1a6dd31420424008a4da kpatch-patch-5_14_0-570_39_1-1-11.el9_6.ppc64le.rpm SHA-256: 75c43d14b7fe26d0d7aa67d644502df7cae46cc15bdb8f4584e83a1be132eb9e kpatch-patch-5_14_0-570_39_1-debuginfo-1-11.el9_6.ppc64le.rpm SHA-256: f3ae07f174c31cd7037c7bf76458b3319e7fae91a2d0f51d47bf9078f065bba8 kpatch-patch-5_14_0-570_39_1-debugsource-1-11.el9_6.ppc64le.rpm SHA-256: a96b381fc4371ca3a627a03d26d9231ef5002723c61ca12bf2da46c065637ef2 kpatch-patch-5_14_0-570_66_1-1-10.el9_6.ppc64le.rpm SHA-256: 75fbb4c0968235528c75bf77c1ee9983cf3d24aad20d94a57d750e4ea8b12984 kpatch-patch-5_14_0-570_66_1-debuginfo-1-
This security update addresses two high-severity kernel vulnerabilities: CVE-2026-46242 (CVSS 7.8), a use-after-free flaw in the eventpoll subsystem, and CVE-2026-53359 (CVSS 8.8), a use-after-free issue in KVM shadow paging. The vulnerabilities affect multiple kernel version ranges, including Linux kernels from 5.15.209 to before 5.16 and from 6.1.175 to before 6.2 for CVE-2026-46242, and from 2.6.36 to before 6.1.177 for CVE-2026-53359. Red Hat has provided live patch modules for Red Hat Enterprise Linux 9.6 Extended Update Support to mitigate these issues without a full reboot.