Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:36531 - Security Advisory
Issued:
2026-07-08
Updated:
2026-07-08

RHSA-2026:36531 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: kpatch-patch-4_18_0-477_107_1, kpatch-patch-4_18_0-477_120_1, kpatch-patch-4_18_0-477_130_1, and kpatch-patch-4_18_0-477_97_1 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for multiple packages is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-4.18.0-477.97.1.el8_8.

Security Fix(es):

  • kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling (CVE-2026-23401)
  • kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (CVE-2026-31402)
  • kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service (CVE-2026-31419)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64

Fixes

  • BZ - 2453803 - CVE-2026-23401 kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling
  • BZ - 2454844 - CVE-2026-31402 kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache
  • BZ - 2457829 - CVE-2026-31419 kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service

CVEs

  • CVE-2026-23401
  • CVE-2026-31402
  • CVE-2026-31419

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8

SRPM
kpatch-patch-4_18_0-477_107_1-1-9.el8_8.src.rpm SHA-256: 29d63aab717e96d34fd3f2a67b04c34764c01118dbcd29a12fdee6b9ef293f46
kpatch-patch-4_18_0-477_120_1-1-8.el8_8.src.rpm SHA-256: c97937b0dd2d841f4499d98ac318dee15f574d92edcf6e7ddf84b9c1f9fd03aa
kpatch-patch-4_18_0-477_130_1-1-6.el8_8.src.rpm SHA-256: 47324c1c5690b26b5cdbc8000f002f56a1b185c6e4108e854dcae004f0e14dbe
kpatch-patch-4_18_0-477_97_1-1-13.el8_8.src.rpm SHA-256: 300cd1a77c6c66d87cc20f54761c5e6af9a4874e06d09aa83aeb9b78b9ea111e
x86_64
kpatch-patch-4_18_0-477_107_1-1-9.el8_8.x86_64.rpm SHA-256: fc92c5aebc4ddba8a219ec5b6aca51cdfeb88d36d2c97f7ec79b2999e439c537
kpatch-patch-4_18_0-477_107_1-debuginfo-1-9.el8_8.x86_64.rpm SHA-256: c6af4e2d01b0c416a83ac31b15dafd73ae966ec2ced912509695739db63b7241
kpatch-patch-4_18_0-477_107_1-debugsource-1-9.el8_8.x86_64.rpm SHA-256: 90cc477492b968ed26bebc6ffb7442a01ab7f55f33dde56aba06baaa63ca59d0
kpatch-patch-4_18_0-477_120_1-1-8.el8_8.x86_64.rpm SHA-256: 060a13f7b1332d086687af5ebfd644a96324d2558018ed173f79746ec01aec91
kpatch-patch-4_18_0-477_120_1-debuginfo-1-8.el8_8.x86_64.rpm SHA-256: 0404c86bc0c0edba4aca0065b9f8a797f0e3aa60069d7fe3dd96b1e4ac5d4374
kpatch-patch-4_18_0-477_120_1-debugsource-1-8.el8_8.x86_64.rpm SHA-256: 1c9d046137d378322c3a07f39ffff9c173d867bec66a2d12e90cdc107785d63f
kpatch-patch-4_18_0-477_130_1-1-6.el8_8.x86_64.rpm SHA-256: b3e18a9acac9a59efeb2d4cb2e94eb8c66ce438a0661a2cd63fcd365fb696b1c
kpatch-patch-4_18_0-477_130_1-debuginfo-1-6.el8_8.x86_64.rpm SHA-256: 782915cb552fa9868c82742dc358409919867275463c6371e9dad0e6b9947ec7
kpatch-patch-4_18_0-477_130_1-debugsource-1-6.el8_8.x86_64.rpm SHA-256: 2e97b95d2fc6a4fd99377b3e110a79eeb531c798c16e05b1560ff02320be210b
kpatch-patch-4_18_0-477_97_1-1-13.el8_8.x86_64.rpm SHA-256: 426388e3fad2daf514960f37e4923b201ffa373415732d1c32937ef3e50410bf
kpatch-patch-4_18_0-477_97_1-debuginfo-1-13.el8_8.x86_64.rpm SHA-256: 507c5591960023c4fe3e66fa169ca8e69c6628ad31b54f88f9363c3f0673e14d
kpatch-patch-4_18_0-477_97_1-debugsource-1-13.el8_8.x86_64.rpm SHA-256: 5d56d8ace76cfe8052b214abbc0c87e9a85e98f40f5ba60befb717d84bd23423

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8

SRPM
kpatch-patch-4_18_0-477_107_1-1-9.el8_8.src.rpm SHA-256: 29d63aab717e96d34fd3f2a67b04c34764c01118dbcd29a12fdee6b9ef293f46
kpatch-patch-4_18_0-477_120_1-1-8.el8_8.src.rpm SHA-256: c97937b0dd2d841f4499d98ac318dee15f574d92edcf6e7ddf84b9c1f9fd03aa
kpatch-patch-4_18_0-477_130_1-1-6.el8_8.src.rpm SHA-256: 47324c1c5690b26b5cdbc8000f002f56a1b185c6e4108e854dcae004f0e14dbe
kpatch-patch-4_18_0-477_97_1-1-13.el8_8.src.rpm SHA-256: 300cd1a77c6c66d87cc20f54761c5e6af9a4874e06d09aa83aeb9b78b9ea111e
ppc64le
kpatch-patch-4_18_0-477_107_1-1-9.el8_8.ppc64le.rpm SHA-256: 46aad29c7b3b3a0b471a7889faf1c628ffa79de113be862f883adc2a06ef2dfc
kpatch-patch-4_18_0-477_107_1-debuginfo-1-9.el8_8.ppc64le.rpm SHA-256: eea2eba22d33d615f51623f9f04fac27775f3fa7f09b2b956c92511750f91ac8
kpatch-patch-4_18_0-477_107_1-debugsource-1-9.el8_8.ppc64le.rpm SHA-256: 341b5356b5791a3e51e825490d6f55cc26a1b0898b9b0141d4d377426c0df91c
kpatch-patch-4_18_0-477_120_1-1-8.el8_8.ppc64le.rpm SHA-256: 6d51c5a9d9562c07ff016a425f21d7f21c3f92dd2264a912fa9a866cbeae8395
kpatch-patch-4_18_0-477_120_1-debuginfo-1-8.el8_8.ppc64le.rpm SHA-256: 3aa00b6487e94e300b0c2415b903eb603e3b46bbb8349f3d530b11efa8456c89
kpatch-patch-4_18_0-477_120_1-debugsource-1-8.el8_8.ppc64le.rpm SHA-256: 3bd19845a9e8dec5de2588701d54ea523c1979995697f5106add88873087305c
kpatch-patch-4_18_0-477_130_1-1-6.el8_8.ppc64le.rpm SHA-256: b24d463cc7a0fe3f20f77a81dd5018e2187480fdf70159c033f44bcb823c9b95
kpatch-patch-4_18_0-477_130_1-debuginfo-1-6.el8_8.ppc64le.rpm SHA-256: d59759d171d6d97bd4159542f4b49c62476b7f40a40cadd0f23139de6fc900dd
kpatch-patch-4_18_0-477_130_1-debugsource-1-6.el8_8.ppc64le.rpm SHA-256: eb466dfd80b526241b21fc9689501d56cce7c4c1071ee3f68a99ea7421863522
kpatch-patch-4_18_0-477_97_1-1-13.el8_8.ppc64le.rpm SHA-256: 464e1e894e5300ddff48101b00e2067716deaf41c0dcd3f7e1e10ce3673656c2
kpatch-patch-4_18_0-477_97_1-debuginfo-1-13.el8_8.ppc64le.rpm SHA-256: 671dfdc9c1e51e0b83e9280fe3cd63f5bcfbc84dcdd485a2cabba5f1e671c67b
kpatch-patch-4_18_0-477_97_1-debugsource-1-13.el8_8.ppc64le.rpm SHA-256: dfac37910e581e04e52c37c1ceaaafb45bd93aae9634a932ffee0eb1c53cb720

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8

SRPM
kpatch-patch-4_18_0-477_107_1-1-9.el8_8.src.rpm SHA-256: 29d63aab717e96d34fd3f2a67b04c34764c01118dbcd29a12fdee6b9ef293f46
kpatch-patch-4_18_0-477_120_1-1-8.el8_8.src.rpm SHA-256: c97937b0dd2d841f4499d98ac318dee15f574d92edcf6e7ddf84b9c1f9fd03aa
kpatch-patch-4_18_0-477_130_1-1-6.el8_8.src.rpm SHA-256: 47324c1c5690b26b5cdbc8000f002f56a1b185c6e4108e854dcae004f0e14dbe
kpatch-patch-4_18_0-477_97_1-1-13.el8_8.src.rpm SHA-256: 300cd1a77c6c66d87cc20f54761c5e6af9a4874e06d09aa83aeb9b78b9ea111e
x86_64
kpatch-patch-4_18_0-477_107_1-1-9.el8_8.x86_64.rpm SHA-256: fc92c5aebc4ddba8a219ec5b6aca51cdfeb88d36d2c97f7ec79b2999e439c537
kpatch-patch-4_18_0-477_107_1-debuginfo-1-9.el8_8.x86_64.rpm SHA-256: c6af4e2d01b0c416a83ac31b15dafd73ae966ec2ced912509695739db63b7241
kpatch-patch-4_18_0-477_107_1-debugsource-1-9.el8_8.x86_64.rpm SHA-256: 90cc477492b968ed26bebc6ffb7442a01ab7f55f33dde56aba06baaa63ca59d0
kpatch-patch-4_18_0-477_120_1-1-8.el8_8.x86_64.rpm SHA-256: 060a13f7b1332d086687af5ebfd644a96324d2558018ed173f79746ec01aec91
kpatch-patch-4_18_0-477_120_1-debuginfo-1-8.el8_8.x86_64.rpm SHA-256: 0404c86bc0c0edba4aca0065b9f8a797f0e3aa60069d7fe3dd96b1e4ac5d4374
kpatch-patch-4_18_0-477_120_1-debugsource-1-8.el8_8.x86_64.rpm SHA-256: 1c9d046137d378322c3a07f39ffff9c173d867bec66a2d12e90cdc107785d63f
kpatch-patch-4_18_0-477_130_1-1-6.el8_8.x86_64.rpm SHA-256: b3e18a9acac9a59efeb2d4cb2e94eb8c66ce438a0661a2cd63fcd365fb696b1c
kpatch-patch-4_18_0-477_130_1-debuginfo-1-6.el8_8.x86_64.rpm SHA-256: 782915cb552fa9868c82742dc358409919867275463c6371e9dad0e6b9947ec7
kpatch-patch-4_18_0-477_130_1-debugsource-1-6.el8_8.x86_64.rpm SHA-256: 2e97b95d2fc6a4fd99377b3e110a79eeb531c798c16e05b1560ff02320be210b
kpatch-patch-4_18_0-477_97_1-1-13.el8_8.x86_64.rpm SHA-256: 426388e3fad2daf514960f37e4923b201ffa373415732d1c32937ef3e50410bf
kpatch-patch-4_18_0-477_97_1-debuginfo-1-13.el8_8.x86_64.rpm SHA-256: 507c5591960023c4fe3e66fa169ca8e69c6628ad31b54f88f9363c3f0673e14d
kpatch-patch-4_18_0-477_97_1-debugsource-1-13.el8_8.x86_64.rpm SHA-256: 5d56d8ace76cfe8052b214abbc0c87e9a85e98f40f5ba60befb717d84bd23423

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility