Red Hat Security Advisory: kpatch-patch-6_12_0-211_16_1 security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-43112 — kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath CVE-2026-43114 — kernel: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry CVE-2026-46323 — kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs CVE-2026-52973 — kernel: futex: Drop CLONE_THREAD requirement for private default hash alloc CVE-2026-53264 — kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle
🎯 Affected products7
- Red Hat Enterprise Linux BaseOS (v. 10)
- kpatch-patch-6_12_0-211_16_1-0:1-8.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- kpatch-patch-6_12_0-211_16_1-0:1-8.el10_2.src as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- kpatch-patch-6_12_0-211_16_1-0:1-8.el10_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- kpatch-patch-6_12_0-211_16_1-debuginfo-0:1-8.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- kpatch-patch-6_12_0-211_16_1-debuginfo-0:1-8.el10_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- kpatch-patch-6_12_0-211_16_1-debugsource-0:1-8.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, prevent the `cifs` kernel module from loading if CIFS client functionality is not required. This can be achieved by blacklisting the module. Create a file named `/etc/modprobe.d/blacklist-cifs.conf` with the following content: ``` blacklist cifs ``` After creating the file, regenerate the initramfs and reboot the system for the changes to take effect. ```bash dracut -f -v reboot ``` Disabling the `cifs` module will prevent the system from mounting CIFS network shares, which may impact functionality relying on this protocol. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:62642
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2466994
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2467015
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2479832
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492413
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492851
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_62642.json