CODERED VTA

Red Hat Ships Important Kernel Fix for UDP Tunnel Use After Free Flaw in RHEL 9.4 Extended Support Channels

High
Circuit board and wiring
Photo by Towfiqu barbhuiya on Unsplash

Red Hat published security advisory RHSA-2026:79786 on 9 October 2026, delivering an updated kernel package rated Important for Red Hat Enterprise Linux 9.4. The errata addresses a single tracked issue, CVE-2026-74705, described by the vendor as a potential use-after-free in UDP tunnel segmentation within the Linux kernel networking stack. The advisory covers a broad set of long-life channels rather than the mainstream RHEL stream: Red Hat Enterprise Linux Server AUS 9.4, Red Hat Enterprise Linux for x86_64 Update Services for SAP Solutions 9.4, Red Hat Enterprise Linux Server for Power LE Update Services for SAP Solutions 9.4, the four-years-of-updates streams for ARM 64 and IBM z Systems, and the Extended Life Cycle streams for x86_64, ARM 64, Power little endian and IBM z Systems. In practical terms, any estate running 9.4 on x86_64, ppc64le, aarch64 or s390x under an extended support subscription is in scope, which in most organisations means the SAP and other change-frozen workloads that were deliberately pinned to 9.4. The issue is tracked internally under Bugzilla 2521498.

Red Hat has not published an exploitation path for this flaw. The errata text describes the defect only as a potential use-after-free in tunnel segmentation and refers readers to the CVE page for the CVSS base score, impact statement and acknowledgements, so there is no proof-of-concept code, attack prerequisite list or privilege requirement stated in the advisory itself. What the advisory does state concretely is the fixed build: kernel 5.14.0-427.155.1.el9_4, shipped alongside matching bpftool 7.3.0-427.155.1.el9_4, kernel-core, kernel-modules, kernel-devel, kernel-headers, kernel-tools, kernel-uki-virt and the corresponding debuginfo packages for each supported architecture. Red Hat notes explicitly that the system must be rebooted for the update to take effect, meaning the running kernel remains the vulnerable one until a restart or a supported live-patch is applied. The vendor also repeats its standing position that all kernel errata should be treated as security relevant, because a bug in the kernel has a higher chance of carrying security impact that only becomes apparent after the fix is public, and that CVE identifiers are sometimes assigned to kernel patches retroactively.

The significance of this advisory lies less in any immediate attack and more in where the affected systems sit. Use-after-free defects in kernel networking code are attractive to attackers because the surrounding code paths handle attacker-influenced packet data, and successful memory corruption in kernel context typically yields either a crash of the host or an avenue toward elevated privileges from a lower-privileged starting point. The specific population here compounds that: Update Services for SAP Solutions and Extended Life Cycle subscribers run these kernels precisely because the applications on top cannot tolerate disruptive change, so patch cycles are longer, reboot windows are scarce, and the gap between advisory publication and a running fixed kernel is measured in weeks rather than hours. On current exploitation evidence, the risk is not acute. FIRST EPSS places CVE-2026-74705 at a 0.5 percent probability of exploitation in the next 30 days, and neither Red Hat nor any authoritative source cited here reports exploitation in the wild, inclusion in a known-exploited catalogue, or public exploit code. The realistic exposure is therefore a known memory-safety defect sitting in the network path of business-critical SAP and legacy workloads for as long as those hosts continue to run the pre-427.155.1 kernel, with the residual risk growing if exploit research catches up before the next maintenance window closes.

Attack Surface

Server OS, Endpoint OS, Infrastructure

Tactics

Privilege Escalation, Impact

Techniques

  • T1068 – Exploitation for Privilege Escalation
  • T1499 – Endpoint Denial of Service
  • T1499.004 – Application or System Exploitation

SuperPRO's Threat Countermeasures Procedures

  1. Update to kernel-5.14.0-427.155.1.el9_4 (and the matching kernel-core, kernel-modules, kernel-modules-core and kernel-modules-extra packages) on all RHEL 9.4 hosts subscribed to AUS, Update Services for SAP Solutions, four-years-of-updates or Extended Life Cycle channels, as shipped in RHSA-2026:79786 for CVE-2026-74705.
  2. Schedule a reboot after installation – Red Hat states the update only takes effect once the system is restarted, so verify the running kernel with 'uname -r' and confirm it reports 5.14.0-427.155.1.el9_4 rather than relying on the installed RPM list alone.
  3. Update the companion packages delivered in the same errata where they are installed, specifically bpftool-7.3.0-427.155.1.el9_4, kernel-tools-5.14.0-427.155.1.el9_4, kernel-devel-5.14.0-427.155.1.el9_4 and kernel-headers-5.14.0-427.155.1.el9_4, so tooling stays version-matched to the patched kernel.
  4. Inventory affected architectures explicitly – x86_64, ppc64le, aarch64 and s390x builds are all listed in the advisory, so include IBM Power and IBM z Systems SAP nodes in the remediation scope rather than limiting the campaign to x86_64 estates.
  5. Use Red Hat Lightspeed patch analysis or 'dnf updateinfo list security –advisory RHSA-2026:79786' to enumerate systems still missing the errata, and track the remaining count as a closure metric until it reaches zero.
  6. For SAP and other hosts where an immediate reboot is not possible, apply the Red Hat kernel live patch for the 5.14.0-427 stream if entitled, and record the deferred hosts as a tracked exception until the next approved maintenance window.
  7. Validate the integrity of downloaded packages against the SHA-256 digests published in RHSA-2026:79786, for example 8b941b7113cdcb29ca7d1a2b900e288324e10d8527953bd744c9195f5d8db7fc for kernel-5.14.0-427.155.1.el9_4.src.rpm, before importing them into internal Satellite or mirrored repositories.

Source

Code Red Cyber / VTA – coderedcyber.ai