Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-15740

Опубликовано: 15 сент. 2025
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2025-15740: kernel security update (MODERATE)

[5.14.0-570.44.1.0.1_6.OL9]

  • nvme-pci: remove two deallocate zeroes quirks [Orabug: 37756650]
  • Disable UKI signing [Orabug: 36571828]
  • Update Oracle Linux certificates (Kevin Lyons)
  • Disable signing for aarch64 (Ilya Okomin)
  • Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
  • Update x509.genkey [Orabug: 24817676]
  • Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5
  • Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
  • Add Oracle Linux IMA certificates
  • Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985764]

[5.14.0-570.44.1_6]

  • ipv6: mcast: Delay put pmc->idev in mld_del_delrec() (CKI Backport Bot) [RHEL-111149] {CVE-2025-38550}
  • posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() (CKI Backport Bot) [RHEL-112780] {CVE-2025-38352}
  • powerpc/pseries/iommu: create DDW for devices with DMA mask less than 64-bits (CKI Backport Bot) [RHEL-113173]

[5.14.0-570.43.1_6]

  • eth: bnxt: fix missing ring index trim on error path (CKI Backport Bot) [RHEL-104561] {CVE-2025-37873}
  • book3s64/radix : Align section vmemmap start address to PAGE_SIZE (Mamatha Inamdar) [RHEL-109492]
  • book3s64/radix: Fix compile errors when CONFIG_ARCH_WANT_OPTIMIZE_DAX_VMEMMAP=n (Mamatha Inamdar) [RHEL-109492]
  • net: introduce per netns packet chains (Paolo Abeni) [RHEL-89050]
  • enic: fix incorrect MTU comparison in enic_change_mtu() (John Meneghini) [RHEL-108274]
  • net/enic: Allow at least 8 RQs to always be used (John Meneghini) [RHEL-108274]
  • enic: get max rq & wq entries supported by hw, 16K queues (John Meneghini) [RHEL-106604]
  • enic: cleanup of enic wq request completion path (John Meneghini) [RHEL-106604]
  • enic: added enic_wq.c and enic_wq.h (John Meneghini) [RHEL-106604]
  • enic: remove unused function cq_enet_wq_desc_dec (John Meneghini) [RHEL-106604]
  • enic: enable rq extended cq support (John Meneghini) [RHEL-106604]
  • enic: enic rq extended cq defines (John Meneghini) [RHEL-106604]
  • enic: enic rq code reorg (John Meneghini) [RHEL-106604]
  • enic: Move function from header file to c file (John Meneghini) [RHEL-106604]
  • enic: add dependency on Page Pool (John Meneghini) [RHEL-106604]
  • enic: remove copybreak tunable (John Meneghini) [RHEL-106604]
  • enic: Use the Page Pool API for RX (John Meneghini) [RHEL-106604]
  • enic: Simplify RX handler function (John Meneghini) [RHEL-106604]
  • enic: Move RX functions to their own file (John Meneghini) [RHEL-106604]
  • enic: Fix typo in comment in table indexed by link speed (John Meneghini) [RHEL-106604]
  • enic: Obtain the Link speed only after the link comes up (John Meneghini) [RHEL-106604]
  • enic: Move RX coalescing set function (John Meneghini) [RHEL-106604]
  • enic: Move kdump check into enic_adjust_resources() (John Meneghini) [RHEL-106604]
  • enic: Move enic resource adjustments to separate function (John Meneghini) [RHEL-106604]
  • enic: Adjust used MSI-X wq/rq/cq/interrupt resources in a more robust way (John Meneghini) [RHEL-106604]
  • enic: Allocate arrays in enic struct based on VIC config (John Meneghini) [RHEL-106604]
  • enic: Save resource counts we read from HW (John Meneghini) [RHEL-106604]
  • enic: Make MSI-X I/O interrupts come after the other required ones (John Meneghini) [RHEL-106604]
  • enic: Create enic_wq/rq structures to bundle per wq/rq data (John Meneghini) [RHEL-106604]
  • enic: Report some per queue statistics in ethtool (John Meneghini) [RHEL-106604]
  • enic: Report per queue statistics in netdev qstats (John Meneghini) [RHEL-106604]
  • enic: Collect per queue statistics (John Meneghini) [RHEL-106604]
  • enic: Use macro instead of static const variables for array sizes (John Meneghini) [RHEL-106604]
  • enic: add ethtool get_channel support (John Meneghini) [RHEL-106604]
  • enic: Validate length of nl attributes in enic_set_vf_port (John Meneghini) [RHEL-106604]
  • enic: Replace hardcoded values for vnic descriptor by defines (John Meneghini) [RHEL-106604]
  • enic: Avoid false positive under FORTIFY_SOURCE (John Meneghini) [RHEL-106604]
  • scsi: fnic: Fix missing DMA mapping error in fnic_send_frame() (John Meneghini) [RHEL-106420]
  • scsi: fnic: Set appropriate logging level for log message (John Meneghini) [RHEL-106420]
  • scsi: fnic: Add and improve logs in FDMI and FDMI ABTS paths (John Meneghini) [RHEL-106420]
  • scsi: fnic: Turn off FDMI ACTIVE flags on link down (John Meneghini) [RHEL-106420]
  • scsi: fnic: Fix crash in fnic_wq_cmpl_handler when FDMI times out (John Meneghini) [RHEL-106420]
  • scsi: fnic: Remove unnecessary NUL-terminations (John Meneghini) [RHEL-106419]
  • scsi: fnic: Remove redundant flush_workqueue() calls (John Meneghini) [RHEL-106419]
  • scsi: fnic: Remove unnecessary spinlock locking and unlocking (John Meneghini) [RHEL-106419]
  • scsi: fnic: Replace fnic->lock_flags with local flags (John Meneghini) [RHEL-106419]
  • scsi: fnic: Replace use of sizeof with standard usage (John Meneghini) [RHEL-106419]
  • scsi: fnic: Fix indentation and remove unnecessary parenthesis (John Meneghini) [RHEL-106419]
  • scsi: fnic: Remove unnecessary debug print (John Meneghini) [RHEL-106419]
  • scsi: fnic: Propagate SCSI error code from fnic_scsi_drv_init() (John Meneghini) [RHEL-106419]
  • scsi: fnic: Test for memory allocation failure and return error code (John Meneghini) [RHEL-106419]
  • scsi: fnic: Return appropriate error code from failure of scsi drv init (John Meneghini) [RHEL-106419]
  • scsi: fnic: Return appropriate error code for mem alloc failure (John Meneghini) [RHEL-106419]
  • scsi: fnic: Remove always-true IS_FNIC_FCP_INITIATOR macro (John Meneghini) [RHEL-106419]
  • scsi: fnic: Fix use of uninitialized value in debug message (John Meneghini) [RHEL-106419]
  • scsi: fnic: Delete incorrect debugfs error handling (John Meneghini) [RHEL-106419]
  • scsi: fnic: Remove unnecessary else to fix warning in FDLS FIP (John Meneghini) [RHEL-106419]
  • scsi: fnic: Remove extern definition from .c files (John Meneghini) [RHEL-106419]
  • scsi: fnic: Remove unnecessary else and unnecessary break in FDLS (John Meneghini) [RHEL-106419]
  • scsi: fnic: Increment driver version (John Meneghini) [RHEL-106419]
  • scsi: fnic: Add support to handle port channel RSCN (John Meneghini) [RHEL-106419]
  • scsi: fnic: Code cleanup (John Meneghini) [RHEL-106419]
  • scsi: fnic: Add stats and related functionality (John Meneghini) [RHEL-106419]
  • scsi: fnic: Modify fnic interfaces to use FDLS (John Meneghini) [RHEL-106419]
  • scsi: fnic: Modify IO path to use FDLS (John Meneghini) [RHEL-106419]
  • scsi: fnic: Add functionality in fnic to support FDLS (John Meneghini) [RHEL-106419]
  • scsi: fnic: Add and integrate support for FIP (John Meneghini) [RHEL-106419]
  • scsi: fnic: Add and integrate support for FDMI (John Meneghini) [RHEL-106419]
  • scsi: fnic: Add Cisco hardware model names (John Meneghini) [RHEL-106419]
  • scsi: fnic: Add support for unsolicited requests and responses (John Meneghini) [RHEL-106419]
  • scsi: fnic: Add support for target based solicited requests and responses (John Meneghini) [RHEL-106419]
  • scsi: fnic: Add support for fabric based solicited requests and responses (John Meneghini) [RHEL-106419]
  • scsi: fnic: Add headers and definitions for FDLS (John Meneghini) [RHEL-106419]
  • scsi: fnic: Replace shost_printk() with dev_info()/dev_err() (John Meneghini) [RHEL-106419]
  • scsi: fnic: Use vcalloc() instead of vmalloc() and memset(0) (John Meneghini) [RHEL-106419]
  • scsi: fnic: Move flush_work initialization out of if block (John Meneghini) [RHEL-106419]
  • scsi: fnic: Move fnic_fnic_flush_tx() to a work queue (John Meneghini) [RHEL-106419]
  • scsi: fnic: Convert snprintf() to sysfs_emit() (John Meneghini) [RHEL-106419]
  • scsi: fnic: Clean up some inconsistent indenting (John Meneghini) [RHEL-106419]
  • scsi: fnic: unlock on error path in fnic_queuecommand() (John Meneghini) [RHEL-106419]
  • scsi: fnic: Increment driver version (John Meneghini) [RHEL-106419]
  • scsi: fnic: Improve logs and add support for multiqueue (MQ) (John Meneghini) [RHEL-106419]
  • scsi: fnic: Add support for multiqueue (MQ) in fnic driver (John Meneghini) [RHEL-106419]
  • scsi: fnic: Add support for multiqueue (MQ) in fnic_main.c (John Meneghini) [RHEL-106419]
  • scsi: fnic: Remove usage of host_lock (John Meneghini) [RHEL-106419]
  • scsi: fnic: Define stats to track multiqueue (MQ) IOs (John Meneghini) [RHEL-106419]
  • scsi: fnic: Modify ISRs to support multiqueue (MQ) (John Meneghini) [RHEL-106419]
  • scsi: fnic: Refactor and redefine fnic.h for multiqueue (John Meneghini) [RHEL-106419]
  • scsi: fnic: Get copy workqueue count and interrupt mode from config (John Meneghini) [RHEL-106419]
  • scsi: fnic: Rename wq_copy to hw_copy_wq (John Meneghini) [RHEL-106419]
  • scsi: fnic: Add and improve log messages (John Meneghini) [RHEL-106419]
  • scsi: fnic: Add and use fnic number (John Meneghini) [RHEL-106419]
  • scsi: fnic: Modify definitions to sync with VIC firmware (John Meneghini) [RHEL-106419]
  • scsi: fnic: Return error if vmalloc() failed (John Meneghini) [RHEL-106419]
  • scsi: fnic: Clean up some inconsistent indenting (John Meneghini) [RHEL-106419]
  • scsi: fnic: Fix sg_reset success path (John Meneghini) [RHEL-106419]
  • scsi: fnic: Remove unused functions fnic_scsi_host_start/end_tag() (John Meneghini) [RHEL-106419]
  • scsi: fnic: Replace sgreset tag with max_tag_id (John Meneghini) [RHEL-106419]
  • scsi: fnic: Replace return codes in fnic_clean_pending_aborts() (John Meneghini) [RHEL-106419]
  • scsi: fnic: Use vmalloc_array() and vcalloc() (John Meneghini) [RHEL-106419]
  • scsi: fnic: Use vzalloc() (John Meneghini) [RHEL-106419]
  • scsi: fnic: Refactor code in fnic probe to initialize SCSI layer (John Meneghini) [RHEL-106419]
  • scsi: fnic: Replace DMA mask of 64 bits with 47 bits (John Meneghini) [RHEL-106419]
  • scsi: fnic: Remove unneeded flush_workqueue() (John Meneghini) [RHEL-106419]
  • scsi: fnic: Remove redundant NULL check (John Meneghini) [RHEL-106419]
  • scsi: fnic: Stop using the SCSI pointer (John Meneghini) [RHEL-106419]
  • scsi: fnic: Fix a tracing statement (John Meneghini) [RHEL-106419]
  • scsi: fnic: Call scsi_done() directly (John Meneghini) [RHEL-106419]
  • Revert 'driver core: Fix uevent_show() vs driver detach race' (Mark Langsdorf) [RHEL-85410]

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

kernel-cross-headers

5.14.0-570.44.1.0.1.el9_6

kernel-tools-libs-devel

5.14.0-570.44.1.0.1.el9_6

libperf

5.14.0-570.44.1.0.1.el9_6

kernel-tools

5.14.0-570.44.1.0.1.el9_6

kernel-tools-libs

5.14.0-570.44.1.0.1.el9_6

python3-perf

5.14.0-570.44.1.0.1.el9_6

kernel-headers

5.14.0-570.44.1.0.1.el9_6

perf

5.14.0-570.44.1.0.1.el9_6

rtla

5.14.0-570.44.1.0.1.el9_6

rv

5.14.0-570.44.1.0.1.el9_6

Oracle Linux x86_64

kernel-debug-devel

5.14.0-570.44.1.0.1.el9_6

kernel-debug-devel-matched

5.14.0-570.44.1.0.1.el9_6

kernel-devel

5.14.0-570.44.1.0.1.el9_6

kernel-devel-matched

5.14.0-570.44.1.0.1.el9_6

kernel-doc

5.14.0-570.44.1.0.1.el9_6

kernel-headers

5.14.0-570.44.1.0.1.el9_6

perf

5.14.0-570.44.1.0.1.el9_6

rtla

5.14.0-570.44.1.0.1.el9_6

rv

5.14.0-570.44.1.0.1.el9_6

kernel-cross-headers

5.14.0-570.44.1.0.1.el9_6

kernel-tools-libs-devel

5.14.0-570.44.1.0.1.el9_6

libperf

5.14.0-570.44.1.0.1.el9_6

kernel

5.14.0-570.44.1.0.1.el9_6

kernel-abi-stablelists

5.14.0-570.44.1.0.1.el9_6

kernel-core

5.14.0-570.44.1.0.1.el9_6

kernel-debug

5.14.0-570.44.1.0.1.el9_6

kernel-debug-core

5.14.0-570.44.1.0.1.el9_6

kernel-debug-modules

5.14.0-570.44.1.0.1.el9_6

kernel-debug-modules-core

5.14.0-570.44.1.0.1.el9_6

kernel-debug-modules-extra

5.14.0-570.44.1.0.1.el9_6

kernel-debug-uki-virt

5.14.0-570.44.1.0.1.el9_6

kernel-modules

5.14.0-570.44.1.0.1.el9_6

kernel-modules-core

5.14.0-570.44.1.0.1.el9_6

kernel-modules-extra

5.14.0-570.44.1.0.1.el9_6

kernel-tools

5.14.0-570.44.1.0.1.el9_6

kernel-tools-libs

5.14.0-570.44.1.0.1.el9_6

kernel-uki-virt

5.14.0-570.44.1.0.1.el9_6

kernel-uki-virt-addons

5.14.0-570.44.1.0.1.el9_6

python3-perf

5.14.0-570.44.1.0.1.el9_6

Связанные CVE

Связанные уязвимости

ubuntu
3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Delay put pmc->idev in mld_del_delrec() pmc->idev is still used in ip6_mc_clear_src(), so as mld_clear_delrec() does, the reference should be put after ip6_mc_clear_src() return.

CVSS3: 7.1
redhat
3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Delay put pmc->idev in mld_del_delrec() pmc->idev is still used in ip6_mc_clear_src(), so as mld_clear_delrec() does, the reference should be put after ip6_mc_clear_src() return.

nvd
3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Delay put pmc->idev in mld_del_delrec() pmc->idev is still used in ip6_mc_clear_src(), so as mld_clear_delrec() does, the reference should be put after ip6_mc_clear_src() return.

CVSS3: 5.5
msrc
2 месяца назад

ipv6: mcast: Delay put pmc->idev in mld_del_delrec()

debian
3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: i ...

Уязвимость ELSA-2025-15740