Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-20649

Опубликовано: 06 окт. 2025
Источник: oracle-oval
Платформа: Oracle Linux 10
Платформа: Oracle Linux 9

Описание

ELSA-2025-20649: Unbreakable Enterprise kernel security update (IMPORTANT)

[6.12.0-103.40.4.4]

  • nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() (Jeff Layton) [Orabug: 38500610] {CVE-2025-38724}
  • io_uring/futex: ensure io_futex_wait() cleans up properly on failure (Jens Axboe) [Orabug: 38500621] {CVE-2025-39698}
  • kernfs: Fix UAF in polling when open file is released (Chen Ridong) [Orabug: 38500629] {CVE-2025-39881}
  • fs: writeback: fix use-after-free in __mark_inode_dirty() (Jiufei Xue) [Orabug: 38500632] {CVE-2025-39866}

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

kernel-uek

6.12.0-103.40.4.4.el10uek

kernel-uek-core

6.12.0-103.40.4.4.el10uek

kernel-uek-debug

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-core

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-devel

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-modules

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-modules-core

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-modules-deprecated

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-modules-desktop

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-modules-extra

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-modules-extra-netfilter

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-modules-usb

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-modules-wireless

6.12.0-103.40.4.4.el10uek

kernel-uek-devel

6.12.0-103.40.4.4.el10uek

kernel-uek-modules

6.12.0-103.40.4.4.el10uek

kernel-uek-modules-core

6.12.0-103.40.4.4.el10uek

kernel-uek-modules-deprecated

6.12.0-103.40.4.4.el10uek

kernel-uek-modules-desktop

6.12.0-103.40.4.4.el10uek

kernel-uek-modules-extra

6.12.0-103.40.4.4.el10uek

kernel-uek-modules-extra-netfilter

6.12.0-103.40.4.4.el10uek

kernel-uek-modules-usb

6.12.0-103.40.4.4.el10uek

kernel-uek-modules-wireless

6.12.0-103.40.4.4.el10uek

kernel-uek-tools

6.12.0-103.40.4.4.el10uek

kernel-uek64k

6.12.0-103.40.4.4.el10uek

kernel-uek64k-core

6.12.0-103.40.4.4.el10uek

kernel-uek64k-devel

6.12.0-103.40.4.4.el10uek

kernel-uek64k-modules

6.12.0-103.40.4.4.el10uek

kernel-uek64k-modules-core

6.12.0-103.40.4.4.el10uek

kernel-uek64k-modules-deprecated

6.12.0-103.40.4.4.el10uek

kernel-uek64k-modules-desktop

6.12.0-103.40.4.4.el10uek

kernel-uek64k-modules-extra

6.12.0-103.40.4.4.el10uek

kernel-uek64k-modules-extra-netfilter

6.12.0-103.40.4.4.el10uek

kernel-uek64k-modules-usb

6.12.0-103.40.4.4.el10uek

kernel-uek64k-modules-wireless

6.12.0-103.40.4.4.el10uek

Oracle Linux x86_64

kernel-uek

6.12.0-103.40.4.4.el10uek

kernel-uek-core

6.12.0-103.40.4.4.el10uek

kernel-uek-debug

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-core

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-devel

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-modules

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-modules-core

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-modules-deprecated

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-modules-desktop

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-modules-extra

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-modules-extra-netfilter

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-modules-usb

6.12.0-103.40.4.4.el10uek

kernel-uek-debug-modules-wireless

6.12.0-103.40.4.4.el10uek

kernel-uek-devel

6.12.0-103.40.4.4.el10uek

kernel-uek-doc

6.12.0-103.40.4.4.el10uek

kernel-uek-modules

6.12.0-103.40.4.4.el10uek

kernel-uek-modules-core

6.12.0-103.40.4.4.el10uek

kernel-uek-modules-deprecated

6.12.0-103.40.4.4.el10uek

kernel-uek-modules-desktop

6.12.0-103.40.4.4.el10uek

kernel-uek-modules-extra

6.12.0-103.40.4.4.el10uek

kernel-uek-modules-extra-netfilter

6.12.0-103.40.4.4.el10uek

kernel-uek-modules-usb

6.12.0-103.40.4.4.el10uek

kernel-uek-modules-wireless

6.12.0-103.40.4.4.el10uek

kernel-uek-tools

6.12.0-103.40.4.4.el10uek

Oracle Linux 9

Oracle Linux aarch64

kernel-uek

6.12.0-103.40.4.4.el9uek

kernel-uek-core

6.12.0-103.40.4.4.el9uek

kernel-uek-debug

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-core

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-devel

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-modules

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-modules-core

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-modules-deprecated

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-modules-desktop

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-modules-extra

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-modules-extra-netfilter

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-modules-usb

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-modules-wireless

6.12.0-103.40.4.4.el9uek

kernel-uek-devel

6.12.0-103.40.4.4.el9uek

kernel-uek-modules

6.12.0-103.40.4.4.el9uek

kernel-uek-modules-core

6.12.0-103.40.4.4.el9uek

kernel-uek-modules-deprecated

6.12.0-103.40.4.4.el9uek

kernel-uek-modules-desktop

6.12.0-103.40.4.4.el9uek

kernel-uek-modules-extra

6.12.0-103.40.4.4.el9uek

kernel-uek-modules-extra-netfilter

6.12.0-103.40.4.4.el9uek

kernel-uek-modules-usb

6.12.0-103.40.4.4.el9uek

kernel-uek-modules-wireless

6.12.0-103.40.4.4.el9uek

kernel-uek-tools

6.12.0-103.40.4.4.el9uek

kernel-uek64k

6.12.0-103.40.4.4.el9uek

kernel-uek64k-core

6.12.0-103.40.4.4.el9uek

kernel-uek64k-devel

6.12.0-103.40.4.4.el9uek

kernel-uek64k-modules

6.12.0-103.40.4.4.el9uek

kernel-uek64k-modules-core

6.12.0-103.40.4.4.el9uek

kernel-uek64k-modules-deprecated

6.12.0-103.40.4.4.el9uek

kernel-uek64k-modules-desktop

6.12.0-103.40.4.4.el9uek

kernel-uek64k-modules-extra

6.12.0-103.40.4.4.el9uek

kernel-uek64k-modules-extra-netfilter

6.12.0-103.40.4.4.el9uek

kernel-uek64k-modules-usb

6.12.0-103.40.4.4.el9uek

kernel-uek64k-modules-wireless

6.12.0-103.40.4.4.el9uek

Oracle Linux x86_64

kernel-uek

6.12.0-103.40.4.4.el9uek

kernel-uek-core

6.12.0-103.40.4.4.el9uek

kernel-uek-debug

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-core

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-devel

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-modules

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-modules-core

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-modules-deprecated

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-modules-desktop

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-modules-extra

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-modules-extra-netfilter

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-modules-usb

6.12.0-103.40.4.4.el9uek

kernel-uek-debug-modules-wireless

6.12.0-103.40.4.4.el9uek

kernel-uek-devel

6.12.0-103.40.4.4.el9uek

kernel-uek-doc

6.12.0-103.40.4.4.el9uek

kernel-uek-modules

6.12.0-103.40.4.4.el9uek

kernel-uek-modules-core

6.12.0-103.40.4.4.el9uek

kernel-uek-modules-deprecated

6.12.0-103.40.4.4.el9uek

kernel-uek-modules-desktop

6.12.0-103.40.4.4.el9uek

kernel-uek-modules-extra

6.12.0-103.40.4.4.el9uek

kernel-uek-modules-extra-netfilter

6.12.0-103.40.4.4.el9uek

kernel-uek-modules-usb

6.12.0-103.40.4.4.el9uek

kernel-uek-modules-wireless

6.12.0-103.40.4.4.el9uek

kernel-uek-tools

6.12.0-103.40.4.4.el9uek

Связанные уязвимости

ubuntu
2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() Lei Lu recently reported that nfsd4_setclientid_confirm() did not check the return value from get_client_locked(). a SETCLIENTID_CONFIRM could race with a confirmed client expiring and fail to get a reference. That could later lead to a UAF. Fix this by getting a reference early in the case where there is an extant confirmed client. If that fails then treat it as if there were no confirmed client found at all. In the case where the unconfirmed client is expiring, just fail and return the result from get_client_locked().

CVSS3: 7
redhat
2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() Lei Lu recently reported that nfsd4_setclientid_confirm() did not check the return value from get_client_locked(). a SETCLIENTID_CONFIRM could race with a confirmed client expiring and fail to get a reference. That could later lead to a UAF. Fix this by getting a reference early in the case where there is an extant confirmed client. If that fails then treat it as if there were no confirmed client found at all. In the case where the unconfirmed client is expiring, just fail and return the result from get_client_locked().

nvd
2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() Lei Lu recently reported that nfsd4_setclientid_confirm() did not check the return value from get_client_locked(). a SETCLIENTID_CONFIRM could race with a confirmed client expiring and fail to get a reference. That could later lead to a UAF. Fix this by getting a reference early in the case where there is an extant confirmed client. If that fails then treat it as if there were no confirmed client found at all. In the case where the unconfirmed client is expiring, just fail and return the result from get_client_locked().

CVSS3: 6.8
msrc
2 месяца назад

nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()

debian
2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: n ...