Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-13565

Опубликовано: 05 мая 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-13565: kernel security update (IMPORTANT)

[5.14.0-611.54.1]

  • Disable UKI signing [Orabug: 36571828]
  • Update Oracle Linux certificates (Kevin Lyons)
  • Disable signing for aarch64 (Ilya Okomin)
  • Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
  • Update x509.genkey [Orabug: 24817676]
  • Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
  • Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
  • Add Oracle Linux IMA certificates
  • Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985764]

[5.14.0-611.54.1]

  • crypto: algif_aead - snapshot IV for async AEAD requests (Vladislav Dronov) [RHEL-172201]
  • crypto: algif_aead - Fix minimum RX size check for decryption (Vladislav Dronov) [RHEL-172201]
  • crypto: authencesn - reject short ahash digests during instance creation (Vladislav Dronov) [RHEL-172201]
  • crypto: authencesn - Fix src offset when decrypting in-place (Vladislav Dronov) [RHEL-172201]
  • crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (Vladislav Dronov) [RHEL-172201] {CVE-2026-31431}
  • crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec (Vladislav Dronov) [RHEL-172201] {CVE-2026-23060}
  • crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl (Vladislav Dronov) [RHEL-172201]
  • crypto: af_alg - limit RX SG extraction by receive buffer budget (Vladislav Dronov) [RHEL-172201] {CVE-2026-31677}
  • crypto: algif_aead - Revert to operating out-of-place (Vladislav Dronov) [RHEL-172201] {CVE-2026-31431}
  • crypto: af-alg - fix NULL pointer dereference in scatterwalk (Vladislav Dronov) [RHEL-172201]

[5.14.0-611.53.1]

  • tracing: Fix a warning when allocating buffered events fails (CKI KWF BOT) [RHEL-169366]
  • tracing: Fix a possible race when disabling buffered events (CKI KWF BOT) [RHEL-169366]
  • tracing: Fix incomplete locking when disabling buffered events (CKI KWF BOT) [RHEL-169366]
  • thunderbolt: Fix wake on connect at runtime (Desnes Nunes) [RHEL-104807]
  • thunderbolt: Fix a logic error in wake on connect (Desnes Nunes) [RHEL-104807]
  • thunderbolt: Use wake on connect and disconnect over suspend (Desnes Nunes) [RHEL-104807]
  • i2c: i801: Revert 'i2c: i801: replace acpi_lock with I2C bus lock' (David Arcari) [RHEL-155311]
  • net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks (CKI Backport Bot) [RHEL-157327] {CVE-2026-23270}

[5.14.0-611.52.1]

  • libceph: reset sparse-read state in osd_fault() (CKI Backport Bot) [RHEL-150464] {CVE-2026-23136}

[5.14.0-611.51.1]

  • nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (Scott Mayhew) [RHEL-167016] {CVE-2026-31402}
  • i40e: support generic devlink param 'max_mac_per_vf' (Mohammad Heib) [RHEL-121643]
  • devlink: Add new 'max_mac_per_vf' generic device param (Mohammad Heib) [RHEL-121643]
  • i40e: improve VF MAC filters accounting (Mohammad Heib) [RHEL-121643]

[5.14.0-611.50.1]

  • smb: client: fix krb5 mount with username option (Paulo Alcantara) [RHEL-158987]
  • md/raid1: fix data lost for writemostly rdev (Nigel Croxon) [RHEL-143624]

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

kernel-cross-headers

5.14.0-611.54.1.el9_7

kernel-tools-libs-devel

5.14.0-611.54.1.el9_7

libperf

5.14.0-611.54.1.el9_7

kernel-tools

5.14.0-611.54.1.el9_7

kernel-tools-libs

5.14.0-611.54.1.el9_7

kernel-headers

5.14.0-611.54.1.el9_7

perf

5.14.0-611.54.1.el9_7

python3-perf

5.14.0-611.54.1.el9_7

rtla

5.14.0-611.54.1.el9_7

rv

5.14.0-611.54.1.el9_7

Oracle Linux x86_64

kernel

5.14.0-611.54.1.el9_7

kernel-abi-stablelists

5.14.0-611.54.1.el9_7

kernel-core

5.14.0-611.54.1.el9_7

kernel-debug

5.14.0-611.54.1.el9_7

kernel-debug-core

5.14.0-611.54.1.el9_7

kernel-debug-modules

5.14.0-611.54.1.el9_7

kernel-debug-modules-core

5.14.0-611.54.1.el9_7

kernel-debug-modules-extra

5.14.0-611.54.1.el9_7

kernel-debug-uki-virt

5.14.0-611.54.1.el9_7

kernel-modules

5.14.0-611.54.1.el9_7

kernel-modules-core

5.14.0-611.54.1.el9_7

kernel-modules-extra

5.14.0-611.54.1.el9_7

kernel-tools

5.14.0-611.54.1.el9_7

kernel-tools-libs

5.14.0-611.54.1.el9_7

kernel-uki-virt

5.14.0-611.54.1.el9_7

kernel-uki-virt-addons

5.14.0-611.54.1.el9_7

kernel-debug-devel

5.14.0-611.54.1.el9_7

kernel-debug-devel-matched

5.14.0-611.54.1.el9_7

kernel-devel

5.14.0-611.54.1.el9_7

kernel-devel-matched

5.14.0-611.54.1.el9_7

kernel-doc

5.14.0-611.54.1.el9_7

kernel-headers

5.14.0-611.54.1.el9_7

perf

5.14.0-611.54.1.el9_7

python3-perf

5.14.0-611.54.1.el9_7

rtla

5.14.0-611.54.1.el9_7

rv

5.14.0-611.54.1.el9_7

kernel-cross-headers

5.14.0-611.54.1.el9_7

kernel-tools-libs-devel

5.14.0-611.54.1.el9_7

libperf

5.14.0-611.54.1.el9_7

Связанные уязвимости

rocky
около 2 месяцев назад

Important: kernel security update

oracle-oval
около 2 месяцев назад

ELSA-2026-13566: kernel security update (IMPORTANT)

rocky
24 дня назад

Important: kernel security update

rocky
около 2 месяцев назад

Important: kernel security update

CVSS3: 7.5
ubuntu
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: libceph: reset sparse-read state in osd_fault() When a fault occurs, the connection is abandoned, reestablished, and any pending operations are retried. The OSD client tracks the progress of a sparse-read reply using a separate state machine, largely independent of the messenger's state. If a connection is lost mid-payload or the sparse-read state machine returns an error, the sparse-read state is not reset. The OSD client will then interpret the beginning of a new reply as the continuation of the old one. If this makes the sparse-read machinery enter a failure state, it may never recover, producing loops like: libceph: [0] got 0 extents libceph: data len 142248331 != extent len 0 libceph: osd0 (1)...:6801 socket error on read libceph: data len 142248331 != extent len 0 libceph: osd0 (1)...:6801 socket error on read Therefore, reset the sparse-read state in osd_fault(), ensuring retries start from a clean state.