Описание
ELSA-2026-13565: kernel security update (IMPORTANT)
[5.14.0-611.54.1]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985764]
[5.14.0-611.54.1]
- crypto: algif_aead - snapshot IV for async AEAD requests (Vladislav Dronov) [RHEL-172201]
- crypto: algif_aead - Fix minimum RX size check for decryption (Vladislav Dronov) [RHEL-172201]
- crypto: authencesn - reject short ahash digests during instance creation (Vladislav Dronov) [RHEL-172201]
- crypto: authencesn - Fix src offset when decrypting in-place (Vladislav Dronov) [RHEL-172201]
- crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (Vladislav Dronov) [RHEL-172201] {CVE-2026-31431}
- crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec (Vladislav Dronov) [RHEL-172201] {CVE-2026-23060}
- crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl (Vladislav Dronov) [RHEL-172201]
- crypto: af_alg - limit RX SG extraction by receive buffer budget (Vladislav Dronov) [RHEL-172201] {CVE-2026-31677}
- crypto: algif_aead - Revert to operating out-of-place (Vladislav Dronov) [RHEL-172201] {CVE-2026-31431}
- crypto: af-alg - fix NULL pointer dereference in scatterwalk (Vladislav Dronov) [RHEL-172201]
[5.14.0-611.53.1]
- tracing: Fix a warning when allocating buffered events fails (CKI KWF BOT) [RHEL-169366]
- tracing: Fix a possible race when disabling buffered events (CKI KWF BOT) [RHEL-169366]
- tracing: Fix incomplete locking when disabling buffered events (CKI KWF BOT) [RHEL-169366]
- thunderbolt: Fix wake on connect at runtime (Desnes Nunes) [RHEL-104807]
- thunderbolt: Fix a logic error in wake on connect (Desnes Nunes) [RHEL-104807]
- thunderbolt: Use wake on connect and disconnect over suspend (Desnes Nunes) [RHEL-104807]
- i2c: i801: Revert 'i2c: i801: replace acpi_lock with I2C bus lock' (David Arcari) [RHEL-155311]
- net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks (CKI Backport Bot) [RHEL-157327] {CVE-2026-23270}
[5.14.0-611.52.1]
- libceph: reset sparse-read state in osd_fault() (CKI Backport Bot) [RHEL-150464] {CVE-2026-23136}
[5.14.0-611.51.1]
- nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (Scott Mayhew) [RHEL-167016] {CVE-2026-31402}
- i40e: support generic devlink param 'max_mac_per_vf' (Mohammad Heib) [RHEL-121643]
- devlink: Add new 'max_mac_per_vf' generic device param (Mohammad Heib) [RHEL-121643]
- i40e: improve VF MAC filters accounting (Mohammad Heib) [RHEL-121643]
[5.14.0-611.50.1]
- smb: client: fix krb5 mount with username option (Paulo Alcantara) [RHEL-158987]
- md/raid1: fix data lost for writemostly rdev (Nigel Croxon) [RHEL-143624]
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
kernel-cross-headers
5.14.0-611.54.1.el9_7
kernel-tools-libs-devel
5.14.0-611.54.1.el9_7
libperf
5.14.0-611.54.1.el9_7
kernel-tools
5.14.0-611.54.1.el9_7
kernel-tools-libs
5.14.0-611.54.1.el9_7
kernel-headers
5.14.0-611.54.1.el9_7
perf
5.14.0-611.54.1.el9_7
python3-perf
5.14.0-611.54.1.el9_7
rtla
5.14.0-611.54.1.el9_7
rv
5.14.0-611.54.1.el9_7
Oracle Linux x86_64
kernel
5.14.0-611.54.1.el9_7
kernel-abi-stablelists
5.14.0-611.54.1.el9_7
kernel-core
5.14.0-611.54.1.el9_7
kernel-debug
5.14.0-611.54.1.el9_7
kernel-debug-core
5.14.0-611.54.1.el9_7
kernel-debug-modules
5.14.0-611.54.1.el9_7
kernel-debug-modules-core
5.14.0-611.54.1.el9_7
kernel-debug-modules-extra
5.14.0-611.54.1.el9_7
kernel-debug-uki-virt
5.14.0-611.54.1.el9_7
kernel-modules
5.14.0-611.54.1.el9_7
kernel-modules-core
5.14.0-611.54.1.el9_7
kernel-modules-extra
5.14.0-611.54.1.el9_7
kernel-tools
5.14.0-611.54.1.el9_7
kernel-tools-libs
5.14.0-611.54.1.el9_7
kernel-uki-virt
5.14.0-611.54.1.el9_7
kernel-uki-virt-addons
5.14.0-611.54.1.el9_7
kernel-debug-devel
5.14.0-611.54.1.el9_7
kernel-debug-devel-matched
5.14.0-611.54.1.el9_7
kernel-devel
5.14.0-611.54.1.el9_7
kernel-devel-matched
5.14.0-611.54.1.el9_7
kernel-doc
5.14.0-611.54.1.el9_7
kernel-headers
5.14.0-611.54.1.el9_7
perf
5.14.0-611.54.1.el9_7
python3-perf
5.14.0-611.54.1.el9_7
rtla
5.14.0-611.54.1.el9_7
rv
5.14.0-611.54.1.el9_7
kernel-cross-headers
5.14.0-611.54.1.el9_7
kernel-tools-libs-devel
5.14.0-611.54.1.el9_7
libperf
5.14.0-611.54.1.el9_7
Связанные уязвимости
In the Linux kernel, the following vulnerability has been resolved: libceph: reset sparse-read state in osd_fault() When a fault occurs, the connection is abandoned, reestablished, and any pending operations are retried. The OSD client tracks the progress of a sparse-read reply using a separate state machine, largely independent of the messenger's state. If a connection is lost mid-payload or the sparse-read state machine returns an error, the sparse-read state is not reset. The OSD client will then interpret the beginning of a new reply as the continuation of the old one. If this makes the sparse-read machinery enter a failure state, it may never recover, producing loops like: libceph: [0] got 0 extents libceph: data len 142248331 != extent len 0 libceph: osd0 (1)...:6801 socket error on read libceph: data len 142248331 != extent len 0 libceph: osd0 (1)...:6801 socket error on read Therefore, reset the sparse-read state in osd_fault(), ensuring retries start from a clean state.