Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-47040

Опубликовано: 30 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-47040: kernel security, bug fix, and enhancement update (IMPORTANT)

[5.14.0-687.31.1]

  • Disable UKI signing [Orabug: 36571828]
  • Update Oracle Linux certificates (Kevin Lyons)
  • Disable signing for aarch64 (Ilya Okomin)
  • Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
  • Update x509.genkey [Orabug: 24817676]
  • Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
  • Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
  • Add Oracle Linux IMA certificates
  • Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985764]

[5.14.0-687.31.1]

  • blk-mq: reinsert cached request to the list (CKI Backport Bot) [RHEL-213163] {CVE-2026-64017}
  • blk-mq: pop cached request if it is usable (CKI Backport Bot) [RHEL-213163] {CVE-2026-64017}
  • futex: Drop CLONE_THREAD requirement for private default hash alloc (Audra Mitchell) [RHEL-193517] {CVE-2026-52973}
  • watchdog: Fix NULL pointer dereference when releasing cdev (Krzysztof Pawlinski) [RHEL-193729]
  • redhat/configs: enable watchdog pretimout panic functionality for x86 (Krzysztof Pawlinski) [RHEL-193729]
  • watchdog: wdat_wdt: Fix ACPI table leak in probe function (Krzysztof Pawlinski) [RHEL-193729]
  • watchdog: Switch to use hrtimer_setup() (Krzysztof Pawlinski) [RHEL-193729]
  • watchdog: iTCO_wdt: Convert comma to semicolon (Krzysztof Pawlinski) [RHEL-193729]
  • watchdog: wdat_wdt: Add timeout value as a param in ping method (Krzysztof Pawlinski) [RHEL-193729]
  • watchdog: iTCO_wdt: Report firmware_version (Krzysztof Pawlinski) [RHEL-193729]
  • watchdog: iTCO_wdt: Set NO_REBOOT if the watchdog is not already running (Krzysztof Pawlinski) [RHEL-193729]
  • watchdog: iTCO_wdt: Using existing macro define covers more scenarios (Krzysztof Pawlinski) [RHEL-193729]
  • watchdog: iTCO_wdt: No need to stop the timer in probe (Krzysztof Pawlinski) [RHEL-193729]
  • watchdog: only run driver set_pretimeout op if device supports it (Krzysztof Pawlinski) [RHEL-193729]
  • watchdog: iTCO_wdt: Make use of the helper function devm_platform_ioremap_resource() (Krzysztof Pawlinski) [RHEL-193729]
  • xfrm: xfrm_alloc_spi shouldn't use 0 as SPI (Sabrina Dubroca) [RHEL-180033] {CVE-2025-39797}
  • xfrm: Duplicate SPI Handling (Sabrina Dubroca) [RHEL-180033] {CVE-2025-39797}
  • iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (Eder Zulian) [RHEL-190342] {CVE-2026-53281}
  • iommu/vt-d: Fix oops due to out of scope access (Eder Zulian) [RHEL-190342]
  • lib/buildid: use __kernel_read() for sleepable context (CKI Backport Bot) [RHEL-189962] {CVE-2026-23002}
  • nfsd: use correct loop termination in nfsd4_revoke_states() (CKI Backport Bot) [RHEL-188257]
  • nfsd: check that server is running in unlock_filesystem (CKI Backport Bot) [RHEL-188257]

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

kernel-cross-headers

5.14.0-687.31.1.el9_8

kernel-tools-libs-devel

5.14.0-687.31.1.el9_8

libperf

5.14.0-687.31.1.el9_8

kernel-tools

5.14.0-687.31.1.el9_8

kernel-headers

5.14.0-687.31.1.el9_8

perf

5.14.0-687.31.1.el9_8

python3-perf

5.14.0-687.31.1.el9_8

rtla

5.14.0-687.31.1.el9_8

rv

5.14.0-687.31.1.el9_8

kernel-tools-libs

5.14.0-687.31.1.el9_8

Oracle Linux x86_64

kernel-debug-modules-core

5.14.0-687.31.1.el9_8

kernel-debug-devel

5.14.0-687.31.1.el9_8

kernel-debug-devel-matched

5.14.0-687.31.1.el9_8

kernel-devel

5.14.0-687.31.1.el9_8

kernel-devel-matched

5.14.0-687.31.1.el9_8

kernel-doc

5.14.0-687.31.1.el9_8

kernel-headers

5.14.0-687.31.1.el9_8

perf

5.14.0-687.31.1.el9_8

python3-perf

5.14.0-687.31.1.el9_8

rtla

5.14.0-687.31.1.el9_8

rv

5.14.0-687.31.1.el9_8

kernel-cross-headers

5.14.0-687.31.1.el9_8

kernel-tools-libs-devel

5.14.0-687.31.1.el9_8

libperf

5.14.0-687.31.1.el9_8

kernel

5.14.0-687.31.1.el9_8

kernel-abi-stablelists

5.14.0-687.31.1.el9_8

kernel-core

5.14.0-687.31.1.el9_8

kernel-debug

5.14.0-687.31.1.el9_8

kernel-debug-core

5.14.0-687.31.1.el9_8

kernel-debug-modules

5.14.0-687.31.1.el9_8

kernel-debug-modules-extra

5.14.0-687.31.1.el9_8

kernel-debug-uki-virt

5.14.0-687.31.1.el9_8

kernel-modules

5.14.0-687.31.1.el9_8

kernel-modules-core

5.14.0-687.31.1.el9_8

kernel-modules-extra

5.14.0-687.31.1.el9_8

kernel-tools

5.14.0-687.31.1.el9_8

kernel-tools-libs

5.14.0-687.31.1.el9_8

kernel-uki-virt

5.14.0-687.31.1.el9_8

kernel-uki-virt-addons

5.14.0-687.31.1.el9_8

Связанные уязвимости

rocky
4 дня назад

Important: kernel security, bug fix, and enhancement update

CVSS3: 7.8
ubuntu
11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: xfrm: Duplicate SPI Handling The issue originates when Strongswan initiates an XFRM_MSG_ALLOCSPI Netlink message, which triggers the kernel function xfrm_alloc_spi(). This function is expected to ensure uniqueness of the Security Parameter Index (SPI) for inbound Security Associations (SAs). However, it can return success even when the requested SPI is already in use, leading to duplicate SPIs assigned to multiple inbound SAs, differentiated only by their destination addresses. This behavior causes inconsistencies during SPI lookups for inbound packets. Since the lookup may return an arbitrary SA among those with the same SPI, packet processing can fail, resulting in packet drops. According to RFC 4301 section 4.4.2 , for inbound processing a unicast SA is uniquely identified by the SPI and optionally protocol. Reproducing the Issue Reliably: To consistently reproduce the problem, restrict the available SPI range in...

CVSS3: 5.3
redhat
11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: xfrm: Duplicate SPI Handling The issue originates when Strongswan initiates an XFRM_MSG_ALLOCSPI Netlink message, which triggers the kernel function xfrm_alloc_spi(). This function is expected to ensure uniqueness of the Security Parameter Index (SPI) for inbound Security Associations (SAs). However, it can return success even when the requested SPI is already in use, leading to duplicate SPIs assigned to multiple inbound SAs, differentiated only by their destination addresses. This behavior causes inconsistencies during SPI lookups for inbound packets. Since the lookup may return an arbitrary SA among those with the same SPI, packet processing can fail, resulting in packet drops. According to RFC 4301 section 4.4.2 , for inbound processing a unicast SA is uniquely identified by the SPI and optionally protocol. Reproducing the Issue Reliably: To consistently reproduce the problem, restrict the available SPI range in...

CVSS3: 7.8
nvd
11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: xfrm: Duplicate SPI Handling The issue originates when Strongswan initiates an XFRM_MSG_ALLOCSPI Netlink message, which triggers the kernel function xfrm_alloc_spi(). This function is expected to ensure uniqueness of the Security Parameter Index (SPI) for inbound Security Associations (SAs). However, it can return success even when the requested SPI is already in use, leading to duplicate SPIs assigned to multiple inbound SAs, differentiated only by their destination addresses. This behavior causes inconsistencies during SPI lookups for inbound packets. Since the lookup may return an arbitrary SA among those with the same SPI, packet processing can fail, resulting in packet drops. According to RFC 4301 section 4.4.2 , for inbound processing a unicast SA is uniquely identified by the SPI and optionally protocol. Reproducing the Issue Reliably: To consistently reproduce the problem, restrict the available SPI range

CVSS3: 6.1
msrc
8 месяцев назад

xfrm: Duplicate SPI Handling