Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-51295

Опубликовано: 07 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-51295: kernel security, bug fix, and enhancement update (MODERATE)

[6.12.0-211.44.1]

  • Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
  • Disable UKI signing [Orabug: 36571828]
  • Update Oracle Linux certificates (Kevin Lyons)
  • Disable signing for aarch64 (Ilya Okomin)
  • Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
  • Update x509.genkey [Orabug: 24817676]
  • Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
  • Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
  • Add Oracle Linux IMA certificates
  • Update module name for cryptographic module [Orabug: 37400433]
  • Clean git history at setup stage

[6.12.0-211.44.1]

  • ice: remove redundant checks from PTP init (Jakub Ramaseuski) [RHEL-193134]
  • ice: implement E825 TX ref clock control and TXC hardware sync status (Jakub Ramaseuski) [RHEL-193134]
  • ice: add Tx reference clock index handling to AN restart command (Jakub Ramaseuski) [RHEL-193134]
  • ice: implement CPI support for E825C (Jakub Ramaseuski) [RHEL-193134]
  • ice: introduce TXC DPLL device and TX ref clock pin framework for E825 (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix missing priority callbacks for U.FL DPLL pins (Jakub Ramaseuski) [RHEL-193134]
  • ice: restore PTP Rx timestamp config after ethtool set-channels (Jakub Ramaseuski) [RHEL-193134]
  • ice: ptp: use primary NAC semaphore on E825 (Jakub Ramaseuski) [RHEL-193134]
  • ice: ptp: serialize E825 PHY timer start with PTP lock (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix setting promisc mode while adding VID filter (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix VF queue configuration with low MTU values (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix locking around wait_event_interruptible_locked_irq (Jakub Ramaseuski) [RHEL-193134]
  • ice: dpll: Fix compilation warning (Jakub Ramaseuski) [RHEL-193134]
  • ice: mention fw_activate action along with devlink reload (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix locking in ice_dcb_rebuild() (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix setting RSS VSI hash for E830 (Jakub Ramaseuski) [RHEL-193134]
  • ice: add dpll peer notification for paired SMA and U.FL pins (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix missing dpll notifications for SW pins (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix SMA and U.FL pin state changes affecting paired pin (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix missing SMA pin initialization in DPLL subsystem (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix infinite recursion in ice_cfg_tx_topo via ice_init_dev_hw (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix NULL pointer dereference in ice_reset_all_vfs() (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix ice_ptp_read_tx_hwtstamp_status_eth56g (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix ready bitmap check for non-E822 devices (Jakub Ramaseuski) [RHEL-193134]
  • ice: perform PHY soft reset for E825C ports at initialization (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix timestamp interrupt configuration for E825C (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix potential NULL pointer deref in error path of ice_set_ringparam() (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix race condition in TX timestamp ring cleanup (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix ICE_AQ_LINK_SPEED_M for 200G (Jakub Ramaseuski) [RHEL-193134]
  • ice: fix PHY config on media change with link-down-on-close (Jakub Ramaseuski) [RHEL-193134]
  • ice: Fix memory leak in ice_set_ringparam() (Jakub Ramaseuski) [RHEL-193134]
  • ice: dpll: fix misplaced header macros (Jakub Ramaseuski) [RHEL-193134]
  • ice: dpll: fix rclk pin state get for E810 (Jakub Ramaseuski) [RHEL-193134]
  • Revert 'ice: dpll: fix rclk pin state get and misplaced header macros' (Jakub Ramaseuski) [RHEL-193134]
  • octeon_ep_vf: add NULL check for napi_build_skb() (CKI Backport Bot) [RHEL-186345]
  • octeon_ep_vf: introduce octep_vf_oq_next_idx() helper (CKI Backport Bot) [RHEL-186345]
  • octeon_ep_vf: avoid compiler and IQ/OQ reordering (CKI Backport Bot) [RHEL-186345]
  • octeon_ep_vf: Relocate counter updates before NAPI (CKI Backport Bot) [RHEL-186345]
  • octeon_ep_vf: ensure dbell BADDR updation (CKI Backport Bot) [RHEL-186345]
  • net: octeon_ep_vf: fix free_irq dev_id mismatch in IRQ rollback (CKI Backport Bot) [RHEL-186345]
  • ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() (CKI Backport Bot) [RHEL-174197] {CVE-2026-43186}

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

kernel-headers

6.12.0-211.44.1.el10_2

perf

6.12.0-211.44.1.el10_2

python3-perf

6.12.0-211.44.1.el10_2

rtla

6.12.0-211.44.1.el10_2

rv

6.12.0-211.44.1.el10_2

kernel-tools

6.12.0-211.44.1.el10_2

kernel-tools-libs

6.12.0-211.44.1.el10_2

kernel-cross-headers

6.12.0-211.44.1.el10_2

kernel-tools-libs-devel

6.12.0-211.44.1.el10_2

libperf

6.12.0-211.44.1.el10_2

Oracle Linux x86_64

kernel

6.12.0-211.44.1.el10_2

kernel-abi-stablelists

6.12.0-211.44.1.el10_2

kernel-debug-modules

6.12.0-211.44.1.el10_2

kernel-debug-modules-extra

6.12.0-211.44.1.el10_2

kernel-debug-uki-virt

6.12.0-211.44.1.el10_2

kernel-modules

6.12.0-211.44.1.el10_2

kernel-modules-core

6.12.0-211.44.1.el10_2

kernel-modules-extra-matched

6.12.0-211.44.1.el10_2

kernel-tools-libs

6.12.0-211.44.1.el10_2

kernel-uki-virt-addons

6.12.0-211.44.1.el10_2

kernel-debug-devel

6.12.0-211.44.1.el10_2

kernel-debug-devel-matched

6.12.0-211.44.1.el10_2

kernel-devel

6.12.0-211.44.1.el10_2

kernel-devel-matched

6.12.0-211.44.1.el10_2

kernel-doc

6.12.0-211.44.1.el10_2

kernel-headers

6.12.0-211.44.1.el10_2

perf

6.12.0-211.44.1.el10_2

python3-perf

6.12.0-211.44.1.el10_2

rtla

6.12.0-211.44.1.el10_2

rv

6.12.0-211.44.1.el10_2

kernel-core

6.12.0-211.44.1.el10_2

kernel-debug

6.12.0-211.44.1.el10_2

kernel-debug-core

6.12.0-211.44.1.el10_2

kernel-debug-modules-core

6.12.0-211.44.1.el10_2

kernel-modules-extra

6.12.0-211.44.1.el10_2

kernel-tools

6.12.0-211.44.1.el10_2

kernel-uki-virt

6.12.0-211.44.1.el10_2

kernel-cross-headers

6.12.0-211.44.1.el10_2

kernel-tools-libs-devel

6.12.0-211.44.1.el10_2

libperf

6.12.0-211.44.1.el10_2

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() On the receive path, __ioam6_fill_trace_data() uses trace->nodelen to decide how much data to write for each node. It trusts this field as-is from the incoming packet, with no consistency check against trace->type (the 24-bit field that tells which data items are present). A crafted packet can set nodelen=0 while setting type bits 0-21, causing the function to write ~100 bytes past the allocated region (into skb_shared_info), which corrupts adjacent heap memory and leads to a kernel panic. Add a shared helper ioam6_trace_compute_nodelen() in ioam6.c to derive the expected nodelen from the type field, and use it: - in ioam6_iptunnel.c (send path, existing validation) to replace the open-coded computation; - in exthdrs.c (receive path, ipv6_hop_ioam) to drop packets whose nodelen is inconsistent with the type field, before any data is written. Per RFC 9...

CVSS3: 7.5
redhat
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() On the receive path, __ioam6_fill_trace_data() uses trace->nodelen to decide how much data to write for each node. It trusts this field as-is from the incoming packet, with no consistency check against trace->type (the 24-bit field that tells which data items are present). A crafted packet can set nodelen=0 while setting type bits 0-21, causing the function to write ~100 bytes past the allocated region (into skb_shared_info), which corrupts adjacent heap memory and leads to a kernel panic. Add a shared helper ioam6_trace_compute_nodelen() in ioam6.c to derive the expected nodelen from the type field, and use it: - in ioam6_iptunnel.c (send path, existing validation) to replace the open-coded computation; - in exthdrs.c (receive path, ipv6_hop_ioam) to drop packets whose nodelen is inconsistent with the type field, before any data is written. Per RFC 9...

CVSS3: 9.8
nvd
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() On the receive path, __ioam6_fill_trace_data() uses trace->nodelen to decide how much data to write for each node. It trusts this field as-is from the incoming packet, with no consistency check against trace->type (the 24-bit field that tells which data items are present). A crafted packet can set nodelen=0 while setting type bits 0-21, causing the function to write ~100 bytes past the allocated region (into skb_shared_info), which corrupts adjacent heap memory and leads to a kernel panic. Add a shared helper ioam6_trace_compute_nodelen() in ioam6.c to derive the expected nodelen from the type field, and use it: - in ioam6_iptunnel.c (send path, existing validation) to replace the open-coded computation; - in exthdrs.c (receive path, ipv6_hop_ioam) to drop packets whose nodelen is inconsistent with the type field, before any data is w

CVSS3: 9.8
debian
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: i ...

rocky
около 1 месяца назад

Moderate: kernel security, bug fix, and enhancement update