Описание
ELSA-2026-51295: kernel security, bug fix, and enhancement update (MODERATE)
[6.12.0-211.44.1]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Update module name for cryptographic module [Orabug: 37400433]
- Clean git history at setup stage
[6.12.0-211.44.1]
- ice: remove redundant checks from PTP init (Jakub Ramaseuski) [RHEL-193134]
- ice: implement E825 TX ref clock control and TXC hardware sync status (Jakub Ramaseuski) [RHEL-193134]
- ice: add Tx reference clock index handling to AN restart command (Jakub Ramaseuski) [RHEL-193134]
- ice: implement CPI support for E825C (Jakub Ramaseuski) [RHEL-193134]
- ice: introduce TXC DPLL device and TX ref clock pin framework for E825 (Jakub Ramaseuski) [RHEL-193134]
- ice: fix missing priority callbacks for U.FL DPLL pins (Jakub Ramaseuski) [RHEL-193134]
- ice: restore PTP Rx timestamp config after ethtool set-channels (Jakub Ramaseuski) [RHEL-193134]
- ice: ptp: use primary NAC semaphore on E825 (Jakub Ramaseuski) [RHEL-193134]
- ice: ptp: serialize E825 PHY timer start with PTP lock (Jakub Ramaseuski) [RHEL-193134]
- ice: fix setting promisc mode while adding VID filter (Jakub Ramaseuski) [RHEL-193134]
- ice: fix VF queue configuration with low MTU values (Jakub Ramaseuski) [RHEL-193134]
- ice: fix locking around wait_event_interruptible_locked_irq (Jakub Ramaseuski) [RHEL-193134]
- ice: dpll: Fix compilation warning (Jakub Ramaseuski) [RHEL-193134]
- ice: mention fw_activate action along with devlink reload (Jakub Ramaseuski) [RHEL-193134]
- ice: fix locking in ice_dcb_rebuild() (Jakub Ramaseuski) [RHEL-193134]
- ice: fix setting RSS VSI hash for E830 (Jakub Ramaseuski) [RHEL-193134]
- ice: add dpll peer notification for paired SMA and U.FL pins (Jakub Ramaseuski) [RHEL-193134]
- ice: fix missing dpll notifications for SW pins (Jakub Ramaseuski) [RHEL-193134]
- ice: fix SMA and U.FL pin state changes affecting paired pin (Jakub Ramaseuski) [RHEL-193134]
- ice: fix missing SMA pin initialization in DPLL subsystem (Jakub Ramaseuski) [RHEL-193134]
- ice: fix infinite recursion in ice_cfg_tx_topo via ice_init_dev_hw (Jakub Ramaseuski) [RHEL-193134]
- ice: fix NULL pointer dereference in ice_reset_all_vfs() (Jakub Ramaseuski) [RHEL-193134]
- ice: fix ice_ptp_read_tx_hwtstamp_status_eth56g (Jakub Ramaseuski) [RHEL-193134]
- ice: fix ready bitmap check for non-E822 devices (Jakub Ramaseuski) [RHEL-193134]
- ice: perform PHY soft reset for E825C ports at initialization (Jakub Ramaseuski) [RHEL-193134]
- ice: fix timestamp interrupt configuration for E825C (Jakub Ramaseuski) [RHEL-193134]
- ice: fix potential NULL pointer deref in error path of ice_set_ringparam() (Jakub Ramaseuski) [RHEL-193134]
- ice: fix race condition in TX timestamp ring cleanup (Jakub Ramaseuski) [RHEL-193134]
- ice: fix ICE_AQ_LINK_SPEED_M for 200G (Jakub Ramaseuski) [RHEL-193134]
- ice: fix PHY config on media change with link-down-on-close (Jakub Ramaseuski) [RHEL-193134]
- ice: Fix memory leak in ice_set_ringparam() (Jakub Ramaseuski) [RHEL-193134]
- ice: dpll: fix misplaced header macros (Jakub Ramaseuski) [RHEL-193134]
- ice: dpll: fix rclk pin state get for E810 (Jakub Ramaseuski) [RHEL-193134]
- Revert 'ice: dpll: fix rclk pin state get and misplaced header macros' (Jakub Ramaseuski) [RHEL-193134]
- octeon_ep_vf: add NULL check for napi_build_skb() (CKI Backport Bot) [RHEL-186345]
- octeon_ep_vf: introduce octep_vf_oq_next_idx() helper (CKI Backport Bot) [RHEL-186345]
- octeon_ep_vf: avoid compiler and IQ/OQ reordering (CKI Backport Bot) [RHEL-186345]
- octeon_ep_vf: Relocate counter updates before NAPI (CKI Backport Bot) [RHEL-186345]
- octeon_ep_vf: ensure dbell BADDR updation (CKI Backport Bot) [RHEL-186345]
- net: octeon_ep_vf: fix free_irq dev_id mismatch in IRQ rollback (CKI Backport Bot) [RHEL-186345]
- ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() (CKI Backport Bot) [RHEL-174197] {CVE-2026-43186}
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
kernel-headers
6.12.0-211.44.1.el10_2
perf
6.12.0-211.44.1.el10_2
python3-perf
6.12.0-211.44.1.el10_2
rtla
6.12.0-211.44.1.el10_2
rv
6.12.0-211.44.1.el10_2
kernel-tools
6.12.0-211.44.1.el10_2
kernel-tools-libs
6.12.0-211.44.1.el10_2
kernel-cross-headers
6.12.0-211.44.1.el10_2
kernel-tools-libs-devel
6.12.0-211.44.1.el10_2
libperf
6.12.0-211.44.1.el10_2
Oracle Linux x86_64
kernel
6.12.0-211.44.1.el10_2
kernel-abi-stablelists
6.12.0-211.44.1.el10_2
kernel-debug-modules
6.12.0-211.44.1.el10_2
kernel-debug-modules-extra
6.12.0-211.44.1.el10_2
kernel-debug-uki-virt
6.12.0-211.44.1.el10_2
kernel-modules
6.12.0-211.44.1.el10_2
kernel-modules-core
6.12.0-211.44.1.el10_2
kernel-modules-extra-matched
6.12.0-211.44.1.el10_2
kernel-tools-libs
6.12.0-211.44.1.el10_2
kernel-uki-virt-addons
6.12.0-211.44.1.el10_2
kernel-debug-devel
6.12.0-211.44.1.el10_2
kernel-debug-devel-matched
6.12.0-211.44.1.el10_2
kernel-devel
6.12.0-211.44.1.el10_2
kernel-devel-matched
6.12.0-211.44.1.el10_2
kernel-doc
6.12.0-211.44.1.el10_2
kernel-headers
6.12.0-211.44.1.el10_2
perf
6.12.0-211.44.1.el10_2
python3-perf
6.12.0-211.44.1.el10_2
rtla
6.12.0-211.44.1.el10_2
rv
6.12.0-211.44.1.el10_2
kernel-core
6.12.0-211.44.1.el10_2
kernel-debug
6.12.0-211.44.1.el10_2
kernel-debug-core
6.12.0-211.44.1.el10_2
kernel-debug-modules-core
6.12.0-211.44.1.el10_2
kernel-modules-extra
6.12.0-211.44.1.el10_2
kernel-tools
6.12.0-211.44.1.el10_2
kernel-uki-virt
6.12.0-211.44.1.el10_2
kernel-cross-headers
6.12.0-211.44.1.el10_2
kernel-tools-libs-devel
6.12.0-211.44.1.el10_2
libperf
6.12.0-211.44.1.el10_2
Связанные CVE
Связанные уязвимости
In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() On the receive path, __ioam6_fill_trace_data() uses trace->nodelen to decide how much data to write for each node. It trusts this field as-is from the incoming packet, with no consistency check against trace->type (the 24-bit field that tells which data items are present). A crafted packet can set nodelen=0 while setting type bits 0-21, causing the function to write ~100 bytes past the allocated region (into skb_shared_info), which corrupts adjacent heap memory and leads to a kernel panic. Add a shared helper ioam6_trace_compute_nodelen() in ioam6.c to derive the expected nodelen from the type field, and use it: - in ioam6_iptunnel.c (send path, existing validation) to replace the open-coded computation; - in exthdrs.c (receive path, ipv6_hop_ioam) to drop packets whose nodelen is inconsistent with the type field, before any data is written. Per RFC 9...
In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() On the receive path, __ioam6_fill_trace_data() uses trace->nodelen to decide how much data to write for each node. It trusts this field as-is from the incoming packet, with no consistency check against trace->type (the 24-bit field that tells which data items are present). A crafted packet can set nodelen=0 while setting type bits 0-21, causing the function to write ~100 bytes past the allocated region (into skb_shared_info), which corrupts adjacent heap memory and leads to a kernel panic. Add a shared helper ioam6_trace_compute_nodelen() in ioam6.c to derive the expected nodelen from the type field, and use it: - in ioam6_iptunnel.c (send path, existing validation) to replace the open-coded computation; - in exthdrs.c (receive path, ipv6_hop_ioam) to drop packets whose nodelen is inconsistent with the type field, before any data is written. Per RFC 9...
In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() On the receive path, __ioam6_fill_trace_data() uses trace->nodelen to decide how much data to write for each node. It trusts this field as-is from the incoming packet, with no consistency check against trace->type (the 24-bit field that tells which data items are present). A crafted packet can set nodelen=0 while setting type bits 0-21, causing the function to write ~100 bytes past the allocated region (into skb_shared_info), which corrupts adjacent heap memory and leads to a kernel panic. Add a shared helper ioam6_trace_compute_nodelen() in ioam6.c to derive the expected nodelen from the type field, and use it: - in ioam6_iptunnel.c (send path, existing validation) to replace the open-coded computation; - in exthdrs.c (receive path, ipv6_hop_ioam) to drop packets whose nodelen is inconsistent with the type field, before any data is w
In the Linux kernel, the following vulnerability has been resolved: i ...