Описание
ELSA-2026-59723: kernel security, bug fix, and enhancement update (IMPORTANT)
[5.14.0-687.42.1]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985764]
[5.14.0-687.42.1]
- net: ipv6: clear suppressed fib6 rule result (Paolo Abeni) [RHEL-246347] {CVE-2026-74581}
- s390/ap: Restrict driver_override versus apmask and aqmask use (Ramesh Chhetri) [RHEL-245333]
- s390/ap: Rename mutex ap_perms_mutex to ap_attr_mutex (Ramesh Chhetri) [RHEL-245333]
- s390/ap: Support driver_override for AP queue devices (Ramesh Chhetri) [RHEL-245333]
- s390/ap: Use all-bits-one apmask/aqmask for vfio in_use() checks (Ramesh Chhetri) [RHEL-245333]
- i2c: stub: Reject I2C block transfers with invalid length (CKI Backport Bot) [RHEL-232111] {CVE-2026-64191}
- Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (CKI Backport Bot) [RHEL-231440] {CVE-2026-64277}
- netfilter: require Ethernet MAC header before using eth_hdr() (CKI Backport Bot) [RHEL-230679] {CVE-2026-53131}
- Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (CKI Backport Bot) [RHEL-230236] {CVE-2026-64276}
- netfilter: xt_policy: fix strict mode inbound policy matching (CKI Backport Bot) [RHEL-228843] {CVE-2026-52920}
- netfilter: ipset: fix race between dump and ip_set_list resize (CKI Backport Bot) [RHEL-227673] {CVE-2026-64189}
- netfilter: conntrack_irc: fix possible out-of-bounds read (CKI Backport Bot) [RHEL-225252] {CVE-2026-53268}
- ksm: use range-walk function to jump over holes in scan_get_next_rmap_item (CKI Backport Bot) [RHEL-189901] {CVE-2025-68211}
- crypto: qat - cancel work on re-enable SR-IOV timeout (CKI Backport Bot) [RHEL-166118]
- sctp: hold socket lock when dumping endpoints in sctp_diag (Jamie Bainbridge) [RHEL-212398]
- sctp: Hold sock lock while iterating over address list (Jamie Bainbridge) [RHEL-212398]
- sctp: Prevent TOCTOU out-of-bounds write (Jamie Bainbridge) [RHEL-212398]
- sctp: Hold RCU read lock while iterating over address list (Jamie Bainbridge) [RHEL-212398]
- zram: fix use-after-free in zram_bvec_write_partial() (CKI Backport Bot) [RHEL-191439] {CVE-2026-53185}
- ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() (CKI Backport Bot) [RHEL-189965] {CVE-2026-23003}
- netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (CKI Backport Bot) [RHEL-189532] {CVE-2026-43114}
- sctp: purge outqueue on stale COOKIE-ECHO handling (CKI Backport Bot) [RHEL-188198] {CVE-2026-52924}
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
kernel-cross-headers
5.14.0-687.42.1.el9_8
kernel-tools-libs-devel
5.14.0-687.42.1.el9_8
libperf
5.14.0-687.42.1.el9_8
kernel-headers
5.14.0-687.42.1.el9_8
perf
5.14.0-687.42.1.el9_8
python3-perf
5.14.0-687.42.1.el9_8
rtla
5.14.0-687.42.1.el9_8
rv
5.14.0-687.42.1.el9_8
kernel-tools
5.14.0-687.42.1.el9_8
kernel-tools-libs
5.14.0-687.42.1.el9_8
Oracle Linux x86_64
kernel
5.14.0-687.42.1.el9_8
kernel-core
5.14.0-687.42.1.el9_8
kernel-debug
5.14.0-687.42.1.el9_8
kernel-debug-uki-virt
5.14.0-687.42.1.el9_8
kernel-modules-extra
5.14.0-687.42.1.el9_8
kernel-tools
5.14.0-687.42.1.el9_8
kernel-tools-libs
5.14.0-687.42.1.el9_8
kernel-uki-virt-addons
5.14.0-687.42.1.el9_8
kernel-debug-devel
5.14.0-687.42.1.el9_8
kernel-debug-devel-matched
5.14.0-687.42.1.el9_8
kernel-devel
5.14.0-687.42.1.el9_8
kernel-devel-matched
5.14.0-687.42.1.el9_8
kernel-doc
5.14.0-687.42.1.el9_8
kernel-headers
5.14.0-687.42.1.el9_8
perf
5.14.0-687.42.1.el9_8
python3-perf
5.14.0-687.42.1.el9_8
rtla
5.14.0-687.42.1.el9_8
rv
5.14.0-687.42.1.el9_8
kernel-cross-headers
5.14.0-687.42.1.el9_8
kernel-tools-libs-devel
5.14.0-687.42.1.el9_8
libperf
5.14.0-687.42.1.el9_8
kernel-abi-stablelists
5.14.0-687.42.1.el9_8
kernel-debug-core
5.14.0-687.42.1.el9_8
kernel-debug-modules
5.14.0-687.42.1.el9_8
kernel-debug-modules-core
5.14.0-687.42.1.el9_8
kernel-debug-modules-extra
5.14.0-687.42.1.el9_8
kernel-modules
5.14.0-687.42.1.el9_8
kernel-modules-core
5.14.0-687.42.1.el9_8
kernel-uki-virt
5.14.0-687.42.1.el9_8
Ссылки на источники
Связанные уязвимости
In the Linux kernel, the following vulnerability has been resolved: ksm: use range-walk function to jump over holes in scan_get_next_rmap_item Currently, scan_get_next_rmap_item() walks every page address in a VMA to locate mergeable pages. This becomes highly inefficient when scanning large virtual memory areas that contain mostly unmapped regions, causing ksmd to use large amount of cpu without deduplicating much pages. This patch replaces the per-address lookup with a range walk using walk_page_range(). The range walker allows KSM to skip over entire unmapped holes in a VMA, avoiding unnecessary lookups. This problem was previously discussed in [1]. Consider the following test program which creates a 32 TiB mapping in the virtual address space but only populates a single page: #include <unistd.h> #include <stdio.h> #include <sys/mman.h> /* 32 TiB */ const size_t size = 32ul * 1024 * 1024 * 1024 * 1024; int main() { char *area = mmap(NULL, size, PROT_READ | PROT_WRITE, MAP_NORE...
In the Linux kernel, the following vulnerability has been resolved: ksm: use range-walk function to jump over holes in scan_get_next_rmap_item Currently, scan_get_next_rmap_item() walks every page address in a VMA to locate mergeable pages. This becomes highly inefficient when scanning large virtual memory areas that contain mostly unmapped regions, causing ksmd to use large amount of cpu without deduplicating much pages. This patch replaces the per-address lookup with a range walk using walk_page_range(). The range walker allows KSM to skip over entire unmapped holes in a VMA, avoiding unnecessary lookups. This problem was previously discussed in [1]. Consider the following test program which creates a 32 TiB mapping in the virtual address space but only populates a single page: #include <unistd.h> #include <stdio.h> #include <sys/mman.h> /* 32 TiB */ const size_t size = 32ul * 1024 * 1024 * 1024 * 1024; int main() { char *area = mmap(NULL, size, PROT_READ | PROT_WRITE, MAP_NORE...
In the Linux kernel, the following vulnerability has been resolved: ksm: use range-walk function to jump over holes in scan_get_next_rmap_item Currently, scan_get_next_rmap_item() walks every page address in a VMA to locate mergeable pages. This becomes highly inefficient when scanning large virtual memory areas that contain mostly unmapped regions, causing ksmd to use large amount of cpu without deduplicating much pages. This patch replaces the per-address lookup with a range walk using walk_page_range(). The range walker allows KSM to skip over entire unmapped holes in a VMA, avoiding unnecessary lookups. This problem was previously discussed in [1]. Consider the following test program which creates a 32 TiB mapping in the virtual address space but only populates a single page: #include <unistd.h> #include <stdio.h> #include <sys/mman.h> /* 32 TiB */ const size_t size = 32ul * 1024 * 1024 * 1024 * 1024; int main() { char *area = mmap(NULL, size, PROT_READ | PROT_WRI
ksm: use range-walk function to jump over holes in scan_get_next_rmap_item