Описание
ELSA-2026-66180-0: kernel security, bug fix, and enhancement update (IMPORTANT)
[5.14.0-687.46.1]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985764]
[5.14.0-687.46.1]
- tcp: call sk_data_ready() after listener migration (Felix Maurer) [RHEL-232236] {CVE-2026-46015}
- flow_dissector: do not dissect PPPoE PFC frames (Felix Maurer) [RHEL-232633] {CVE-2026-46306}
- inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (Felix Maurer) [RHEL-226126] {CVE-2026-46266}
- ipv4: icmp: convert to dev_net_rcu() (Felix Maurer) [RHEL-226126]
- ipv6: mcast: Fix use-after-free when processing MLD queries (Felix Maurer) [RHEL-226071] {CVE-2026-53275}
- ipv6: prevent possible UaF in addrconf_permanent_addr() (Felix Maurer) [RHEL-225592] {CVE-2026-43339}
- ipv6: account for fraggap on the paged allocation path (Felix Maurer) [RHEL-212891]
- ipv4: account for fraggap on the paged allocation path (Felix Maurer) [RHEL-212891] {CVE-2026-53366}
- inet: ping: fix recent breakage (Felix Maurer) [RHEL-212891]
- net: unify alloclen calculation for paged requests (Felix Maurer) [RHEL-212891]
- net: guard timestamp cmsgs to real error queue skbs (Felix Maurer) [RHEL-225858] {CVE-2026-53223}
- rhashtable: clear stale iter->p on table restart (CKI Backport Bot) [RHEL-248451] {CVE-2026-64563}
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246930] {CVE-2026-74480}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244971] {CVE-2026-72129}
- Revert 'net/smc: Introduce TCP ULP support' (Jan Polensky) [RHEL-227559] {CVE-2026-46330}
- smb: client: fix double-free in SMB2_close() replay (CKI Backport Bot) [RHEL-240049] {CVE-2026-64597}
- crypto: pcrypt - Fix handling of MAY_BACKLOG requests (Ricardo Robaina) [RHEL-226689] {CVE-2026-43493}
- net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (CKI Backport Bot) [RHEL-230988] {CVE-2026-64034}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225785] {CVE-2026-46149}
- netfilter: conntrack: remove sprintf usage (CKI Backport Bot) [RHEL-224454] {CVE-2026-53002}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189457] {CVE-2026-43133}
- mm/ksm: add option to deduplicate only zero pages (Andrea Arcangeli) [RHEL-249161]
- mm/ksm: don't waste time searching stable tree for fast changing page (Andrea Arcangeli) [RHEL-249161]
- mm/hugetlb.c: undo errant change (Andrea Arcangeli) [RHEL-249161]
- mm/ksm: refactor out try_to_merge_with_zero_page() (Andrea Arcangeli) [RHEL-249161]
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
kernel-cross-headers
5.14.0-687.46.1.el9_8
kernel-tools-libs-devel
5.14.0-687.46.1.el9_8
libperf
5.14.0-687.46.1.el9_8
kernel-headers
5.14.0-687.46.1.el9_8
perf
5.14.0-687.46.1.el9_8
python3-perf
5.14.0-687.46.1.el9_8
rtla
5.14.0-687.46.1.el9_8
rv
5.14.0-687.46.1.el9_8
kernel-tools
5.14.0-687.46.1.el9_8
kernel-tools-libs
5.14.0-687.46.1.el9_8
Oracle Linux x86_64
kernel
5.14.0-687.46.1.el9_8
kernel-abi-stablelists
5.14.0-687.46.1.el9_8
kernel-core
5.14.0-687.46.1.el9_8
kernel-debug
5.14.0-687.46.1.el9_8
kernel-debug-core
5.14.0-687.46.1.el9_8
kernel-debug-modules
5.14.0-687.46.1.el9_8
kernel-debug-modules-core
5.14.0-687.46.1.el9_8
kernel-debug-modules-extra
5.14.0-687.46.1.el9_8
kernel-modules
5.14.0-687.46.1.el9_8
kernel-modules-core
5.14.0-687.46.1.el9_8
kernel-modules-extra
5.14.0-687.46.1.el9_8
kernel-tools
5.14.0-687.46.1.el9_8
kernel-tools-libs
5.14.0-687.46.1.el9_8
kernel-uki-virt-addons
5.14.0-687.46.1.el9_8
kernel-debug-devel
5.14.0-687.46.1.el9_8
kernel-debug-devel-matched
5.14.0-687.46.1.el9_8
kernel-devel
5.14.0-687.46.1.el9_8
kernel-devel-matched
5.14.0-687.46.1.el9_8
kernel-doc
5.14.0-687.46.1.el9_8
kernel-headers
5.14.0-687.46.1.el9_8
perf
5.14.0-687.46.1.el9_8
python3-perf
5.14.0-687.46.1.el9_8
rtla
5.14.0-687.46.1.el9_8
rv
5.14.0-687.46.1.el9_8
kernel-cross-headers
5.14.0-687.46.1.el9_8
kernel-tools-libs-devel
5.14.0-687.46.1.el9_8
libperf
5.14.0-687.46.1.el9_8
kernel-debug-uki-virt
5.14.0-687.46.1.el9_8
kernel-uki-virt
5.14.0-687.46.1.el9_8
Ссылки на источники
Связанные уязвимости
In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation Commit cc3ed80ae69f ("KVM: nSVM: always use vmcb01 to for vmsave/vmload of guest state") made KVM always use vmcb01 for the fields controlled by VMSAVE/VMLOAD, but it missed updating the VMLOAD/VMSAVE emulation code to always use vmcb01. As a result, if VMSAVE/VMLOAD is executed by an L2 guest and is not intercepted by L1, KVM will mistakenly use vmcb02. Always use vmcb01 instead of the current VMCB.
In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation Commit cc3ed80ae69f ("KVM: nSVM: always use vmcb01 to for vmsave/vmload of guest state") made KVM always use vmcb01 for the fields controlled by VMSAVE/VMLOAD, but it missed updating the VMLOAD/VMSAVE emulation code to always use vmcb01. As a result, if VMSAVE/VMLOAD is executed by an L2 guest and is not intercepted by L1, KVM will mistakenly use vmcb02. Always use vmcb01 instead of the current VMCB.
In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation Commit cc3ed80ae69f ("KVM: nSVM: always use vmcb01 to for vmsave/vmload of guest state") made KVM always use vmcb01 for the fields controlled by VMSAVE/VMLOAD, but it missed updating the VMLOAD/VMSAVE emulation code to always use vmcb01. As a result, if VMSAVE/VMLOAD is executed by an L2 guest and is not intercepted by L1, KVM will mistakenly use vmcb02. Always use vmcb01 instead of the current VMCB.
In the Linux kernel, the following vulnerability has been resolved: K ...