Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-66180-0

Опубликовано: 10 сент. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-66180-0: kernel security, bug fix, and enhancement update (IMPORTANT)

[5.14.0-687.46.1]

  • Disable UKI signing [Orabug: 36571828]
  • Update Oracle Linux certificates (Kevin Lyons)
  • Disable signing for aarch64 (Ilya Okomin)
  • Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
  • Update x509.genkey [Orabug: 24817676]
  • Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
  • Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
  • Add Oracle Linux IMA certificates
  • Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985764]

[5.14.0-687.46.1]

  • tcp: call sk_data_ready() after listener migration (Felix Maurer) [RHEL-232236] {CVE-2026-46015}
  • flow_dissector: do not dissect PPPoE PFC frames (Felix Maurer) [RHEL-232633] {CVE-2026-46306}
  • inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (Felix Maurer) [RHEL-226126] {CVE-2026-46266}
  • ipv4: icmp: convert to dev_net_rcu() (Felix Maurer) [RHEL-226126]
  • ipv6: mcast: Fix use-after-free when processing MLD queries (Felix Maurer) [RHEL-226071] {CVE-2026-53275}
  • ipv6: prevent possible UaF in addrconf_permanent_addr() (Felix Maurer) [RHEL-225592] {CVE-2026-43339}
  • ipv6: account for fraggap on the paged allocation path (Felix Maurer) [RHEL-212891]
  • ipv4: account for fraggap on the paged allocation path (Felix Maurer) [RHEL-212891] {CVE-2026-53366}
  • inet: ping: fix recent breakage (Felix Maurer) [RHEL-212891]
  • net: unify alloclen calculation for paged requests (Felix Maurer) [RHEL-212891]
  • net: guard timestamp cmsgs to real error queue skbs (Felix Maurer) [RHEL-225858] {CVE-2026-53223}
  • rhashtable: clear stale iter->p on table restart (CKI Backport Bot) [RHEL-248451] {CVE-2026-64563}
  • net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246930] {CVE-2026-74480}
  • nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244971] {CVE-2026-72129}
  • Revert 'net/smc: Introduce TCP ULP support' (Jan Polensky) [RHEL-227559] {CVE-2026-46330}
  • smb: client: fix double-free in SMB2_close() replay (CKI Backport Bot) [RHEL-240049] {CVE-2026-64597}
  • crypto: pcrypt - Fix handling of MAY_BACKLOG requests (Ricardo Robaina) [RHEL-226689] {CVE-2026-43493}
  • net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (CKI Backport Bot) [RHEL-230988] {CVE-2026-64034}
  • scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225785] {CVE-2026-46149}
  • netfilter: conntrack: remove sprintf usage (CKI Backport Bot) [RHEL-224454] {CVE-2026-53002}
  • KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189457] {CVE-2026-43133}
  • mm/ksm: add option to deduplicate only zero pages (Andrea Arcangeli) [RHEL-249161]
  • mm/ksm: don't waste time searching stable tree for fast changing page (Andrea Arcangeli) [RHEL-249161]
  • mm/hugetlb.c: undo errant change (Andrea Arcangeli) [RHEL-249161]
  • mm/ksm: refactor out try_to_merge_with_zero_page() (Andrea Arcangeli) [RHEL-249161]

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

kernel-cross-headers

5.14.0-687.46.1.el9_8

kernel-tools-libs-devel

5.14.0-687.46.1.el9_8

libperf

5.14.0-687.46.1.el9_8

kernel-headers

5.14.0-687.46.1.el9_8

perf

5.14.0-687.46.1.el9_8

python3-perf

5.14.0-687.46.1.el9_8

rtla

5.14.0-687.46.1.el9_8

rv

5.14.0-687.46.1.el9_8

kernel-tools

5.14.0-687.46.1.el9_8

kernel-tools-libs

5.14.0-687.46.1.el9_8

Oracle Linux x86_64

kernel

5.14.0-687.46.1.el9_8

kernel-abi-stablelists

5.14.0-687.46.1.el9_8

kernel-core

5.14.0-687.46.1.el9_8

kernel-debug

5.14.0-687.46.1.el9_8

kernel-debug-core

5.14.0-687.46.1.el9_8

kernel-debug-modules

5.14.0-687.46.1.el9_8

kernel-debug-modules-core

5.14.0-687.46.1.el9_8

kernel-debug-modules-extra

5.14.0-687.46.1.el9_8

kernel-modules

5.14.0-687.46.1.el9_8

kernel-modules-core

5.14.0-687.46.1.el9_8

kernel-modules-extra

5.14.0-687.46.1.el9_8

kernel-tools

5.14.0-687.46.1.el9_8

kernel-tools-libs

5.14.0-687.46.1.el9_8

kernel-uki-virt-addons

5.14.0-687.46.1.el9_8

kernel-debug-devel

5.14.0-687.46.1.el9_8

kernel-debug-devel-matched

5.14.0-687.46.1.el9_8

kernel-devel

5.14.0-687.46.1.el9_8

kernel-devel-matched

5.14.0-687.46.1.el9_8

kernel-doc

5.14.0-687.46.1.el9_8

kernel-headers

5.14.0-687.46.1.el9_8

perf

5.14.0-687.46.1.el9_8

python3-perf

5.14.0-687.46.1.el9_8

rtla

5.14.0-687.46.1.el9_8

rv

5.14.0-687.46.1.el9_8

kernel-cross-headers

5.14.0-687.46.1.el9_8

kernel-tools-libs-devel

5.14.0-687.46.1.el9_8

libperf

5.14.0-687.46.1.el9_8

kernel-debug-uki-virt

5.14.0-687.46.1.el9_8

kernel-uki-virt

5.14.0-687.46.1.el9_8

Связанные уязвимости

rocky
4 дня назад

Important: kernel security, bug fix, and enhancement update

CVSS3: 7.9
ubuntu
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation Commit cc3ed80ae69f ("KVM: nSVM: always use vmcb01 to for vmsave/vmload of guest state") made KVM always use vmcb01 for the fields controlled by VMSAVE/VMLOAD, but it missed updating the VMLOAD/VMSAVE emulation code to always use vmcb01. As a result, if VMSAVE/VMLOAD is executed by an L2 guest and is not intercepted by L1, KVM will mistakenly use vmcb02. Always use vmcb01 instead of the current VMCB.

CVSS3: 7.9
redhat
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation Commit cc3ed80ae69f ("KVM: nSVM: always use vmcb01 to for vmsave/vmload of guest state") made KVM always use vmcb01 for the fields controlled by VMSAVE/VMLOAD, but it missed updating the VMLOAD/VMSAVE emulation code to always use vmcb01. As a result, if VMSAVE/VMLOAD is executed by an L2 guest and is not intercepted by L1, KVM will mistakenly use vmcb02. Always use vmcb01 instead of the current VMCB.

CVSS3: 7.9
nvd
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation Commit cc3ed80ae69f ("KVM: nSVM: always use vmcb01 to for vmsave/vmload of guest state") made KVM always use vmcb01 for the fields controlled by VMSAVE/VMLOAD, but it missed updating the VMLOAD/VMSAVE emulation code to always use vmcb01. As a result, if VMSAVE/VMLOAD is executed by an L2 guest and is not intercepted by L1, KVM will mistakenly use vmcb02. Always use vmcb01 instead of the current VMCB.

CVSS3: 7.9
debian
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: K ...