Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-66325-0

Опубликовано: 10 сент. 2026
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2026-66325-0: kernel security, bug fix, and enhancement update (IMPORTANT)

[4.18.0-553.162.1]

  • Update Oracle Linux certificates (Kevin Lyons)
  • Disable signing for aarch64 (Ilya Okomin)
  • Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
  • Update x509.genkey [Orabug: 24817676]
  • Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.3
  • Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]
  • Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985772]

[4.18.0-553.162.1]

  • scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (Laurence Oberman) [RHEL-194117]
  • tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Xin Long) [RHEL-228877] {CVE-2026-63801}
  • tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (Xin Long) [RHEL-238050] {CVE-2026-68117}
  • sctp: fix race between sctp_wait_for_connect and peeloff (Xin Long) [RHEL-229464] {CVE-2026-63971}
  • sctp: diag: reject stale associations in dump_one path (Xin Long) [RHEL-231561] {CVE-2026-52917}
  • sctp: validate stream count in sctp_process_strreset_inreq() (Xin Long) [RHEL-236135] {CVE-2026-68315}
  • sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [RHEL-237394] {CVE-2026-68376}
  • sctp: auth: verify auth requirement when auth_chunk is NULL (Xin Long) [RHEL-237088] {CVE-2026-68300}
  • gfs2: harden gfs2_glock_hold (Andreas Gruenbacher) [RHEL-240340]
  • gfs2: gfs2_glock_hold cleanup (Andreas Gruenbacher) [RHEL-240340]
  • sctp: validate embedded INIT chunk and address list lengths in cookie (Xin Long) [RHEL-190202]
  • sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (Xin Long) [RHEL-190202] {CVE-2026-53246}
  • netfilter: nf_log: validate MAC header was set before dumping it (CKI Backport Bot) [RHEL-232055] {CVE-2026-52942}
  • netfilter: nf_conntrack_sip: don't use simple_strtoul (CKI Backport Bot) [RHEL-232024] {CVE-2026-52986}
  • scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-230822] {CVE-2025-68745}
  • scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225791] {CVE-2026-46149}

[4.18.0-553.161.1]

  • security/keys: fix missed RCU read section on lookup (Bruno Meneguele) [RHEL-225679] {CVE-2026-64015}
  • ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227760] {CVE-2026-64113}
  • xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
  • net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
  • net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
  • net: use qdisc_pkt_len_segs_init() in sch_handle_ingress() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
  • net_sched: initialize qdisc_skb_cb(skb)->pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
  • net: init shinfo->gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
  • net: add more sanity checks to qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
  • net_sched: make room for (struct qdisc_skb_cb)->pkt_segs (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
  • net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
  • sch_cake: do not use skb_mac_header() in cake_overhead() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
  • net: do not use skb_mac_header() in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
  • net: Skip GSO length estimation if transport header is not set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}

[4.18.0-553.160.1]

  • rhashtable: clear stale iter->p on table restart (CKI Backport Bot) [RHEL-248433] {CVE-2026-64563}
  • net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246938] {CVE-2026-74480}
  • nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244910] {CVE-2026-72129}
  • crypto: pcrypt - Fix handling of MAY_BACKLOG requests (Ricardo Robaina) [RHEL-226702] {CVE-2026-43493}
  • crypto: pcrypt - Delay write to padata->info (Ricardo Robaina) [RHEL-226702] {CVE-2026-43493}
  • crypto: pcrypt - Do not clear MAY_SLEEP flag in original request (Ricardo Robaina) [RHEL-226702] {CVE-2026-43493}
  • smb: client: validate DFS referral PathConsumed (CKI Backport Bot) [RHEL-237655] {CVE-2026-68343}
  • netfilter: synproxy: refresh tcphdr after skb_ensure_writable (CKI Backport Bot) [RHEL-228903] {CVE-2026-64007}
  • netfilter: conntrack: remove sprintf usage (CKI Backport Bot) [RHEL-224448] {CVE-2026-53002}

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

kernel-tools-libs-devel

4.18.0-553.162.1.el8_10

bpftool

4.18.0-553.162.1.el8_10

kernel-cross-headers

4.18.0-553.162.1.el8_10

kernel-headers

4.18.0-553.162.1.el8_10

kernel-tools

4.18.0-553.162.1.el8_10

kernel-tools-libs

4.18.0-553.162.1.el8_10

perf

4.18.0-553.162.1.el8_10

python3-perf

4.18.0-553.162.1.el8_10

Oracle Linux x86_64

kernel-tools-libs-devel

4.18.0-553.162.1.el8_10

bpftool

4.18.0-553.162.1.el8_10

kernel-abi-stablelists

4.18.0-553.162.1.el8_10

kernel-core

4.18.0-553.162.1.el8_10

kernel-doc

4.18.0-553.162.1.el8_10

kernel-modules-extra

4.18.0-553.162.1.el8_10

kernel-tools

4.18.0-553.162.1.el8_10

kernel

4.18.0-553.162.1.el8_10

kernel-cross-headers

4.18.0-553.162.1.el8_10

kernel-debug

4.18.0-553.162.1.el8_10

kernel-debug-core

4.18.0-553.162.1.el8_10

kernel-debug-devel

4.18.0-553.162.1.el8_10

kernel-debug-modules

4.18.0-553.162.1.el8_10

kernel-debug-modules-extra

4.18.0-553.162.1.el8_10

kernel-devel

4.18.0-553.162.1.el8_10

kernel-headers

4.18.0-553.162.1.el8_10

kernel-modules

4.18.0-553.162.1.el8_10

kernel-tools-libs

4.18.0-553.162.1.el8_10

perf

4.18.0-553.162.1.el8_10

python3-perf

4.18.0-553.162.1.el8_10

Связанные уязвимости

rocky
7 дней назад

Important: kernel security, bug fix, and enhancement update

CVSS3: 9.8
ubuntu
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clear cmds after chip reset Commit aefed3e5548f ("scsi: qla2xxx: target: Fix offline port handling and host reset handling") caused two problems: 1. Commands sent to FW, after chip reset got stuck and never freed as FW is not going to respond to them anymore. 2. BUG_ON(cmd->sg_mapped) in qlt_free_cmd(). Commit 26f9ce53817a ("scsi: qla2xxx: Fix missed DMA unmap for aborted commands") attempted to fix this, but introduced another bug under different circumstances when two different CPUs were racing to call qlt_unmap_sg() at the same time: BUG_ON(!valid_dma_direction(dir)) in dma_unmap_sg_attrs(). So revert "scsi: qla2xxx: Fix missed DMA unmap for aborted commands" and partially revert "scsi: qla2xxx: target: Fix offline port handling and host reset handling" at __qla2x00_abort_all_cmds.

CVSS3: 4.7
redhat
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clear cmds after chip reset Commit aefed3e5548f ("scsi: qla2xxx: target: Fix offline port handling and host reset handling") caused two problems: 1. Commands sent to FW, after chip reset got stuck and never freed as FW is not going to respond to them anymore. 2. BUG_ON(cmd->sg_mapped) in qlt_free_cmd(). Commit 26f9ce53817a ("scsi: qla2xxx: Fix missed DMA unmap for aborted commands") attempted to fix this, but introduced another bug under different circumstances when two different CPUs were racing to call qlt_unmap_sg() at the same time: BUG_ON(!valid_dma_direction(dir)) in dma_unmap_sg_attrs(). So revert "scsi: qla2xxx: Fix missed DMA unmap for aborted commands" and partially revert "scsi: qla2xxx: target: Fix offline port handling and host reset handling" at __qla2x00_abort_all_cmds.

CVSS3: 9.8
nvd
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clear cmds after chip reset Commit aefed3e5548f ("scsi: qla2xxx: target: Fix offline port handling and host reset handling") caused two problems: 1. Commands sent to FW, after chip reset got stuck and never freed as FW is not going to respond to them anymore. 2. BUG_ON(cmd->sg_mapped) in qlt_free_cmd(). Commit 26f9ce53817a ("scsi: qla2xxx: Fix missed DMA unmap for aborted commands") attempted to fix this, but introduced another bug under different circumstances when two different CPUs were racing to call qlt_unmap_sg() at the same time: BUG_ON(!valid_dma_direction(dir)) in dma_unmap_sg_attrs(). So revert "scsi: qla2xxx: Fix missed DMA unmap for aborted commands" and partially revert "scsi: qla2xxx: target: Fix offline port handling and host reset handling" at __qla2x00_abort_all_cmds.

msrc
9 месяцев назад

scsi: qla2xxx: Clear cmds after chip reset