Описание
ELSA-2026-66325-0: kernel security, bug fix, and enhancement update (IMPORTANT)
[4.18.0-553.162.1]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.3
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985772]
[4.18.0-553.162.1]
- scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (Laurence Oberman) [RHEL-194117]
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Xin Long) [RHEL-228877] {CVE-2026-63801}
- tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (Xin Long) [RHEL-238050] {CVE-2026-68117}
- sctp: fix race between sctp_wait_for_connect and peeloff (Xin Long) [RHEL-229464] {CVE-2026-63971}
- sctp: diag: reject stale associations in dump_one path (Xin Long) [RHEL-231561] {CVE-2026-52917}
- sctp: validate stream count in sctp_process_strreset_inreq() (Xin Long) [RHEL-236135] {CVE-2026-68315}
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [RHEL-237394] {CVE-2026-68376}
- sctp: auth: verify auth requirement when auth_chunk is NULL (Xin Long) [RHEL-237088] {CVE-2026-68300}
- gfs2: harden gfs2_glock_hold (Andreas Gruenbacher) [RHEL-240340]
- gfs2: gfs2_glock_hold cleanup (Andreas Gruenbacher) [RHEL-240340]
- sctp: validate embedded INIT chunk and address list lengths in cookie (Xin Long) [RHEL-190202]
- sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (Xin Long) [RHEL-190202] {CVE-2026-53246}
- netfilter: nf_log: validate MAC header was set before dumping it (CKI Backport Bot) [RHEL-232055] {CVE-2026-52942}
- netfilter: nf_conntrack_sip: don't use simple_strtoul (CKI Backport Bot) [RHEL-232024] {CVE-2026-52986}
- scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-230822] {CVE-2025-68745}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225791] {CVE-2026-46149}
[4.18.0-553.161.1]
- security/keys: fix missed RCU read section on lookup (Bruno Meneguele) [RHEL-225679] {CVE-2026-64015}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227760] {CVE-2026-64113}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: use qdisc_pkt_len_segs_init() in sch_handle_ingress() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)->pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: init shinfo->gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: add more sanity checks to qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)->pkt_segs (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- sch_cake: do not use skb_mac_header() in cake_overhead() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: do not use skb_mac_header() in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: Skip GSO length estimation if transport header is not set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
[4.18.0-553.160.1]
- rhashtable: clear stale iter->p on table restart (CKI Backport Bot) [RHEL-248433] {CVE-2026-64563}
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246938] {CVE-2026-74480}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244910] {CVE-2026-72129}
- crypto: pcrypt - Fix handling of MAY_BACKLOG requests (Ricardo Robaina) [RHEL-226702] {CVE-2026-43493}
- crypto: pcrypt - Delay write to padata->info (Ricardo Robaina) [RHEL-226702] {CVE-2026-43493}
- crypto: pcrypt - Do not clear MAY_SLEEP flag in original request (Ricardo Robaina) [RHEL-226702] {CVE-2026-43493}
- smb: client: validate DFS referral PathConsumed (CKI Backport Bot) [RHEL-237655] {CVE-2026-68343}
- netfilter: synproxy: refresh tcphdr after skb_ensure_writable (CKI Backport Bot) [RHEL-228903] {CVE-2026-64007}
- netfilter: conntrack: remove sprintf usage (CKI Backport Bot) [RHEL-224448] {CVE-2026-53002}
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
kernel-tools-libs-devel
4.18.0-553.162.1.el8_10
bpftool
4.18.0-553.162.1.el8_10
kernel-cross-headers
4.18.0-553.162.1.el8_10
kernel-headers
4.18.0-553.162.1.el8_10
kernel-tools
4.18.0-553.162.1.el8_10
kernel-tools-libs
4.18.0-553.162.1.el8_10
perf
4.18.0-553.162.1.el8_10
python3-perf
4.18.0-553.162.1.el8_10
Oracle Linux x86_64
kernel-tools-libs-devel
4.18.0-553.162.1.el8_10
bpftool
4.18.0-553.162.1.el8_10
kernel-abi-stablelists
4.18.0-553.162.1.el8_10
kernel-core
4.18.0-553.162.1.el8_10
kernel-doc
4.18.0-553.162.1.el8_10
kernel-modules-extra
4.18.0-553.162.1.el8_10
kernel-tools
4.18.0-553.162.1.el8_10
kernel
4.18.0-553.162.1.el8_10
kernel-cross-headers
4.18.0-553.162.1.el8_10
kernel-debug
4.18.0-553.162.1.el8_10
kernel-debug-core
4.18.0-553.162.1.el8_10
kernel-debug-devel
4.18.0-553.162.1.el8_10
kernel-debug-modules
4.18.0-553.162.1.el8_10
kernel-debug-modules-extra
4.18.0-553.162.1.el8_10
kernel-devel
4.18.0-553.162.1.el8_10
kernel-headers
4.18.0-553.162.1.el8_10
kernel-modules
4.18.0-553.162.1.el8_10
kernel-tools-libs
4.18.0-553.162.1.el8_10
perf
4.18.0-553.162.1.el8_10
python3-perf
4.18.0-553.162.1.el8_10
Ссылки на источники
Связанные уязвимости
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clear cmds after chip reset Commit aefed3e5548f ("scsi: qla2xxx: target: Fix offline port handling and host reset handling") caused two problems: 1. Commands sent to FW, after chip reset got stuck and never freed as FW is not going to respond to them anymore. 2. BUG_ON(cmd->sg_mapped) in qlt_free_cmd(). Commit 26f9ce53817a ("scsi: qla2xxx: Fix missed DMA unmap for aborted commands") attempted to fix this, but introduced another bug under different circumstances when two different CPUs were racing to call qlt_unmap_sg() at the same time: BUG_ON(!valid_dma_direction(dir)) in dma_unmap_sg_attrs(). So revert "scsi: qla2xxx: Fix missed DMA unmap for aborted commands" and partially revert "scsi: qla2xxx: target: Fix offline port handling and host reset handling" at __qla2x00_abort_all_cmds.
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clear cmds after chip reset Commit aefed3e5548f ("scsi: qla2xxx: target: Fix offline port handling and host reset handling") caused two problems: 1. Commands sent to FW, after chip reset got stuck and never freed as FW is not going to respond to them anymore. 2. BUG_ON(cmd->sg_mapped) in qlt_free_cmd(). Commit 26f9ce53817a ("scsi: qla2xxx: Fix missed DMA unmap for aborted commands") attempted to fix this, but introduced another bug under different circumstances when two different CPUs were racing to call qlt_unmap_sg() at the same time: BUG_ON(!valid_dma_direction(dir)) in dma_unmap_sg_attrs(). So revert "scsi: qla2xxx: Fix missed DMA unmap for aborted commands" and partially revert "scsi: qla2xxx: target: Fix offline port handling and host reset handling" at __qla2x00_abort_all_cmds.
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clear cmds after chip reset Commit aefed3e5548f ("scsi: qla2xxx: target: Fix offline port handling and host reset handling") caused two problems: 1. Commands sent to FW, after chip reset got stuck and never freed as FW is not going to respond to them anymore. 2. BUG_ON(cmd->sg_mapped) in qlt_free_cmd(). Commit 26f9ce53817a ("scsi: qla2xxx: Fix missed DMA unmap for aborted commands") attempted to fix this, but introduced another bug under different circumstances when two different CPUs were racing to call qlt_unmap_sg() at the same time: BUG_ON(!valid_dma_direction(dir)) in dma_unmap_sg_attrs(). So revert "scsi: qla2xxx: Fix missed DMA unmap for aborted commands" and partially revert "scsi: qla2xxx: target: Fix offline port handling and host reset handling" at __qla2x00_abort_all_cmds.