Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-67150-0

Опубликовано: 14 сент. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-67150-0: kernel security, bug fix, and enhancement update (IMPORTANT)

[5.14.0-687.47.1]

  • Disable UKI signing [Orabug: 36571828]
  • Update Oracle Linux certificates (Kevin Lyons)
  • Disable signing for aarch64 (Ilya Okomin)
  • Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
  • Update x509.genkey [Orabug: 24817676]
  • Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
  • Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
  • Add Oracle Linux IMA certificates
  • Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985764]

[5.14.0-687.47.1]

  • dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244958] {CVE-2026-72098}
  • mm/khugepaged: write all dirty file folios when collapsing (Rafael Aquini) [RHEL-236332] {CVE-2026-68086}
  • drm/amdgpu: Fix use-after-free race in VM acquire (CKI Backport Bot) [RHEL-222396] {CVE-2026-43370}
  • drm/i915: Fix potential overflow of shmem scatterlist length (CKI Backport Bot) [RHEL-222481] {CVE-2026-43368}
  • drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (CKI Backport Bot) [RHEL-222417] {CVE-2026-31656}
  • drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CKI Backport Bot) [RHEL-221275] {CVE-2026-31566}
  • drm/xe: always keep track of remap prev/next (CKI Backport Bot) [RHEL-222300] {CVE-2026-31479}
  • drm/xe: Issue GGTT invalidation under lock in ggtt_node_remove (Jose Exposito) [RHEL-222458]
  • drm/xe: Open-code GGTT MMIO access protection (CKI Backport Bot) [RHEL-222458] {CVE-2026-23466}
  • drm/xe/pt: Reset current_op in xe_pt_update_ops_init() (Jose Exposito) [RHEL-236583] {CVE-2026-68264}
  • tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Xin Long) [RHEL-228880] {CVE-2026-63801}
  • tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (Xin Long) [RHEL-238037] {CVE-2026-68117}
  • sctp: fix race between sctp_wait_for_connect and peeloff (Xin Long) [RHEL-229470] {CVE-2026-63971}
  • sctp: diag: reject stale associations in dump_one path (Xin Long) [RHEL-231574] {CVE-2026-52917}
  • sctp: validate stream count in sctp_process_strreset_inreq() (Xin Long) [RHEL-236147] {CVE-2026-68315}
  • sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [RHEL-237395] {CVE-2026-68376}
  • sctp: auth: verify auth requirement when auth_chunk is NULL (Xin Long) [RHEL-237093] {CVE-2026-68300}
  • selftests: nft_queue.sh: add a parallel stress test (Florian Westphal) [RHEL-224489]
  • kselftest: add test for nfqueue induced conntrack race (Florian Westphal) [RHEL-224489]
  • selftests: netfilter: nft_queue.sh: avoid flakes on debug kernels (Florian Westphal) [RHEL-224489]
  • selftests: netfilter: nft_queue.sh: fix spurious timeout on debug kernel (Florian Westphal) [RHEL-224489]
  • selftests: netfilter: nft_queue.sh: reduce test file size for debug build (Florian Westphal) [RHEL-224489]
  • netfilter: nfnetlink_queue: make hash table per queue (Florian Westphal) [RHEL-224489] {CVE-2026-43084}
  • netfilter: nfnetlink_queue: optimize verdict lookup with hash table (Florian Westphal) [RHEL-224489]
  • netfilter: nfnetlink_queue: nfqnl_instance GFP_ATOMIC -> GFP_KERNEL_ACCOUNT allocation (Florian Westphal) [RHEL-224489]
  • scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-235907] {CVE-2025-68745}
  • sctp: validate embedded INIT chunk and address list lengths in cookie (Xin Long) [RHEL-190206]
  • sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (Xin Long) [RHEL-190206] {CVE-2026-53246}
  • wifi: cfg80211: reject empty PMSR peer lists (Jose Ignacio Tornos Martinez) [RHEL-237652] {CVE-2026-68406}
  • wifi: cfg80211: reject unsupported PMSR FTM location requests (Jose Ignacio Tornos Martinez) [RHEL-237652] {CVE-2026-68406}
  • wifi: cfg80211: validate PMSR measurement type data (Jose Ignacio Tornos Martinez) [RHEL-237652] {CVE-2026-68406}
  • wifi: cfg80211: validate PMSR FTM preamble range (Jose Ignacio Tornos Martinez) [RHEL-237652] {CVE-2026-68406}
  • wifi: cfg80211: bound element ID read when checking non-inheritance (Jose Ignacio Tornos Martinez) [RHEL-236961] {CVE-2026-68402}
  • wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232010] {CVE-2026-64255}
  • wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb (Jose Ignacio Tornos Martinez) [RHEL-231682] {CVE-2026-64117}
  • wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231682] {CVE-2026-64117}
  • wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230975] {CVE-2026-64037}
  • wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230587] {CVE-2026-53182}
  • net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229728] {CVE-2026-52947}
  • wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227619] {CVE-2026-64515}
  • wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227619] {CVE-2026-64515}
  • Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232670] {CVE-2026-53072}
  • Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231059] {CVE-2026-63947}
  • Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230073] {CVE-2026-53209}
  • Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230005] {CVE-2026-63944}
  • Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228756] {CVE-2026-63975}
  • scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (CKI Backport Bot) [RHEL-228721] {CVE-2026-63889}
  • Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227910] {CVE-2026-63946}
  • ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227882] {CVE-2026-64113}
  • Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227536] {CVE-2026-43334}
  • iommu/amd: Fix clone_alias() to use the original device's devid (CKI Backport Bot) [RHEL-227454] {CVE-2026-53053}
  • Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-226431] {CVE-2026-63945}
  • Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame (CKI Backport Bot) [RHEL-225646] {CVE-2026-53254}
  • Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225646] {CVE-2026-53254}
  • Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225576] {CVE-2026-53256}
  • Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225553] {CVE-2026-52918}
  • xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188228] {CVE-2026-53091}
  • net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188228] {CVE-2026-53091}
  • net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188228] {CVE-2026-53091}
  • net_sched: initialize qdisc_skb_cb(skb)->pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188228] {CVE-2026-53091}
  • net: init shinfo->gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188228] {CVE-2026-53091}
  • net_sched: make room for (struct qdisc_skb_cb)->pkt_segs (Ivan Vecera) [RHEL-188228] {CVE-2026-53091}
  • net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188228] {CVE-2026-53091}
  • rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193025]
  • rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193025]
  • qede: fix off-by-one in BD ring consumption on build_skb failure (CKI Backport Bot) [RHEL-193050]
  • rtnetlink: add missing netlink_ns_capable() check for peer netns (Guillaume Nault) [RHEL-172532] {CVE-2026-31692}
  • rtnetlink: Try the outer netns attribute in rtnl_get_peer_net(). (Guillaume Nault) [RHEL-172532] {CVE-2026-31692}
  • rtnetlink: fix double call of rtnl_link_get_net_ifla() (Guillaume Nault) [RHEL-172532] {CVE-2026-31692}
  • vxcan: Set VXCAN_INFO_PEER to vxcan_link_ops.peer_type. (Guillaume Nault) [RHEL-172532] {CVE-2026-31692}
  • veth: Set VETH_INFO_PEER to veth_link_ops.peer_type. (Guillaume Nault) [RHEL-172532] {CVE-2026-31692}
  • rtnetlink: Add peer_type in struct rtnl_link_ops. (Guillaume Nault) [RHEL-172532] {CVE-2026-31692}
  • gfs2: Fix data loss during inode evict (Andreas Gruenbacher) [RHEL-178219]
  • gfs2: minor evict_[un]linked_inode cleanup (Andreas Gruenbacher) [RHEL-178219]
  • gfs2: Avoid unnecessary transactions in evict_linked_inode (Andreas Gruenbacher) [RHEL-178219]
  • gfs2: Remove unnecessary check in gfs2_evict_inode (Andreas Gruenbacher) [RHEL-178219]
  • gfs2: Call unlock_new_inode before d_instantiate (Andreas Gruenbacher) [RHEL-178219]
  • gfs2: Don't remember delete unless it's successful (Andreas Gruenbacher) [RHEL-178219]
  • gfs2: Remove redundant check for GLF_INSTANTIATE_NEEDED (Andreas Gruenbacher) [RHEL-178219]
  • gfs2: fiemap page fault fix (Andreas Gruenbacher) [RHEL-178219]
  • gfs2: Don't get stuck writing page onto itself under direct I/O (Andreas Gruenbacher) [RHEL-178219]

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

kernel-cross-headers

5.14.0-687.47.1.el9_8

kernel-tools-libs-devel

5.14.0-687.47.1.el9_8

libperf

5.14.0-687.47.1.el9_8

kernel-tools

5.14.0-687.47.1.el9_8

kernel-tools-libs

5.14.0-687.47.1.el9_8

kernel-headers

5.14.0-687.47.1.el9_8

perf

5.14.0-687.47.1.el9_8

python3-perf

5.14.0-687.47.1.el9_8

rtla

5.14.0-687.47.1.el9_8

rv

5.14.0-687.47.1.el9_8

Oracle Linux x86_64

kernel

5.14.0-687.47.1.el9_8

kernel-core

5.14.0-687.47.1.el9_8

kernel-debug-core

5.14.0-687.47.1.el9_8

kernel-debug-modules

5.14.0-687.47.1.el9_8

kernel-debug-modules-core

5.14.0-687.47.1.el9_8

kernel-uki-virt

5.14.0-687.47.1.el9_8

kernel-debug-devel

5.14.0-687.47.1.el9_8

kernel-debug-devel-matched

5.14.0-687.47.1.el9_8

kernel-devel

5.14.0-687.47.1.el9_8

kernel-devel-matched

5.14.0-687.47.1.el9_8

kernel-doc

5.14.0-687.47.1.el9_8

kernel-headers

5.14.0-687.47.1.el9_8

perf

5.14.0-687.47.1.el9_8

python3-perf

5.14.0-687.47.1.el9_8

rtla

5.14.0-687.47.1.el9_8

rv

5.14.0-687.47.1.el9_8

kernel-cross-headers

5.14.0-687.47.1.el9_8

kernel-tools-libs-devel

5.14.0-687.47.1.el9_8

libperf

5.14.0-687.47.1.el9_8

kernel-abi-stablelists

5.14.0-687.47.1.el9_8

kernel-debug

5.14.0-687.47.1.el9_8

kernel-debug-modules-extra

5.14.0-687.47.1.el9_8

kernel-debug-uki-virt

5.14.0-687.47.1.el9_8

kernel-modules

5.14.0-687.47.1.el9_8

kernel-modules-core

5.14.0-687.47.1.el9_8

kernel-modules-extra

5.14.0-687.47.1.el9_8

kernel-tools

5.14.0-687.47.1.el9_8

kernel-tools-libs

5.14.0-687.47.1.el9_8

kernel-uki-virt-addons

5.14.0-687.47.1.el9_8

Связанные уязвимости

oracle-oval
3 дня назад

ELSA-2026-67471-0: kernel security, bug fix, and enhancement update (IMPORTANT)

CVSS3: 9.8
ubuntu
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clear cmds after chip reset Commit aefed3e5548f ("scsi: qla2xxx: target: Fix offline port handling and host reset handling") caused two problems: 1. Commands sent to FW, after chip reset got stuck and never freed as FW is not going to respond to them anymore. 2. BUG_ON(cmd->sg_mapped) in qlt_free_cmd(). Commit 26f9ce53817a ("scsi: qla2xxx: Fix missed DMA unmap for aborted commands") attempted to fix this, but introduced another bug under different circumstances when two different CPUs were racing to call qlt_unmap_sg() at the same time: BUG_ON(!valid_dma_direction(dir)) in dma_unmap_sg_attrs(). So revert "scsi: qla2xxx: Fix missed DMA unmap for aborted commands" and partially revert "scsi: qla2xxx: target: Fix offline port handling and host reset handling" at __qla2x00_abort_all_cmds.

CVSS3: 4.7
redhat
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clear cmds after chip reset Commit aefed3e5548f ("scsi: qla2xxx: target: Fix offline port handling and host reset handling") caused two problems: 1. Commands sent to FW, after chip reset got stuck and never freed as FW is not going to respond to them anymore. 2. BUG_ON(cmd->sg_mapped) in qlt_free_cmd(). Commit 26f9ce53817a ("scsi: qla2xxx: Fix missed DMA unmap for aborted commands") attempted to fix this, but introduced another bug under different circumstances when two different CPUs were racing to call qlt_unmap_sg() at the same time: BUG_ON(!valid_dma_direction(dir)) in dma_unmap_sg_attrs(). So revert "scsi: qla2xxx: Fix missed DMA unmap for aborted commands" and partially revert "scsi: qla2xxx: target: Fix offline port handling and host reset handling" at __qla2x00_abort_all_cmds.

CVSS3: 9.8
nvd
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clear cmds after chip reset Commit aefed3e5548f ("scsi: qla2xxx: target: Fix offline port handling and host reset handling") caused two problems: 1. Commands sent to FW, after chip reset got stuck and never freed as FW is not going to respond to them anymore. 2. BUG_ON(cmd->sg_mapped) in qlt_free_cmd(). Commit 26f9ce53817a ("scsi: qla2xxx: Fix missed DMA unmap for aborted commands") attempted to fix this, but introduced another bug under different circumstances when two different CPUs were racing to call qlt_unmap_sg() at the same time: BUG_ON(!valid_dma_direction(dir)) in dma_unmap_sg_attrs(). So revert "scsi: qla2xxx: Fix missed DMA unmap for aborted commands" and partially revert "scsi: qla2xxx: target: Fix offline port handling and host reset handling" at __qla2x00_abort_all_cmds.

msrc
9 месяцев назад

scsi: qla2xxx: Clear cmds after chip reset