Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-68507

Опубликовано: 17 сент. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-68507: kernel security, bug fix, and enhancement update (IMPORTANT)

[6.12.0-211.56.1]

  • Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
  • Disable UKI signing [Orabug: 36571828]
  • Update Oracle Linux certificates (Kevin Lyons)
  • Disable signing for aarch64 (Ilya Okomin)
  • Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
  • Update x509.genkey [Orabug: 24817676]
  • Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
  • Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
  • Add Oracle Linux IMA certificates
  • Update module name for cryptographic module [Orabug: 37400433]
  • Clean git history at setup stage

[6.12.0-211.56.1]

  • redhat/configs: automotive: enable SENSORS_INA2XX (Jared Kangas) [RHEL-255518]
  • hwmon: (ina2xx) Use scoped_guard() to acquire the subsystem lock (Jared Kangas) [RHEL-255518]
  • hwmon: (ina2xx) clean up unused define and outdated comment (Jared Kangas) [RHEL-255518]
  • hwmon: (ina2xx) Make it easier to add more devices (Jared Kangas) [RHEL-255518]
  • hwmon: (ina2xx) Rely on subsystem locking (Jared Kangas) [RHEL-255518]
  • hwmon: (ina2xx) make regulator 'vs' support optional (Jared Kangas) [RHEL-255518]
  • hwmon: (ina226) Add support for SY24655 (Jared Kangas) [RHEL-255518]
  • hwmon: (ina2xx) Add support for INA260 (Jared Kangas) [RHEL-255518]
  • hwmon: (ina2xx) Add support for has_alerts configuration flag (Jared Kangas) [RHEL-255518]
  • hwmon: (core) Use device name as a fallback in devm_hwmon_device_register_with_info (Jared Kangas) [RHEL-255518]
  • hwmon: Support guard() and scoped_guard for subsystem locks (Jared Kangas) [RHEL-255518]
  • hwmon: Serialize accesses in hwmon core (Jared Kangas) [RHEL-255518]
  • wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (Izabela Bakollari) [RHEL-241004] {CVE-2026-68363}
  • wifi: iwlwifi: mld: stop TX during firmware restart (Izabela Bakollari) [RHEL-243307] {CVE-2026-64175}
  • wifi: iwlwifi: mvm: fix driver-set TX rates on old devices (Izabela Bakollari) [RHEL-243363] {CVE-2026-64176}
  • net: wwan: t7xx: fix potential skb->frags overflow in RX path (Izabela Bakollari) [RHEL-245528] {CVE-2026-23172}
  • wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (Izabela Bakollari) [RHEL-246405] {CVE-2026-63869}
  • smb: client: fix multiuser mount with krb5 (Jorge San Emeterio Villalain) [RHEL-254105]
  • time/sched_clock: Export symbol for sched_clock register function (Eric Chanudet) [RHEL-255225]
  • clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path (Mattijs Korpershoek) [RHEL-255519]
  • configs: Add NXP timer Kconfig options for automotive builds (Mattijs Korpershoek) [RHEL-255519]
  • clocksource: move NXP timer selection to drivers/clocksource (Mattijs Korpershoek) [RHEL-255519]
  • arm64: dts: s32g: add PIT support for s32g2 and s32g3 (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/nxp-pit: Prevent driver unbind (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/nxp-pit: Add NXP Automotive s32g2 / s32g3 support (Mattijs Korpershoek) [RHEL-255519]
  • ARM: imx: Kconfig: Adjust select after renamed config option (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Rename the VF PIT to NXP PIT (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Unify the function name for irq ack (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Consolidate calls to pit_*_disable/enable (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Encapsulate set counter function (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Enable and disable module on error (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Encapsulate clocksource enable / disable (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Use the node name for the interrupt and timer names (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Encapsulate the PTLCVAL macro (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Encapsulate the macros (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Register the clocksource from the driver (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Convert raw values to BIT macros (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Allocate the struct timer at init time (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Encapsulate the initialization of the cycles_per_jiffy (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Pass the cpu number as parameter (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Rework the base address usage (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Set the scene for multiple timers (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Add COMPILE_TEST option (Mattijs Korpershoek) [RHEL-255519]
  • clocksource/drivers/vf-pit: Replace raw_readl/writel to readl/writel (Mattijs Korpershoek) [RHEL-255519]
  • redhat/configs: automotive: enable NVMEM_S32G_OCOTP (Mattijs Korpershoek) [RHEL-255516]
  • arm64: dts: s32g: Add device tree information for the OCOTP driver (Mattijs Korpershoek) [RHEL-255516]
  • nvmem: s32g-ocotp: Add driver for S32G OCOTP (Mattijs Korpershoek) [RHEL-255516]
  • dt-bindings: nvmem: Add the nxp,s32g-ocotp yaml file (Mattijs Korpershoek) [RHEL-255516]
  • octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (Michal Schmidt) [RHEL-231041] {CVE-2026-72045}
  • octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify (Michal Schmidt) [RHEL-231041] {CVE-2026-63923}
  • dm_early_create: fix freeing used table on dm_resume failure (CKI Backport Bot) [RHEL-244953] {CVE-2026-72102}
  • net: slip: serialize receive against buffer reallocation (CKI Backport Bot) [RHEL-241018] {CVE-2026-68143}
  • net: qrtr: restrict socket creation to the initial network namespace (CKI Backport Bot) [RHEL-240243] {CVE-2026-68294}
  • ALSA: hda/tas2781: Fix device-0 reset issue and handle -EXDEV in block data processing (CKI Backport Bot) [RHEL-239776]
  • ice: reject out-of-range ptype in ice_parser_profile_init (CKI Backport Bot) [RHEL-237211] {CVE-2026-68128}
  • ALSA: timer: don't re-enter an instance callback that is still running (CKI Backport Bot) [RHEL-237201] {CVE-2026-68200}
  • netfilter: handle unreadable frags (CKI Backport Bot) [RHEL-234265] {CVE-2026-64414}
  • net: ena: PHC: Fix potential use-after-free in get_timestamp (CKI Backport Bot) [RHEL-230631] {CVE-2026-52971}
  • ALSA: timer: Fix UAF at snd_timer_user_params() (CKI Backport Bot) [RHEL-228700] {CVE-2026-53192}
  • ALSA: seq: Serialize UMP output teardown with event_input (CKI Backport Bot) [RHEL-227727] {CVE-2026-64029}
  • ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes (CKI Backport Bot) [RHEL-227086] {CVE-2026-53193}
  • ALSA: timer: Forcibly close timer instances at closing (CKI Backport Bot) [RHEL-227086] {CVE-2026-53193}
  • hwrng: virtio: clamp device-reported used.len at copy_data() (CKI Backport Bot) [RHEL-225748] {CVE-2026-64456}
  • IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (CKI Backport Bot) [RHEL-191611] {CVE-2026-53176}
  • soc: qcom: socinfo: Avoid out of bounds read of serial number (CKI Backport Bot) [RHEL-191223] {CVE-2024-58007}

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

kernel-cross-headers

6.12.0-211.56.1.el10_2

kernel-headers

6.12.0-211.56.1.el10_2

kernel-tools

6.12.0-211.56.1.el10_2

kernel-tools-libs

6.12.0-211.56.1.el10_2

kernel-tools-libs-devel

6.12.0-211.56.1.el10_2

libperf

6.12.0-211.56.1.el10_2

perf

6.12.0-211.56.1.el10_2

python3-perf

6.12.0-211.56.1.el10_2

rtla

6.12.0-211.56.1.el10_2

rv

6.12.0-211.56.1.el10_2

Oracle Linux x86_64

kernel

6.12.0-211.56.1.el10_2

kernel-abi-stablelists

6.12.0-211.56.1.el10_2

kernel-core

6.12.0-211.56.1.el10_2

kernel-cross-headers

6.12.0-211.56.1.el10_2

kernel-debug

6.12.0-211.56.1.el10_2

kernel-debug-core

6.12.0-211.56.1.el10_2

kernel-debug-devel

6.12.0-211.56.1.el10_2

kernel-debug-devel-matched

6.12.0-211.56.1.el10_2

kernel-debug-modules

6.12.0-211.56.1.el10_2

kernel-debug-modules-core

6.12.0-211.56.1.el10_2

kernel-debug-modules-extra

6.12.0-211.56.1.el10_2

kernel-debug-uki-virt

6.12.0-211.56.1.el10_2

kernel-devel

6.12.0-211.56.1.el10_2

kernel-devel-matched

6.12.0-211.56.1.el10_2

kernel-doc

6.12.0-211.56.1.el10_2

kernel-headers

6.12.0-211.56.1.el10_2

kernel-modules

6.12.0-211.56.1.el10_2

kernel-modules-core

6.12.0-211.56.1.el10_2

kernel-modules-extra

6.12.0-211.56.1.el10_2

kernel-modules-extra-matched

6.12.0-211.56.1.el10_2

kernel-tools

6.12.0-211.56.1.el10_2

kernel-tools-libs

6.12.0-211.56.1.el10_2

kernel-tools-libs-devel

6.12.0-211.56.1.el10_2

kernel-uki-virt

6.12.0-211.56.1.el10_2

kernel-uki-virt-addons

6.12.0-211.56.1.el10_2

libperf

6.12.0-211.56.1.el10_2

perf

6.12.0-211.56.1.el10_2

python3-perf

6.12.0-211.56.1.el10_2

rtla

6.12.0-211.56.1.el10_2

rv

6.12.0-211.56.1.el10_2

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: soc: qcom: socinfo: Avoid out of bounds read of serial number On MSM8916 devices, the serial number exposed in sysfs is constant and does not change across individual devices. It's always: db410c:/sys/devices/soc0$ cat serial_number 2644893864 The firmware used on MSM8916 exposes SOCINFO_VERSION(0, 8), which does not have support for the serial_num field in the socinfo struct. There is an existing check to avoid exposing the serial number in that case, but it's not correct: When checking the item_size returned by SMEM, we need to make sure the *end* of the serial_num is within bounds, instead of comparing with the *start* offset. The serial_number currently exposed on MSM8916 devices is just an out of bounds read of whatever comes after the socinfo struct in SMEM. Fix this by changing offsetof() to offsetofend(), so that the size of the field is also taken into account.

CVSS3: 7.1
redhat
больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: soc: qcom: socinfo: Avoid out of bounds read of serial number On MSM8916 devices, the serial number exposed in sysfs is constant and does not change across individual devices. It's always: db410c:/sys/devices/soc0$ cat serial_number 2644893864 The firmware used on MSM8916 exposes SOCINFO_VERSION(0, 8), which does not have support for the serial_num field in the socinfo struct. There is an existing check to avoid exposing the serial number in that case, but it's not correct: When checking the item_size returned by SMEM, we need to make sure the *end* of the serial_num is within bounds, instead of comparing with the *start* offset. The serial_number currently exposed on MSM8916 devices is just an out of bounds read of whatever comes after the socinfo struct in SMEM. Fix this by changing offsetof() to offsetofend(), so that the size of the field is also taken into account.

CVSS3: 7.1
nvd
больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: soc: qcom: socinfo: Avoid out of bounds read of serial number On MSM8916 devices, the serial number exposed in sysfs is constant and does not change across individual devices. It's always: db410c:/sys/devices/soc0$ cat serial_number 2644893864 The firmware used on MSM8916 exposes SOCINFO_VERSION(0, 8), which does not have support for the serial_num field in the socinfo struct. There is an existing check to avoid exposing the serial number in that case, but it's not correct: When checking the item_size returned by SMEM, we need to make sure the *end* of the serial_num is within bounds, instead of comparing with the *start* offset. The serial_number currently exposed on MSM8916 devices is just an out of bounds read of whatever comes after the socinfo struct in SMEM. Fix this by changing offsetof() to offsetofend(), so that the size of the field is also taken into account.

CVSS3: 7.1
msrc
больше 1 года назад

soc: qcom: socinfo: Avoid out of bounds read of serial number

CVSS3: 7.1
debian
больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: s ...