Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-68570

Опубликовано: 18 сент. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-68570: kernel security, bug fix, and enhancement update (IMPORTANT)

[5.14.0-687.49.1]

  • Disable UKI signing [Orabug: 36571828]
  • Update Oracle Linux certificates (Kevin Lyons)
  • Disable signing for aarch64 (Ilya Okomin)
  • Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
  • Update x509.genkey [Orabug: 24817676]
  • Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
  • Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
  • Add Oracle Linux IMA certificates
  • Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985764]

[5.14.0-687.49.1]

  • selinux: check connect-related permissions on TCP Fast Open (CKI Backport Bot) [RHEL-258014] {CVE-2026-72243}
  • gfs2: Get rid of sd_async_glock_wait (Andreas Gruenbacher) [RHEL-253986]
  • watchdog: fix hrtimer start when pretimeout is zero (Krzysztof Pawlinski) [RHEL-255217]
  • iommu/vt-d: Fix UCTP context table slot when copying root entries (Desnes Nunes) [RHEL-256733]
  • wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (Izabela Bakollari) [RHEL-246399] {CVE-2026-63869}
  • wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (Izabela Bakollari) [RHEL-240350] {CVE-2026-64174}
  • wifi: brcmfmac: cyw: fix heap overflow on a short auth frame (Izabela Bakollari) [RHEL-242723] {CVE-2026-72003}
  • net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() (Izabela Bakollari) [RHEL-244100] {CVE-2026-72298}
  • wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (Izabela Bakollari) [RHEL-241012] {CVE-2026-68363}
  • wifi: iwlwifi: mld: stop TX during firmware restart (Izabela Bakollari) [RHEL-243302] {CVE-2026-64175}
  • wifi: iwlwifi: mvm: fix driver-set TX rates on old devices (Izabela Bakollari) [RHEL-243366] {CVE-2026-64176}
  • net: wwan: t7xx: fix potential skb->frags overflow in RX path (Izabela Bakollari) [RHEL-245512] {CVE-2026-23172}
  • gfs2: Remove the glock lru list and shrinker (Andreas Gruenbacher) [RHEL-252544]
  • gfs2: Skip dlm unlocks earlier (Andreas Gruenbacher) [RHEL-252544]
  • gfs2: Don't cache unreferenced glocks (Andreas Gruenbacher) [RHEL-252544]
  • gfs2: Enable automatic glock hash table shrinking (Andreas Gruenbacher) [RHEL-252544]
  • gfs2: Introduce glock_{type,number,sbd} helpers (Andreas Gruenbacher) [RHEL-252544]
  • gfs2: Minor gfs2_glock_cb cleanup (Andreas Gruenbacher) [RHEL-252544]
  • gfs2: Clean up glock demote logic (Andreas Gruenbacher) [RHEL-252544]
  • libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (CKI Backport Bot) [RHEL-237156] {CVE-2026-68159}
  • libceph: Amend checking to fix make W=1 build breakage (CKI Backport Bot) [RHEL-237156] {CVE-2026-68159}
  • gfs2: Clean up SDF_JOURNAL_LIVE flag handling (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: No longer thaw filesystems during a withdraw (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: gfs2_freeze_unlock cleanup (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: Refcounting fix in gfs2_thaw_super (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: Minor gfs2_{freeze,thaw}_super cleanup (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: Withdraw immediately in gfs2_trans_add_meta (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: New gfs2_withdraw_helper (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: Clean up properly during a withdraw (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: Rename gfs2_{gl_dq_holders => withdraw_glocks} (Andreas Gruenbacher) [RHEL-252540]
  • Revert 'gfs2: fix infinite loop when checking ail item count before go_inval' (Andreas Gruenbacher) [RHEL-252540]
  • Revert 'gfs2: Allow some glocks to be used during withdraw' (Andreas Gruenbacher) [RHEL-252540]
  • Revert 'gfs2: Check for log write errors before telling dlm to unlock' (Andreas Gruenbacher) [RHEL-252540]
  • Revert 'gfs2: fix a deadlock on withdraw-during-mount' (Andreas Gruenbacher) [RHEL-252540]
  • Revert 'gfs2: Force withdraw to replay journals and wait for it to finish' (6/6) (Andreas Gruenbacher) [RHEL-252540]
  • Revert 'gfs2: Force withdraw to replay journals and wait for it to finish' (5/6) (Andreas Gruenbacher) [RHEL-252540]
  • Revert 'gfs2: Force withdraw to replay journals and wait for it to finish' (4/6) (Andreas Gruenbacher) [RHEL-252540]
  • Revert 'gfs2: Force withdraw to replay journals and wait for it to finish' (3/6) (Andreas Gruenbacher) [RHEL-252540]
  • Revert 'gfs2: Force withdraw to replay journals and wait for it to finish' (2/6) (Andreas Gruenbacher) [RHEL-252540]
  • Revert 'gfs2: Force withdraw to replay journals and wait for it to finish' (1/6) (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: Follow-up to flag rename in sysfs status file (Andreas Gruenbacher) [RHEL-252540]
  • Revert 'gfs2: don't stop reads while withdraw in progress' (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: Rename LM_FLAG_{NOEXP -> RECOVER} (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: Kill gfs2_io_error_bh_wd (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: Withdraw immediately on log write errors (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: Rename gfs2_{withdrawing_or_ => }withdrawn (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: Fix freeze consistency check in log_write_header (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: Get rid of delayed withdraws (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: Fix usage of bio->bi_status in gfs2_end_log_write (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: Asynchronous withdraw (Andreas Gruenbacher) [RHEL-252540]
  • gfs2: Add clean argument to lm_unmount hook (Andreas Gruenbacher) [RHEL-252540]
  • xfrm: Fix dev use-after-free in xfrm async resumption (Sabrina Dubroca) [RHEL-232965] {CVE-2026-31663}
  • xfrm: hold dev ref until after transport_finish NF_HOOK (Sabrina Dubroca) [RHEL-232965] {CVE-2026-31663}
  • xfrm: hold device only for the asynchronous decryption (Sabrina Dubroca) [RHEL-232965] {CVE-2026-31663}
  • xfrm: input: hold netns during deferred transport reinjection (Sabrina Dubroca) [RHEL-227508] {CVE-2026-63919}
  • xfrm: fix stale skb->prev after async crypto steals a GSO segment (Sabrina Dubroca) [RHEL-236120] {CVE-2026-68426}
  • xfrm: propagate -EINPROGRESS from validate_xmit_xfrm() (Sabrina Dubroca) [RHEL-236120] {CVE-2026-68426}
  • xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (Sabrina Dubroca) [RHEL-228016] {CVE-2026-53239}
  • ip6: vti: Use ip6_tnl.net in vti6_changelink(). (Sabrina Dubroca) [RHEL-231753] {CVE-2026-63917}
  • ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). (Sabrina Dubroca) [RHEL-228936] {CVE-2026-63921}
  • dm_early_create: fix freeing used table on dm_resume failure (CKI Backport Bot) [RHEL-244932] {CVE-2026-72102}
  • ALSA: timer: don't re-enter an instance callback that is still running (CKI Backport Bot) [RHEL-243028] {CVE-2026-68200}
  • ice: reject out-of-range ptype in ice_parser_profile_init (CKI Backport Bot) [RHEL-240325] {CVE-2026-68128}
  • RDMA/rxe: Fix a use-after-free problem in rxe_mmap (Kamal Heib) [RHEL-233826] {CVE-2026-64582}
  • RDMA/rxe: Reject unknown opcodes before ICRC processing (Kamal Heib) [RHEL-226877] {CVE-2026-46133}
  • RDMA/rxe: Fix race condition in QP timer handlers (Kamal Heib) [RHEL-226914] {CVE-2026-45910}
  • RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (Kamal Heib) [RHEL-228182] {CVE-2026-46043}
  • RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (Kamal Heib) [RHEL-226315] {CVE-2026-46114}
  • net: ena: PHC: Fix potential use-after-free in get_timestamp (CKI Backport Bot) [RHEL-230627] {CVE-2026-52971}
  • ALSA: timer: Fix UAF at snd_timer_user_params() (CKI Backport Bot) [RHEL-228693] {CVE-2026-53192}
  • ALSA: seq: Serialize UMP output teardown with event_input (CKI Backport Bot) [RHEL-227713] {CVE-2026-64029}
  • ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes (CKI Backport Bot) [RHEL-227087] {CVE-2026-53193}
  • ALSA: timer: Forcibly close timer instances at closing (CKI Backport Bot) [RHEL-227087] {CVE-2026-53193}
  • netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check (CKI Backport Bot) [RHEL-226406] {CVE-2026-63913}
  • IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (CKI Backport Bot) [RHEL-191605] {CVE-2026-53176}
  • USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (Desnes Nunes) [RHEL-191035] {CVE-2026-53195}
  • USB: serial: io_ti: fix heap overflow in get_manuf_info() (Desnes Nunes) [RHEL-191035] {CVE-2026-53196}

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

kernel-cross-headers

5.14.0-687.49.1.el9_8

kernel-tools-libs-devel

5.14.0-687.49.1.el9_8

libperf

5.14.0-687.49.1.el9_8

kernel-headers

5.14.0-687.49.1.el9_8

perf

5.14.0-687.49.1.el9_8

python3-perf

5.14.0-687.49.1.el9_8

rtla

5.14.0-687.49.1.el9_8

rv

5.14.0-687.49.1.el9_8

kernel-tools

5.14.0-687.49.1.el9_8

kernel-tools-libs

5.14.0-687.49.1.el9_8

Oracle Linux x86_64

kernel-debug-devel

5.14.0-687.49.1.el9_8

kernel-debug-devel-matched

5.14.0-687.49.1.el9_8

kernel-devel

5.14.0-687.49.1.el9_8

kernel-devel-matched

5.14.0-687.49.1.el9_8

kernel-doc

5.14.0-687.49.1.el9_8

kernel-headers

5.14.0-687.49.1.el9_8

perf

5.14.0-687.49.1.el9_8

python3-perf

5.14.0-687.49.1.el9_8

rtla

5.14.0-687.49.1.el9_8

rv

5.14.0-687.49.1.el9_8

kernel-cross-headers

5.14.0-687.49.1.el9_8

kernel-tools-libs-devel

5.14.0-687.49.1.el9_8

libperf

5.14.0-687.49.1.el9_8

kernel

5.14.0-687.49.1.el9_8

kernel-abi-stablelists

5.14.0-687.49.1.el9_8

kernel-core

5.14.0-687.49.1.el9_8

kernel-debug

5.14.0-687.49.1.el9_8

kernel-debug-core

5.14.0-687.49.1.el9_8

kernel-debug-modules

5.14.0-687.49.1.el9_8

kernel-debug-modules-core

5.14.0-687.49.1.el9_8

kernel-debug-modules-extra

5.14.0-687.49.1.el9_8

kernel-debug-uki-virt

5.14.0-687.49.1.el9_8

kernel-modules

5.14.0-687.49.1.el9_8

kernel-modules-core

5.14.0-687.49.1.el9_8

kernel-modules-extra

5.14.0-687.49.1.el9_8

kernel-tools

5.14.0-687.49.1.el9_8

kernel-tools-libs

5.14.0-687.49.1.el9_8

kernel-uki-virt

5.14.0-687.49.1.el9_8

kernel-uki-virt-addons

5.14.0-687.49.1.el9_8

Связанные уязвимости

rocky
5 дней назад

Important: kernel security, bug fix, and enhancement update

CVSS3: 8.4
ubuntu
7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: fix potential skb->frags overflow in RX path When receiving data in the DPMAIF RX path, the t7xx_dpmaif_set_frag_to_skb() function adds page fragments to an skb without checking if the number of fragments has exceeded MAX_SKB_FRAGS. This could lead to a buffer overflow in skb_shinfo(skb)->frags[] array, corrupting adjacent memory and potentially causing kernel crashes or other undefined behavior. This issue was identified through static code analysis by comparing with a similar vulnerability fixed in the mt76 driver commit b102f0c522cf ("mt76: fix array overflow on receiving too many fragments for a packet"). The vulnerability could be triggered if the modem firmware sends packets with excessive fragments. While under normal protocol conditions (MTU 3080 bytes, BAT buffer 3584 bytes), a single packet should not require additional fragments, the kernel should not blindly trust firmware behavior. Mali...

CVSS3: 7.4
redhat
7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: fix potential skb->frags overflow in RX path When receiving data in the DPMAIF RX path, the t7xx_dpmaif_set_frag_to_skb() function adds page fragments to an skb without checking if the number of fragments has exceeded MAX_SKB_FRAGS. This could lead to a buffer overflow in skb_shinfo(skb)->frags[] array, corrupting adjacent memory and potentially causing kernel crashes or other undefined behavior. This issue was identified through static code analysis by comparing with a similar vulnerability fixed in the mt76 driver commit b102f0c522cf ("mt76: fix array overflow on receiving too many fragments for a packet"). The vulnerability could be triggered if the modem firmware sends packets with excessive fragments. While under normal protocol conditions (MTU 3080 bytes, BAT buffer 3584 bytes), a single packet should not require additional fragments, the kernel should not blindly trust firmware behavior. Mali...

CVSS3: 8.4
nvd
7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: fix potential skb->frags overflow in RX path When receiving data in the DPMAIF RX path, the t7xx_dpmaif_set_frag_to_skb() function adds page fragments to an skb without checking if the number of fragments has exceeded MAX_SKB_FRAGS. This could lead to a buffer overflow in skb_shinfo(skb)->frags[] array, corrupting adjacent memory and potentially causing kernel crashes or other undefined behavior. This issue was identified through static code analysis by comparing with a similar vulnerability fixed in the mt76 driver commit b102f0c522cf ("mt76: fix array overflow on receiving too many fragments for a packet"). The vulnerability could be triggered if the modem firmware sends packets with excessive fragments. While under normal protocol conditions (MTU 3080 bytes, BAT buffer 3584 bytes), a single packet should not require additional fragments, the kernel should not blindly trust firmware behavior. Mal

CVSS3: 8.4
debian
7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: n ...