Oracle Linux Security Advisory ELSA-2025-14009 http://linux.oracle.com/errata/ELSA-2025-14009.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-abi-stablelists-6.12.0-55.28.1.0.1.el10_0.noarch.rpm kernel-core-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-cross-headers-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-debug-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-debug-core-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-debug-devel-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-debug-devel-matched-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-debug-modules-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-debug-modules-core-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-debug-modules-extra-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-debug-uki-virt-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-devel-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-devel-matched-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-doc-6.12.0-55.28.1.0.1.el10_0.noarch.rpm kernel-headers-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-modules-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-modules-core-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-modules-extra-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-tools-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-tools-libs-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-tools-libs-devel-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-uki-virt-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm kernel-uki-virt-addons-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm libperf-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm perf-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm python3-perf-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm rtla-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm rv-6.12.0-55.28.1.0.1.el10_0.x86_64.rpm aarch64: kernel-cross-headers-6.12.0-55.28.1.0.1.el10_0.aarch64.rpm kernel-headers-6.12.0-55.28.1.0.1.el10_0.aarch64.rpm kernel-tools-6.12.0-55.28.1.0.1.el10_0.aarch64.rpm kernel-tools-libs-6.12.0-55.28.1.0.1.el10_0.aarch64.rpm kernel-tools-libs-devel-6.12.0-55.28.1.0.1.el10_0.aarch64.rpm libperf-6.12.0-55.28.1.0.1.el10_0.aarch64.rpm perf-6.12.0-55.28.1.0.1.el10_0.aarch64.rpm python3-perf-6.12.0-55.28.1.0.1.el10_0.aarch64.rpm rtla-6.12.0-55.28.1.0.1.el10_0.aarch64.rpm rv-6.12.0-55.28.1.0.1.el10_0.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/kernel-6.12.0-55.28.1.0.1.el10_0.src.rpm Related CVEs: CVE-2025-21867 CVE-2025-38124 CVE-2025-38250 CVE-2025-38380 CVE-2025-38471 Description of changes: [6.12.0-55.28.1.0.1] - nvme-pci: remove two deallocate zeroes quirks [Orabug: 37756650] - Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782] - Disable UKI signing [Orabug: 36571828] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5.el9 - Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535] - Add Oracle Linux IMA certificates - Update module name for cryptographic module [Orabug: 37400433] [6.12.0-55.28.1] - Conflict with xdp-tools < 1.5.4 - Bump internal version to 55.28.1 - tls: always refresh the queue when reading sock - CVE-2025-38471 - selftests: net: bpf_offload: add 'libbpf_global' to ignored maps - selftests: net: fix error message in bpf_offload - selftests: net: add more info to error in bpf_offload - net: fix udp gso skb_segment after pull from frag_list - CVE-2025-38124 - powerpc/pseries/vas: Add close() callback in vas_vm_ops struct - s390/pci: Serialize device addition and removal - s390/pci: Allow re-add of a reserved but not yet removed device - s390/pci: Prevent self deletion in disable_slot() - s390/pci: Remove redundant bus removal and disable from zpci_release_device() - s390/pci: Fix duplicate pci_dev_put() in disable_slot() when PF has child VFs - s390/pci: Fix missing check for zpci_create_device() error return - s390/pci: Fix potential double remove of hotplug slot - s390/topology: Improve topology detection - Bluetooth: hci_core: Fix use-after-free in vhci_flush() - CVE-2025-38250 - selftests/bpf: Adjust data size to have ETH_HLEN - CVE-2025-21867 - bpf, test_run: Fix use-after-free issue in eth_skb_pkt_type() - CVE-2025-21867 - i2c/designware: Fix an initialization issue - CVE-2025-38380 _______________________________________________ El-errata mailing list El-errata@oss.oracle.com https://oss.oracle.com/mailman/listinfo/el-errata