Synopsis: ELSA-2026-50006 can now be patched using Ksplice CVEs: CVE-2025-22121 CVE-2025-40083 CVE-2025-40212 CVE-2025-40214 CVE-2025-40231 CVE-2025-40233 CVE-2025-40240 CVE-2025-40248 CVE-2025-40273 CVE-2025-40277 CVE-2025-40279 CVE-2025-40280 CVE-2025-40281 CVE-2025-40292 CVE-2025-40297 CVE-2025-40309 CVE-2025-40318 CVE-2025-40320 CVE-2025-40328 CVE-2025-40348 CVE-2025-68188
Users with Oracle Linux Premier Support can now use Ksplice to patch against the latest Oracle Linux Security Advisory, ELSA-2026-50006. More information about this errata can be found at https://linux.oracle.com/errata/ELSA-2026-50006.html INSTALLING THE UPDATES We recommend that all users of Ksplice Uptrack running UEKR8 6.12.0 on OL9 and OL10 install these updates. On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf, these updates will be installed automatically and you do not need to take any action. Alternatively, you can install these updates by running: # /usr/sbin/uptrack-upgrade -y DESCRIPTION * CVE-2025-22121: Out-of-bounds memory access in ext4 filesystem driver. * CVE-2025-40083: Null pointer dereference in Quick Fair Queueing scheduler (QFQ) driver. * CVE-2025-40212: Reference count leak in NFS server driver. * CVE-2025-40214: Use-after-free in Unix domain sockets driver. * CVE-2025-40231: Deadlock in Virtual Socket protocol driver. * CVE-2025-40233: Kernel crash in OCFS2 filesystem driver. * CVE-2025-40240: Remote null pointer dereference in SCTP Protocol driver. * CVE-2025-40248: Use-after-free in Virtual Socket protocol driver. Orabug: 38858283 * CVE-2025-40273: Kernel oops in NFS server for NFS version 4 driver. * CVE-2025-40277: Out-of-bounds memory access in VMware graphics driver. * CVE-2025-40279: Use of uninitialized memory in Netfilter Connection Mark Retriever driver. * CVE-2025-40280: Use-after-free in TIPC Protocol driver. * CVE-2025-40281: Out-of-bounds memory access in SCTP Protocol driver. * CVE-2025-40292: Null pointer dereference in Virtio network driver. * CVE-2025-40297: Use-after-free in 802.1d Ethernet Bridging driver. * CVE-2025-40309: Use-after-free in Bluetooth Classic (BR/EDR) features driver. * CVE-2025-40318: Use-after-free in Bluetooth subsystem. * CVE-2025-40320: Use-after-free in SMB/CIFS client driver. * CVE-2025-40328: Use-after-free in SMB/CIFS client driver. * CVE-2025-40348: Null pointer dereference in Slab memory allocator. * CVE-2025-68188: Use-after-free in TCP/IP networking driver. * Note: Oracle has determined some CVEs are not applicable. The kernel is not affected by the following CVEs since the code under consideration is not compiled. CVE-2025-22107, CVE-2025-23130, CVE-2025-37803, CVE-2025-40077, CVE-2025-40084, CVE-2025-40106, CVE-2025-40223, CVE-2025-40225, CVE-2025-40226, CVE-2025-40243, CVE-2025-40244, CVE-2025-40245, CVE-2025-40278, CVE-2025-40282, CVE-2025-40285, CVE-2025-40286, CVE-2025-40306, CVE-2025-40311, CVE-2025-40312, CVE-2025-40313, CVE-2025-40314, CVE-2025-40315, CVE-2025-40316, CVE-2025-40317, CVE-2025-40333, CVE-2025-40347, CVE-2025-40349, CVE-2025-40351, CVE-2025-40357, CVE-2025-40358, CVE-2025-68168, CVE-2025-68172, CVE-2025-68176, CVE-2025-68177, CVE-2025-68179, CVE-2025-68184, CVE-2025-68204, CVE-2025-68210, CVE-2025-68240, CVE-2025-68246, CVE-2025-68249, CVE-2025-68252, CVE-2025-68310, CVE-2025-68311, CVE-2025-68315, CVE-2025-68320, CVE-2025-68322, CVE-2025-68734 SUPPORT Ksplice support is available at [email protected]. _______________________________________________ El-errata mailing list [email protected] https://oss.oracle.com/mailman/listinfo/el-errata
