[El-errata] New Ksplice updates for UEKR6 5.4.17 on OL7 and OL8 (ELSA-2023-12825)

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Tue Oct 3 07:53:09 UTC 2023

Synopsis: ELSA-2023-12825 can now be patched using Ksplice
CVEs: CVE-2023-42753 CVE-2023-5090

Users with Oracle Linux Premier Support can now use Ksplice to patch
against the latest Oracle Linux Security Advisory, ELSA-2023-12825.
More information about this errata can be found at


We recommend that all users of Ksplice Uptrack running UEKR6 5.4.17 on
OL7 and OL8 install these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


* CVE-2023-5090: Privilege escalation from KVM guests when configuring the x2apic.

A logic error in the KVM MSR interception routine allows a KVM guest to
configure the host x2apic.  A local, unprivileged guest VM could use this
flaw to escalate privileges to that of the host hypervisor.

* CVE-2023-42753: Privilege escalation in the netfilter subsystem.

A logic error when calculating an array offset in the netfilter
subsystem could lead to an out-of-bounds access. A local attacker could
use this flaw to escalate privileges or to cause a denial-of-service.

Orabug: 35824307


Ksplice support is available at ksplice-support_ww at oracle.com.

More information about the El-errata mailing list