[El-errata] New Ksplice updates for RHCK 9 (ELSA-2026-19225)

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Fri Aug 7 17:17:31 UTC 2026


Synopsis: ELSA-2026-19225 can now be patched using Ksplice
CVEs: CVE-2024-47701 CVE-2024-47742 CVE-2025-21858 CVE-2025-23131 CVE-2025-37756 CVE-2025-37757 CVE-2025-37824 CVE-2025-37921 CVE-2025-37978 CVE-2025-38018 CVE-2025-38111 CVE-2025-38120 CVE-2025-38184 CVE-2025-38231 CVE-2025-38264 CVE-2025-38305 CVE-2025-38310 CVE-2025-38342 CVE-2025-38399 CVE-2025-38445 CVE-2025-38461 CVE-2025-38473 CVE-2025-38509 CVE-2025-38512 CVE-2025-38572 CVE-2025-38587 CVE-2025-38588 CVE-2025-38616 CVE-2025-38617 CVE-2025-38618 CVE-2025-38622 CVE-2025-38685 CVE-2025-38688 CVE-2025-38732 CVE-2025-39703 CVE-2025-39791 CVE-2025-39860 CVE-2025-39866 CVE-2025-39922 CVE-2025-39926 CVE-2025-39946 CVE-2025-39963 CVE-2025-39977 CVE-2025-40129 CVE-2025-40153 CVE-2025-40194 CVE-2025-40231 CVE-2025-40273 CVE-2025-68215 CVE-2025-68295 CVE-2025-68776 CVE-2025-71131 CVE-2026-23243 CVE-2026-43304

Users with Oracle Linux Premier Support can now use Ksplice to patch
against the latest Oracle Linux Security Advisory, ELSA-2026-19225.
More information about this errata can be found at
https://linux.oracle.com/errata/ELSA-2026-19225.html

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack running RHCK 9 install
these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


DESCRIPTION

* CVE-2024-47701: Privilege escalation in ext4 filesystem.

* CVE-2024-47742: Privilege escalation in the firmware loader driver.

* CVE-2025-21858: Privilege escalation in Generic Network Virtualization Encapsulation driver.

* CVE-2025-23131: Null pointer dereference in Distributed Lock Manager (DLM) driver.

* CVE-2025-37756: Undefined behaviour in Transport Layer Security driver.

* CVE-2025-37757: Memory leak in the TIPC Protocol driver.

* CVE-2025-37824: Null pointer dereference in TIPC Protocol driver.

* CVE-2025-37921: Deadlock in Virtual eXtensible Local Area Network (VXLAN) driver.

* CVE-2025-37978: Kernel oops in Block layer data integrity driver.

* CVE-2025-38018: Null pointer dereference in Transport Layer Security driver.

* CVE-2025-38111: Out-of-bounds memory usage in MDIO bus driver.

* CVE-2025-38120: Memory disclosure in Netfilter driver.

* CVE-2025-38184: NULL pointer dereference in IP/UDP media type driver.

* CVE-2025-38231: Null pointer dereference in NFS server driver.

* CVE-2025-38264: Kernel crash in NVM Express over Fabrics TCP driver.

* CVE-2025-38305: Deadlock in Precision Time Protocol (PTP) driver.

* CVE-2025-38310: Out-of-bounds memory access in IPv6 Segment Routing Header encapsulation driver.

* CVE-2025-38342: Out-of-bounds memory access in software node component.

* CVE-2025-38399: Null pointer dereference in Generic Target Core Mod (TCM) and ConfigFS Infrastructure driver.

* CVE-2025-38445: Kernel panic in RAID-1 (mirroring) mode driver.

* CVE-2025-38461: Denial-of-service in Virtual Socket protocol driver.

* CVE-2025-38473: Null pointer dereference in Bluetooth subsystem.

* CVE-2025-38509: Kernel assertion failure in Generic IEEE 802.11 Networking Stack (mac80211) driver.

* CVE-2025-38512: Missing check for A-MSDU attacks in Wireless driver.

* CVE-2025-38572: Out-of-bounds memory access in IPv6 networking stack.

* CVE-2025-38587: Infinite loop in IPV6 subsystem.

* CVE-2025-38588: Infinite loop in IPV6 subsystem.

* CVE-2025-38616: Out-of-bounds memory access in TLS networking stack.

* CVE-2025-38617: Racing in raw-packet protocol stack.

* CVE-2025-38618: Use-after-free in Virtual Socket protocol driver.

* CVE-2025-38622: Kernel oops in UDP networking stack.

* CVE-2025-38685: Out-of-bounds memory access in frame buffer device driver.

* CVE-2025-38688: Out-of-bounds memory access in Generic IOMMU driver.

* CVE-2025-38732: Memory leak in Netfilter packet rejection driver.

* CVE-2025-39703: Kernel panic in High-availability Seamless Redundancy (HSR & PRP) driver.

* CVE-2025-39791: Deadlock in Crypt target driver.

* CVE-2025-39860: Use-after-free in Bluetooth subsystem.

* CVE-2025-39866: Use-after-free in writeback filesystem logic.

* CVE-2025-39922: Use-after-free in Intel(R) 10GbE PCI Express adapters driver.

* CVE-2025-39926: Undefined behavior in Generic Netlink Family driver.

* CVE-2025-39946: Out-of-bounds memory access in Transport Layer Security driver.

* CVE-2025-39963: Reference counting error in IO uring driver.

* CVE-2025-39977: Use-after-free in futex driver.

* CVE-2025-40129: Null pointer dereference in SUNRPC_GSS.

* CVE-2025-40153: Soft lockup in HugeTLB filesystem.

* CVE-2025-40194: Kernel crash in Intel P state control driver.

* CVE-2025-40231: Deadlock in Virtual Socket protocol driver.

* CVE-2025-40273: Kernel oops in NFS server for NFS version 4 driver.

* CVE-2025-68215: Use-after-free in PTP clock driver.

* CVE-2025-68295: Memory leak in SMB/CIFS client driver.

* CVE-2025-68776: Null pointer dereference in High-availability Seamless Redundancy (HSR & PRP) driver.

* CVE-2025-71131: Use-after-free in Sequence Number IV Generator driver.

* CVE-2026-23243: Out-of-bounds memory access in InfiniBand driver.

* CVE-2026-43304: Out-of-bounds memory access in Ceph core library driver.

* Use-after-free in Intel Wireless WiFi MLD Firmware driver.

* Note: Oracle has determined some CVEs are not applicable.

The kernel is not affected by the following CVEs
since the code under consideration is not compiled.

CVE-2022-49026, CVE-2023-52894, CVE-2023-53356, CVE-2023-53423,
CVE-2023-53551, CVE-2023-54042, CVE-2024-43832, CVE-2024-46692,
CVE-2024-50034, CVE-2024-50112, CVE-2024-56640, CVE-2024-56670,
CVE-2025-21998, CVE-2025-37837, CVE-2025-37841, CVE-2025-38005,
CVE-2025-38043, CVE-2025-38138, CVE-2025-38155, CVE-2025-38156,
CVE-2025-38281, CVE-2025-38316, CVE-2025-38317, CVE-2025-38326,
CVE-2025-38343, CVE-2025-38429, CVE-2025-38448, CVE-2025-38489,
CVE-2025-38497, CVE-2025-38510, CVE-2025-38535, CVE-2025-38576,
CVE-2025-38581, CVE-2025-38586, CVE-2025-38599, CVE-2025-39726,
CVE-2025-39739, CVE-2025-39801, CVE-2025-39857, CVE-2025-39869,
CVE-2025-39904, CVE-2025-39923, CVE-2025-39935, CVE-2025-39937,
CVE-2025-39938, CVE-2025-39939, CVE-2025-39952, CVE-2025-39958,
CVE-2025-40013, CVE-2025-40045, CVE-2025-40155, CVE-2025-40282,
CVE-2025-40317, CVE-2025-68344, CVE-2025-68346, CVE-2025-68347,
CVE-2025-68747, CVE-2025-68748, CVE-2025-68753, CVE-2025-68757,
CVE-2025-71119, CVE-2026-45904, CVE-2025-38639, CVE-2025-40087,
CVE-2023-53125, CVE-2025-37866, CVE-2025-38326, CVE-2025-39919,
CVE-2025-40352, CVE-2026-23045, CVE-2025-40013, CVE-2024-56641,
CVE-2025-38734, CVE-2026-23042, CVE-2025-40175, CVE-2025-68746,
CVE-2026-23202, CVE-2025-40066, CVE-2026-23207


SUPPORT

Ksplice support is available at ksplice-support_ww at oracle.com.





More information about the El-errata mailing list