[El-errata] New Ksplice updates for RHCK 9 (ELSA-2026-27789)
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Sun Aug 30 09:51:56 UTC 2026
Synopsis: ELSA-2026-27789 can now be patched using Ksplice
CVEs: CVE-2025-68741 CVE-2026-23204 CVE-2026-23216 CVE-2026-23270 CVE-2026-23392 CVE-2026-23401 CVE-2026-31402 CVE-2026-31419 CVE-2026-31613 CVE-2026-31669 CVE-2026-31709 CVE-2026-43037 CVE-2026-43116 CVE-2026-43125 CVE-2026-43128 CVE-2026-43158 CVE-2026-43163 CVE-2026-43187 CVE-2026-43190 CVE-2026-43303 CVE-2026-43350 CVE-2026-43501 CVE-2026-43503 CVE-2026-45852 CVE-2026-45984 CVE-2026-46117 CVE-2026-46135 CVE-2026-46181 CVE-2026-46300 CVE-2026-46331 CVE-2026-46333 CVE-2026-64112
Users with Oracle Linux Premier Support can now use Ksplice to patch
against the latest Oracle Linux Security Advisory, ELSA-2026-27789.
More information about this errata can be found at
https://linux.oracle.com/errata/ELSA-2026-27789.html
INSTALLING THE UPDATES
We recommend that all users of Ksplice Uptrack running RHCK 9 install
these updates.
On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.
Alternatively, you can install these updates by running:
# /usr/sbin/uptrack-upgrade -y
DESCRIPTION
* CVE-2025-68741: Use-after-free in QLogic QLA2XXX Fibre Channel driver.
* CVE-2026-23204: Out-of-bounds memory access in U32 network classifer.
* CVE-2026-23216: Use-after-free in SCSI Target Mode Stack driver.
* CVE-2026-23270: Use-after-free in connection tracking tc action driver.
* CVE-2026-23392: Use-after-free in Netfilter driver.
* CVE-2026-23401: Use-after-free in x86 KVM.
* CVE-2026-31402: Out-of-bounds memory access in NFS server driver.
* CVE-2026-31419: Use-after-free in Bonding driver.
* CVE-2026-31613: Out-of-bounds memory access in SMB/CIFS client driver.
* CVE-2026-31669: Use-after-free in MPTCP: Multipath TCP driver.
* CVE-2026-31709, CVE-2026-43350: Out-of-bounds memory access in SMB/CIFS client driver.
* CVE-2026-43037: Out-of-bounds write in IPv6: IP-in-IPv6 tunnel (RFC2473) driver.
* CVE-2026-43116: Use-after-free in Netfilter driver.
* CVE-2026-43125: Out-of-bounds memory access in Distributed Lock Manager (DLM) driver.
* CVE-2026-43128: Use-after-free in InfiniBand driver.
* CVE-2026-43158, CVE-2026-43187: Data corruption in XFS filesystem driver.
* CVE-2026-43163: Use-after-free in Multiple devices (RAID and LVM) driver.
* CVE-2026-43190: Out-of-bounds memory access in Netfilter driver.
* CVE-2026-43303: Use-after-free in memory management subsystem.
* CVE-2026-43501: Out-of-bounds memory access in IPv6 networking stack.
* CVE-2026-43503, CVE-2026-46300: Privilege escalation in Networking driver.
* CVE-2026-45852: Memory leak in Software RDMA over Ethernet (RoCE) driver.
* CVE-2026-45984: Use-after-free in GFS2 filesystem driver.
* CVE-2026-46117: Triggerable warning in Microsoft Azure Network Adapter driver.
* CVE-2026-46135: Race condition in NVME-over-TCP driver.
* CVE-2026-46181: Use-after-free in Mellanox devices driver.
* CVE-2026-46331: Page cache corruption in Packet Editing driver.
* CVE-2026-46333: Permission bypass in ptrace subsystem.
* CVE-2026-64112: Use-after-free in Rados block device driver.
* Note: Oracle has determined some CVEs are not applicable.
The kernel is not affected by the following CVEs
since the code under consideration is not compiled.
CVE-2025-68310, CVE-2026-31568, CVE-2026-46273
SUPPORT
Ksplice support is available at ksplice-support_ww at oracle.com.
More information about the El-errata
mailing list