[El-errata] New Ksplice updates for RHCK 10 (ELSA-2026-39494)

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Mon Aug 31 10:35:35 UTC 2026


Synopsis: ELSA-2026-39494 can now be patched using Ksplice
CVEs: CVE-2024-56603 CVE-2025-68741 CVE-2025-71066 CVE-2026-23270 CVE-2026-23392 CVE-2026-23401 CVE-2026-23402 CVE-2026-23455 CVE-2026-31402 CVE-2026-31419 CVE-2026-31613 CVE-2026-31614 CVE-2026-31636 CVE-2026-31641 CVE-2026-31669 CVE-2026-31709 CVE-2026-31719 CVE-2026-43006 CVE-2026-43027 CVE-2026-43037 CVE-2026-43038 CVE-2026-43074 CVE-2026-43112 CVE-2026-43116 CVE-2026-43128 CVE-2026-43158 CVE-2026-43187 CVE-2026-43190 CVE-2026-43198 CVE-2026-43303 CVE-2026-43329 CVE-2026-43341 CVE-2026-43350 CVE-2026-43501 CVE-2026-43503 CVE-2026-45898 CVE-2026-45998 CVE-2026-46113 CVE-2026-46117 CVE-2026-46125 CVE-2026-46135 CVE-2026-46139 CVE-2026-46145 CVE-2026-46155 CVE-2026-46166 CVE-2026-46173 CVE-2026-46176 CVE-2026-46189 CVE-2026-46195 CVE-2026-46227 CVE-2026-46242 CVE-2026-46243 CVE-2026-46244 CVE-2026-46259 CVE-2026-46300 CVE-2026-46331 CVE-2026-46333 CVE-2026-53359 CVE-2026-53362 CVE-2026-53366 CVE-2026-63912 CVE-2026-64439 CVE-2026-64600

Users with Oracle Linux Premier Support can now use Ksplice to patch
against the latest Oracle Linux Security Advisory, ELSA-2026-39494.
More information about this errata can be found at
https://linux.oracle.com/errata/ELSA-2026-39494.html

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack running RHCK 10 install
these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


DESCRIPTION

* CVE-2024-56603: Privilege escalation in CAN bus subsystem driver.

* CVE-2025-68741: Use-after-free in QLogic QLA2XXX Fibre Channel driver.

* CVE-2025-71066: Use-after-free in ETS network scheduler.

* CVE-2026-23270: Use-after-free in connection tracking tc action driver.

* CVE-2026-23392: Use-after-free in Netfilter driver.

* CVE-2026-23401: Use-after-free in x86 KVM.

* CVE-2026-23402: Triggerable warning in x86 KVM.

* CVE-2026-23455: Out-of-bounds memory access in Netfilter driver.

* CVE-2026-31402: Out-of-bounds memory access in NFS server driver.

* CVE-2026-31419: Use-after-free in Bonding driver.

* CVE-2026-31613: Out-of-bounds memory access in SMB/CIFS client driver.

* CVE-2026-31614, CVE-2026-46155: Out-of-bounds memory access in SMB client.

* CVE-2026-31636: Out-of-bounds memory access in RxRPC session sockets driver.

* CVE-2026-31641: Out-of-bounds memory access in RxRPC session sockets driver.

* CVE-2026-31669: Use-after-free in MPTCP: Multipath TCP driver.

* CVE-2026-31709, CVE-2026-43350, CVE-2026-46139, CVE-2026-46195: Memory exposure in SMB/CIFS client.

* CVE-2026-31719: Authentication bypass in Kerberos crypto subsystem.

* CVE-2026-43006: Out-of-bounds memory access in io_uring subsystem.

* CVE-2026-43027: Use-after-free in Netfilter driver.

* CVE-2026-43037: Out-of-bounds write in IPv6: IP-in-IPv6 tunnel (RFC2473) driver.

* CVE-2026-43038: Out-of-bounds write in IPv6 Networking driver.

* CVE-2026-43074: Use-after-free in epoll.

* CVE-2026-43112: Out-of-bounds memory access in SMB/CIFS client driver.

* CVE-2026-43116: Use-after-free in Netfilter driver.

* CVE-2026-43128: Use-after-free in InfiniBand driver.

* CVE-2026-43158, CVE-2026-43187: Data corruption in XFS filesystem driver.

* CVE-2026-43190: Out-of-bounds memory access in Netfilter driver.

* CVE-2026-43198: Race condition in TCP/IP networking driver.

* CVE-2026-43303: Use-after-free in memory management subsystem.

* CVE-2026-43329: Off-by-one action count in Netfilter driver.

* CVE-2026-43341: Out-of-bounds memory access in IPv6 IOAM implementation.

* CVE-2026-43501: Out-of-bounds memory access in IPv6 networking stack.

* CVE-2026-43503, CVE-2026-46300: Privilege escalation in Networking driver.

* CVE-2026-45898: Workqueue list corruption in iWARP Connection Manager.

* CVE-2026-45998: Use-after-free in RxRPC session sockets driver.

* CVE-2026-46113, CVE-2026-53359: Use-after-free in KVM shadow paging.

* CVE-2026-46117: Triggerable warning in Microsoft Azure Network Adapter driver.

* CVE-2026-46125: Use-after-free in mac80211 wireless driver.

* CVE-2026-46135: Race condition in NVME-over-TCP driver.

* CVE-2026-46145: Out-of-bounds access in Microsoft Azure Network Adapter driver.

* CVE-2026-46166: Use-after-free in mac80211 wireless driver.

* CVE-2026-46173: Use-after-free in process exit handling.

* CVE-2026-46176: Use-after-free in InfiniBand driver.

* CVE-2026-46189: Double-free in InfiniBand driver.

* CVE-2026-46227: Use-after-free in SCTP Protocol driver.

* CVE-2026-46242: Use-after-free in eventpoll subsystem.

* CVE-2026-46243: Overly permissive privilege checks in Kerberos/SPNEGO driver.

* CVE-2026-46244: Permission bypass in Netfilter driver.

* CVE-2026-46259: Use-after-free in /proc filesystem driver.

* CVE-2026-46331: Page cache corruption in Packet Editing driver.

* CVE-2026-46333: Permission bypass in ptrace subsystem.

* CVE-2026-53362: Out-of-bounds memory write in IPv6 networking stack.

* CVE-2026-53366: Out-of-bounds memory access in TCP/IP networking driver.

* CVE-2026-63912: Memory corruption in XFRM ESP networking driver.

* CVE-2026-64439: Use-after-free in Kerberos crypto subsystem.

* CVE-2026-64600: Data corruption in XFS filesystem.

* Note: Oracle has determined some CVEs are not applicable.

The kernel is not affected by the following CVEs
since the code under consideration is not compiled.

CVE-2025-68310, CVE-2026-23206, CVE-2026-31568, CVE-2026-31739,
CVE-2026-43205, CVE-2026-43330, CVE-2026-46152, CVE-2026-46273,
CVE-2026-46316, CVE-2026-53354


SUPPORT

Ksplice support is available at ksplice-support_ww at oracle.com.





More information about the El-errata mailing list