[El-errata] New Ksplice updates for UEKR8 6.12.0 on OL9 and OL10 (ELSA-2026-50006)
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Mon Jan 26 18:27:26 UTC 2026
Synopsis: ELSA-2026-50006 can now be patched using Ksplice
CVEs: CVE-2025-22121 CVE-2025-40083 CVE-2025-40212 CVE-2025-40214 CVE-2025-40231 CVE-2025-40233 CVE-2025-40240 CVE-2025-40248 CVE-2025-40273 CVE-2025-40277 CVE-2025-40279 CVE-2025-40280 CVE-2025-40281 CVE-2025-40292 CVE-2025-40297 CVE-2025-40309 CVE-2025-40318 CVE-2025-40320 CVE-2025-40328 CVE-2025-40348 CVE-2025-68188
Users with Oracle Linux Premier Support can now use Ksplice to patch
against the latest Oracle Linux Security Advisory, ELSA-2026-50006.
More information about this errata can be found at
https://linux.oracle.com/errata/ELSA-2026-50006.html
INSTALLING THE UPDATES
We recommend that all users of Ksplice Uptrack running UEKR8 6.12.0 on
OL9 and OL10 install these updates.
On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.
Alternatively, you can install these updates by running:
# /usr/sbin/uptrack-upgrade -y
DESCRIPTION
* CVE-2025-22121: Out-of-bounds memory access in ext4 filesystem driver.
* CVE-2025-40083: Null pointer dereference in Quick Fair Queueing scheduler (QFQ) driver.
* CVE-2025-40212: Reference count leak in NFS server driver.
* CVE-2025-40214: Use-after-free in Unix domain sockets driver.
* CVE-2025-40231: Deadlock in Virtual Socket protocol driver.
* CVE-2025-40233: Kernel crash in OCFS2 filesystem driver.
* CVE-2025-40240: Remote null pointer dereference in SCTP Protocol driver.
* CVE-2025-40248: Use-after-free in Virtual Socket protocol driver.
Orabug: 38858283
* CVE-2025-40273: Kernel oops in NFS server for NFS version 4 driver.
* CVE-2025-40277: Out-of-bounds memory access in VMware graphics driver.
* CVE-2025-40279: Use of uninitialized memory in Netfilter Connection Mark Retriever driver.
* CVE-2025-40280: Use-after-free in TIPC Protocol driver.
* CVE-2025-40281: Out-of-bounds memory access in SCTP Protocol driver.
* CVE-2025-40292: Null pointer dereference in Virtio network driver.
* CVE-2025-40297: Use-after-free in 802.1d Ethernet Bridging driver.
* CVE-2025-40309: Use-after-free in Bluetooth Classic (BR/EDR) features driver.
* CVE-2025-40318: Use-after-free in Bluetooth subsystem.
* CVE-2025-40320: Use-after-free in SMB/CIFS client driver.
* CVE-2025-40328: Use-after-free in SMB/CIFS client driver.
* CVE-2025-40348: Null pointer dereference in Slab memory allocator.
* CVE-2025-68188: Use-after-free in TCP/IP networking driver.
* Note: Oracle has determined some CVEs are not applicable.
The kernel is not affected by the following CVEs
since the code under consideration is not compiled.
CVE-2025-22107, CVE-2025-23130, CVE-2025-37803, CVE-2025-40077,
CVE-2025-40084, CVE-2025-40106, CVE-2025-40223, CVE-2025-40225,
CVE-2025-40226, CVE-2025-40243, CVE-2025-40244, CVE-2025-40245,
CVE-2025-40278, CVE-2025-40282, CVE-2025-40285, CVE-2025-40286,
CVE-2025-40306, CVE-2025-40311, CVE-2025-40312, CVE-2025-40313,
CVE-2025-40314, CVE-2025-40315, CVE-2025-40316, CVE-2025-40317,
CVE-2025-40333, CVE-2025-40347, CVE-2025-40349, CVE-2025-40351,
CVE-2025-40357, CVE-2025-40358, CVE-2025-68168, CVE-2025-68172,
CVE-2025-68176, CVE-2025-68177, CVE-2025-68179, CVE-2025-68184,
CVE-2025-68204, CVE-2025-68210, CVE-2025-68240, CVE-2025-68246,
CVE-2025-68249, CVE-2025-68252, CVE-2025-68310, CVE-2025-68311,
CVE-2025-68315, CVE-2025-68320, CVE-2025-68322, CVE-2025-68734
SUPPORT
Ksplice support is available at ksplice-support_ww at oracle.com.
More information about the El-errata
mailing list