[El-errata] New Ksplice updates for UEKR7 5.15.0 on OL8 and OL9 (ELSA-2026-50373)

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Thu Jul 16 06:44:25 UTC 2026


Synopsis: ELSA-2026-50373 can now be patched using Ksplice
CVEs: CVE-2025-40103 CVE-2026-23113 CVE-2026-23274 CVE-2026-23351 CVE-2026-23455 CVE-2026-43027 CVE-2026-43037 CVE-2026-43038 CVE-2026-43329 CVE-2026-43499 CVE-2026-46113 CVE-2026-46331 CVE-2026-53163

Users with Oracle Linux Premier Support can now use Ksplice to patch
against the latest Oracle Linux Security Advisory, ELSA-2026-50373.
More information about this errata can be found at
https://linux.oracle.com/errata/ELSA-2026-50373.html

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack running UEKR7 5.15.0 on
OL8 and OL9 install these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


DESCRIPTION

* CVE-2025-40103: Reference count leak in SMB/CIFS client driver.

* CVE-2026-23113: Infinite loop in io_uring.

* CVE-2026-23274: Use-after-free in Netfilter driver.

* CVE-2026-23351: Use-after-free in Netfilter driver.

* CVE-2026-23455: Out-of-bounds memory access in Netfilter driver.

* CVE-2026-43027: Use-after-free in Netfilter driver.

* CVE-2026-43037: Out-of-bounds write in IPv6: IP-in-IPv6 tunnel (RFC2473) driver.

* CVE-2026-43038: Out-of-bounds write in IPv6 Networking driver.

* CVE-2026-43329: Off-by-one action count in Netfilter driver.

* CVE-2026-43499, CVE-2026-53163: Use-after-free in core kernel RT-mutex.

Orabug: 39425999


* CVE-2026-46113: Use-after-free in KVM shadow paging.

Orabug: 39673886


* CVE-2026-46331: Page cache corruption in Packet Editing driver.

Orabug: 39668793


* Redundant lock in Integrity Measurement Architecture(IMA) driver.

Orabug: 39390378


* Note: Oracle has determined some CVEs are not applicable.

The kernel is not affected by the following CVEs
since the code under consideration is not compiled.

CVE-2024-56557, CVE-2025-37778, CVE-2025-38006, CVE-2025-38562,
CVE-2025-71150, CVE-2026-23220, CVE-2026-23227, CVE-2026-23268,
CVE-2026-23269, CVE-2026-23291, CVE-2026-23298, CVE-2026-23324,
CVE-2026-23339, CVE-2026-23372, CVE-2026-23403, CVE-2026-23404,
CVE-2026-23405, CVE-2026-23406, CVE-2026-23407, CVE-2026-23408,
CVE-2026-23409, CVE-2026-23410, CVE-2026-23411, CVE-2026-23428,
CVE-2026-23446, CVE-2026-23460, CVE-2026-23463, CVE-2026-31417,
CVE-2026-31433, CVE-2026-31464, CVE-2026-31478, CVE-2026-31483,
CVE-2026-31485, CVE-2026-31507, CVE-2026-31509, CVE-2026-31545,
CVE-2026-31634, CVE-2026-31660, CVE-2026-31695, CVE-2026-31720,
CVE-2026-31721, CVE-2026-31726, CVE-2026-31728, CVE-2026-31737,
CVE-2026-31747, CVE-2026-31748, CVE-2026-31749, CVE-2026-31751,
CVE-2026-31754, CVE-2026-31755, CVE-2026-31756, CVE-2026-31770,
CVE-2026-31780, CVE-2026-43011, CVE-2026-43032, CVE-2026-43324,
CVE-2026-43327, CVE-2026-43340, CVE-2026-43342, CVE-2026-43343,
CVE-2026-43373, CVE-2026-43380, CVE-2026-43426, CVE-2026-43458,
CVE-2026-43476, CVE-2026-43480, CVE-2026-45924, CVE-2026-45958


SUPPORT

Ksplice support is available at ksplice-support_ww at oracle.com.




More information about the El-errata mailing list