[El-errata] New Ksplice updates for UEKR7 5.15.0 on OL8 and OL9 (ELSA-2026-50373)
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Thu Jul 16 06:44:25 UTC 2026
Synopsis: ELSA-2026-50373 can now be patched using Ksplice
CVEs: CVE-2025-40103 CVE-2026-23113 CVE-2026-23274 CVE-2026-23351 CVE-2026-23455 CVE-2026-43027 CVE-2026-43037 CVE-2026-43038 CVE-2026-43329 CVE-2026-43499 CVE-2026-46113 CVE-2026-46331 CVE-2026-53163
Users with Oracle Linux Premier Support can now use Ksplice to patch
against the latest Oracle Linux Security Advisory, ELSA-2026-50373.
More information about this errata can be found at
https://linux.oracle.com/errata/ELSA-2026-50373.html
INSTALLING THE UPDATES
We recommend that all users of Ksplice Uptrack running UEKR7 5.15.0 on
OL8 and OL9 install these updates.
On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.
Alternatively, you can install these updates by running:
# /usr/sbin/uptrack-upgrade -y
DESCRIPTION
* CVE-2025-40103: Reference count leak in SMB/CIFS client driver.
* CVE-2026-23113: Infinite loop in io_uring.
* CVE-2026-23274: Use-after-free in Netfilter driver.
* CVE-2026-23351: Use-after-free in Netfilter driver.
* CVE-2026-23455: Out-of-bounds memory access in Netfilter driver.
* CVE-2026-43027: Use-after-free in Netfilter driver.
* CVE-2026-43037: Out-of-bounds write in IPv6: IP-in-IPv6 tunnel (RFC2473) driver.
* CVE-2026-43038: Out-of-bounds write in IPv6 Networking driver.
* CVE-2026-43329: Off-by-one action count in Netfilter driver.
* CVE-2026-43499, CVE-2026-53163: Use-after-free in core kernel RT-mutex.
Orabug: 39425999
* CVE-2026-46113: Use-after-free in KVM shadow paging.
Orabug: 39673886
* CVE-2026-46331: Page cache corruption in Packet Editing driver.
Orabug: 39668793
* Redundant lock in Integrity Measurement Architecture(IMA) driver.
Orabug: 39390378
* Note: Oracle has determined some CVEs are not applicable.
The kernel is not affected by the following CVEs
since the code under consideration is not compiled.
CVE-2024-56557, CVE-2025-37778, CVE-2025-38006, CVE-2025-38562,
CVE-2025-71150, CVE-2026-23220, CVE-2026-23227, CVE-2026-23268,
CVE-2026-23269, CVE-2026-23291, CVE-2026-23298, CVE-2026-23324,
CVE-2026-23339, CVE-2026-23372, CVE-2026-23403, CVE-2026-23404,
CVE-2026-23405, CVE-2026-23406, CVE-2026-23407, CVE-2026-23408,
CVE-2026-23409, CVE-2026-23410, CVE-2026-23411, CVE-2026-23428,
CVE-2026-23446, CVE-2026-23460, CVE-2026-23463, CVE-2026-31417,
CVE-2026-31433, CVE-2026-31464, CVE-2026-31478, CVE-2026-31483,
CVE-2026-31485, CVE-2026-31507, CVE-2026-31509, CVE-2026-31545,
CVE-2026-31634, CVE-2026-31660, CVE-2026-31695, CVE-2026-31720,
CVE-2026-31721, CVE-2026-31726, CVE-2026-31728, CVE-2026-31737,
CVE-2026-31747, CVE-2026-31748, CVE-2026-31749, CVE-2026-31751,
CVE-2026-31754, CVE-2026-31755, CVE-2026-31756, CVE-2026-31770,
CVE-2026-31780, CVE-2026-43011, CVE-2026-43032, CVE-2026-43324,
CVE-2026-43327, CVE-2026-43340, CVE-2026-43342, CVE-2026-43343,
CVE-2026-43373, CVE-2026-43380, CVE-2026-43426, CVE-2026-43458,
CVE-2026-43476, CVE-2026-43480, CVE-2026-45924, CVE-2026-45958
SUPPORT
Ksplice support is available at ksplice-support_ww at oracle.com.
More information about the El-errata
mailing list