[El-errata] ELSA-2026-71233 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Mon Oct 5 18:15:38 UTC 2026


Oracle Linux Security Advisory ELSA-2026-71233

http://linux.oracle.com/errata/ELSA-2026-71233.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-abi-stablelists-6.12.0-211.60.1.el10_2.noarch.rpm
kernel-core-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-cross-headers-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-debug-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-debug-core-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-debug-devel-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-debug-devel-matched-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-debug-modules-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-debug-modules-core-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-debug-modules-extra-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-debug-uki-virt-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-devel-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-devel-matched-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-doc-6.12.0-211.60.1.el10_2.noarch.rpm
kernel-headers-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-modules-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-modules-core-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-modules-extra-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-modules-extra-matched-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-tools-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-tools-libs-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-tools-libs-devel-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-uki-virt-6.12.0-211.60.1.el10_2.x86_64.rpm
kernel-uki-virt-addons-6.12.0-211.60.1.el10_2.x86_64.rpm
libperf-6.12.0-211.60.1.el10_2.x86_64.rpm
perf-6.12.0-211.60.1.el10_2.x86_64.rpm
python3-perf-6.12.0-211.60.1.el10_2.x86_64.rpm
rtla-6.12.0-211.60.1.el10_2.x86_64.rpm
rv-6.12.0-211.60.1.el10_2.x86_64.rpm

aarch64:
kernel-cross-headers-6.12.0-211.60.1.el10_2.aarch64.rpm
kernel-headers-6.12.0-211.60.1.el10_2.aarch64.rpm
kernel-tools-6.12.0-211.60.1.el10_2.aarch64.rpm
kernel-tools-libs-6.12.0-211.60.1.el10_2.aarch64.rpm
kernel-tools-libs-devel-6.12.0-211.60.1.el10_2.aarch64.rpm
libperf-6.12.0-211.60.1.el10_2.aarch64.rpm
perf-6.12.0-211.60.1.el10_2.aarch64.rpm
python3-perf-6.12.0-211.60.1.el10_2.aarch64.rpm
rtla-6.12.0-211.60.1.el10_2.aarch64.rpm
rv-6.12.0-211.60.1.el10_2.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/kernel-6.12.0-211.60.1.el10_2.src.rpm

Related CVEs:

CVE-2026-23007
CVE-2026-53266
CVE-2026-63802
CVE-2026-63831
CVE-2026-64053
CVE-2026-64383
CVE-2026-64564
CVE-2026-68201
CVE-2026-72243
CVE-2026-74569
CVE-2026-80844
CVE-2026-81000
CVE-2026-89846




Description of changes:

[6.12.0-211.60.1]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Update module name for cryptographic module [Orabug: 37400433]
- Clean git history at setup stage

[6.12.0-211.60.1]
- pppoe: reload header pointer after dev_hard_header() (Guillaume Nault) [RHEL-242509] {CVE-2026-68121}
- nvme-tcp: fix host memory disclosure on R2T for a read command (CKI Backport Bot) [RHEL-263403] {CVE-2026-89481}
- af_unix: Drop all SCM attributes for SOCKMAP. (Davide Caratti) [RHEL-229262] {CVE-2026-53005}
- af_unix: Don't use skb_recv_datagram() in unix_stream_read_skb(). (Davide Caratti) [RHEL-229262]
- af_unix: Don't check SOCK_DEAD in unix_stream_read_skb(). (Davide Caratti) [RHEL-229262]
- ipvs: do not propagate one-packet flag to synced conns (CKI Backport Bot) [RHEL-255860] {CVE-2026-80714}
- drm/amdgpu/vce: fix integer overflow in image size (Mika Penttilä) [RHEL-257136] {CVE-2026-68108}
- drm/amdkfd: fix 32-bit overflow in CWSR total size calculation (Mika Penttilä) [RHEL-237844] {CVE-2026-68257}
- drm/xe: Hold a dma-buf reference for imported BOs (CKI Backport Bot) [RHEL-236300] {CVE-2026-68266}
- drm/virtio: use uninterruptible resv lock for plane updates (CKI Backport Bot) [RHEL-229327] {CVE-2026-64098}
- drm/amdgpu/userq: fix access to stale wptr mapping (Mika Penttilä) [RHEL-225409] {CVE-2026-46311}
- drm/amdgpu: do not use amdgpu_bo_gpu_offset_no_check individually (Mika Penttilä) [RHEL-225409] {CVE-2026-46311}
- drm/amdgpu: Fix context pstate override handling (CKI Backport Bot) [RHEL-236714] {CVE-2026-68273}
- drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (CKI Backport Bot) [RHEL-237962] {CVE-2026-68267}
- drm/xe/rtp: Refactor OAG MMIO trigger register whitelisting (CKI Backport Bot) [RHEL-237962] {CVE-2026-68267}
- drm/xe/xe3: Apply wa_14024997852 (CKI Backport Bot) [RHEL-237962] {CVE-2026-68267}
- drm/xe/eustall: Fix drm_dev_put called before stream disable in close (CKI Backport Bot) [RHEL-229371] {CVE-2026-53290}
- drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check (Mika Penttilä) [RHEL-225316]
- drm/amdgpu/vcn3: Avoid overflow on msg bound check (Mika Penttilä) [RHEL-225316] {CVE-2026-46230}
- drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (Mika Penttilä) [RHEL-225316] {CVE-2026-46230}
- drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (CKI Backport Bot) [RHEL-226047] {CVE-2026-46204}
- fbcon: Set fb_display[i]->mode to NULL when the mode is released (Mika Penttilä) [RHEL-250108] {CVE-2025-40323}
- drm/amdgpu/vcn4: Avoid overflow on msg bound check (Mika Penttilä) [RHEL-225444] {CVE-2026-46199}
- drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (Mika Penttilä) [RHEL-225444] {CVE-2026-46199}
- powerpc/powernv/iommu: iommu incorrectly bypass DMA APIs (Jerry Snitselaar) [RHEL-252331]
- powerpc/iommu: bypass DMA APIs for coherent allocations for pre-mapped memory (Jerry Snitselaar) [RHEL-252331]
- accel/ivpu: Add buffer overflow check in MS get_info_ioctl (CKI Backport Bot) [RHEL-230647] {CVE-2026-53203}
- libceph: fix potential use-after-free in have_mon_and_osd_map() (CKI Backport Bot) [RHEL-169081] {CVE-2025-68285}
- libceph: reset sparse-read state in osd_fault() (CKI Backport Bot) [RHEL-169079] {CVE-2026-23136}
- libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (CKI Backport Bot) [RHEL-169072] {CVE-2026-22990}
- libceph: prevent potential out-of-bounds reads in handle_auth_done() (CKI Backport Bot) [RHEL-169068] {CVE-2026-22984}
- libceph: make decode_pool() more resilient against corrupted osdmaps (CKI Backport Bot) [RHEL-169064] {CVE-2025-71116}

[6.12.0-211.59.1]
- net: tun: bound receive headroom (CKI Backport Bot) [RHEL-264371] {CVE-2026-81000}
- xfrm: ah6: validate routing header segments_left (CKI Backport Bot) [RHEL-264303] {CVE-2026-80844}
- scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (CKI Backport Bot) [RHEL-262556] {CVE-2026-89846}
- netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (CKI Backport Bot) [RHEL-260585] {CVE-2026-74569}
- redhat/configs: automotive: debug: enable KASAN_INLINE (Jared Kangas) [RHEL-259788]
- watchdog: s32g_wdt: remove incorrect options in watchdog_info struct (Jared Kangas) [RHEL-259788]
- usb: chipidea: fix usage_count leak when autosuspend_delay is negative (Jared Kangas) [RHEL-259788]
- usb: chipidea: core: convert ci_role_switch to local variable (Jared Kangas) [RHEL-259788]
- usb: chipidea: otg: not wait vbus drop if use role_switch (Jared Kangas) [RHEL-259788]
- usb: chipidea: core: allow ci_irq_handler() handle both ID and VBUS change (Jared Kangas) [RHEL-259788]
- rtc: pcf85063: fix incorrect maximum clock rate handling (Jared Kangas) [RHEL-259788]
- mmc: sdhci-esdhc-imx: fix resume error handling (Jared Kangas) [RHEL-259788]
- mmc: sdhci-esdhc-imx: make non-fatal errors non-blocking in suspend (Jared Kangas) [RHEL-259788]
- mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend (Jared Kangas) [RHEL-259788]
- mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt (Jared Kangas) [RHEL-259788]
- mmc: sdhci-esdhc-imx: restore pinctrl before restoring ios timing on resume (Jared Kangas) [RHEL-259788]
- mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore (Jared Kangas) [RHEL-259788]
- mmc: sdhci-esdhc-imx: restore DLL override for DDR modes on resume (Jared Kangas) [RHEL-259788]
- mmc: sdhci-esdhc-imx: remove unnecessary mmc_card_wake_sdio_irq check for tuning save/restore (Jared Kangas) [RHEL-259788]
- i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ) (Jared Kangas) [RHEL-259788]
- i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (Jared Kangas) [RHEL-259788]
- i2c: imx: Cancel hrtimer before clearing slave pointer (Jared Kangas) [RHEL-259788]
- i2c: imx: Fix slave registration race and error handling (Jared Kangas) [RHEL-259788]
- i2c: imx: mark I2C adapter when hardware is powered down (Jared Kangas) [RHEL-259788]
- gpio: pca953x: fix cache_only and IRQ state on restore_context() failure (Jared Kangas) [RHEL-259788]
- gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock (Jared Kangas) [RHEL-259788]
- gpio: pca953x: drop bitmap_complement() where feasible (Jared Kangas) [RHEL-259788]
- gpio: pca953x: enable latch only on edge-triggered inputs (Jared Kangas) [RHEL-259788]
- gpio: pca953x: handle short interrupt pulses on PCAL devices (Jared Kangas) [RHEL-259788]
- gpio: pca953x: Add support for level-triggered interrupts (Jared Kangas) [RHEL-259788]
- gpio: pca953x: fix wrong error probe return value (Jared Kangas) [RHEL-259788]
- gpio: pca953x: fix IRQ storm on system wake up (Jared Kangas) [RHEL-259788]
- gpio: pca953x: log an error when failing to get the reset GPIO (Jared Kangas) [RHEL-259788]
- gpio: pca953x: Improve interrupt support (Jared Kangas) [RHEL-259788]
- selinux: check connect-related permissions on TCP Fast Open (CKI Backport Bot) [RHEL-258024] {CVE-2026-72243}
- smb: client: fix double-free in SMB2_flush() replay (CKI Backport Bot) [RHEL-253205] {CVE-2026-64383}
- RHEL: revert "block: only zero non-PI metadata tuples in bio_integrity_prep" (Jeff Moyer) [RHEL-189638] {CVE-2026-23007}
- block: always allocate integrity buffer when required (Jeff Moyer) [RHEL-189638]
- block: don't overwrite bip_vcnt in bio_integrity_copy_user() (Jeff Moyer) [RHEL-232375] {CVE-2026-64053}
- blk-cgroup: fix UAF in __blkcg_rstat_flush() (Jeff Moyer) [RHEL-230292] {CVE-2026-63802}
- bnxt_en: Gate TPH enablement behind BNXT_SUPPORTS_QUEUE_API check (CKI Backport Bot) [RHEL-247283]
- ALSA: timer: drain a slave's callback before its master detaches it (CKI Backport Bot) [RHEL-236084] {CVE-2026-68201}
- sctp: don't free the ASCONF's own transport in DEL-IP processing (CKI Backport Bot) [RHEL-234288] {CVE-2026-64564}
- mac802154: llsec: add skb_cow_data() before in-place crypto (CKI Backport Bot) [RHEL-231034] {CVE-2026-63831}
- sctp: prevent peer transport count overflow (Xin Long) [RHEL-216247]
- netfilter: bridge: make ebt_snat ARP rewrite writable (CKI Backport Bot) [RHEL-190036] {CVE-2026-53266}
- module.lds,codetag: force 0 sh_addr for sections (Joe Lawrence) [RHEL-159298]

[6.12.0-211.58.1]
- crypto: af_alg - Fix incorrect boolean values in af_alg_ctx (CKI Backport Bot) [RHEL-264234] {CVE-2025-39964}
- crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CKI Backport Bot) [RHEL-264234] {CVE-2025-39964}

[6.12.0-211.57.1]
- nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (CKI Backport Bot) [RHEL-260452] {CVE-2026-64534}
- mm/hugetlb: fix list corruption in allocate_file_region_entries() (Rafael Aquini) [RHEL-254491] {CVE-2026-74518}
- redhat/configs: automotive: enable PWM_FSL_FTM as a module (Mattijs Korpershoek) [RHEL-255517]
- arm64: dts: s32g: add PWM support for s32g2 and s32g3 (Mattijs Korpershoek) [RHEL-255517]
- pwm: Add the S32G support in the Freescale FTM driver (Mattijs Korpershoek) [RHEL-255517]
- pwm: fsl-ftm: Drop driver local locking (Mattijs Korpershoek) [RHEL-255517]
- pwm: fsl-ftm: Handle clk_get_rate() returning 0 (Mattijs Korpershoek) [RHEL-255517]
- libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (CKI Backport Bot) [RHEL-237164] {CVE-2026-68159}
- libceph: Amend checking to fix make W=1 build breakage (CKI Backport Bot) [RHEL-237164] {CVE-2026-68159}
- Bluetooth: RFCOMM: Fix session UAF in set_termios (CKI Backport Bot) [RHEL-241107] {CVE-2026-68188}
- libceph: Reject monmaps advertising zero monitors (CKI Backport Bot) [RHEL-240892] {CVE-2026-68155}
- redhat: look for secureboot-uki-virt in /etc (Jan Stancek) [RHEL-169478]
- redhat/kernel.spec: derive pesign_name_0 from secureboot_key_0 (Jan Stancek) [RHEL-169478]
- redhat/kernel.spec.template: Simplify uki-virt signing (Jan Stancek) [RHEL-169478]
- redhat/kernel.spec.template: Fix indentation of uki-virt generation code (Jan Stancek) [RHEL-169478]
- redhat: sign centos kernel and UKIs with 800 certs (Jan Stancek) [RHEL-169478]
- iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry (Eder Zulian) [RHEL-228471]
- iommu/vt-d: Fix race condition during PASID entry replacement (Eder Zulian) [RHEL-228471] {CVE-2026-45945}
- iommu/vt-d: Clear Present bit before tearing down context entry (Eder Zulian) [RHEL-228471] {CVE-2026-45944}
- iommu/vt-d: Clear Present bit before tearing down PASID entry (Eder Zulian) [RHEL-228471] {CVE-2026-45894}
- Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (CKI Backport Bot) [RHEL-236849] {CVE-2026-68391}
- net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (CKI Backport Bot) [RHEL-236786] {CVE-2026-68293}
- dm cache policy smq: check allocation under invalidate lock (CKI Backport Bot) [RHEL-231825] {CVE-2026-53062}
- dm cache policy smq: fix missing locks in invalidating cache blocks (CKI Backport Bot) [RHEL-231825] {CVE-2026-53062}
- crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree (CKI Backport Bot) [RHEL-230408] {CVE-2026-45959}
- keys: Pin request_key_auth payload in instantiate paths (CKI Backport Bot) [RHEL-225496] {CVE-2026-63823}




More information about the El-errata mailing list