[El-errata] ELSA-2026-500375 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Thu Oct 8 08:58:11 UTC 2026


Oracle Linux Security Advisory ELSA-2026-500375

http://linux.oracle.com/errata/ELSA-2026-500375.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-uek-5.4.17-2136.360.3.el8uek.x86_64.rpm
kernel-uek-container-5.4.17-2136.360.3.el8uek.x86_64.rpm
kernel-uek-container-debug-5.4.17-2136.360.3.el8uek.x86_64.rpm
kernel-uek-debug-5.4.17-2136.360.3.el8uek.x86_64.rpm
kernel-uek-debug-devel-5.4.17-2136.360.3.el8uek.x86_64.rpm
kernel-uek-devel-5.4.17-2136.360.3.el8uek.x86_64.rpm
kernel-uek-doc-5.4.17-2136.360.3.el8uek.noarch.rpm


SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/kernel-uek-5.4.17-2136.360.3.el8uek.src.rpm

Related CVEs:

CVE-2026-23455
CVE-2026-23457
CVE-2026-31588
CVE-2026-31662
CVE-2026-31664
CVE-2026-64306
CVE-2026-64312
CVE-2026-64313
CVE-2026-68121
CVE-2026-74469
CVE-2026-80590
CVE-2026-80844
CVE-2026-81000




Description of changes:

[5.4.17-2136.360.3]
- IB/mlx4: delete allocated id_map_entry while sending REJ (Praveen Kumar Kannoju)  [Orabug: 39999072]
- net: tun: bound receive headroom (Asim Viladi Oglu Manizada)  [Orabug: 40020673]  {CVE-2026-81000}
- xfrm: ah6: validate routing header segments_left (Asim Viladi Oglu Manizada)  [Orabug: 39982188]  {CVE-2026-80844}
- inet: frags: strip GSO state from fragments before reassembly (Xinyang Ge)  [Orabug: 39972532]  {CVE-2026-80590}
- sctp: prevent peer transport count overflow (Asim Viladi Oglu Manizada)  [Orabug: 39886843]  {CVE-2026-74469}
- pppoe: reload header pointer after dev_hard_header() (Asim Viladi Oglu Manizada)  [Orabug: 39859408]  {CVE-2026-68121}

[5.4.17-2136.360.2]
- Revert "net/mlx5: Add poll-eq API to be used by ULP's" (Praveen Kumar Kannoju)  [Orabug: 39764468]

[5.4.17-2136.360.1]
- x86/alternatives: Guard struct alt_instr kABI layout (Saeed Mirzamohammadi) [Orabug: 39860383]
- crypto: ecc - Fix carry overflow in vli multiplication (Anastasia Tishchenko) [Orabug: 39785911] {CVE-2026-64313}
- crypto: pcrypt - restore callback for non-parallel fallback (Ruijie Li) [Orabug: 39785907] {CVE-2026-64312}
- crypto: drbg - Fix returning success on failure in CTR_DRBG (Eric Biggers) [Orabug: 39785894] {CVE-2026-64306}
- KVM: x86: Use scratch field in MMIO fragment to hold small write values (Sean Christopherson) [Orabug: 39273524] {CVE-2026-31588}
- xfrm: clear trailing padding in build_polexpire() (Yasuaki Torimaru) [Orabug: 39262403] {CVE-2026-31664}
- tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (Oleh Konko) [Orabug: 39262395] {CVE-2026-31662}
- netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() (Lukas Johannes Möller) [Orabug: 39167519] {CVE-2026-23457}
- netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (Jenny Guanni Qu) [Orabug: 39167511] {CVE-2026-23455}




More information about the El-errata mailing list