From gregory.herrero at oracle.com Wed Aug 5 22:17:25 2026 From: gregory.herrero at oracle.com (Oracle Ksplice) Date: Wed, 05 Aug 2026 22:17:25 +0000 Subject: [Ksplice][Ubuntu-22.04-Updates] New Ksplice updates for Ubuntu 22.04 Jammy (USN-8493-1) Message-ID: Synopsis: USN-8493-1 can now be patched using Ksplice CVEs: CVE-2023-53673 CVE-2025-71089 CVE-2026-23193 CVE-2026-23216 CVE-2026-23278 CVE-2026-23455 CVE-2026-31402 CVE-2026-31607 CVE-2026-31637 CVE-2026-31657 CVE-2026-31659 CVE-2026-31669 CVE-2026-31685 CVE-2026-43011 CVE-2026-43037 CVE-2026-43038 CVE-2026-43186 CVE-2026-43304 CVE-2026-43341 CVE-2026-43383 CVE-2026-43406 CVE-2026-43407 CVE-2026-43493 CVE-2026-43501 CVE-2026-45988 CVE-2026-46043 CVE-2026-46119 CVE-2026-46135 CVE-2026-46243 Systems running Ubuntu 22.04 Jammy can now use Ksplice to patch against the latest Ubuntu Security Notice, USN-8493-1. INSTALLING THE UPDATES We recommend that all users of Ksplice Uptrack running Ubuntu 22.04 Jammy install these updates. On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf, these updates will be installed automatically and you do not need to take any action. Alternatively, you can install these updates by running: # /usr/sbin/uptrack-upgrade -y DESCRIPTION * CVE-2023-53673: Use-after-free in Bluetooth subsystem. * CVE-2025-71089: Use-after-free in IOMMU Shared Virtual Addressing. * CVE-2026-23193, CVE-2026-23216: Use-after-free in SCSI Target Mode Stack driver. * CVE-2026-23278: Use-after-free in Netfilter driver. * CVE-2026-23455: Out-of-bounds memory access in Netfilter driver. * CVE-2026-31402: Out-of-bounds memory access in NFS server driver. * CVE-2026-31607: Out-of-bounds memory access in USB/IP driver. * CVE-2026-31637: Undefined behavior in RxRPC Kerberos security driver. * CVE-2026-31657: Use-after-free in Bridge Loop Avoidance driver. * CVE-2026-31659: Out-of-bounds memory access in BATMAN Advanced Meshing Protocol driver. * CVE-2026-31669: Use-after-free in MPTCP: Multipath TCP driver. * CVE-2026-31685: MAC header bypass in Netfilter driver. * CVE-2026-43011: Double free in X.25 Packet Layer driver. * CVE-2026-43037: Out-of-bounds write in IPv6: IP-in-IPv6 tunnel (RFC2473) driver. * CVE-2026-43038: Out-of-bounds write in IPv6 Networking driver. * CVE-2026-43186: Out-of-bounds memory access in Networking driver. * CVE-2026-43304: Out-of-bounds memory access in Ceph core library driver. * CVE-2026-43341: Out-of-bounds memory access in IPv6 IOAM implementation. * CVE-2026-43383: Timing side channel in networking stack. * CVE-2026-43406: Out-of-bounds memory access in Ceph core library driver. * CVE-2026-43407: Out-of-bounds memory access in Ceph core library driver. * CVE-2026-43493: Use-after-free in Parallel crypto engine driver. * CVE-2026-43501: Out-of-bounds memory access in IPv6 networking stack. * CVE-2026-45988: Undefined behavior in RxRPC session sockets driver. * CVE-2026-46043: Out-of-bounds memory access in RDMA RXE driver. * CVE-2026-46119: Out-of-bounds memory access in Ceph core library driver. * CVE-2026-46135: Race condition in NVME-over-TCP driver. * CVE-2026-46243: Credential bypass in CIFS Kerberos/SPNEGO advanced session setup driver. * Note: Oracle has determined some CVEs are not applicable. The kernel is not affected by the following CVEs since the code under consideration is not compiled. CVE-2025-37822, CVE-2026-23180, CVE-2026-23182, CVE-2026-23202, CVE-2026-23206 SUPPORT Ksplice support is available at ksplice-support_ww at oracle.com.