[Ksplice][Ubuntu-22.04-Updates] New Ksplice updates for Ubuntu 22.04 Jammy (USN-8575-1)

Oracle Ksplice gregory.herrero at oracle.com
Tue Sep 1 19:16:40 UTC 2026


Synopsis: USN-8575-1 can now be patched using Ksplice
CVEs: CVE-2023-53629 CVE-2024-35865 CVE-2025-38710 CVE-2026-23112 CVE-2026-23204 CVE-2026-23340 CVE-2026-23391 CVE-2026-23392 CVE-2026-31454 CVE-2026-31469 CVE-2026-31586 CVE-2026-31665 CVE-2026-31673 CVE-2026-31694 CVE-2026-43060 CVE-2026-43074 CVE-2026-43190 CVE-2026-43278 CVE-2026-43329 CVE-2026-43502 CVE-2026-45852 CVE-2026-45864 CVE-2026-45899 CVE-2026-46259 CVE-2026-46319 CVE-2026-52955 CVE-2026-52958 CVE-2026-52993 CVE-2026-53002 CVE-2026-53006 CVE-2026-53040 CVE-2026-53043 CVE-2026-53050 CVE-2026-64018 CVE-2026-64032 CVE-2026-64114 CVE-2026-64115

Systems running Ubuntu 22.04 Jammy can now use Ksplice to patch
against the latest Ubuntu Security Notice, USN-8575-1.

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack running Ubuntu 22.04
Jammy install these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


DESCRIPTION

* CVE-2023-53629: Use-after-free in Distributed Lock Manager (DLM) driver.

* CVE-2024-35865: Use-after-free in SMB/CIFS client driver.

* CVE-2025-38710: Out-of-bounds memory access in GFS2 filesystem driver.

* CVE-2026-23112: Null pointer dereference in NVMe/TCP target subsystem.

* CVE-2026-23204: Out-of-bounds memory access in Universal 32bit comparisons (U32) driver.

* CVE-2026-23340: Use-after-free in Queuing Discipline (qdisc) subsystem.

* CVE-2026-23391, CVE-2026-43060: Use-after-free in Netfilter driver.

* CVE-2026-23392: Use-after-free in Netfilter driver.

* CVE-2026-31454: Use-after-free in XFS filesystem driver.

* CVE-2026-31469: Use-after-free in Virtio network driver.

* CVE-2026-31586: Use-after-free in memory management core.

* CVE-2026-31665: Use-after-free in Netfilter nf_tables conntrack module driver.

* CVE-2026-31673: Use-after-free in Unix domain sockets driver.

* CVE-2026-31694: Out-of-bounds memory access in FUSE filesystem.

* CVE-2026-43074: Use-after-free in epoll.

* CVE-2026-43190: Out-of-bounds memory access in Netfilter driver.

* CVE-2026-43278: Use-after-free in Multiple devices (RAID and LVM) driver.

* CVE-2026-43329: Off-by-one action count in Netfilter driver.

* CVE-2026-43502: Use-after-free in Reliable Datagram Sockets Protocol driver.

* CVE-2026-45852: Memory leak in Software RDMA over Ethernet (RoCE) driver.

* CVE-2026-45864: Infinite loop in NTFS Read-Write filesystem driver.

* CVE-2026-45899: Data corruption in Ext4 filesystem.

* CVE-2026-46259: Use-after-free in /proc filesystem driver.

* CVE-2026-46319: Use-after-free in Connection Tracking Action module.

* CVE-2026-52955: Out-of-bounds memory access in Ceph core library driver.

* CVE-2026-52958: Out-of-bounds memory access in Ceph core library driver.

* CVE-2026-52993: Use-after-free in TIPC Protocol driver.

* CVE-2026-53002: Out-of-bounds memory access in Netfilter driver.

* CVE-2026-53006: Use-after-free in Networking driver.

* CVE-2026-53040: Out-of-bounds memory access in OCFS2 filesystem.

* CVE-2026-53043: Out-of-bounds memory access in O2CB Kernelspace Clustering driver.

* CVE-2026-53050: Use-after-free in Quota driver.

* CVE-2026-64018: Out-of-bounds memory access in Microsoft Azure Network Adapter (MANA) driver.

* CVE-2026-64032: Use-after-free in IGMP/MLD snooping driver.

* CVE-2026-64114: Out-of-bounds memory access in IPv4 networking stack.

* CVE-2026-64115: Remote use-after-free in Virtual Socket protocol driver.

* Note: Oracle has determined some CVEs are not applicable.

The kernel is not affected by the following CVEs
since the code under consideration is not compiled.

CVE-2024-56727, CVE-2025-40005, CVE-2025-71221, CVE-2026-23222,
CVE-2026-23227, CVE-2026-23438, CVE-2026-23463, CVE-2026-31464,
CVE-2026-31483, CVE-2026-31485, CVE-2026-31489, CVE-2026-31550,
CVE-2026-31585, CVE-2026-31594, CVE-2026-31599, CVE-2026-31615,
CVE-2026-31627, CVE-2026-31686, CVE-2026-31687, CVE-2026-31737,
CVE-2026-31756, CVE-2026-31770, CVE-2026-43058, CVE-2026-43104,
CVE-2026-43105, CVE-2026-43132, CVE-2026-43145, CVE-2026-43148,
CVE-2026-43149, CVE-2026-43196, CVE-2026-43202, CVE-2026-43205,
CVE-2026-43207, CVE-2026-43227, CVE-2026-43236, CVE-2026-43242,
CVE-2026-43261, CVE-2026-43264, CVE-2026-43269, CVE-2026-43270,
CVE-2026-43296, CVE-2026-43302, CVE-2026-43324, CVE-2026-43327,
CVE-2026-43426, CVE-2026-45839, CVE-2026-45867, CVE-2026-45868,
CVE-2026-45869, CVE-2026-45885, CVE-2026-45904, CVE-2026-45954,
CVE-2026-45956, CVE-2026-45958, CVE-2026-45986, CVE-2026-46002,
CVE-2026-46019, CVE-2026-46077, CVE-2026-46112, CVE-2026-46219,
CVE-2026-46249, CVE-2026-46250, CVE-2026-46273, CVE-2026-46301,
CVE-2026-53045, CVE-2026-53068, CVE-2026-53294, CVE-2026-53296,
CVE-2026-64039, CVE-2026-64056, CVE-2026-64153, CVE-2026-64165,
CVE-2026-64166, CVE-2026-64168, CVE-2026-64221, CVE-2026-64587


SUPPORT

Ksplice support is available at ksplice-support_ww at oracle.com.





More information about the Ksplice-Ubuntu-22.04-updates mailing list