[Ksplice][Ubuntu-24.04-Updates] New Ksplice updates for Ubuntu 24.04 Noble (USN-8278-1)
Oracle Ksplice
gregory.herrero at oracle.com
Mon Jun 29 16:51:13 UTC 2026
Synopsis: USN-8278-1 can now be patched using Ksplice
CVEs: CVE-2025-40149 CVE-2025-71183 CVE-2025-71194 CVE-2026-22976 CVE-2026-22977 CVE-2026-22979 CVE-2026-22984 CVE-2026-22988 CVE-2026-22998 CVE-2026-23001 CVE-2026-23003 CVE-2026-23010 CVE-2026-23011 CVE-2026-23050 CVE-2026-23057 CVE-2026-23059 CVE-2026-23069 CVE-2026-23086 CVE-2026-23087 CVE-2026-23097 CVE-2026-23099 CVE-2026-23105 CVE-2026-23113 CVE-2026-23120 CVE-2026-23139 CVE-2026-23159 CVE-2026-23168 CVE-2026-23173 CVE-2026-23193 CVE-2026-23200 CVE-2026-23204 CVE-2026-23216 CVE-2026-23274 CVE-2026-23394 CVE-2026-31419 CVE-2026-31431 CVE-2026-31504 CVE-2026-31533 CVE-2026-43033 CVE-2026-43077 CVE-2026-43078 CVE-2026-46028
Systems running Ubuntu 24.04 Noble can now use Ksplice to patch
against the latest Ubuntu Security Notice, USN-8278-1.
INSTALLING THE UPDATES
We recommend that all users of Ksplice Uptrack running Ubuntu 24.04
Noble install these updates.
On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.
Alternatively, you can install these updates by running:
# /usr/sbin/uptrack-upgrade -y
DESCRIPTION
* CVE-2025-40149: Use-after-free in Transport Layer Security HW offload driver.
* CVE-2025-71183: Kernel assertion failure in Btrfs filesystem driver.
* CVE-2025-71194: Deadlock in Btrfs filesystem driver.
* CVE-2026-22976: Null pointer dereference in QFQ network scheduler.
* CVE-2026-22977: Kernel panic in TCP/IP networking driver.
* CVE-2026-22979: Memory leak in TCP/IP networking driver.
* CVE-2026-22984: Out-of-bounds memory access in Ceph core library driver.
* CVE-2026-22988: Use-after-free in TCP/IP networking driver.
* CVE-2026-22998: Null pointer dereference in NVME subsystem.
* CVE-2026-23001: Use-after-free in MAC-VLAN driver.
* CVE-2026-23003: Use of uninitialized memory in IP-in-IPv6 tunnel driver.
* CVE-2026-23010: Use-after-free in IPv6.
* CVE-2026-23011: Kernel panic in GRE tunnel.
* CVE-2026-23050: Deadlock in NFS client driver.
* CVE-2026-23057: Out-of-bounds memory access in Virtual Socket protocol driver.
* CVE-2026-23059: Out-of-bounds memory access in QLogic QLA2XXX Fibre Channel driver.
* CVE-2026-23069: Memory exhaustion in Virtual Socket protocol driver.
* CVE-2026-23086: Memory exhaustion in Virtual Socket protocol driver.
* CVE-2026-23087: Memory leak in XEN SCSI backend driver.
* CVE-2026-23097: Deadlock in Page migration driver.
* CVE-2026-23099: Out-of-bounds memory access in Bonding driver.
* CVE-2026-23105: Undefined behavior in QFQ network scheduler.
* CVE-2026-23113: Infinite loop in io_uring.
* CVE-2026-23120: Data race in Layer Two Tunneling Protocol (L2TP) driver.
* CVE-2026-23139: Memory leak in Netfilter driver.
* CVE-2026-23159: Null pointer dereference in Kernel performance events and counters driver.
* CVE-2026-23168: Deadlock in FUSE.
* CVE-2026-23173: Null pointer dereference in MLX5 TC classifier action driver.
* CVE-2026-23193, CVE-2026-23216: Use-after-free in SCSI Target Mode Stack driver.
* CVE-2026-23200: Kernel panic in IPv6.
* CVE-2026-23204: Out-of-bounds memory access in U32 network classifer.
* CVE-2026-23274: Use-after-free in Netfilter driver.
* CVE-2026-23394: Use-after-free in Unix domain sockets driver.
* CVE-2026-31419: Use-after-free in Bonding driver.
* CVE-2026-31431, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078, CVE-2026-46028: Privilege escalation in userspace AEAD crypto API.
* CVE-2026-31504: Use-after-free in Packet socket driver.
* CVE-2026-31533: Use-after-free in Transport Layer Security driver.
* Note: Oracle has determined some CVEs are not applicable.
The kernel is not affected by the following CVEs
since the code under consideration is not compiled.
CVE-2025-71162, CVE-2025-71163, CVE-2025-71185, CVE-2025-71186,
CVE-2025-71188, CVE-2025-71189, CVE-2025-71190, CVE-2025-71191,
CVE-2025-71192, CVE-2025-71193, CVE-2025-71196, CVE-2025-71199,
CVE-2025-71200, CVE-2025-71270, CVE-2026-23026, CVE-2026-23030,
CVE-2026-23033, CVE-2026-23049, CVE-2026-23064, CVE-2026-23068,
CVE-2026-23085, CVE-2026-23102, CVE-2026-23107, CVE-2026-23116,
CVE-2026-23128, CVE-2026-23142, CVE-2026-23144, CVE-2026-23170,
CVE-2026-23180, CVE-2026-23182, CVE-2026-23187, CVE-2026-23202,
CVE-2026-23206
SUPPORT
Ksplice support is available at ksplice-support_ww at oracle.com.
More information about the Ksplice-Ubuntu-24.04-updates
mailing list