Oracle Linux 10 : ELSA-2026-64775-0: / kernel (ELSA-2026-647750)

high Nessus Plugin ID 344653

Synopsis

The remote Oracle Linux host is missing one or more security updates.

Description

The remote Oracle Linux 10 host has packages installed that are affected by multiple vulnerabilities as referenced in the ELSA-2026-647750 advisory.

- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244969] {CVE-2026-72098}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244928] {CVE-2026-72129}
- wifi: mac80211: defer link RX stats percpu free to RCU (Jose Ignacio Tornos Martinez) [RHEL-237706] {CVE-2026-68409}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Jose Ignacio Tornos Martinez) [RHEL-237681] {CVE-2026-68193}
- wifi: mt76: mt7925: fix crash in reset link replay (Jose Ignacio Tornos Martinez) [RHEL-237527] {CVE-2026-68307}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232015] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230977] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230604] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229725] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232673] {CVE-2026-53072}
- accel/qaic: Add overflow check to remap_pfn_range during mmap (CKI Backport Bot) [RHEL-232178] {CVE-2026-64051}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231067] {CVE-2026-63947}
- Bluetooth: virtio_bt: validate rx pkt_type header length (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: virtio_bt: clamp rx length before skb_put (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230076] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230013] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228750] {CVE-2026-63975}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227889] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227532] {CVE-2026-43334}
- vfio/pci: Check BAR resources before exporting a DMABUF (CKI Backport Bot) [RHEL-227133] {CVE-2026-64042}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225690] {CVE-2026-64015}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225653] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225574] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225552] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)->pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: init shinfo->gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)->pkt_segs (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- vfio/pci: Clean up DMABUFs before disabling function (CKI Backport Bot) [RHEL-189549] {CVE-2026-53322}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189468] {CVE-2026-43133}
- fuse: fix race between interrupt and resend (Miklos Szeredi) [RHEL-218495] {CVE-2026-64265}
- fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req (Miklos Szeredi) [RHEL-218495] {CVE-2026-64265}
- rhashtable: clear stale iter->p on table restart (CKI Backport Bot) [RHEL-248457] {CVE-2026-64563}
- udp: Fix wildcard bind conflict check when using hash2 (Felix Maurer) [RHEL-218016] {CVE-2026-31503}
- tcp: call sk_data_ready() after listener migration (Felix Maurer) [RHEL-232246] {CVE-2026-46015}
- flow_dissector: do not dissect PPPoE PFC frames (Felix Maurer) [RHEL-232629] {CVE-2026-46306}
- inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (Felix Maurer) [RHEL-226125] {CVE-2026-46266}
- ipv6: anycast: insert aca into global hash under idev->lock (Felix Maurer) [RHEL-230763] {CVE-2026-53259}
- ipv6: mcast: Fix use-after-free when processing MLD queries (Felix Maurer) [RHEL-226073] {CVE-2026-53275}
- ipv6: prevent possible UaF in addrconf_permanent_addr() (Felix Maurer) [RHEL-225606] {CVE-2026-43339}
- net: guard timestamp cmsgs to real error queue skbs (Felix Maurer) [RHEL-225864] {CVE-2026-53223}
- net: add pskb_may_pull() to skb_gro_receive_list() (Felix Maurer) [RHEL-229309] {CVE-2026-53235}
- can: bcm: extend bcm_tx_lock usage for data and timer updates (Abhishek Rawal) [RHEL-216700] {CVE-2025-38004}
- can: bcm: add locking when updating filter and timer values (Abhishek Rawal) [RHEL-216700] {CVE-2025-38004}
- can: bcm: fix locking for bcm_op runtime updates (Abhishek Rawal) [RHEL-216700] {CVE-2025-38004}
- can: bcm: add locking for bcm_op runtime updates (Abhishek Rawal) [RHEL-216700] {CVE-2025-38004}
- smb: client: fix double-free in SMB2_close() replay (Paulo Alcantara) [RHEL-240056] {CVE-2026-64597}
- netfilter: nfnetlink_queue: make hash table per queue (Florian Westphal) [RHEL-132852] {CVE-2026-43084}
- ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (Abhishek Rawal) [RHEL-228009] {CVE-2026-53075}
- vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() (Abhishek Rawal) [RHEL-231711] {CVE-2026-63993}
- ipv6: sit: reload inner IPv6 header after GSO offloads (Abhishek Rawal) [RHEL-225920] {CVE-2026-53228}
- ipv6: add NULL checks for idev in SRv6 paths (Abhishek Rawal) [RHEL-218012] {CVE-2026-23442}
- nvmet-auth: validate reply message payload bounds against transfer length (CKI Backport Bot) [RHEL-234153] {CVE-2026-64319}
- KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (CKI Backport Bot) [RHEL-234204] {CVE-2026-64287}
- KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (CKI Backport Bot) [RHEL-229347] {CVE-2026-53277}
- ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (CKI Backport Bot) [RHEL-227269] {CVE-2026-64002}

Tenable has extracted the preceding description block directly from the Oracle Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://linux.oracle.com/errata/ELSA-2026-64775-0.html

Plugin Details

Severity: High

ID: 344653

File Name: oraclelinux_ELSA-2026-647750.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/10/2026

Updated: 9/10/2026

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.8

Percentile: 99.33

CVSS v2

Risk Factor: Medium

Base Score: 6.2

Temporal Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:C

CVSS Score Source: CVE-2025-38004

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.4

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:oracle:linux:10, cpe:/o:oracle:linux:10:2:baseos_patch, p-cpe:/a:oracle:linux:kernel-abi-stablelists, p-cpe:/a:oracle:linux:kernel-core, p-cpe:/a:oracle:linux:kernel-cross-headers, p-cpe:/a:oracle:linux:kernel-debug-core, p-cpe:/a:oracle:linux:kernel-debug-devel-matched, p-cpe:/a:oracle:linux:kernel-debug-devel, p-cpe:/a:oracle:linux:kernel-debug-modules-core, p-cpe:/a:oracle:linux:kernel-debug-modules-extra, p-cpe:/a:oracle:linux:kernel-debug-modules, p-cpe:/a:oracle:linux:kernel-debug-uki-virt, p-cpe:/a:oracle:linux:kernel-debug, p-cpe:/a:oracle:linux:kernel-devel-matched, p-cpe:/a:oracle:linux:kernel-devel, p-cpe:/a:oracle:linux:kernel-headers, p-cpe:/a:oracle:linux:kernel-modules-core, p-cpe:/a:oracle:linux:kernel-modules-extra-matched, p-cpe:/a:oracle:linux:kernel-modules-extra, p-cpe:/a:oracle:linux:kernel-modules, p-cpe:/a:oracle:linux:kernel-tools-libs-devel, p-cpe:/a:oracle:linux:kernel-tools-libs, p-cpe:/a:oracle:linux:kernel-tools, p-cpe:/a:oracle:linux:kernel-uki-virt-addons, p-cpe:/a:oracle:linux:kernel-uki-virt, p-cpe:/a:oracle:linux:kernel, p-cpe:/a:oracle:linux:libperf, p-cpe:/a:oracle:linux:perf, p-cpe:/a:oracle:linux:python3-perf, p-cpe:/a:oracle:linux:rtla, p-cpe:/a:oracle:linux:rv

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/OracleLinux

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/10/2026

Vulnerability Publication Date: 6/8/2025

Reference Information

CVE: CVE-2025-38004, CVE-2026-23442, CVE-2026-31503, CVE-2026-43339, CVE-2026-46015, CVE-2026-46266, CVE-2026-46306, CVE-2026-52933, CVE-2026-53075, CVE-2026-53223, CVE-2026-53228, CVE-2026-53235, CVE-2026-53259, CVE-2026-53275, CVE-2026-53277, CVE-2026-63993, CVE-2026-64002, CVE-2026-64265, CVE-2026-64287, CVE-2026-64319, CVE-2026-64563, CVE-2026-64597