Oracle Linux 8 : kernel (ELSA-2026-71329)

high Nessus Plugin ID 352254

Synopsis

The remote Oracle Linux host is missing one or more security updates.

Description

The remote Oracle Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the ELSA-2026-71329 advisory.

- pppoe: reload header pointer after dev_hard_header() (Guillaume Nault) [RHEL-237293] {CVE-2026-68121}
- nvme-tcp: reject a read that transferred too few bytes (CKI Backport Bot) [RHEL-263345] {CVE-2026-89480}
- nvme: rename and document nvme_end_request (CKI Backport Bot) [RHEL-263345] {CVE-2026-89480}
- ipvs: do not propagate one-packet flag to synced conns (CKI Backport Bot) [RHEL-255839] {CVE-2026-80714}
- netfilter: nf_queue: hold bridge skb->dev while queued (CKI Backport Bot) [RHEL-231233] {CVE-2026-52912}
- drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CKI Backport Bot) [RHEL-221269] {CVE-2026-31566}
- net: tun: bound receive headroom (CKI Backport Bot) [RHEL-264385] {CVE-2026-81000}
- xfrm: ah6: validate routing header segments_left (CKI Backport Bot) [RHEL-264314] {CVE-2026-80844}
- scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (CKI Backport Bot) [RHEL-262571] {CVE-2026-89846}
- ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (CKI Backport Bot) [RHEL-243620] {CVE-2026-72261}
- mac802154: llsec: add skb_cow_data() before in-place crypto (Abhishek Rawal) [RHEL-231030] {CVE-2026-63831}
- sctp: don't free the ASCONF's own transport in DEL-IP processing (CKI Backport Bot) [RHEL-234282] {CVE-2026-64564}
- drm/amdgpu: Fix use-after-free race in VM acquire (CKI Backport Bot) [RHEL-222381] {CVE-2026-43370}
- crypto: af_alg - Fix incorrect boolean values in af_alg_ctx (CKI Backport Bot) [RHEL-264205] {CVE-2025-39964}
- crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CKI Backport Bot) [RHEL-264205] {CVE-2025-39964}
- nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (CKI Backport Bot) [RHEL-260522] {CVE-2026-64534}
- nvmet-tcp: pass iov_len instead of sg->length to bvec_set_page() (Chris Leech) [RHEL-260522] {CVE-2026-64534}
- nvmet-tcp: remove nvmet_tcp_finish_cmd (CKI Backport Bot) [RHEL-260522] {CVE-2026-64534}
- nvmet-tcp: fix NULL pointer dereference during release (Chris Leech) [RHEL-260522] {CVE-2026-64534}
- nvmet-tcp: don't map pages which can't come from HIGHMEM (CKI Backport Bot) [RHEL-260522] {CVE-2026-64534}
- keys: Pin request_key_auth payload in instantiate paths (Bruno Meneguele) [RHEL-225491] {CVE-2026-63823}
- iommu/vt-d: Clear Present bit before tearing down PASID entry (Eder Zulian) [RHEL-228475] {CVE-2026-45894}
- iommu/amd: Fix clone_alias() to use the original device's devid (Eder Zulian) [RHEL-227450] {CVE-2026-53053}
- Bluetooth: RFCOMM: Fix session UAF in set_termios (CKI Backport Bot) [RHEL-237326] {CVE-2026-68188}
- net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (CKI Backport Bot) [RHEL-236787] {CVE-2026-68293}
- RDMA/rxe: Fix a use-after-free problem in rxe_mmap (Kamal Heib) [RHEL-233821] {CVE-2026-64582}
- RDMA/rxe: Reject unknown opcodes before ICRC processing (Kamal Heib) [RHEL-226871] {CVE-2026-46133}
- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (Kamal Heib) [RHEL-228181] {CVE-2026-46043}
- dm cache policy smq: check allocation under invalidate lock (CKI Backport Bot) [RHEL-231810] {CVE-2026-53062}
- dm cache policy smq: fix missing locks in invalidating cache blocks (CKI Backport Bot) [RHEL-231810] {CVE-2026-53062}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231060] {CVE-2026-63947}
- Bluetooth: L2CAP: Fix potential user-after-free (CKI Backport Bot) [RHEL-229428] {CVE-2023-54214}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228747] {CVE-2026-63975}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227528] {CVE-2026-43334}
- Bluetooth: Fix race condition in hidp_session_thread (CKI Backport Bot) [RHEL-227382] {CVE-2023-54120}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225633] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225571] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225535] {CVE-2026-52918}

Tenable has extracted the preceding description block directly from the Oracle Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://linux.oracle.com/errata/ELSA-2026-71329.html

Plugin Details

Severity: High

ID: 352254

File Name: oraclelinux_ELSA-2026-71329.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/30/2026

Updated: 9/30/2026

Supported Sensors: Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.9

Percentile: 99.35

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-31566

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:oracle:linux:8, cpe:/o:oracle:linux:8:10:baseos_patch, p-cpe:/a:oracle:linux:bpftool, p-cpe:/a:oracle:linux:kernel-abi-stablelists, p-cpe:/a:oracle:linux:kernel-core, p-cpe:/a:oracle:linux:kernel-cross-headers, p-cpe:/a:oracle:linux:kernel-debug-core, p-cpe:/a:oracle:linux:kernel-debug-devel, p-cpe:/a:oracle:linux:kernel-debug-modules-extra, p-cpe:/a:oracle:linux:kernel-debug-modules, p-cpe:/a:oracle:linux:kernel-debug, p-cpe:/a:oracle:linux:kernel-devel, p-cpe:/a:oracle:linux:kernel-headers, p-cpe:/a:oracle:linux:kernel-modules-extra, p-cpe:/a:oracle:linux:kernel-modules, p-cpe:/a:oracle:linux:kernel-tools-libs-devel, p-cpe:/a:oracle:linux:kernel-tools-libs, p-cpe:/a:oracle:linux:kernel-tools, p-cpe:/a:oracle:linux:kernel, p-cpe:/a:oracle:linux:perf, p-cpe:/a:oracle:linux:python3-perf

Required KB Items: Host/OracleLinux, Host/RedHat/release, Host/RedHat/rpm-list, Host/local_checks_enabled

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 4/23/2026

Reference Information

CVE: CVE-2026-31566, CVE-2026-52912, CVE-2026-68121, CVE-2026-80714, CVE-2026-89480