Oracle Linux 8 : kernel (ELSA-2026-75747)

high Nessus Plugin ID 363163

Synopsis

The remote Oracle Linux host is missing one or more security updates.

Description

The remote Oracle Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the ELSA-2026-75747 advisory.

- nvme/ioctl: check SUBMIT_IO with CAP_SYS_ADMIN (Chris Leech) [RHEL-269479] {CVE-2026-90227}
- nvme-pci: fix mempool alloc size (Maurizio Lombardi) [RHEL-230386] {CVE-2022-50756}
- nvme-pci: use max of PRP or SGL for iod size (Maurizio Lombardi) [RHEL-230386] {CVE-2022-50756}
- nvme: add missing SRCU grace period in error path (CKI Backport Bot) [RHEL-270894] {CVE-2026-89972}
- netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() (CKI Backport Bot) [RHEL-270661] {CVE-2026-97417}
- crypto: af_alg - Cap AEAD AD length to 0x80000000 (Pablo Alessandro Santos Hugen) [RHEL-259055] {CVE-2026-52972}
- ipvlan: inherit needed_headroom and needed_tailroom from phy_dev (Jamie Bainbridge) [RHEL-254254] {CVE-2026-74744}
- vxlan: require CAP_NET_ADMIN in the device netns for changelink (Jamie Bainbridge) [RHEL-238885] {CVE-2026-68432}
- tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (Jamie Bainbridge) [RHEL-230777] {CVE-2026-63992}
- net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink (Jamie Bainbridge) [RHEL-247003] {CVE-2026-72052}
- net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (Jamie Bainbridge) [RHEL-247023] {CVE-2026-63829}
- tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() (Jamie Bainbridge) [RHEL-259654] {CVE-2026-63994}
- nvme-tcp: fix host memory disclosure on R2T for a read command (CKI Backport Bot) [RHEL-263413] {CVE-2026-89481}
- netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (CKI Backport Bot) [RHEL-260589] {CVE-2026-74569}
- KVM: s390: vsie: zero stale crypto bits (CKI Backport Bot) [RHEL-258125] {CVE-2026-80921}
- net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (Mohammad Heib) [RHEL-225698] {CVE-2026-53230}
- ipvs: clear IPv4 options after rebasing tunnel ICMP errors (Phil Sutter) [RHEL-254393] {CVE-2026-74669}
- KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (CKI Backport Bot) [RHEL-254507] {CVE-2026-74516}
- netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst (CKI Backport Bot) [RHEL-252413] {CVE-2026-72255}
- netfilter: flowtable: publish GC-visible tuple last (CKI Backport Bot) [RHEL-250542] {CVE-2026-74746}
- RDMA/bnxt_re: Prevent handling any completions after qp destroy (Kamal Heib) [RHEL-231374] {CVE-2023-54048}
- gfs2: add some missing log locking (Andrew Price) [RHEL-230306] {CVE-2026-53049}
- gfs2: Move gfs2_remove_from_journal to log.c (Andrew Price) [RHEL-230306] {CVE-2026-53049}
- gfs2: Fix unlikely race in gdlm_put_lock (CKI Backport Bot) [RHEL-231267] {CVE-2025-40242}
- gfs2: Unlock fewer glocks on unmount (CKI Backport Bot) [RHEL-231267] {CVE-2025-40242}
- media: tuner: xc5000: Fix use-after-free in xc5000_release (Kate Hsuan) [RHEL-231646] {CVE-2025-39994}
- net/sched: act_ct: Only release RCU read lock after ct_ft (Ivan Vecera) [RHEL-229652] {CVE-2026-46319}
- sched: act_ct: take care of padding in struct zones_ht_key (Ivan Vecera) [RHEL-229652] {CVE-2026-46319}
- sched: act_ct: add netns into the key of tcf_ct_flow_table (Ivan Vecera) [RHEL-229652] {CVE-2026-46319}
- RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CKI Backport Bot) [RHEL-232580] {CVE-2026-45856}
- gfs2: Fix slab-use-after-free in qd_put (CKI Backport Bot) [RHEL-227251] {CVE-2026-45861}
- net/sched: qfq: Use cl_is_active to determine whether class is active in qfq_rm_from_ag (CKI Backport Bot) [RHEL-226861] {CVE-2026-23105}
- net_sched: qfq: Fix double list add in class with netem as child qdisc (CKI Backport Bot) [RHEL-226861] {CVE-2026-23105}
- ipvs: clear the svc scheduler ptr early on edit (CKI Backport Bot) [RHEL-225976] {CVE-2026-53270}

Tenable has extracted the preceding description block directly from the Oracle Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://linux.oracle.com/errata/ELSA-2026-75747.html

Plugin Details

Severity: High

ID: 363163

File Name: oraclelinux_ELSA-2026-75747.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/6/2026

Updated: 10/6/2026

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7

Percentile: 98.06

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-63794

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:oracle:linux:8, cpe:/o:oracle:linux:8:10:baseos_patch, p-cpe:/a:oracle:linux:bpftool, p-cpe:/a:oracle:linux:kernel-abi-stablelists, p-cpe:/a:oracle:linux:kernel-core, p-cpe:/a:oracle:linux:kernel-cross-headers, p-cpe:/a:oracle:linux:kernel-debug-core, p-cpe:/a:oracle:linux:kernel-debug-devel, p-cpe:/a:oracle:linux:kernel-debug-modules-extra, p-cpe:/a:oracle:linux:kernel-debug-modules, p-cpe:/a:oracle:linux:kernel-debug, p-cpe:/a:oracle:linux:kernel-devel, p-cpe:/a:oracle:linux:kernel-headers, p-cpe:/a:oracle:linux:kernel-modules-extra, p-cpe:/a:oracle:linux:kernel-modules, p-cpe:/a:oracle:linux:kernel-tools-libs-devel, p-cpe:/a:oracle:linux:kernel-tools-libs, p-cpe:/a:oracle:linux:kernel-tools, p-cpe:/a:oracle:linux:kernel, p-cpe:/a:oracle:linux:perf, p-cpe:/a:oracle:linux:python3-perf

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/OracleLinux

Exploit Ease: No known exploits are available

Patch Publication Date: 10/5/2026

Vulnerability Publication Date: 7/21/2021

Reference Information

CVE: CVE-2022-50756, CVE-2023-54048, CVE-2025-39994, CVE-2025-40242, CVE-2026-23105, CVE-2026-45856, CVE-2026-45861, CVE-2026-46319, CVE-2026-52972, CVE-2026-53049, CVE-2026-53230, CVE-2026-53270, CVE-2026-63794, CVE-2026-63829, CVE-2026-63992, CVE-2026-63994, CVE-2026-68432, CVE-2026-72052, CVE-2026-72255, CVE-2026-74516, CVE-2026-74569, CVE-2026-74669, CVE-2026-74744, CVE-2026-74746, CVE-2026-80921, CVE-2026-89481, CVE-2026-89972, CVE-2026-90227, CVE-2026-97417