Oracle Linux 8 / 9 : Unbreakable Enterprise kernel (ELSA-2026-500377)

high Nessus Plugin ID 363954

Synopsis

The remote Oracle Linux host is missing one or more security updates.

Description

The remote Oracle Linux 8 / 9 host has packages installed that are affected by multiple vulnerabilities as referenced in the ELSA-2026-500377 advisory.

- tcp: fix potential race in tcp_v6_syn_recv_sock() (Eric Dumazet) [Orabug: 39331624] {CVE-2026-43198}
- RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (Bjoern Doebel) [Orabug: 39886288] {CVE-2026-74268}
- tcp: clear sock_ops cb flags before force-closing a child socket (Sechang Lim) [Orabug: 39886588] {CVE-2026-74378}
- net: af_key: zero aligned sockaddr tail in PF_KEY exports (Zhengchuan Liang) [Orabug: 39331155] {CVE-2026-43088}
- usb: usbfs: fix use-after-free of usb_device in usbdev_release() (Miguel Penaranda) [Orabug: 39982120] {CVE-2026-80824}
- USB: serial: option: fix slab OOB read in interrupt URB callback (Jiale Yao) [Orabug: 39982131] {CVE-2026-80827}
- ALSA: usb-audio: Complete cleanup after system-resume errors (Will Porter) [Orabug: 39982135] {CVE-2026-80828}
- ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (Marouane El Moufid) [Orabug: 39982139] {CVE-2026-80829}
- usb: core: Add lock to usb_wakeup_notification() (Griffin Kroah-Hartman) [Orabug: 39982143] {CVE-2026-80830}
- ipv6: seg6: clear IPv4 control block on IPIP decapsulation (Kyle Zeng) [Orabug: 39982172] {CVE-2026-80840}
- net: bridge: mcast: fix use-after-free of a master VLAN's multicast context (Norbert Szetei) [Orabug:
39982180] {CVE-2026-80842}
- xfrm: fix xfrm_state_construct() auth-trunc leak (Zihan Xi) [Orabug: 39982183] {CVE-2026-80843}
- xfrm: ah6: validate routing header segments_left (Asim Viladi Oglu Manizada) [Orabug: 39982187,40035522] {CVE-2026-80844}
- usb: gadget: f_tcm: keep port count until LUN teardown completes (Shuangpeng Bai) [Orabug: 39982217] {CVE-2026-80854}
- fuse: fix invalidate lock leak on open O_TRUNC DAX failure (Baokun Li) [Orabug: 39982221] {CVE-2026-80855}
- fuse: fix invalidate lock leak on setattr writeback failure (Baokun Li) [Orabug: 39982224] {CVE-2026-80856}
- xhci: dbgtty: Fix unregister on tty_register_driver() failure (Lucas De Marchi) [Orabug: 40010372] {CVE-2026-80923}
- nvmet-tcp: bound SGL data length before allocating command buffers (Ibrahim Hashimov) [Orabug: 39982006] {CVE-2026-80789}
- HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (Jose Villasenor Montfort) [Orabug: 39981987] {CVE-2026-80783}
- kcov: fix data corruption and race conditions on PREEMPT_RT (Tetsuo Handa) [Orabug: 40010347] {CVE-2026-80916}
- ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() (Eric Dumazet) [Orabug: 39885781] {CVE-2026-72323}
- ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (Ji'An Zhou) [Orabug:
40017137] {CVE-2026-53242}
- ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (Mehul Rao) [Orabug: 39343942] {CVE-2026-43437}
- bpf: Fix use-after-free in offloaded map/prog info fill (Jiayuan Chen) [Orabug: 39622047] {CVE-2026-53089}
- KVM: arm64: Prevent access to vCPU events before init (Oliver Upton) [Orabug: 38601896] {CVE-2025-40102}
- can: j1939: implement NETDEV_UNREGISTER notification handler (Tetsuo Handa) [Orabug: 38494827] {CVE-2025-39925}
- bpf: Remove tst_run from lwt_seg6local_prog_ops. (Sebastian Andrzej Siewior) [Orabug: 37074553] {CVE-2024-46754}
- ipvs: reload ip header after head reallocation (Florian Westphal) [Orabug: 39884703] {CVE-2026-68476}
- ext4: don't enable DAX on new encrypted files (Eric Biggers) [Orabug: 39982070] {CVE-2026-80806}
- RDMA/rxe: Fix OOB in free_rd_atomic_resources() (Peiyang He) [Orabug: 39982237] {CVE-2026-80863}
- inet: frags: strip GSO state from fragments before reassembly (Xinyang Ge) [Orabug: 39972531,39974835] {CVE-2026-80590}
- HID: hyperv: validate initial device info bounds (Michael Bommarito) [Orabug: 39981945] {CVE-2026-80765}
- HID: sensor: custom: Fix use-after-free in enable_sensor (Haoxiang Li) [Orabug: 39981954] {CVE-2026-80767}
- HID: core: fix number/pointer type confusion on long items (Jann Horn) [Orabug: 40010353] {CVE-2026-80918}
- can: isotp: fix timer drain order, wakeup handling and tx_gen ordering (Oliver Hartkopp) [Orabug:
39982403] {CVE-2026-80889}
- mptcp: pm: ADD_ADDR rtx: free sk if last (Matthieu Baerts) [Orabug: 39460461] {CVE-2026-46170}
- mptcp: pm: ADD_ADDR rtx: always decrease sk refcount (Matthieu Baerts) [Orabug: 39460401] {CVE-2026-46158}
- iomap: adjust read range correctly for non-block-aligned positions (Joanne Koong) [Orabug: 38847820] {CVE-2025-68794}
- xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (Xiang Mei) [Orabug: 39839297] {CVE-2026-64581}
- HID: core: fix OOB read of field->usage in hid_set_field() (Baul Lee) [Orabug: 39981979] {CVE-2026-80781}
- HID: magicmouse: do not keep a stale msc->input if no input is claimed (Jose Villasenor Montfort) [Orabug: 39981983] {CVE-2026-80782}
- mptcp: avoid combining some incoming suboptions (Matthieu Baerts) [Orabug: 39973016] {CVE-2026-80587}
- nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations (Greg Kroah-Hartman) [Orabug:
39982002] {CVE-2026-80788}
- nvmet-fc: fix invalid free in LS IOD error path (Honghui Jiang) [Orabug: 39982010] {CVE-2026-80790}
- ipv6: fix use-after-free in ip6_finish_output2() (Luxiao Xu) [Orabug: 39982017] {CVE-2026-80792}
- ipv4: reject undersized MTUs in ip_do_fragment() (Yong Wang) [Orabug: 39982021] {CVE-2026-80793}
- libceph: fix OOB read in decode_watchers() via missing bounds check (Pavitra Jha) [Orabug: 39972906] {CVE-2026-80557}
- xfs: bounds-check buffer log item's dirty bitmap (Ibrahim Hashimov) [Orabug: 39972835] {CVE-2026-80536}
- inet: frags: publish queues before arming timer (Zhiling Zou) [Orabug: 39919187] {CVE-2026-74662}
- packet: synchronize pressure clearing with ring reconfiguration (Zihan Xi) [Orabug: 39919201] {CVE-2026-74666}
- net/sched: reject overly deep qdisc hierarchies (Zijie Huang) [Orabug: 39919191] {CVE-2026-74663}
- packet: use consistent hard_header_len in TX_RING send path (Qihang) [Orabug: 39919209] {CVE-2026-74668}
- packet: use consistent hard_header_len in non-ring send paths (Qihang) [Orabug: 39917533] {CVE-2026-74582}
- serial: amba-pl011: synchronize DMA teardown (Fan Wu) [Orabug: 39973443] {CVE-2026-80737}
- NTB: ntb_netdev: Preserve RX queue depth on allocation failure (Koichiro Den) [Orabug: 39919082] {CVE-2026-74626}
- perf/core: Fix group leader use-after-free after sibling detach (Aditya Chillara) [Orabug: 39919114] {CVE-2026-74637}
- mm/huge_memory: fix huge_zero_pfn race (Lorenzo Stoakes) [Orabug: 39919100] {CVE-2026-74632}
- xfs: validate attr entry pointer before field access (Hongling Zeng) [Orabug: 39982067] {CVE-2026-80805}
- ext4: stop retrying saturated xattr cache entries (Matthias Goergens) [Orabug: 39982077] {CVE-2026-80808}
- ocfs2: fix missing metadata reservation for large xattrs (Ian Bridges) [Orabug: 39982081] {CVE-2026-80809}
- ALSA: dummy: Check card index validity at probe (Takashi Iwai) [Orabug: 39982087] {CVE-2026-80812}
- rndis_host: add overflow check in rndis_rx_fixup() (Griffin Kroah-Hartman) [Orabug: 39982092] {CVE-2026-80814}
- Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (Ali Ahmet Memis) [Orabug: 39982102] {CVE-2026-80819}
- PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems (Steffen Persvold) [Orabug:
40010350] {CVE-2026-80917}
- ring-buffer: Use current_context for safe per-CPU buffer swap (Tengda Wu) [Orabug: 39919010] {CVE-2026-74601}
- binfmt_misc: use exe_file_deny_write_access() for the interpreter clone (Christian Brauner) [Orabug:
39974107] {CVE-2026-74486}
- net/x25: fix use-after-free of the socket by its timers (Baul Lee) [Orabug: 39919087] {CVE-2026-74628}
- af_packet: Don't send zero-byte data in tpacket_snd(). (Eric Dumazet) [Orabug: 39973457] {CVE-2026-80742}
- net: packet: fix wrong transport_header when sending VLAN-tagged frame (Wei Fang) [Orabug: 39982352] {CVE-2026-80906}
- netfilter: flowtable: publish GC-visible tuple last (Jeremy Jean) [Orabug: 39972761] {CVE-2026-74746}
- netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path (Alexey Velichayshiy) [Orabug: 39973466] {CVE-2026-80744}
- netfilter: ipset: fix refcount race between list:set GC and swap (Xiang Mei) [Orabug: 39972772] {CVE-2026-74748}
- net: atlantic: free stranded TX buffers on ring deinit (Yangyu Chen) [Orabug: 39919072] {CVE-2026-74623}
- net/sched: act_ct: fix sk_buff leak when the header checks reject a packet (Hyunjung Ko) [Orabug:
39919065] {CVE-2026-74621}
- mm/ptdump: always stabilise against page table freeing using init_mm (Lorenzo Stoakes) [Orabug:
39919004] {CVE-2026-74599}
- sched/psi: Shut down rtpoll_timer in psi_cgroup_free() (Tejun Heo) [Orabug: 39918989] {CVE-2026-74594}
- i2c: imx: Fix slave registration race and error handling (Liem) [Orabug: 39973286] {CVE-2026-80678}
- binfmt_misc: restore write access when removing an entry (Christian Brauner) [Orabug: 39886902] {CVE-2026-74487}
- scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write (Ibrahim Hashimov) [Orabug: 39886847] {CVE-2026-74470}
- net: pktgen: fix proc entry use-after-free (Chengfeng Ye) [Orabug: 39886875] {CVE-2026-74479}
- igc: remove napi_synchronize() in igc_down() (David Carlier) [Orabug: 39973387] {CVE-2026-80715}
- wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() (Maoyi Xie) [Orabug: 39884956] {CVE-2026-72070}
- super: fix emergency thaw deadlock on frozen block devices (Christian Brauner) [Orabug: 39859442] {CVE-2026-68132}
- ftrace: Add global mutex to serialize trace_parser access (Tengda Wu) [Orabug: 39859492] {CVE-2026-68146}
- net/sched: serialize qdisc_rtab_list against concurrent get/put (Aldo Ariel Panzardo) [Orabug: 39859462] {CVE-2026-68138}
- libceph: fix two unsafe bare decodes in decode_lockers() (Pavitra Jha) [Orabug: 39852162] {CVE-2026-68082}
- ceph: fix hanging __ceph_get_caps() with stale mds_wanted (Max Kellermann) [Orabug: 39972807] {CVE-2026-80527}
- libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (Xiang Mei) [Orabug: 39859534] {CVE-2026-68159}
- ceph: avoid fs reclaim while using current->journal_info (Max Kellermann) [Orabug: 39972810] {CVE-2026-80528}
- sctp: avoid auth_enable sysctl UAF during netns teardown (Zhiling Zou) [Orabug: 39859549] {CVE-2026-68162}
- serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (Jiangshan Yi) [Orabug: 39868565] {CVE-2026-68434}
- wifi: brcmfmac: drain bus_reset work on device removal (Fan Wu) [Orabug: 39843565] {CVE-2026-64586}
- ALSA: seq: close a re-opened queue timer in the destructor (Norbert Szetei) [Orabug: 39859660] {CVE-2026-68202}
- media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (Mirela Rabulea) [Orabug: 39859672] {CVE-2026-68205}
- wifi: ath6kl: fix use-after-free in aggr_reset_state() (Daniel Hodges) [Orabug: 39859648] {CVE-2026-68198}
- drm/i915/hdcp: check streams[] bounds before overflow (Jani Nikula) [Orabug: 39859828] {CVE-2026-68253}
- drm/i915/vrr: require valid min/max vfreq for VRR (Jani Nikula) [Orabug: 39859832] {CVE-2026-68254}
- drm/virtio: bound EDID block reads to the response buffer (Bryam Vargas) [Orabug: 39859836] {CVE-2026-68255}
- drm/virtio: use uninterruptible resv lock for plane updates (Deepanshu Kartikey) [Orabug: 39754773] {CVE-2026-64098}
- drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (Ashutosh Desai) [Orabug: 39859888] {CVE-2026-68277}
- drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (Ashutosh Desai) [Orabug: 39859896] {CVE-2026-68279}
- usb: gadget: f_tcm: synchronize delayed set_alt with teardown (Cen Zhang) [Orabug: 39860172] {CVE-2026-68367}
- drm/dp/mst: fix buffer overflows in sideband chunk accumulation (Ashutosh Desai) [Orabug: 39859892] {CVE-2026-68278}
- fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list (Reinette Chatre) [Orabug:
39884753] {CVE-2026-72015}
- net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (Bryam Vargas) [Orabug: 39884827] {CVE-2026-72035}
- gpio: tegra: do not call pinctrl for GPIO direction (Runyu Xiao) [Orabug: 39884922] {CVE-2026-72063}
- octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (Junrui Luo) [Orabug: 39884855] {CVE-2026-72045}
- net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) [Orabug: 39884875] {CVE-2026-72051}
- net: mana: Validate the packet length reported by the NIC (Dexuan Cui) [Orabug: 39884929] {CVE-2026-72065}
- net/sched: act_ct: preserve tc_skb_cb across defragmentation (Zihan Xi) [Orabug: 39884899] {CVE-2026-72057}
- net: ipip: require CAP_NET_ADMIN in the device netns for changelink (Maoyi Xie) [Orabug: 39884883] {CVE-2026-72053}
- mmc: vub300: fix use-after-free on probe failure (Guangshuo Li) [Orabug: 39884968] {CVE-2026-72073}
- dm-verity: make error counter atomic (Mikulas Patocka) [Orabug: 39885054] {CVE-2026-72096}
- dm-integrity: don't increment hash_offset twice (Mikulas Patocka) [Orabug: 39885064] {CVE-2026-72099}
- scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() (Abdun Nihaal) [Orabug: 39885038] {CVE-2026-72087}
- bpf,fork: wipe ->bpf_storage before bailouts that access it (Jann Horn) [Orabug: 39885094] {CVE-2026-72110}
- thunderbolt: Prevent XDomain delayed work use-after-free on disconnect (Michael Bommarito) [Orabug:
39887152] {CVE-2026-74575}
- can: esd_usb: kill anchored URBs before freeing netdevs (Fan Wu) [Orabug: 39843561] {CVE-2026-64585}
- i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (Vincent Jardin) [Orabug: 39885191] {CVE-2026-72142}
- tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (Jarkko Sakkinen) [Orabug: 39885221] {CVE-2026-72152}
- mtd: spi-nor: swp: Improve locking user experience (Miquel Raynal) [Orabug: 39885230] {CVE-2026-72155}
- 9p: skip nlink update in cacheless mode to fix WARN_ON (Breno Leitao) [Orabug: 39885290] {CVE-2026-72170}
- selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() (Tristan Madani) [Orabug: 39885551] {CVE-2026-72242}
- netfilter: nft_set_pipapo: don't leak bad clone into future transaction (Florian Westphal) [Orabug:
39885581] {CVE-2026-72252}
- netfilter: nf_conntrack_sip: validate skb_dst() before accessing it (Pablo Neira Ayuso) [Orabug:
39885585] {CVE-2026-72253}
- netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst (Haoze Xie) [Orabug: 39885591] {CVE-2026-72255}
- VDUSE: avoid leaking information to userspace (Jason Wang) [Orabug: 39885723] {CVE-2026-72305}
- tipc: restrict socket queue dumps in enqueue tracepoints (Li Xiasong) [Orabug: 39885709] {CVE-2026-72299}
- audit: fix recursive locking deadlock in audit_dupe_exe() (Ricardo Robaina) [Orabug: 39859311] {CVE-2026-68096}
- Input: mms114 - reject an oversized device packet size (Bryam Vargas) [Orabug: 39785798] {CVE-2026-64270}
- Input: mms114 - fix touch indexing for MMS134S and MMS136 (Dmitry Torokhov) [Orabug: 39785807] {CVE-2026-64272}
- bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (Matt Bobrowski) [Orabug:
39760896] {CVE-2026-64192}
- mm: do file ownership checks with the proper mount idmap (Pedro Falcato) [Orabug: 39785859] {CVE-2026-64294}
- xfs: fix ilock leak on error in xfs_dq_get_next_id (Long Li) [Orabug: 39972825] {CVE-2026-80534}
- drm/amdgpu: Fix UVD decode image min size calculation (David Rosca) [Orabug: 39972847] {CVE-2026-80540}
- drm/amdgpu: Reject UVD message with dimensions above 4096 (David Rosca) [Orabug: 39982361] {CVE-2026-80908}
- drm/amdgpu: validate GEM_CREATE domain combinations (Candice Li) [Orabug: 39972852] {CVE-2026-80541}
- drm/amdgpu: Reject UVD message with invalid number of h265 refs (David Rosca) [Orabug: 39982365] {CVE-2026-80909}
- libceph: Avoid using invalid osd indices from primary_temp (Raphael Zimmer) [Orabug: 39972915] {CVE-2026-80558}
- libceph: fix multiple unsafe decodes in decode_locker() (Pavitra Jha) [Orabug: 39972927] {CVE-2026-80561}
- Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (Bryam Vargas) [Orabug:
39972955] {CVE-2026-80569}
- Input: synaptics-rmi4 - zero report size on F54 work error (Dmitry Torokhov) [Orabug: 39972960] {CVE-2026-80570}
- Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (Richard Davies) [Orabug:
39972975] {CVE-2026-80574}
- Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (Dmitry Torokhov) [Orabug: 39973486] {CVE-2026-80754}
- mptcp: options: reset DSS fields in case of unexpected size (Matthieu Baerts) [Orabug: 39973013] {CVE-2026-80586}
- selinux: do not cancel a policy conversion that never started (Bryam Vargas) [Orabug: 39973494] {CVE-2026-80756}
- selinux: reject a class permission count below its inherited common (Bryam Vargas) [Orabug: 39973498] {CVE-2026-80757}
- selinux: require every boolean value to be defined (Bryam Vargas) [Orabug: 39982381] {CVE-2026-80913}
- fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() (Zhan Xusheng) [Orabug:
39918992] {CVE-2026-74595}
- thunderbolt: Bound the DROM dual link port number before indexing sw->ports (Bryam Vargas) [Orabug:
39918961] {CVE-2026-74585}
- sctp: clear new_transport when removing a peer (Qing Ming) [Orabug: 39918965] {CVE-2026-74586}
- sctp: fix use-after-free of cached ASCONF chunk (Yuxiang Yang) [Orabug: 39918969] {CVE-2026-74587}
- sctp: keep chunk->transport in step with the list it is queued on (Baul Lee) [Orabug: 39918973] {CVE-2026-74588}
- bpf, sockmap: Fix sk_redir use-after-free in send verdict (Chengfeng Ye) [Orabug: 39918977] {CVE-2026-74589}
- ip6_tunnel: clear skb2->cb[] in ip6ip6_err() (Zhiling Zou) [Orabug: 39918996] {CVE-2026-74597}
- ipv6: fix Route Information option length validation (Yuejie Shi) [Orabug: 39919000] {CVE-2026-74598}
- Revert 'thermal/drivers/hwmon: Cleanup coding style a bit' (Rafael J. Wysocki) [Orabug: 39919019] {CVE-2026-74604}
- tipc: read le->link under the node lock in tipc_node_link_down() (Jun Yang) [Orabug: 39919032] {CVE-2026-74609}
- vhost: reset the vring metadata cache on vring reconfiguration (Jun Yang) [Orabug: 39917525] {CVE-2026-74580}
- vsock/virtio: avoid refilling the RX queue after teardown (Weiming Shi) [Orabug: 39919042] {CVE-2026-74613}
- vsock/virtio: read virtqueues under worker locks (Weiming Shi) [Orabug: 39919046] {CVE-2026-74614}
- vxlan: do not arm the ageing timer on a device that is down (Baul Lee) [Orabug: 39919049] {CVE-2026-74615}
- xdp: reject clones that overrun skb_shared_info tailroom (Zhiling Zou) [Orabug: 39919053] {CVE-2026-74616}
- net/sched: act_gact, act_police: range check the fallback control action (Hyunjung Ko) [Orabug:
39919061] {CVE-2026-74620}
- net: atlantic: free RX pages of consumed but not refilled buffers (Yangyu Chen) [Orabug: 39919068] {CVE-2026-74622}
- netfilter: bridge: release template ct on non-IP path (Zhiling Zou) [Orabug: 39919078] {CVE-2026-74625}
- ipv6: prevent in6_dev_get() from resurrecting inet6_dev (Kyle Zeng) [Orabug: 39919092] {CVE-2026-74630}
- fbdev: bitblit: bound-check glyph index in bit_cursor() (Rik van Riel) [Orabug: 39919107] {CVE-2026-74635}
- tracing: Fix race between update_event_fields and, event_define_fields (Michael Wu) [Orabug: 39919111] {CVE-2026-74636}
- ALSA: usx2y: bound the hwdep mmap fault offset (Baul Lee) [Orabug: 39919124] {CVE-2026-74641}
- staging: rtl8723bs: validate monitor transmit frame lengths (Mariano Baragiola) [Orabug: 39919138] {CVE-2026-74648}
- staging: rtl8723bs: fix missing shared-key auth challenge length check (Panagiotis Petrakopoulos) [Orabug: 39919142] {CVE-2026-74649}
- staging: rtl8723bs: fix OOB read in WMM_param_handler() (Muhammad Bilal) [Orabug: 39919146] {CVE-2026-74650}
- staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (Muhammad Bilal) [Orabug: 39919150] {CVE-2026-74651}
- serial: 8250_dma: Clear stale RX state on shutdown (Cunhao Lu) [Orabug: 39919159] {CVE-2026-74654}
- ipv4: fix use-after-free in fib_nhc_update_mtu() (Chengfeng Ye) [Orabug: 39919165] {CVE-2026-74656}
- ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops (Zihan Xi) [Orabug: 39919169] {CVE-2026-74657}
- futex: Prevent robust futex exit race some more (Keno Fischer) [Orabug: 39919174] {CVE-2026-74658}
- Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (Marco Elver) [Orabug: 39786570] {CVE-2026-64434}
- Input: evdev - fix information leak in evdev_pass_values() (Dmitry Torokhov) [Orabug: 39919227] {CVE-2026-74673}
- vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (Joshua Rogers) [Orabug: 39919232] {CVE-2026-74675}
- vt: add permission check for KDSKBMETA ioctl (Joshua Rogers) [Orabug: 39919236] {CVE-2026-74676}
- netfilter: ebt_nflog: pin the NFLOG backend (Chengfeng Ye) [Orabug: 39919181] {CVE-2026-74660}
- net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header (Qihang) [Orabug: 39973427] {CVE-2026-80731}
- net: openvswitch: reallocate update replies for mismatched IDs (Zhiling Zou) [Orabug: 39919195] {CVE-2026-74664}
- net/packet: reset the MAC header on the packet-socket transmit path (Doruk Tan Ozturk) [Orabug:
39919205] {CVE-2026-74667}
- ipvs: clear IPv4 options after rebasing tunnel ICMP errors (Kyle Zeng) [Orabug: 39919213] {CVE-2026-74669}
- ima: fix out-of-bounds read in xattr_verify() (Lincoln Wallace) [Orabug: 39919219] {CVE-2026-74671}
- usb: gadget: f_ncm: Use unsigned int for ndp_index (Sonali Pradhan) [Orabug: 39919247] {CVE-2026-74679}
- usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (Aleksandr Nogikh) [Orabug: 39919251] {CVE-2026-74680}
- ALSA: usb-audio: fix OOB write on Type II inbound URBs (Baul Lee) [Orabug: 39919256] {CVE-2026-74682}
- Input: evdev - sanitize event type index when fetching event masks (Dmitry Torokhov) [Orabug: 39919260] {CVE-2026-74683}
- sctp: clear control chunk transport if it is being removed (Xin Long) [Orabug: 39919275] {CVE-2026-74688}
- net: remove WARN_ON_ONCE() from sk_mc_loop() (Eric Dumazet) [Orabug: 39973435] {CVE-2026-80733}
- tcp: fix TFO max_qlen accounting across reuseport migration (Jiayuan Chen) [Orabug: 39919306] {CVE-2026-74696}
- bnxt_en: Disable EOP for TPA on all chips to prevent data corruption (Michael Chan) [Orabug: 39919309] {CVE-2026-74697}
- net/openvswitch: check Ethernet header length in key_extract() (Cen Zhang) [Orabug: 39919320] {CVE-2026-74701}
- net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter (Toke Hoiland-Jorgensen) [Orabug: 39919330] {CVE-2026-74704}
- udp: fix potential use-after-free in tunnel segmentation (Luoxuanqiang) [Orabug: 39919334] {CVE-2026-74705}
- net/mlx5: fw_tracer, return NULL on create error (Michael Guralnik) [Orabug: 39919359] {CVE-2026-74717}
- net/sched: cls_route: fix fastmap use-after-free on filter (Jamal Hadi Salim) [Orabug: 39917538] {CVE-2026-74583}
- bpf: Preserve pointer state for commuted arithmetic (Yiyang Chen) [Orabug: 39919369] {CVE-2026-74720}
- bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor (Xiang Mei) [Orabug: 39919388] {CVE-2026-74726}
- NFS: Pin the 'struct nfs_server' during a FREE_STATEID call (Anna Schumaker) [Orabug: 39919399] {CVE-2026-74730}
- mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (Kiryl Shutsemau) [Orabug:
39886887] {CVE-2026-74482}
- HID: logitech-dj: Fix maxfield check in DJ short report validation (Hyeongjun An) [Orabug: 39974286] {CVE-2026-64427}
- drm/vmwgfx: bound DMA command body size against suffix pointer (Zack Rusin) [Orabug: 39886755] {CVE-2026-74443}
- drm/vmwgfx: validate DRAW_PRIMITIVES header size before division (Zack Rusin) [Orabug: 39886759] {CVE-2026-74444}
- drm/vc4: Zero the tile state data array before each BIN job (Maira Canal) [Orabug: 39886787] {CVE-2026-74453}
- can: peak_usb: validate uCAN receive record lengths (Pengpeng Hou) [Orabug: 39886795] {CVE-2026-74455}
- can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error (Maoyi Xie) [Orabug: 39886799] {CVE-2026-74456}
- can: peak_usb: add bounds check for USB channel index (James Gao) [Orabug: 39886804] {CVE-2026-74457}
- can: softing: fw_parse(): validate firmware record spans (Pengpeng Hou) [Orabug: 39973358] {CVE-2026-80706}
- can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents (Pengpeng Hou) [Orabug: 39886808] {CVE-2026-74458}
- can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer (Oleksij Rempel) [Orabug:
39973363] {CVE-2026-80707}
- can: ems_usb: validate CPC message lengths (Pengpeng Hou) [Orabug: 39886813] {CVE-2026-74460}
- i2c: imx: Cancel hrtimer before clearing slave pointer (Liem) [Orabug: 39886817] {CVE-2026-74461}
- net: openvswitch: fix skb leak on flow key update failure during ct (Ilya Maximets) [Orabug: 39886825] {CVE-2026-74464}
- net: openvswitch: fix potential UAF on meter attach failure (Ilya Maximets) [Orabug: 39886829] {CVE-2026-74465}
- sctp: prevent peer transport count overflow (Asim Viladi Oglu Manizada) [Orabug: 39886842,40035526] {CVE-2026-74469}
- sctp: reject stale cookies with mismatched verification tags (Yuxiang Yang) [Orabug: 39982313] {CVE-2026-80890}
- tracing: Check return value of __register_event() in trace_module_add_events() (Masami Hiramatsu) [Orabug: 39886850] {CVE-2026-74471}
- vxlan: use pskb_network_may_pull() in route_shortcircuit() (Eric Dumazet) [Orabug: 39886856] {CVE-2026-74473}
- vxlan: use neigh_ha_snapshot() in route_shortcircuit() (Eric Dumazet) [Orabug: 39886864] {CVE-2026-74475}
- vxlan: re-fetch eth header after route_shortcircuit() (Eric Dumazet) [Orabug: 39973297] {CVE-2026-80681}
- net: ipv6: clear suppressed fib6 rule result (Zhiling Zou) [Orabug: 39917530] {CVE-2026-74581}
- net: bridge: stop fast-leave after deleting a port group (Zhiling Zou) [Orabug: 39886879] {CVE-2026-74480}
- mm/page_reporting: use system_freezable_wq to fix UAF during suspend (Link Lin) [Orabug: 39886883] {CVE-2026-74481}
- binfmt_misc: reject a flag character as the field delimiter (Christian Brauner) [Orabug: 39886897] {CVE-2026-74485}
- wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (Catherine) [Orabug: 39886906] {CVE-2026-74488}
- tipc: avoid use-after-free in poll trace queue dumps (Zihan Xi) [Orabug: 39886911] {CVE-2026-74490}
- netfilter: ipset: do not update comments from kernel-side hash adds (David Lee) [Orabug: 39886916] {CVE-2026-74492}
- ipvs: do not propagate one-packet flag to synced conns (Zhiling Zou) [Orabug: 39973383] {CVE-2026-80714}
- igbvf: Fix leak in TX DMA error cleanup (Matt Vollrath) [Ora ...

Please note that the description has been truncated due to length. Please refer to vendor advisory for the full description.

Tenable has extracted the preceding description block directly from the Oracle Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://linux.oracle.com/errata/ELSA-2026-500377.html

Plugin Details

Severity: High

ID: 363954

File Name: oraclelinux_ELSA-2026-500377.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/7/2026

Updated: 10/7/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.9

Percentile: 99.36

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-64272

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:oracle:linux:8, cpe:/o:oracle:linux:9, cpe:/o:oracle:linux:9:8:baseos_patch, p-cpe:/a:oracle:linux:bpftool, p-cpe:/a:oracle:linux:kernel-uek-container-debug, p-cpe:/a:oracle:linux:kernel-uek-container, p-cpe:/a:oracle:linux:kernel-uek-core, p-cpe:/a:oracle:linux:kernel-uek-debug-core, p-cpe:/a:oracle:linux:kernel-uek-debug-devel, p-cpe:/a:oracle:linux:kernel-uek-debug-modules-extra, p-cpe:/a:oracle:linux:kernel-uek-debug-modules, p-cpe:/a:oracle:linux:kernel-uek-debug, p-cpe:/a:oracle:linux:kernel-uek-devel, p-cpe:/a:oracle:linux:kernel-uek-doc, p-cpe:/a:oracle:linux:kernel-uek-modules-extra, p-cpe:/a:oracle:linux:kernel-uek-modules, p-cpe:/a:oracle:linux:kernel-uek64k-core, p-cpe:/a:oracle:linux:kernel-uek64k-devel, p-cpe:/a:oracle:linux:kernel-uek64k-modules-extra, p-cpe:/a:oracle:linux:kernel-uek64k-modules, p-cpe:/a:oracle:linux:kernel-uek64k, p-cpe:/a:oracle:linux:kernel-uek

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/OracleLinux

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/7/2026

Vulnerability Publication Date: 9/18/2024

Reference Information

CVE: CVE-2024-46754, CVE-2024-58240, CVE-2025-38653, CVE-2025-39925, CVE-2025-40102, CVE-2025-68794, CVE-2026-43088, CVE-2026-43198, CVE-2026-43437, CVE-2026-43491, CVE-2026-46158, CVE-2026-46170, CVE-2026-52977, CVE-2026-53089, CVE-2026-53090, CVE-2026-53242, CVE-2026-64098, CVE-2026-64192, CVE-2026-64270, CVE-2026-64272, CVE-2026-64294, CVE-2026-64427, CVE-2026-64434, CVE-2026-64535, CVE-2026-64543, CVE-2026-64562, CVE-2026-64563, CVE-2026-64564, CVE-2026-64567, CVE-2026-64569, CVE-2026-64571, CVE-2026-64572, CVE-2026-64576, CVE-2026-64579, CVE-2026-64581, CVE-2026-64582, CVE-2026-64585, CVE-2026-64586, CVE-2026-68082, CVE-2026-68096, CVE-2026-68104, CVE-2026-68106, CVE-2026-68111, CVE-2026-68115, CVE-2026-68117, CVE-2026-68121, CVE-2026-68123, CVE-2026-68125, CVE-2026-68129, CVE-2026-68131, CVE-2026-68132, CVE-2026-68138, CVE-2026-68139, CVE-2026-68142, CVE-2026-68143, CVE-2026-68144, CVE-2026-68146, CVE-2026-68153, CVE-2026-68154, CVE-2026-68155, CVE-2026-68156, CVE-2026-68157, CVE-2026-68158, CVE-2026-68159, CVE-2026-68160, CVE-2026-68162, CVE-2026-68180, CVE-2026-68184, CVE-2026-68186, CVE-2026-68187, CVE-2026-68188, CVE-2026-68190, CVE-2026-68192, CVE-2026-68197, CVE-2026-68198, CVE-2026-68199, CVE-2026-68202, CVE-2026-68205, CVE-2026-68212, CVE-2026-68213, CVE-2026-68214, CVE-2026-68216, CVE-2026-68217, CVE-2026-68218, CVE-2026-68226, CVE-2026-68227, CVE-2026-68234, CVE-2026-68243, CVE-2026-68244, CVE-2026-68248, CVE-2026-68249, CVE-2026-68250, CVE-2026-68253, CVE-2026-68254, CVE-2026-68255, CVE-2026-68277, CVE-2026-68278, CVE-2026-68279, CVE-2026-68284, CVE-2026-68294, CVE-2026-68297, CVE-2026-68299, CVE-2026-68300, CVE-2026-68301, CVE-2026-68304, CVE-2026-68309, CVE-2026-68313, CVE-2026-68315, CVE-2026-68320, CVE-2026-68325, CVE-2026-68326, CVE-2026-68328, CVE-2026-68338, CVE-2026-68344, CVE-2026-68349, CVE-2026-68350, CVE-2026-68351, CVE-2026-68352, CVE-2026-68353, CVE-2026-68354, CVE-2026-68355, CVE-2026-68363, CVE-2026-68365, CVE-2026-68367, CVE-2026-68368, CVE-2026-68373, CVE-2026-68376, CVE-2026-68377, CVE-2026-68388, CVE-2026-68398, CVE-2026-68402, CVE-2026-68403, CVE-2026-68405, CVE-2026-68406, CVE-2026-68410, CVE-2026-68411, CVE-2026-68413, CVE-2026-68414, CVE-2026-68422, CVE-2026-68425, CVE-2026-68428, CVE-2026-68430, CVE-2026-68432, CVE-2026-68433, CVE-2026-68434, CVE-2026-68444, CVE-2026-68446, CVE-2026-68450, CVE-2026-68476, CVE-2026-72015, CVE-2026-72019, CVE-2026-72035, CVE-2026-72045, CVE-2026-72051, CVE-2026-72053, CVE-2026-72057, CVE-2026-72063, CVE-2026-72065, CVE-2026-72070, CVE-2026-72073, CVE-2026-72087, CVE-2026-72096, CVE-2026-72099, CVE-2026-72110, CVE-2026-72113, CVE-2026-72114, CVE-2026-72115, CVE-2026-72116, CVE-2026-72117, CVE-2026-72118, CVE-2026-72119, CVE-2026-72121, CVE-2026-72123, CVE-2026-72124, CVE-2026-72125, CVE-2026-72142, CVE-2026-72152, CVE-2026-72155, CVE-2026-72170, CVE-2026-72242, CVE-2026-72252, CVE-2026-72253, CVE-2026-72255, CVE-2026-72299, CVE-2026-72305, CVE-2026-72323, CVE-2026-74268, CVE-2026-74378, CVE-2026-74443, CVE-2026-74444, CVE-2026-74453, CVE-2026-74455, CVE-2026-74456, CVE-2026-74457, CVE-2026-74458, CVE-2026-74460, CVE-2026-74461, CVE-2026-74464, CVE-2026-74465, CVE-2026-74469, CVE-2026-74470, CVE-2026-74471, CVE-2026-74473, CVE-2026-74475, CVE-2026-74479, CVE-2026-74480, CVE-2026-74481, CVE-2026-74482, CVE-2026-74485, CVE-2026-74486, CVE-2026-74487, CVE-2026-74488, CVE-2026-74490, CVE-2026-74492, CVE-2026-74495, CVE-2026-74497, CVE-2026-74498, CVE-2026-74499, CVE-2026-74505, CVE-2026-74507, CVE-2026-74508, CVE-2026-74512, CVE-2026-74517, CVE-2026-74518, CVE-2026-74519, CVE-2026-74523, CVE-2026-74540, CVE-2026-74546, CVE-2026-74547, CVE-2026-74548, CVE-2026-74549, CVE-2026-74556, CVE-2026-74557, CVE-2026-74564, CVE-2026-74566, CVE-2026-74567, CVE-2026-74569, CVE-2026-74575, CVE-2026-74577, CVE-2026-74579, CVE-2026-74580, CVE-2026-74581, CVE-2026-74582, CVE-2026-74583, CVE-2026-74585, CVE-2026-74586, CVE-2026-74587, CVE-2026-74588, CVE-2026-74589, CVE-2026-74594, CVE-2026-74595, CVE-2026-74597, CVE-2026-74598, CVE-2026-74599, CVE-2026-74601, CVE-2026-74604, CVE-2026-74609, CVE-2026-74613, CVE-2026-74614, CVE-2026-74615, CVE-2026-74616, CVE-2026-74620, CVE-2026-74621, CVE-2026-74622, CVE-2026-74623, CVE-2026-74625, CVE-2026-74626, CVE-2026-74628, CVE-2026-74630, CVE-2026-74632, CVE-2026-74635, CVE-2026-74636, CVE-2026-74637, CVE-2026-74641, CVE-2026-74648, CVE-2026-74649, CVE-2026-74650, CVE-2026-74651, CVE-2026-74654, CVE-2026-74656, CVE-2026-74657, CVE-2026-74658, CVE-2026-74660, CVE-2026-74662, CVE-2026-74663, CVE-2026-74664, CVE-2026-74666, CVE-2026-74667, CVE-2026-74668, CVE-2026-74669, CVE-2026-74671, CVE-2026-74673, CVE-2026-74675, CVE-2026-74676, CVE-2026-74679, CVE-2026-74680, CVE-2026-74682, CVE-2026-74683, CVE-2026-74688, CVE-2026-74696, CVE-2026-74697, CVE-2026-74701, CVE-2026-74704, CVE-2026-74705, CVE-2026-74717, CVE-2026-74720, CVE-2026-74726, CVE-2026-74730, CVE-2026-74746, CVE-2026-74748, CVE-2026-80527, CVE-2026-80528, CVE-2026-80534, CVE-2026-80536, CVE-2026-80540, CVE-2026-80541, CVE-2026-80557, CVE-2026-80558, CVE-2026-80561, CVE-2026-80569, CVE-2026-80570, CVE-2026-80574, CVE-2026-80586, CVE-2026-80587, CVE-2026-80590, CVE-2026-80678, CVE-2026-80681, CVE-2026-80706, CVE-2026-80707, CVE-2026-80714, CVE-2026-80715, CVE-2026-80716, CVE-2026-80717, CVE-2026-80722, CVE-2026-80731, CVE-2026-80733, CVE-2026-80737, CVE-2026-80742, CVE-2026-80744, CVE-2026-80754, CVE-2026-80756, CVE-2026-80757, CVE-2026-80765, CVE-2026-80767, CVE-2026-80781, CVE-2026-80782, CVE-2026-80783, CVE-2026-80788, CVE-2026-80789, CVE-2026-80790, CVE-2026-80792, CVE-2026-80793, CVE-2026-80805, CVE-2026-80806, CVE-2026-80808, CVE-2026-80809, CVE-2026-80812, CVE-2026-80814, CVE-2026-80819, CVE-2026-80824, CVE-2026-80827, CVE-2026-80828, CVE-2026-80829, CVE-2026-80830, CVE-2026-80840, CVE-2026-80842, CVE-2026-80843, CVE-2026-80844, CVE-2026-80854, CVE-2026-80855, CVE-2026-80856, CVE-2026-80863, CVE-2026-80889, CVE-2026-80890, CVE-2026-80906, CVE-2026-80908, CVE-2026-80909, CVE-2026-80913, CVE-2026-80916, CVE-2026-80917, CVE-2026-80918, CVE-2026-80923, CVE-2026-97509