Oracle Linux 9 : Unbreakable Enterprise kernel (ELSA-2026-500374)

high Nessus Plugin ID 364137

Synopsis

The remote Oracle Linux host is missing one or more security updates.

Description

The remote Oracle Linux 9 host has packages installed that are affected by multiple vulnerabilities as referenced in the ELSA-2026-500374 advisory.

- mptcp: fix bad accounting in __mptcp_subflow_push_pending() (Paolo Abeni) [Orabug: 40078583] {CVE-2026-97522}
- mptcp: close race between scheduler and state change (Paolo Abeni) [Orabug: 40078588] {CVE-2026-97523}
- mptcp: avoid unneeded actions on subflow reset (Paolo Abeni) [Orabug: 40078594] {CVE-2026-97524}
- ocfs2: validate directory-index entry counts when reading metadata (Doruk Tan Ozturk) [Orabug: 40020935] {CVE-2026-89492}
- svcrdma: Reject Write/Reply chunks with segcount 0 (Chris Mason) [Orabug: 40072707] {CVE-2026-93228}
- svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id (Chuck Lever) [Orabug: 40021075] {CVE-2026-89535}
- rpcrdma: arm rn_done before publishing the notification (Chuck Lever) [Orabug: 40033153] {CVE-2026-89798}
- sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir (Luxiao Xu) [Orabug:
40021120] {CVE-2026-89543}
- SUNRPC: fix gssx_dec_option_array error path bugs (Chris Mason) [Orabug: 40021135] {CVE-2026-89544}
- sunrpc: defer rq_argp and rq_resp free until after RCU grace period (Jeff Layton) [Orabug: 40021143] {CVE-2026-89545}
- ip: orphan prefetched skbs before multicast forwarding (Zhiling Zou) [Orabug: 40021224] {CVE-2026-89564}
- ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv() (Andrea Mayer) [Orabug: 40021207] {CVE-2026-89561}
- bpf: Disable preemption in bpf_get_stackid (Jiri Olsa) [Orabug: 40033158] {CVE-2026-89799}
- acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks (Terry Bowman) [Orabug: 40021333] {CVE-2026-89589}
- erofs: skip sufficiently large global buffers when resizing (Nikhil Gurudasani) [Orabug: 40021393] {CVE-2026-89602}
- NFSD: Prevent client use-after-free during close_lru reaping (Chuck Lever) [Orabug: 40034294] {CVE-2026-90037}
- NFSD: Prevent client use-after-free during blocked-lock reaping (Chuck Lever) [Orabug: 40034286] {CVE-2026-90036}
- HID: sony: clean up device list on probe failure (Doruk Tan Ozturk) [Orabug: 40034309] {CVE-2026-90041}
- HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind (Doruk Tan Ozturk) [Orabug: 40021493] {CVE-2026-89625}
- btrfs: fix extent map leak in NOCOW direct I/O write (Shuangpeng Bai) [Orabug: 40021561] {CVE-2026-89644}
- ceph: properly decrypt filenames in vmalloc() buffers (Sam Edwards) [Orabug: 40034317] {CVE-2026-90042}
- NFSD: Guard admin state-revocation walks with NFSD_NET_UP (Chuck Lever) [Orabug: 40034301] {CVE-2026-90039}
- NFSD: Prevent client use-after-free during delegation revoke (Chuck Lever) [Orabug: 40021620] {CVE-2026-89659}
- NFSD: Prevent client use-after-free during admin state revocation (Chuck Lever) [Orabug: 40021626] {CVE-2026-89660}
- nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache (Jeff Layton) [Orabug: 40021653] {CVE-2026-89667}
- nfsd: fix stale s2s_cp_stateids IDR entry for async COPY (Jeff Layton) [Orabug: 40021687] {CVE-2026-89676}
- nfsd: fix clock domain mismatch in clients_still_reclaiming() (Jeff Layton) [Orabug: 40021710] {CVE-2026-89685}
- nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown (Jeff Layton) [Orabug:
40021778] {CVE-2026-89708}
- nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage (Jeff Layton) [Orabug: 40021748] {CVE-2026-89698}
- Revert 'NFSD: Remove the cap on number of operations per NFSv4 COMPOUND' (Chuck Lever) [Orabug:
38686996] {CVE-2025-40210}
- nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() (Jeff Layton) [Orabug: 40021727] {CVE-2026-89693}
- nfsd: validate sockaddr length per family in listener_set (Jeff Layton) [Orabug: 40021754] {CVE-2026-89700}
- zram: set default primary compressor in zram_destroy_comps() (Sergey Senozhatsky) [Orabug: 40021806] {CVE-2026-89717}
- zram: fix out-of-bounds access in writeback_store() (Longlong Xia) [Orabug: 40021808] {CVE-2026-89718}
- zram: fix out-of-bounds access in read_block_state() (Longlong Xia) [Orabug: 40021813] {CVE-2026-89719}
- cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read (Terry Bowman) [Orabug: 40021856] {CVE-2026-89731}
- mm/migrate_device: clear stale mapping after freeing swapcache (Arvind Yadav) [Orabug: 40021923] {CVE-2026-89755}
- KEYS: trusted: Fix TPM teardown ordering (Chengfeng Ye) [Orabug: 40021952] {CVE-2026-89763}
- crypto: iaa - unmap dst before software fallback on decompress (Vinicius Costa Gomes) [Orabug: 40020455] {CVE-2026-80945}
- crypto: virtio - bound the akcipher result length (Bryam Vargas) [Orabug: 39982162] {CVE-2026-80836}
- vlan: fix skb_under_panic and races when toggling HW VLAN offload (Eric Dumazet) [Orabug: 40013132] {CVE-2026-80925}
- net/packet: defer vmalloc TX_RING free until skbs finish (Kyle Zeng) [Orabug: 39982175] {CVE-2026-80841}
- tcp: clamp route advmss to TCP_MIN_MSS (Yong Wang) [Orabug: 39982195] {CVE-2026-80847}
- fuse: fix race between interrupt and resend (Miklos Szeredi) [Orabug: 39982400] {CVE-2026-80860}
- usb: xhci: bail out of setup if the controller is inaccessible (Breno Leitao) [Orabug: 39982230] {CVE-2026-80861}
- xfs: initialise args->total for parent pointer updates (Javier Tia) [Orabug: 40078705] {CVE-2026-97551}
- fou: Fix use-after-free in fou_create() (Luoxuanqiang) [Orabug: 39886929] {CVE-2026-74496}
- i2c: smbus: reject oversized block transfers in the common path (Weiming Shi) [Orabug: 40073050] {CVE-2026-93287}
- ALSA: us122l: Prevent write upgrades for read mappings (Kazuki Hanai) [Orabug: 40079109] {CVE-2026-97931}
- net: usb: pegasus: don't rely on id table pointer arithmetic (Gary Guo) [Orabug: 40078670] {CVE-2026-97540}
- wifi: ath9k_htc: don't store usb_device_id (Gary Guo) [Orabug: 40078677] {CVE-2026-97541}
- usb: xusbatm: don't rely on id table pointer arithmetic (Gary Guo) [Orabug: 40078663] {CVE-2026-97539}
- xfs: bail out on bitmap errors in xrep_agfl_fill (Darrick J. Wong) [Orabug: 40078682] {CVE-2026-97542}
- xfs: destroy seen inode bitmap when we fail to add a dirpath (Darrick J. Wong) [Orabug: 40078684] {CVE-2026-97543}
- xfs: don't leak dqacct if rhashtable insertion fails (Darrick J. Wong) [Orabug: 40078687] {CVE-2026-97544}
- xfs: don't leak new_bp if xfs_btree_bload_drop_buf fails (Darrick J. Wong) [Orabug: 40078689] {CVE-2026-97545}
- xfs: don't spin forever on zero-length dirents when salvaging them (Darrick J. Wong) [Orabug: 40078692] {CVE-2026-97546}
- xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN (Lin Jiapeng) [Orabug:
39972815,40078696] {CVE-2026-80530,CVE-2026-97547}
- xfs: initialise error in xfs_defer_finish_one() (Javier Tia) [Orabug: 40078708] {CVE-2026-97552}
- smb: client: fix heap overflow in DACL owner/group rewrite (Bjoern Doebel) [Orabug: 40078720] {CVE-2026-97555}
- smb: client: avoid leaking refcount when cifs_sb_tlink() fails (Bjoern Doebel) [Orabug: 40078724] {CVE-2026-97556}
- smb: client: avoid leaking refcount in cifs_queue_oplock_break() (Bjoern Doebel) [Orabug: 40078730] {CVE-2026-97557}
- smb: client: fix one-byte OOB read in smb2_parse_native_symlink() (Paulo Alcantara) [Orabug: 40078747] {CVE-2026-97560}
- smb: client: pin DFS superblock in iterator callback (Karl Mehltretter) [Orabug: 40078757] {CVE-2026-97562}
- smb: client: reject userspace cifs.idmap descriptions (Aohan Mei) [Orabug: 40078772] {CVE-2026-97564}
- mptcp: syncookies: remember the request backup flag (Matthieu Baerts) [Orabug: 40078794] {CVE-2026-97568}
- bnxt_en: Propagate RX ring init failures in bnxt_init_nic() (Joe Damato) [Orabug: 40078806] {CVE-2026-97572}
- bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset() (Joe Damato) [Orabug: 40078811] {CVE-2026-97573}
- media: v4l2-ctrls: validate AV1 tile counts (Michael Bommarito) [Orabug: 40078824] {CVE-2026-97575}
- media: v4l2-ctrls: validate HEVC tile counts (Michael Bommarito) [Orabug: 40078826] {CVE-2026-97576}
- afs: Clear stale peer app data after address list changes (Chengfeng Ye) [Orabug: 40078852] {CVE-2026-97583}
- afs: Fix incorrect free in candidate cleanup in afs_lookup_server() (David Howells) [Orabug: 40078858] {CVE-2026-97584}
- mac802154: fix use-after-free of sdata via queued RX frames (Ibrahim Hashimov) [Orabug: 40078888] {CVE-2026-97595}
- ipvs: reject invalid states in connection template sync records (Kyle Zeng) [Orabug: 40078891] {CVE-2026-97596}
- ipv4: fib: bound automatic table ID allocation (Zihan Xi) [Orabug: 40078901] {CVE-2026-97598}
- ieee802154: cc2520: fix FIFOP work use-after-free (Fan Wu) [Orabug: 40078912] {CVE-2026-97600}
- ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink (Zhiling Zou) [Orabug: 40078919] {CVE-2026-97601}
- inet: frags: invalidate queues before flushing them (Yilin Zhang) [Orabug: 40078925] {CVE-2026-97602}
- fbdev: vfb: defer cleanup until the last reference (Weiming Shi) [Orabug: 40078939] {CVE-2026-97604}
- erofs: preserve LZMA decoders on resize failure (Nikhil Gurudasani) [Orabug: 40078947] {CVE-2026-97605}
- fs: autofs: fix memory leak in autofs_fill_super() (Jeffin Philip) [Orabug: 40078951] {CVE-2026-97606}
- vdpa: ifcvf: Put device on unsupported feature error (Xiongweimin) [Orabug: 40078955] {CVE-2026-97607}
- netfilter: nf_log: unregister loggers before per-net teardown (Chengfeng Ye) [Orabug: 40078958] {CVE-2026-97608}
- net: openvswitch: fix use-after-free of the flow table mask array (Norbert Szetei) [Orabug: 40078968] {CVE-2026-97611}
- net: mpls: clear inner_protocol when the last label is popped (Fourie Zhang) [Orabug: 40078972] {CVE-2026-97612}
- net: mana: Reserve extra CQ slot for the fence completion CQE (Sahil Chandna) [Orabug: 40078976] {CVE-2026-97613}
- net/sched: act_api: release all action references on NEWACTION failure (Luoxuanqiang) [Orabug: 40078985] {CVE-2026-97616}
- ring-buffer: Check resize_disabled before publishing the new subbuf order (David Carlier) [Orabug:
40078989] {CVE-2026-97617}
- drm/i915: Fix memory leak in query_perf_config_list() (Thorsten Blum) [Orabug: 40079005] {CVE-2026-97899}
- drm/drm_exec: fix up contended obj when num_objects is 0 (Sunil Khatri) [Orabug: 40079009] {CVE-2026-97900}
- fs: don't return -EINVAL for successful nested thaw (Moritz Tanner) [Orabug: 40079015] {CVE-2026-97902}
- cpufreq: initialize policy rwsem before sysfs publication (Runyu Xiao) [Orabug: 40079019] {CVE-2026-97904}
- cpufreq: zero-initialize policy cpumask before sysfs publication (Zhongqiu Han) [Orabug: 40079023] {CVE-2026-97905}
- Bluetooth: btrtl: Don't leak return code when parsing firmware format v2 (Rongrong) [Orabug: 40079032] {CVE-2026-97907}
- accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr (Magdalena Schulfer) [Orabug: 40079055] {CVE-2026-97917}
- tracing: Keep the entry count when the histogram stats allocation fails (Donggeun Yoo) [Orabug:
40079065] {CVE-2026-97920}
- tracing: Free histogram the field rejected for a bad modifier (Donggeun Yoo) [Orabug: 40079067] {CVE-2026-97921}
- tracing: Free histogram var refs regardless of how often they are referenced (Donggeun Yoo) [Orabug:
40079069] {CVE-2026-97922}
- tracing: Free histogram the var ref when its initialization fails (Donggeun Yoo) [Orabug: 40079077] {CVE-2026-97923}
- tick/broadcast: Plug clockevents replacement race (Thomas Gleixner) [Orabug: 40079083] {CVE-2026-97925}
- ALSA: usbusx2y: validate URB actual_length in interrupt callback (Tristan Madani) [Orabug: 40079099] {CVE-2026-97929}
- ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf (Tristan Madani) [Orabug: 40079104] {CVE-2026-97930}
- tracing: Fix memory corruption from the histogram stacktrace modifier (Donggeun Yoo) [Orabug: 40079129] {CVE-2026-97936}
- ipv6: fix fib6 walker UAF on seq stop (Zihan Xi) [Orabug: 40079142] {CVE-2026-97940}
- x86/mm: Fix user-space data loss with MADV_FREE and THP (Vernon Yang) [Orabug: 40079153] {CVE-2026-97945}
- scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands (Maurizio Lombardi) [Orabug: 40079174] {CVE-2026-97951}
- net: stmmac: fix TX descriptor availability check for TSO traffic (Lorenzo Bianconi) [Orabug: 40079183] {CVE-2026-97953}
- net: hinic: fix mailbox segment buffer overflow (Aamir Ahmed) [Orabug: 40079196] {CVE-2026-97957}
- net/sched: cls_api: Don't replay RTM_GETCHAIN in tc_ctl_chain(). (Kuniyuki Iwashima) [Orabug: 40079199] {CVE-2026-97958}
- net/sched: cls_route: free emptied bucket on filter move (Victor Nogueira) [Orabug: 40079204] {CVE-2026-97959}
- net: stmmac: initialize ptp_lock at probe time (Lorenzo Bianconi) [Orabug: 40079216] {CVE-2026-97963}
- ppp_synctty: ensure a writeable skb header (Qingfang Deng) [Orabug: 40079219] {CVE-2026-97964}
- vxlan: initialize _md in vxlan_xmit_one() (Eric Dumazet) [Orabug: 40079222] {CVE-2026-97965}
- net: macb: destroy the phylink instance on the probe error path (Nicolai Buchwitz) [Orabug: 40079249] {CVE-2026-97973}
- Bluetooth: btintel_pcie: validate packet_len before skb_put_data (Kiran K) [Orabug: 40079258] {CVE-2026-97976}
- Bluetooth: btusb: Fix UAF of btusb_data by rx_work (Luiz Augusto von Dentz) [Orabug: 40079261] {CVE-2026-97977}
- eth: ice: don't dereference pointers from TP_printk() (Jakub Kicinski) [Orabug: 40079263] {CVE-2026-97978}
- ice: add missing xa_destroy for sched_node_ids (Jacob Keller) [Orabug: 40079266] {CVE-2026-97979}
- net: ipv6: Fix UDP length overflow with PMTU discover and big MTU (Alice Mikityanska) [Orabug: 40079279] {CVE-2026-97984}
- af_unix: Update last skb marker in manage_oob(). (Kuniyuki Iwashima) [Orabug: 40079300] {CVE-2026-97985}
- virtio_input: stop callbacks before unregistering input device (Karl Mehltretter) [Orabug: 40079307] {CVE-2026-97986}
- virtio_input: reset device if input_register_device() fails (Xiongweimin) [Orabug: 40079311] {CVE-2026-97987}
- vdpa_sim_net: check TX pull result before RX copy (Linfeng Sun) [Orabug: 40079323] {CVE-2026-97990}
- vdpa_sim_blk: reject out-of-range sector starts (Linfeng Sun) [Orabug: 40079328] {CVE-2026-97991}
- vhost-vdpa: protect config_ctx from being freed under the config callback (Yu Zhang) [Orabug: 40079332] {CVE-2026-97992}
- vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx (Yu Zhang) [Orabug: 40079336] {CVE-2026-97993}
- vhost/vdpa: reject VRING_NUM larger than device max (Jia Jia) [Orabug: 40079341] {CVE-2026-97994}
- virtio_console: do not free control-out buffers on remove (Jia Jia) [Orabug: 40079347] {CVE-2026-97995}
- virtio: fix use-after-free in unregister_virtio_device() (Karl Mehltretter) [Orabug: 40079351] {CVE-2026-97996}
- netfilter: nfnetlink_log: cope with concurrent instance destruction (Florian Westphal) [Orabug:
40079359] {CVE-2026-97998}
- ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev (Edward Adam Davis) [Orabug: 40079373] {CVE-2026-98006}
- bpf: Reject non-scalar bpf_loop iteration counts (Kumar Kartikeya Dwivedi) [Orabug: 40079377] {CVE-2026-98007}
- net: macb: fix NULL pointer dereference on unbind with fixed-link (Vineeth Karumanchi) [Orabug:
40079379] {CVE-2026-98008}
- net/sched: ets: clamp quantum in parse and fallback paths (Jamal Hadi Salim) [Orabug: 40079383] {CVE-2026-98009}
- net/sched: drr: clamp quantum in change class (Jamal Hadi Salim) [Orabug: 40079387] {CVE-2026-98010}
- net/sched: hhf: clamp quantum in change and init paths (Jamal Hadi Salim) [Orabug: 40079394] {CVE-2026-98011}
- net/sched: sfq: clamp quantum in change path (Jamal Hadi Salim) [Orabug: 40079398] {CVE-2026-98012}
- net/mlx5: E-Switch, prevent mc_list repopulation during vport disable (Lama Kayal) [Orabug: 40079405] {CVE-2026-98014}
- net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put (Yael Chemla) [Orabug: 40079408] {CVE-2026-98015}
- net/mlx5e: Fix use-after-free race in sample_restore_put() (Carolina Jubran) [Orabug: 40079415] {CVE-2026-98016}
- net/sched: defer qdisc freeing after failed creation (Weiming Shi) [Orabug: 40079419] {CVE-2026-98017}
- pds_core: fix cmd_regs access racing BAR unmap on reset (Nikhil P. Rao) [Orabug: 40079430] {CVE-2026-98020}
- net: reject oversized tx_queue_len at netlink parse time (Jamal Hadi Salim) [Orabug: 40079434] {CVE-2026-98021}
- net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations (Jamal Hadi Salim) [Orabug:
40079442] {CVE-2026-98022}
- vxlan: reject dynamic fdb entries that reference a nexthop id (Seungwon Bae) [Orabug: 40079446] {CVE-2026-98023}
- net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow (Jason Winter) [Orabug: 40079453] {CVE-2026-98025}
- net: bridge: mcast: properly convert mglist to rcu (Nikolay Aleksandrov) [Orabug: 40079458] {CVE-2026-98026}
- net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size (Jakub Kicinski) [Orabug:
40079463] {CVE-2026-98027}
- eth: nfp: drop the replaced rule from the list when reprogramming fails (Jakub Kicinski) [Orabug:
40079467] {CVE-2026-98028}
- eth: nfp: bound the ntuple rule dump by the caller's buffer size (Jakub Kicinski) [Orabug: 40079470] {CVE-2026-98029}
- net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size (Jakub Kicinski) [Orabug:
40079473] {CVE-2026-98030}
- nexthop: Initialize extack in remove_nh_grp_entry() (Ido Schimmel) [Orabug: 40079482] {CVE-2026-98031}
- bpf: Reject untrusted allocated-object pointers (Ning Ding) [Orabug: 40079500] {CVE-2026-98037}
- bpf: Require MEM_PERCPU for percpu kptr stores (Kumar Kartikeya Dwivedi) [Orabug: 40079506] {CVE-2026-98039}
- bpf: Don't predict JMP32 pointer vs zero comparisons (Eduard Zingerman) [Orabug: 40079510] {CVE-2026-98041}
- bpf: Mark faultable stack helpers as sleepable (Kumar Kartikeya Dwivedi) [Orabug: 40079520] {CVE-2026-98045}
- bpf: Mark bpf_btf_find_by_name_kind() as sleepable (Kumar Kartikeya Dwivedi) [Orabug: 40079522] {CVE-2026-98046}
- net: bcmasp: fix tx_spb_ring_full() checking same slot cnt times (Justin Chen) [Orabug: 40079537] {CVE-2026-98051}
- net: bcmasp: clear txcb->last before writing each descriptor (Justin Chen) [Orabug: 40079541] {CVE-2026-98052}
- ASoC: Intel: avs: Fix unbalanced module reference count (Cezary Rojewski) [Orabug: 40079546] {CVE-2026-98054}
- ASoC: Intel: avs: Clean up the bus when fetching ML caps fails (Cezary Rojewski) [Orabug: 40079548] {CVE-2026-98055}
- nvme: remove stale namespaces by NSID range during scan (Mohamed Khalfella) [Orabug: 40079550] {CVE-2026-98056}
- ring-buffer: Add checking nr_subbufs to persistent ring buffer validation (Steven Rostedt) [Orabug:
40079555] {CVE-2026-98057}
- bpf: Mark sched_process_wait argument as nullable (Kumar Kartikeya Dwivedi) [Orabug: 40079562] {CVE-2026-98059}
- bpf: Fix NULL-ptr-deref in btf_var_show() (Jiayuan Chen) [Orabug: 40079569] {CVE-2026-98063}
- bpf: Fix NULL-ptr-deref when showing a void BTF type (Jiayuan Chen) [Orabug: 40079572] {CVE-2026-98064}
- ALSA: caiaq: Fix potential double-free at error path (Takashi Iwai) [Orabug: 40079576] {CVE-2026-98066}
- bonding: do not clear curr_active_slave prematurely when releasing all slaves (Eric Dumazet) [Orabug:
40079606] {CVE-2026-98074}
- bpf: reject BPF_PSEUDO_FUNC reference to the main program (Eduard Zingerman) [Orabug: 40079610] {CVE-2026-98075}
- tracing/probes: Fix use-after-free on field name/type of events with multiple probes (Henry Martin) [Orabug: 40079616] {CVE-2026-98076}
- netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() (Joas Antonio Dos Santos) [Orabug:
40079621] {CVE-2026-98077}
- ipvs: fix reversed sequence option serialization (Kyle Zeng) [Orabug: 40079625] {CVE-2026-98078}
- btrfs: do not force reloc root creation during qgroup_account_snapshot() (Qu Wenruo) [Orabug: 40079634] {CVE-2026-98080}
- btrfs: zoned: finish active block group cleanup if call_zone_finish() fails (Johannes Thumshirn) [Orabug: 40079639] {CVE-2026-98081}
- btrfs: fix the possible bioc_list memory leak during error (Qu Wenruo) [Orabug: 40079643] {CVE-2026-98082}
- btrfs: fix transaction use-after-free in raid stripe insertion (Shuangpeng Bai) [Orabug: 40079647] {CVE-2026-98083}
- ALSA: ump: do not touch legacy_rmidi before it exists (Qingyu Zhang) [Orabug: 40079657] {CVE-2026-98086}
- scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues() (Ivy Lopez) [Orabug: 40079664] {CVE-2026-98088}
- bonding: alb: fix uninitialized transport header access in alb_determine_nd() (Eric Dumazet) [Orabug:
40079670] {CVE-2026-98089}
- btrfs: restore active device pointers after failed sprout (Guanghui Yang) [Orabug: 40079672] {CVE-2026-98090}
- btrfs: detach failed sprout device from transaction update list (Guanghui Yang) [Orabug: 40079676] {CVE-2026-98091}
- ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close() (Wangdicheng) [Orabug: 40079682] {CVE-2026-98092}
- af_packet: Don't cast tpacket_hdr.tp_len to int in tpacket_parse_header(). (Kuniyuki Iwashima) [Orabug:
40079695] {CVE-2026-98095}
- ipv6: sr: restore network header before routing and forwarding (Eric Dumazet) [Orabug: 40079699] {CVE-2026-98096}
- tipc: Dont send random pad bytes in RESET/ACTIVATE messages (David Laight) [Orabug: 40079706] {CVE-2026-98097}
- tipc: fix NULL deref in tipc_named_node_up() on empty publication list (Tung Nguyen) [Orabug: 40079713] {CVE-2026-98098}
- ipv6: mcast: fix RCU list diversion in ip6_mc_del1_src() (Eric Dumazet) [Orabug: 40079730] {CVE-2026-98102}
- igmp: convert struct ip_sf_list to RCU (Eric Dumazet) [Orabug: 40079734] {CVE-2026-98103}
- net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted (Jamal Hadi Salim) [Orabug:
40079740] {CVE-2026-98104}
- Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect (Pauli Virtanen) [Orabug: 40079748] {CVE-2026-98107}
- Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan (Pauli Virtanen) [Orabug: 40079753] {CVE-2026-98108}
- Bluetooth: hci_core: Fix race condition during device registration (Aleksandr Nogikh) [Orabug: 40079757] {CVE-2026-98109}
- Bluetooth: btintel: bound firmware ID by TLV length (Laxman Acharya Padhya) [Orabug: 40079759] {CVE-2026-98110}
- Bluetooth: btintel: validate version TLV value lengths (Laxman Acharya Padhya) [Orabug: 40079761] {CVE-2026-98111}
- ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF (Yilin Zhang) [Orabug: 40079779] {CVE-2026-98116}
- vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del() (Baul Lee) [Orabug: 40079802] {CVE-2026-98122}
- sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration (Henry Martin) [Orabug: 40079806] {CVE-2026-98123}
- smb/client: validate new EOF for zero range (Huiwen He) [Orabug: 40079822] {CVE-2026-98126}
- smb/client: validate new EOF for insert range (Huiwen He) [Orabug: 40079827] {CVE-2026-98127}
- scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add() (Milan P. Gandhi) [Orabug:
40079831] {CVE-2026-98128}
- scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add() (Milan P. Gandhi) [Orabug: 40079837] {CVE-2026-98129}
- sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START (Xin Long) [Orabug: 40079843] {CVE-2026-98130}
- drm/cirrus-qemu: Validate BAR0 size during probe (Slawomir Stepien) [Orabug: 40079874] {CVE-2026-98142}
- bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic (Jiayuan Chen) [Orabug: 40079901] {CVE-2026-98151}
- nvmet-rdma: fix queue leak when connect backlog is exceeded (Xixin Liu) [Orabug: 40079902] {CVE-2026-98152}
- nvme-rdma: fix -EIO cleanup order in queue_rq (Xixin Liu) [Orabug: 40079913] {CVE-2026-98154}
- EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation (Jad Keskes) [Orabug: 40079927] {CVE-2026-98157}
- mm/damon/core: avoid infinite kdamond_merge_regions() internal loop (Seongjae Park) [Orabug: 40033139] {CVE-2026-89796}
- af_unix: Unlink scc_entry in unix_del_edge(). (Kuniyuki Iwashima) [Orabug: 39972794] {CVE-2026-80521}
- l2tp: fix tunnel and session refcount leak on seq_file release (Eric Dumazet) [Orabug: 39972719] {CVE-2026-74735}
- ASoC: meson: aiu: Validate written enum values (Hyeongjun An) [Orabug: 39886372] {CVE-2026-74294}
- ASoC: topology: Check PCM and DAI name strings before use (Cassio Gabriel) [Orabug: 39886361] {CVE-2026-74291}
- ipv4: fib: Don't dump dying fib_info in fib_leaf_notify(). (Kuniyuki Iwashima) [Orabug: 39886353] {CVE-2026-74289}
- bpf: Guard __get_user acesss with access_ok for uprobe_multi data (Jiri Olsa) [Orabug: 39886262] {CVE-2026-74258}
- RDMA/bnxt_re: Proper rollback if the ioremap fails (Selvin Xavier) [Orabug: 39886234] {CVE-2026-72496}
- md/raid10: fix writes_pending and barrier reference leaks on discard failures (Abd-Alrhman Masalkhi) [Orabug: 39886086] {CVE-2026-72438}
- sctp: fix err_chunk memory leaks in INIT handling (Xin Long) [Orabug: 39886018] {CVE-2026-72413}
- bpf: Mask pseudo pointer values in verifier logs (Nuoqi Gui) [Orabug: 39885989] {CVE-2026-72402}
- Bluetooth: ISO: fix malformed ISO_END/CONT handling (Pauli Virtanen) [Orabug: 39885808] {CVE-2026-72334}
- bpf: Reject redirect helpers without a bpf_net_context (Daniel Borkmann) [Orabug: 39860076] {CVE-2026-68337}
- drm/vc4: hvs/v3d: Fix null dereference in unbind (Gregor Herburger) [Orabug: 39859967] {CVE-2026-68303}
- tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (Cen Zhang) [Orabug: 39859926] {CVE-2026-68289}
- net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (Yehyeong Lee) [Orabug: 39859921] {CVE-2026-68288}
- drop_monitor: fix size calculations for 64-bit attributes (Eric Dumazet) [Orabug: 39859917] {CVE-2026-68287}
- drop_monitor: perform u64_stats updates under IRQ-disabled section (Eric Dumazet) [Orabug: 39859913] {CVE-2026-68286}
- ppp_async: drop the errored frame instead of resetting its headroom (Vlatko Kosturjak) [Orabug:
40079934] {CVE-2026-98158}
- wifi: mt76: mt7921: validate CLC firmware records (Laxman Acharya Padhya) [Orabug: 40079939] {CVE-2026-98159}
- netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state (Florian Westphal) [Orabug: 40073059] {CVE-2026-93288}
- scsi: core: Do not block on tag allocation in scsi_eh_lock_door() (Zizhi Wo) [Orabug: 40073071] {CVE-2026-93781}
- vhost-scsi: flush backend after device ioctls (Jia Jia) [Orabug: 40073076] {CVE-2026-93782}
- Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame (Jiale Yao) [Orabug: 40073080] {CVE-2026-93783}
- wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie() (Deepanshu Kartikey) [Orabug: 40073087] {CVE-2026-93784}
- cifs: validate idmap key payload length (Li Qiang) [Orabug: 40073095] {CVE-2026-93785}
- smb: client: bound dirent name against ...

Please note that the description has been truncated due to length. Please refer to vendor advisory for the full description.

Tenable has extracted the preceding description block directly from the Oracle Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://linux.oracle.com/errata/ELSA-2026-500374.html

Plugin Details

Severity: High

ID: 364137

File Name: oraclelinux_ELSA-2026-500374.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/8/2026

Updated: 10/8/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.9

Percentile: 99.36

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-53089

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:oracle:linux:9, p-cpe:/a:oracle:linux:kernel-uek-core, p-cpe:/a:oracle:linux:kernel-uek-debug-core, p-cpe:/a:oracle:linux:kernel-uek-debug-devel, p-cpe:/a:oracle:linux:kernel-uek-debug-modules-core, p-cpe:/a:oracle:linux:kernel-uek-debug-modules-deprecated, p-cpe:/a:oracle:linux:kernel-uek-debug-modules-desktop, p-cpe:/a:oracle:linux:kernel-uek-debug-modules-extra-netfilter, p-cpe:/a:oracle:linux:kernel-uek-debug-modules-extra, p-cpe:/a:oracle:linux:kernel-uek-debug-modules-usb, p-cpe:/a:oracle:linux:kernel-uek-debug-modules-wireless, p-cpe:/a:oracle:linux:kernel-uek-debug-modules, p-cpe:/a:oracle:linux:kernel-uek-debug, p-cpe:/a:oracle:linux:kernel-uek-devel, p-cpe:/a:oracle:linux:kernel-uek-doc, p-cpe:/a:oracle:linux:kernel-uek-modules-core, p-cpe:/a:oracle:linux:kernel-uek-modules-deprecated, p-cpe:/a:oracle:linux:kernel-uek-modules-desktop, p-cpe:/a:oracle:linux:kernel-uek-modules-extra-netfilter, p-cpe:/a:oracle:linux:kernel-uek-modules-extra, p-cpe:/a:oracle:linux:kernel-uek-modules-usb, p-cpe:/a:oracle:linux:kernel-uek-modules-wireless, p-cpe:/a:oracle:linux:kernel-uek-modules, p-cpe:/a:oracle:linux:kernel-uek-tools, p-cpe:/a:oracle:linux:kernel-uek64k-core, p-cpe:/a:oracle:linux:kernel-uek64k-devel, p-cpe:/a:oracle:linux:kernel-uek64k-modules-core, p-cpe:/a:oracle:linux:kernel-uek64k-modules-deprecated, p-cpe:/a:oracle:linux:kernel-uek64k-modules-desktop, p-cpe:/a:oracle:linux:kernel-uek64k-modules-extra-netfilter, p-cpe:/a:oracle:linux:kernel-uek64k-modules-extra, p-cpe:/a:oracle:linux:kernel-uek64k-modules-usb, p-cpe:/a:oracle:linux:kernel-uek64k-modules-wireless, p-cpe:/a:oracle:linux:kernel-uek64k-modules, p-cpe:/a:oracle:linux:kernel-uek64k, p-cpe:/a:oracle:linux:kernel-uek

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/OracleLinux

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/7/2026

Vulnerability Publication Date: 2/27/2025

Reference Information

CVE: CVE-2025-21817, CVE-2025-22108, CVE-2025-38205, CVE-2025-38206, CVE-2025-38266, CVE-2025-38525, CVE-2025-38621, CVE-2025-39925, CVE-2025-40074, CVE-2025-40102, CVE-2025-40210, CVE-2025-68299, CVE-2025-71142, CVE-2026-100070, CVE-2026-100071, CVE-2026-100075, CVE-2026-100079, CVE-2026-23459, CVE-2026-43197, CVE-2026-43198, CVE-2026-43344, CVE-2026-45897, CVE-2026-45901, CVE-2026-45963, CVE-2026-53078, CVE-2026-53089, CVE-2026-53090, CVE-2026-53092, CVE-2026-53102, CVE-2026-53113, CVE-2026-53250, CVE-2026-53313, CVE-2026-53364, CVE-2026-64031, CVE-2026-64058, CVE-2026-64205, CVE-2026-64210, CVE-2026-64216, CVE-2026-64290, CVE-2026-64427, CVE-2026-64507, CVE-2026-64520, CVE-2026-64562, CVE-2026-64563, CVE-2026-64564, CVE-2026-64567, CVE-2026-64568, CVE-2026-64569, CVE-2026-64570, CVE-2026-64571, CVE-2026-64572, CVE-2026-64574, CVE-2026-64575, CVE-2026-64576, CVE-2026-64577, CVE-2026-64579, CVE-2026-64580, CVE-2026-64581, CVE-2026-64586, CVE-2026-68082, CVE-2026-68093, CVE-2026-68096, CVE-2026-68102, CVE-2026-68106, CVE-2026-68107, CVE-2026-68108, CVE-2026-68110, CVE-2026-68111, CVE-2026-68112, CVE-2026-68113, CVE-2026-68115, CVE-2026-68116, CVE-2026-68117, CVE-2026-68118, CVE-2026-68119, CVE-2026-68121, CVE-2026-68123, CVE-2026-68125, CVE-2026-68126, CVE-2026-68128, CVE-2026-68129, CVE-2026-68131, CVE-2026-68132, CVE-2026-68133, CVE-2026-68136, CVE-2026-68138, CVE-2026-68139, CVE-2026-68142, CVE-2026-68143, CVE-2026-68145, CVE-2026-68146, CVE-2026-68148, CVE-2026-68149, CVE-2026-68150, CVE-2026-68153, CVE-2026-68154, CVE-2026-68155, CVE-2026-68156, CVE-2026-68157, CVE-2026-68158, CVE-2026-68159, CVE-2026-68160, CVE-2026-68161, CVE-2026-68162, CVE-2026-68164, CVE-2026-68165, CVE-2026-68166, CVE-2026-68169, CVE-2026-68180, CVE-2026-68181, CVE-2026-68184, CVE-2026-68186, CVE-2026-68187, CVE-2026-68188, CVE-2026-68189, CVE-2026-68192, CVE-2026-68193, CVE-2026-68194, CVE-2026-68197, CVE-2026-68198, CVE-2026-68199, CVE-2026-68200, CVE-2026-68201, CVE-2026-68202, CVE-2026-68205, CVE-2026-68206, CVE-2026-68212, CVE-2026-68213, CVE-2026-68214, CVE-2026-68216, CVE-2026-68217, CVE-2026-68218, CVE-2026-68226, CVE-2026-68227, CVE-2026-68234, CVE-2026-68235, CVE-2026-68236, CVE-2026-68243, CVE-2026-68244, CVE-2026-68245, CVE-2026-68246, CVE-2026-68247, CVE-2026-68248, CVE-2026-68249, CVE-2026-68250, CVE-2026-68251, CVE-2026-68252, CVE-2026-68253, CVE-2026-68254, CVE-2026-68255, CVE-2026-68256, CVE-2026-68257, CVE-2026-68259, CVE-2026-68264, CVE-2026-68266, CVE-2026-68267, CVE-2026-68269, CVE-2026-68271, CVE-2026-68272, CVE-2026-68273, CVE-2026-68276, CVE-2026-68277, CVE-2026-68278, CVE-2026-68279, CVE-2026-68284, CVE-2026-68286, CVE-2026-68287, CVE-2026-68288, CVE-2026-68289, CVE-2026-68293, CVE-2026-68294, CVE-2026-68296, CVE-2026-68297, CVE-2026-68299, CVE-2026-68300, CVE-2026-68301, CVE-2026-68303, CVE-2026-68304, CVE-2026-68307, CVE-2026-68309, CVE-2026-68310, CVE-2026-68311, CVE-2026-68313, CVE-2026-68315, CVE-2026-68317, CVE-2026-68318, CVE-2026-68319, CVE-2026-68320, CVE-2026-68325, CVE-2026-68326, CVE-2026-68328, CVE-2026-68329, CVE-2026-68336, CVE-2026-68337, CVE-2026-68338, CVE-2026-68339, CVE-2026-68343, CVE-2026-68346, CVE-2026-68348, CVE-2026-68349, CVE-2026-68350, CVE-2026-68351, CVE-2026-68352, CVE-2026-68353, CVE-2026-68355, CVE-2026-68362, CVE-2026-68363, CVE-2026-68365, CVE-2026-68372, CVE-2026-68373, CVE-2026-68374, CVE-2026-68376, CVE-2026-68377, CVE-2026-68386, CVE-2026-68388, CVE-2026-68391, CVE-2026-68392, CVE-2026-68394, CVE-2026-68398, CVE-2026-68402, CVE-2026-68403, CVE-2026-68405, CVE-2026-68406, CVE-2026-68407, CVE-2026-68410, CVE-2026-68411, CVE-2026-68413, CVE-2026-68414, CVE-2026-68416, CVE-2026-68419, CVE-2026-68422, CVE-2026-68425, CVE-2026-68427, CVE-2026-68428, CVE-2026-68429, CVE-2026-68430, CVE-2026-68432, CVE-2026-68433, CVE-2026-68439, CVE-2026-68442, CVE-2026-68444, CVE-2026-68445, CVE-2026-68446, CVE-2026-68450, CVE-2026-72015, CVE-2026-72017, CVE-2026-72030, CVE-2026-72032, CVE-2026-72040, CVE-2026-72045, CVE-2026-72046, CVE-2026-72051, CVE-2026-72065, CVE-2026-72070, CVE-2026-72101, CVE-2026-72103, CVE-2026-72111, CVE-2026-72113, CVE-2026-72114, CVE-2026-72115, CVE-2026-72116, CVE-2026-72117, CVE-2026-72118, CVE-2026-72119, CVE-2026-72121, CVE-2026-72124, CVE-2026-72125, CVE-2026-72130, CVE-2026-72137, CVE-2026-72175, CVE-2026-72183, CVE-2026-72213, CVE-2026-72244, CVE-2026-72253, CVE-2026-72254, CVE-2026-72299, CVE-2026-72305, CVE-2026-72334, CVE-2026-72402, CVE-2026-72413, CVE-2026-72438, CVE-2026-72496, CVE-2026-74258, CVE-2026-74268, CVE-2026-74289, CVE-2026-74291, CVE-2026-74294, CVE-2026-74334, CVE-2026-74352, CVE-2026-74425, CVE-2026-74436, CVE-2026-74440, CVE-2026-74441, CVE-2026-74442, CVE-2026-74443, CVE-2026-74444, CVE-2026-74445, CVE-2026-74446, CVE-2026-74447, CVE-2026-74448, CVE-2026-74450, CVE-2026-74453, CVE-2026-74454, CVE-2026-74455, CVE-2026-74456, CVE-2026-74457, CVE-2026-74458, CVE-2026-74460, CVE-2026-74464, CVE-2026-74465, CVE-2026-74469, CVE-2026-74470, CVE-2026-74471, CVE-2026-74472, CVE-2026-74473, CVE-2026-74474, CVE-2026-74475, CVE-2026-74476, CVE-2026-74479, CVE-2026-74480, CVE-2026-74481, CVE-2026-74482, CVE-2026-74483, CVE-2026-74484, CVE-2026-74485, CVE-2026-74486, CVE-2026-74487, CVE-2026-74488, CVE-2026-74490, CVE-2026-74492, CVE-2026-74495, CVE-2026-74496, CVE-2026-74497, CVE-2026-74498, CVE-2026-74499, CVE-2026-74500, CVE-2026-74501, CVE-2026-74502, CVE-2026-74504, CVE-2026-74505, CVE-2026-74507, CVE-2026-74508, CVE-2026-74509, CVE-2026-74510, CVE-2026-74512, CVE-2026-74515, CVE-2026-74516, CVE-2026-74517, CVE-2026-74518, CVE-2026-74519, CVE-2026-74523, CVE-2026-74531, CVE-2026-74532, CVE-2026-74535, CVE-2026-74536, CVE-2026-74540, CVE-2026-74541, CVE-2026-74543, CVE-2026-74546, CVE-2026-74547, CVE-2026-74548, CVE-2026-74549, CVE-2026-74550, CVE-2026-74552, CVE-2026-74553, CVE-2026-74555, CVE-2026-74556, CVE-2026-74557, CVE-2026-74564, CVE-2026-74565, CVE-2026-74566, CVE-2026-74567, CVE-2026-74569, CVE-2026-74572, CVE-2026-74574, CVE-2026-74575, CVE-2026-74577, CVE-2026-74579, CVE-2026-74580, CVE-2026-74581, CVE-2026-74582, CVE-2026-74583, CVE-2026-74585, CVE-2026-74586, CVE-2026-74587, CVE-2026-74588, CVE-2026-74589, CVE-2026-74590, CVE-2026-74592, CVE-2026-74594, CVE-2026-74595, CVE-2026-74597, CVE-2026-74598, CVE-2026-74599, CVE-2026-74601, CVE-2026-74602, CVE-2026-74603, CVE-2026-74604, CVE-2026-74606, CVE-2026-74607, CVE-2026-74608, CVE-2026-74609, CVE-2026-74610, CVE-2026-74612, CVE-2026-74613, CVE-2026-74614, CVE-2026-74615, CVE-2026-74616, CVE-2026-74618, CVE-2026-74619, CVE-2026-74620, CVE-2026-74621, CVE-2026-74622, CVE-2026-74623, CVE-2026-74624, CVE-2026-74625, CVE-2026-74626, CVE-2026-74628, CVE-2026-74630, CVE-2026-74632, CVE-2026-74634, CVE-2026-74635, CVE-2026-74636, CVE-2026-74637, CVE-2026-74641, CVE-2026-74642, CVE-2026-74644, CVE-2026-74653, CVE-2026-74654, CVE-2026-74656, CVE-2026-74657, CVE-2026-74658, CVE-2026-74660, CVE-2026-74661, CVE-2026-74662, CVE-2026-74663, CVE-2026-74664, CVE-2026-74665, CVE-2026-74666, CVE-2026-74667, CVE-2026-74668, CVE-2026-74669, CVE-2026-74670, CVE-2026-74671, CVE-2026-74672, CVE-2026-74673, CVE-2026-74675, CVE-2026-74676, CVE-2026-74677, CVE-2026-74678, CVE-2026-74680, CVE-2026-74682, CVE-2026-74683, CVE-2026-74688, CVE-2026-74689, CVE-2026-74691, CVE-2026-74696, CVE-2026-74700, CVE-2026-74701, CVE-2026-74704, CVE-2026-74705, CVE-2026-74710, CVE-2026-74712, CVE-2026-74714, CVE-2026-74717, CVE-2026-74718, CVE-2026-74720, CVE-2026-74722, CVE-2026-74724, CVE-2026-74725, CVE-2026-74726, CVE-2026-74730, CVE-2026-74735, CVE-2026-74736, CVE-2026-74739, CVE-2026-74740, CVE-2026-74742, CVE-2026-74743, CVE-2026-74744, CVE-2026-74746, CVE-2026-74748, CVE-2026-74753, CVE-2026-80521, CVE-2026-80525, CVE-2026-80527, CVE-2026-80528, CVE-2026-80529, CVE-2026-80530, CVE-2026-80531, CVE-2026-80532, CVE-2026-80533, CVE-2026-80534, CVE-2026-80535, CVE-2026-80536, CVE-2026-80539, CVE-2026-80540, CVE-2026-80541, CVE-2026-80557, CVE-2026-80558, CVE-2026-80561, CVE-2026-80569, CVE-2026-80570, CVE-2026-80572, CVE-2026-80574, CVE-2026-80576, CVE-2026-80578, CVE-2026-80585, CVE-2026-80586, CVE-2026-80587, CVE-2026-80589, CVE-2026-80590, CVE-2026-80681, CVE-2026-80686, CVE-2026-80691, CVE-2026-80695, CVE-2026-80700, CVE-2026-80702, CVE-2026-80703, CVE-2026-80704, CVE-2026-80706, CVE-2026-80707, CVE-2026-80711, CVE-2026-80714, CVE-2026-80715, CVE-2026-80716, CVE-2026-80717, CVE-2026-80722, CVE-2026-80723, CVE-2026-80725, CVE-2026-80726, CVE-2026-80727, CVE-2026-80728, CVE-2026-80730, CVE-2026-80731, CVE-2026-80733, CVE-2026-80736, CVE-2026-80737, CVE-2026-80739, CVE-2026-80742, CVE-2026-80744, CVE-2026-80749, CVE-2026-80754, CVE-2026-80755, CVE-2026-80756, CVE-2026-80757, CVE-2026-80759, CVE-2026-80762, CVE-2026-80763, CVE-2026-80764, CVE-2026-80765, CVE-2026-80766, CVE-2026-80767, CVE-2026-80774, CVE-2026-80779, CVE-2026-80780, CVE-2026-80781, CVE-2026-80782, CVE-2026-80783, CVE-2026-80784, CVE-2026-80788, CVE-2026-80789, CVE-2026-80790, CVE-2026-80791, CVE-2026-80792, CVE-2026-80793, CVE-2026-80805, CVE-2026-80806, CVE-2026-80808, CVE-2026-80809, CVE-2026-80812, CVE-2026-80814, CVE-2026-80815, CVE-2026-80819, CVE-2026-80820, CVE-2026-80824, CVE-2026-80825, CVE-2026-80827, CVE-2026-80828, CVE-2026-80829, CVE-2026-80830, CVE-2026-80836, CVE-2026-80837, CVE-2026-80838, CVE-2026-80839, CVE-2026-80840, CVE-2026-80841, CVE-2026-80842, CVE-2026-80843, CVE-2026-80844, CVE-2026-80845, CVE-2026-80847, CVE-2026-80851, CVE-2026-80852, CVE-2026-80854, CVE-2026-80855, CVE-2026-80856, CVE-2026-80860, CVE-2026-80861, CVE-2026-80862, CVE-2026-80863, CVE-2026-80864, CVE-2026-80878, CVE-2026-80887, CVE-2026-80888, CVE-2026-80889, CVE-2026-80890, CVE-2026-80892, CVE-2026-80893, CVE-2026-80894, CVE-2026-80901, CVE-2026-80903, CVE-2026-80904, CVE-2026-80906, CVE-2026-80907, CVE-2026-80908, CVE-2026-80909, CVE-2026-80911, CVE-2026-80912, CVE-2026-80913, CVE-2026-80914, CVE-2026-80915, CVE-2026-80916, CVE-2026-80917, CVE-2026-80918, CVE-2026-80923, CVE-2026-80925, CVE-2026-80930, CVE-2026-80932, CVE-2026-80940, CVE-2026-80941, CVE-2026-80944, CVE-2026-80945, CVE-2026-80947, CVE-2026-80949, CVE-2026-80963, CVE-2026-80964, CVE-2026-80965, CVE-2026-80967, CVE-2026-80969, CVE-2026-80971, CVE-2026-80972, CVE-2026-80973, CVE-2026-80974, CVE-2026-80976, CVE-2026-80977, CVE-2026-80978, CVE-2026-80987, CVE-2026-80988, CVE-2026-80989, CVE-2026-80990, CVE-2026-80994, CVE-2026-80996, CVE-2026-80999, CVE-2026-81000, CVE-2026-81001, CVE-2026-81002, CVE-2026-81005, CVE-2026-81008, CVE-2026-81011, CVE-2026-81012, CVE-2026-81013, CVE-2026-81014, CVE-2026-81017, CVE-2026-89438, CVE-2026-89439, CVE-2026-89440, CVE-2026-89442, CVE-2026-89443, CVE-2026-89444, CVE-2026-89448, CVE-2026-89451, CVE-2026-89453, CVE-2026-89461, CVE-2026-89462, CVE-2026-89469, CVE-2026-89472, CVE-2026-89476, CVE-2026-89477, CVE-2026-89478, CVE-2026-89479, CVE-2026-89480, CVE-2026-89481, CVE-2026-89482, CVE-2026-89483, CVE-2026-89484, CVE-2026-89485, CVE-2026-89487, CVE-2026-89488, CVE-2026-89490, CVE-2026-89491, CVE-2026-89492, CVE-2026-89493, CVE-2026-89494, CVE-2026-89495, CVE-2026-89496, CVE-2026-89501, CVE-2026-89502, CVE-2026-89508, CVE-2026-89510, CVE-2026-89511, CVE-2026-89515, CVE-2026-89524, CVE-2026-89525, CVE-2026-89526, CVE-2026-89530, CVE-2026-89531, CVE-2026-89532, CVE-2026-89533, CVE-2026-89535, CVE-2026-89536, CVE-2026-89538, CVE-2026-89539, CVE-2026-89540, CVE-2026-89541, CVE-2026-89542, CVE-2026-89543, CVE-2026-89544, CVE-2026-89545, CVE-2026-89547, CVE-2026-89548, CVE-2026-89549, CVE-2026-89550, CVE-2026-89551, CVE-2026-89552, CVE-2026-89553, CVE-2026-89554, CVE-2026-89555, CVE-2026-89557, CVE-2026-89558, CVE-2026-89559, CVE-2026-89560, CVE-2026-89561, CVE-2026-89562, CVE-2026-89563, CVE-2026-89564, CVE-2026-89565, CVE-2026-89566, CVE-2026-89567, CVE-2026-89569, CVE-2026-89573, CVE-2026-89574, CVE-2026-89575, CVE-2026-89576, CVE-2026-89579, CVE-2026-89580, CVE-2026-89581, CVE-2026-89582, CVE-2026-89583, CVE-2026-89585, CVE-2026-89586, CVE-2026-89587, CVE-2026-89588, CVE-2026-89589, CVE-2026-89593, CVE-2026-89595, CVE-2026-89596, CVE-2026-89598, CVE-2026-89602, CVE-2026-89603, CVE-2026-89604, CVE-2026-89606, CVE-2026-89607, CVE-2026-89608, CVE-2026-89618, CVE-2026-89625, CVE-2026-89626, CVE-2026-89627, CVE-2026-89628, CVE-2026-89634, CVE-2026-89636, CVE-2026-89640, CVE-2026-89643, CVE-2026-89644, CVE-2026-89645, CVE-2026-89647, CVE-2026-89649, CVE-2026-89650, CVE-2026-89651, CVE-2026-89652, CVE-2026-89653, CVE-2026-89655, CVE-2026-89656, CVE-2026-89657, CVE-2026-89658, CVE-2026-89659, CVE-2026-89660, CVE-2026-89662, CVE-2026-89663, CVE-2026-89666, CVE-2026-89667, CVE-2026-89669, CVE-2026-89671, CVE-2026-89673, CVE-2026-89674, CVE-2026-89676, CVE-2026-89680, CVE-2026-89683, CVE-2026-89684, CVE-2026-89685, CVE-2026-89686, CVE-2026-89688, CVE-2026-89690, CVE-2026-89691, CVE-2026-89693, CVE-2026-89694, CVE-2026-89696, CVE-2026-89698, CVE-2026-89699, CVE-2026-89700, CVE-2026-89702, CVE-2026-89703, CVE-2026-89704, CVE-2026-89706, CVE-2026-89707, CVE-2026-89708, CVE-2026-89710, CVE-2026-89711, CVE-2026-89712, CVE-2026-89713, CVE-2026-89717, CVE-2026-89718, CVE-2026-89719, CVE-2026-89726, CVE-2026-89729, CVE-2026-89731, CVE-2026-89741, CVE-2026-89744, CVE-2026-89746, CVE-2026-89747, CVE-2026-89749, CVE-2026-89751, CVE-2026-89752, CVE-2026-89753, CVE-2026-89755, CVE-2026-89756, CVE-2026-89762, CVE-2026-89763, CVE-2026-89765, CVE-2026-89768, CVE-2026-89771, CVE-2026-89776, CVE-2026-89777, CVE-2026-89778, CVE-2026-89783, CVE-2026-89784, CVE-2026-89786, CVE-2026-89787, CVE-2026-89789, CVE-2026-89793, CVE-2026-89796, CVE-2026-89798, CVE-2026-89799, CVE-2026-89800, CVE-2026-89801, CVE-2026-89802, CVE-2026-89803, CVE-2026-89807, CVE-2026-89816, CVE-2026-89817, CVE-2026-89818, CVE-2026-89819, CVE-2026-89821, CVE-2026-89822, CVE-2026-89823, CVE-2026-89824, CVE-2026-89842, CVE-2026-89843, CVE-2026-89844, CVE-2026-89845, CVE-2026-89846, CVE-2026-89847, CVE-2026-89848, CVE-2026-89849, CVE-2026-89850, CVE-2026-89851, CVE-2026-89852, CVE-2026-89853, CVE-2026-89854, CVE-2026-89855, CVE-2026-89856, CVE-2026-89857, CVE-2026-89858, CVE-2026-89860, CVE-2026-89861, CVE-2026-89863, CVE-2026-89864, CVE-2026-89865, CVE-2026-89872, CVE-2026-89874, CVE-2026-89876, CVE-2026-89877, CVE-2026-89878, CVE-2026-89879, CVE-2026-89880, CVE-2026-89881, CVE-2026-89886, CVE-2026-89890, CVE-2026-89891, CVE-2026-89892, CVE-2026-89893, CVE-2026-89894, CVE-2026-89897, CVE-2026-89899, CVE-2026-89900, CVE-2026-89927, CVE-2026-89929, CVE-2026-89930, CVE-2026-89931, CVE-2026-89932, CVE-2026-89940, CVE-2026-89941, CVE-2026-89942, CVE-2026-89944, CVE-2026-89945, CVE-2026-89947, CVE-2026-89948, CVE-2026-89950, CVE-2026-89951, CVE-2026-89952, CVE-2026-89953, CVE-2026-89965, CVE-2026-89968, CVE-2026-89969, CVE-2026-89970, CVE-2026-89973, CVE-2026-89974, CVE-2026-89975, CVE-2026-89979, CVE-2026-89982, CVE-2026-89983, CVE-2026-89984, CVE-2026-89986, CVE-2026-89988, CVE-2026-89989, CVE-2026-89990, CVE-2026-89995, CVE-2026-89997, CVE-2026-89998, CVE-2026-89999, CVE-2026-90000, CVE-2026-90003, CVE-2026-90007, CVE-2026-90011, CVE-2026-90012, CVE-2026-90015, CVE-2026-90025, CVE-2026-90031, CVE-2026-90032, CVE-2026-90033, CVE-2026-90034, CVE-2026-90035, CVE-2026-90036, CVE-2026-90037, CVE-2026-90039, CVE-2026-90041, CVE-2026-90042, CVE-2026-90049, CVE-2026-90050, CVE-2026-90053, CVE-2026-90054, CVE-2026-90055, CVE-2026-90057, CVE-2026-90058, CVE-2026-90060, CVE-2026-90062, CVE-2026-90063, CVE-2026-90067, CVE-2026-90068, CVE-2026-90070, CVE-2026-90071, CVE-2026-90072, CVE-2026-90073, CVE-2026-90075, CVE-2026-90076, CVE-2026-90078, CVE-2026-90088, CVE-2026-90091, CVE-2026-90092, CVE-2026-90101, CVE-2026-90102, CVE-2026-90103, CVE-2026-90109, CVE-2026-90110, CVE-2026-90112, CVE-2026-90114, CVE-2026-90115, CVE-2026-90119, CVE-2026-90125, CVE-2026-90126, CVE-2026-90128, CVE-2026-90130, CVE-2026-90135, CVE-2026-90137, CVE-2026-90138, CVE-2026-90139, CVE-2026-90140, CVE-2026-90141, CVE-2026-90147, CVE-2026-90148, CVE-2026-90150, CVE-2026-90151, CVE-2026-90157, CVE-2026-90159, CVE-2026-90160, CVE-2026-90178, CVE-2026-90180, CVE-2026-90184, CVE-2026-90185, CVE-2026-90186, CVE-2026-90187, CVE-2026-90188, CVE-2026-90189, CVE-2026-90190, CVE-2026-90194, CVE-2026-90196, CVE-2026-90198, CVE-2026-90201, CVE-2026-90202, CVE-2026-90203, CVE-2026-90207, CVE-2026-90213, CVE-2026-90215, CVE-2026-90216, CVE-2026-90218, CVE-2026-90219, CVE-2026-90220, CVE-2026-90227, CVE-2026-90228, CVE-2026-90230, CVE-2026-90235, CVE-2026-90241, CVE-2026-90243, CVE-2026-90248, CVE-2026-90253, CVE-2026-90254, CVE-2026-90255, CVE-2026-90262, CVE-2026-90274, CVE-2026-90275, CVE-2026-90279, CVE-2026-90283, CVE-2026-90284, CVE-2026-90285, CVE-2026-90290, CVE-2026-90293, CVE-2026-90294, CVE-2026-90302, CVE-2026-90307, CVE-2026-90308, CVE-2026-90313, CVE-2026-90314, CVE-2026-90316, CVE-2026-90318, CVE-2026-90322, CVE-2026-90325, CVE-2026-90329, CVE-2026-90334, CVE-2026-90344, CVE-2026-90352, CVE-2026-90353, CVE-2026-90354, CVE-2026-90357, CVE-2026-90358, CVE-2026-90360, CVE-2026-90361, CVE-2026-90362, CVE-2026-90364, CVE-2026-90368, CVE-2026-90372, CVE-2026-90373, CVE-2026-90375, CVE-2026-90380, CVE-2026-90382, CVE-2026-90383, CVE-2026-90385, CVE-2026-90387, CVE-2026-90388, CVE-2026-90389, CVE-2026-90390, CVE-2026-90392, CVE-2026-90393, CVE-2026-90395, CVE-2026-90397, CVE-2026-90398, CVE-2026-90399, CVE-2026-90400, CVE-2026-90402, CVE-2026-90403, CVE-2026-90404, CVE-2026-90407, CVE-2026-90411, CVE-2026-90413, CVE-2026-90414, CVE-2026-90415, CVE-2026-90416, CVE-2026-90431, CVE-2026-90434, CVE-2026-90435, CVE-2026-92477, CVE-2026-92481, CVE-2026-92484, CVE-2026-92489, CVE-2026-92494, CVE-2026-92495, CVE-2026-92496, CVE-2026-92497, CVE-2026-92498, CVE-2026-92501, CVE-2026-92502, CVE-2026-92504, CVE-2026-92507, CVE-2026-92508, CVE-2026-92509, CVE-2026-92510, CVE-2026-92511, CVE-2026-92512, CVE-2026-92515, CVE-2026-92521, CVE-2026-92522, CVE-2026-92523, CVE-2026-92524, CVE-2026-92525, CVE-2026-93037, CVE-2026-93039, CVE-2026-93045, CVE-2026-93046, CVE-2026-93048, CVE-2026-93049, CVE-2026-93051, CVE-2026-93053, CVE-2026-93054, CVE-2026-93055, CVE-2026-93056, CVE-2026-93061, CVE-2026-93062, CVE-2026-93064, CVE-2026-93065, CVE-2026-93067, CVE-2026-93070, CVE-2026-93073, CVE-2026-93093, CVE-2026-93097, CVE-2026-93098, CVE-2026-93101, CVE-2026-93102, CVE-2026-93103, CVE-2026-93107, CVE-2026-93108, CVE-2026-93109, CVE-2026-93110, CVE-2026-93117, CVE-2026-93119, CVE-2026-93130, CVE-2026-93137, CVE-2026-93138, CVE-2026-93140, CVE-2026-93145, CVE-2026-93149, CVE-2026-93150, CVE-2026-93151, CVE-2026-93161, CVE-2026-93162, CVE-2026-93163, CVE-2026-93165, CVE-2026-93172, CVE-2026-93173, CVE-2026-93174, CVE-2026-93177, CVE-2026-93178, CVE-2026-93182, CVE-2026-93185, CVE-2026-93186, CVE-2026-93188, CVE-2026-93189, CVE-2026-93190, CVE-2026-93203, CVE-2026-93204, CVE-2026-93205, CVE-2026-93206, CVE-2026-93207, CVE-2026-93209, CVE-2026-93210, CVE-2026-93211, CVE-2026-93212, CVE-2026-93213, CVE-2026-93219, CVE-2026-93222, CVE-2026-93224, CVE-2026-93226, CVE-2026-93228, CVE-2026-93229, CVE-2026-93234, CVE-2026-93239, CVE-2026-93240, CVE-2026-93242, CVE-2026-93247, CVE-2026-93250, CVE-2026-93252, CVE-2026-93256, CVE-2026-93262, CVE-2026-93264, CVE-2026-93268, CVE-2026-93269, CVE-2026-93271, CVE-2026-93274, CVE-2026-93281, CVE-2026-93287, CVE-2026-93288, CVE-2026-93781, CVE-2026-93782, CVE-2026-93783, CVE-2026-93784, CVE-2026-93785, CVE-2026-93787, CVE-2026-93788, CVE-2026-93789, CVE-2026-93790, CVE-2026-93791, CVE-2026-93792, CVE-2026-93793, CVE-2026-93794, CVE-2026-93795, CVE-2026-93796, CVE-2026-93797, CVE-2026-93798, CVE-2026-93799, CVE-2026-93800, CVE-2026-93801, CVE-2026-93802, CVE-2026-93803, CVE-2026-93804, CVE-2026-93805, CVE-2026-93806, CVE-2026-93807, CVE-2026-93808, CVE-2026-93809, CVE-2026-93810, CVE-2026-93813, CVE-2026-93814, CVE-2026-93820, CVE-2026-93822, CVE-2026-93823, CVE-2026-93824, CVE-2026-93825, CVE-2026-93826, CVE-2026-93827, CVE-2026-93828, CVE-2026-93829, CVE-2026-97408, CVE-2026-97409, CVE-2026-97410, CVE-2026-97412, CVE-2026-97415, CVE-2026-97416, CVE-2026-97417, CVE-2026-97419, CVE-2026-97420, CVE-2026-97421, CVE-2026-97425, CVE-2026-97427, CVE-2026-97428, CVE-2026-97429, CVE-2026-97430, CVE-2026-97438, CVE-2026-97440, CVE-2026-97441, CVE-2026-97442, CVE-2026-97443, CVE-2026-97444, CVE-2026-97445, CVE-2026-97446, CVE-2026-97447, CVE-2026-97448, CVE-2026-97449, CVE-2026-97450, CVE-2026-97451, CVE-2026-97452, CVE-2026-97453, CVE-2026-97454, CVE-2026-97455, CVE-2026-97456, CVE-2026-97472, CVE-2026-97473, CVE-2026-97481, CVE-2026-97483, CVE-2026-97484, CVE-2026-97492, CVE-2026-97494, CVE-2026-97495, CVE-2026-97496, CVE-2026-97497, CVE-2026-97500, CVE-2026-97505, CVE-2026-97507, CVE-2026-97508, CVE-2026-97509, CVE-2026-97510, CVE-2026-97516, CVE-2026-97517, CVE-2026-97518, CVE-2026-97520, CVE-2026-97521, CVE-2026-97522, CVE-2026-97523, CVE-2026-97524, CVE-2026-97539, CVE-2026-97540, CVE-2026-97541, CVE-2026-97542, CVE-2026-97543, CVE-2026-97544, CVE-2026-97545, CVE-2026-97546, CVE-2026-97547, CVE-2026-97551, CVE-2026-97552, CVE-2026-97555, CVE-2026-97556, CVE-2026-97557, CVE-2026-97560, CVE-2026-97562, CVE-2026-97564, CVE-2026-97568, CVE-2026-97572, CVE-2026-97573, CVE-2026-97575, CVE-2026-97576, CVE-2026-97583, CVE-2026-97584, CVE-2026-97595, CVE-2026-97596, CVE-2026-97598, CVE-2026-97600, CVE-2026-97601, CVE-2026-97602, CVE-2026-97604, CVE-2026-97605, CVE-2026-97606, CVE-2026-97607, CVE-2026-97608, CVE-2026-97611, CVE-2026-97612, CVE-2026-97613, CVE-2026-97616, CVE-2026-97617, CVE-2026-97899, CVE-2026-97900, CVE-2026-97902, CVE-2026-97904, CVE-2026-97905, CVE-2026-97907, CVE-2026-97917, CVE-2026-97920, CVE-2026-97921, CVE-2026-97922, CVE-2026-97923, CVE-2026-97925, CVE-2026-97929, CVE-2026-97930, CVE-2026-97931, CVE-2026-97936, CVE-2026-97940, CVE-2026-97945, CVE-2026-97951, CVE-2026-97953, CVE-2026-97957, CVE-2026-97958, CVE-2026-97959, CVE-2026-97963, CVE-2026-97964, CVE-2026-97965, CVE-2026-97973, CVE-2026-97976, CVE-2026-97977, CVE-2026-97978, CVE-2026-97979, CVE-2026-97984, CVE-2026-97985, CVE-2026-97986, CVE-2026-97987, CVE-2026-97990, CVE-2026-97991, CVE-2026-97992, CVE-2026-97993, CVE-2026-97994, CVE-2026-97995, CVE-2026-97996, CVE-2026-97998, CVE-2026-98006, CVE-2026-98007, CVE-2026-98008, CVE-2026-98009, CVE-2026-98010, CVE-2026-98011, CVE-2026-98012, CVE-2026-98014, CVE-2026-98015, CVE-2026-98016, CVE-2026-98017, CVE-2026-98020, CVE-2026-98021, CVE-2026-98022, CVE-2026-98023, CVE-2026-98025, CVE-2026-98026, CVE-2026-98027, CVE-2026-98028, CVE-2026-98029, CVE-2026-98030, CVE-2026-98031, CVE-2026-98037, CVE-2026-98039, CVE-2026-98041, CVE-2026-98045, CVE-2026-98046, CVE-2026-98051, CVE-2026-98052, CVE-2026-98054, CVE-2026-98055, CVE-2026-98056, CVE-2026-98057, CVE-2026-98059, CVE-2026-98063, CVE-2026-98064, CVE-2026-98066, CVE-2026-98074, CVE-2026-98075, CVE-2026-98076, CVE-2026-98077, CVE-2026-98078, CVE-2026-98080, CVE-2026-98081, CVE-2026-98082, CVE-2026-98083, CVE-2026-98086, CVE-2026-98088, CVE-2026-98089, CVE-2026-98090, CVE-2026-98091, CVE-2026-98092, CVE-2026-98095, CVE-2026-98096, CVE-2026-98097, CVE-2026-98098, CVE-2026-98102, CVE-2026-98103, CVE-2026-98104, CVE-2026-98107, CVE-2026-98108, CVE-2026-98109, CVE-2026-98110, CVE-2026-98111, CVE-2026-98116, CVE-2026-98122, CVE-2026-98123, CVE-2026-98126, CVE-2026-98127, CVE-2026-98128, CVE-2026-98129, CVE-2026-98130, CVE-2026-98142, CVE-2026-98151, CVE-2026-98152, CVE-2026-98154, CVE-2026-98157, CVE-2026-98158, CVE-2026-98159