Oracle Linux Security Advisory ELSA-2026-3966 http://linux.oracle.com/errata/ELSA-2026-3966.html
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-abi-stablelists-5.14.0-611.38.1.el9_7.noarch.rpm kernel-core-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-cross-headers-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-debug-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-debug-core-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-debug-devel-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-debug-devel-matched-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-debug-modules-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-debug-modules-core-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-debug-modules-extra-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-debug-uki-virt-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-devel-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-devel-matched-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-doc-5.14.0-611.38.1.el9_7.noarch.rpm kernel-headers-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-modules-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-modules-core-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-modules-extra-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-tools-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-tools-libs-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-tools-libs-devel-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-uki-virt-5.14.0-611.38.1.el9_7.x86_64.rpm kernel-uki-virt-addons-5.14.0-611.38.1.el9_7.x86_64.rpm libperf-5.14.0-611.38.1.el9_7.x86_64.rpm perf-5.14.0-611.38.1.el9_7.x86_64.rpm python3-perf-5.14.0-611.38.1.el9_7.x86_64.rpm rtla-5.14.0-611.38.1.el9_7.x86_64.rpm rv-5.14.0-611.38.1.el9_7.x86_64.rpm aarch64: kernel-cross-headers-5.14.0-611.38.1.el9_7.aarch64.rpm kernel-headers-5.14.0-611.38.1.el9_7.aarch64.rpm kernel-tools-5.14.0-611.38.1.el9_7.aarch64.rpm kernel-tools-libs-5.14.0-611.38.1.el9_7.aarch64.rpm kernel-tools-libs-devel-5.14.0-611.38.1.el9_7.aarch64.rpm libperf-5.14.0-611.38.1.el9_7.aarch64.rpm perf-5.14.0-611.38.1.el9_7.aarch64.rpm python3-perf-5.14.0-611.38.1.el9_7.aarch64.rpm rtla-5.14.0-611.38.1.el9_7.aarch64.rpm rv-5.14.0-611.38.1.el9_7.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/kernel-5.14.0-611.38.1.el9_7.src.rpm Related CVEs: CVE-2025-38106 CVE-2026-23001 Description of changes: [5.14.0-611.38.1] - Disable UKI signing [Orabug: 36571828] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5] - Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535] - Add Oracle Linux IMA certificates - Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985764] [5.14.0-611.38.1] - mlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats (CKI Backport Bot) [RHEL-143194] {CVE-2025-68800} [5.14.0-611.37.1] - printk: Use console_is_usable on console_unblank (CKI Backport Bot) [RHEL-148302] - printk: Check CON_SUSPEND when unblanking a console (CKI Backport Bot) [RHEL-148302] - printk: Avoid irq_work for printk_deferred() on suspend (CKI Backport Bot) [RHEL-148302] - printk: Avoid scheduling irq_work on suspend (CKI Backport Bot) [RHEL-148302] - printk: nbcon: Allow reacquire during panic (CKI Backport Bot) [RHEL-148302] - printk: Allow printk_trigger_flush() to flush all types (CKI Backport Bot) [RHEL-148302] - printk: nbcon: Use raw_cpu_ptr() instead of open coding (CKI Backport Bot) [RHEL-148302] - backport "printk: Add helper for flush type logic" and associated changes (CKI Backport Bot) [RHEL-148302] - printk: Remove redundant deferred check in vprintk() (CKI Backport Bot) [RHEL-148302] - printk: Introduce force_legacy_kthread() macro (CKI Backport Bot) [RHEL-148302] - printk: Add is_printk_legacy_deferred() (CKI Backport Bot) [RHEL-148302] - io_uring/sqpoll: don't put task_struct on tctx setup failure (Jeff Moyer) [RHEL-137988] - io_uring: consistently use rcu semantics with sqpoll thread (Jeff Moyer) [RHEL-137988] - io_uring: fix use-after-free of sq->thread in __io_uring_show_fdinfo() (Jeff Moyer) [RHEL-137988] {CVE-2025-38106} - io_uring/sqpoll: fix sqpoll error handling races (Jeff Moyer) [RHEL-137988] - io_uring/sqpoll: annotate debug task == current with data_race() (Jeff Moyer) [RHEL-137988] - macvlan: fix possible UAF in macvlan_forward_source() (CKI Backport Bot) [RHEL-144125] {CVE-2026-23001} - net/smc: Fix lookup of netdev by using ib_device_get_netdev() (CKI Backport Bot) [RHEL-114786] _______________________________________________ El-errata mailing list [email protected] https://oss.oracle.com/mailman/listinfo/el-errata
