{
  "cves": [
    "CVE-2025-38292",
    "CVE-2025-38079",
    "CVE-2025-38085",
    "CVE-2025-38137",
    "CVE-2024-56721",
    "CVE-2025-38159",
    "CVE-2025-38084"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "MODERATE"
  },
  "description": "[6.12.0-55.27.1.0.1]\n- nvme-pci: remove two deallocate zeroes quirks [Orabug: 37756650]\n- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]\n- Disable UKI signing [Orabug: 36571828]\n- Update Oracle Linux certificates (Kevin Lyons)\n- Disable signing for aarch64 (Ilya Okomin)\n- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]\n- Update x509.genkey [Orabug: 24817676]\n- Conflict with shim-ia32 and shim-x64 = 15.3-1.0.5.el9\n- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]\n- Add Oracle Linux IMA certificates\n- Update module name for cryptographic module [Orabug: 37400433]\n\n* Thu Aug 14 2025 Alex Burmashev alexander.burmashev@oracle.com [6.12.0-55.27.1]\n- Bump internal version to 55.27.1\n- Fix includes for mm: fix copy_vma() error handling for hugetlb mappings\n- Revert sch_htb: make htb_qlen_notify() idempotent\n- Revert sch_drr: make drr_qlen_notify() idempotent\n- Revert sch_qfq: make qfq_qlen_notify() idempotent\n- Revert codel: remove sch-q.qlen check before qdisc_tree_reduce_backlog()\n- Revert sch_htb: make htb_deactivate() idempotent\n- Revert net/sched: Always pass notifications when child class becomes empty\n- wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds - CVE-2025-38159\n- Documentation: Fix pci=config_acs= example\n- PCI/ACS: Fix 'pci=config_acs=' parameter\n- Revert 'smb: client: fix TCP timers deadlock after rmmod' - CVE-2025-22077\n- Revert smb: client: Fix netns refcount imbalance causing leaks and use-after-free \n- smb: client: Fix netns refcount imbalance causing leaks and use-after-free\n- wifi: ath12k: fix invalid access to memory - CVE-2025-38292\n- x86/CPU/AMD: Terminate the erratum_1386_microcode array - CVE-2024-56721\n- crypto: algif_hash - fix double free in hash_accept - CVE-2025-38079\n- net/sched: Always pass notifications when child class becomes empty - CVE-2025-38350\n- sch_htb: make htb_deactivate() idempotent - CVE-2025-38350\n- codel: remove sch-q.qlen check before qdisc_tree_reduce_backlog() - CVE-2025-38350\n- sch_qfq: make qfq_qlen_notify() idempotent - CVE-2025-38350\n- sch_drr: make drr_qlen_notify() idempotent - CVE-2025-38350\n- sch_htb: make htb_qlen_notify() idempotent - CVE-2025-38350\n- mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race - CVE-2025-38085\n- mm/hugetlb: unshare page tables during VMA split, not before - CVE-2025-38084\n- tools/testing/vma: add missing function stub\n- mm: fix copy_vma() error handling for hugetlb mappings\n- PCI: Use downstream bridges for distributing resources\n- PCI/pwrctrl: Cancel outstanding rescan work when unregistering - CVE-2025-38137\n- bnxt_en: Skip MAC loopback selftest if it is unsupported by FW\n- bnxt_en: Skip PHY loopback ethtool selftest if unsupported by FW",
  "id": "ELSA-2025-13598",
  "ovalId": "oval:com.oracle.elsa:def:202513598",
  "source": "oracle_linux",
  "title": "ELSA-2025-13598:  kernel security update (MODERATE)",
  "url": "https://linux.oracle.com/errata/ELSA-2025-13598.html"
}