{
  "cves": [
    "CVE-2025-39866",
    "CVE-2025-39965",
    "CVE-2025-39946",
    "CVE-2025-39718",
    "CVE-2025-39881",
    "CVE-2025-39963",
    "CVE-2025-39977",
    "CVE-2025-39964",
    "CVE-2025-39973",
    "CVE-2025-39698"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[6.12.0-104.43.4.3]\n- io_uring/futex: ensure io_futex_wait() cleans up properly on failure (Jens Axboe)  [Orabug: 38572958]  {CVE-2025-39698}\n- fs: writeback: fix use-after-free in __mark_inode_dirty() (Jiufei Xue)  [Orabug: 38572953]  {CVE-2025-39866}\n- kernfs: Fix UAF in polling when open file is released (Chen Ridong)  [Orabug: 38572951]  {CVE-2025-3988}\n- vsock/virtio: Validate length in packet header before skb_put() (Will Deacon)  [Orabug: 38572950]  {CVE-2025-39718}\n- crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (Herbert Xu)  [Orabug: 38572948]  {CVE-2025-39964}\n- io_uring: fix incorrect io_kiocb reference in io_link_skb (Yang Xiuwei)  [Orabug: 38572947]  {CVE-2025-39963}\n- xfrm: xfrm_alloc_spi shouldn't use 0 as SPI (Sabrina Dubroca)  [Orabug: 38572946]  {CVE-2025-39965}\n- tls: make sure to abort the stream if headers are bogus (Jakub Kicinski)  [Orabug: 38572944]  {CVE-2025-39946}\n- futex: Prevent use-after-free during requeue-PI (Sebastian Andrzej Siewior)  [Orabug: 38572943]  {CVE-2025-39977}\n- i40e: add validation for ring_len param (Lukasz Czapnik)  [Orabug: 38572941]  {CVE-2025-39973}",
  "id": "ELSA-2025-20719",
  "ovalId": "oval:com.oracle.elsa:def:202520719",
  "source": "oracle_linux",
  "title": "ELSA-2025-20719: Unbreakable Enterprise kernel security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2025-20719.html"
}