{"cves":["CVE-2022-50673","CVE-2025-38403","CVE-2025-40135","CVE-2025-40158","CVE-2025-40170","CVE-2025-40269","CVE-2025-68349","CVE-2026-22998"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[4.18.0-553.104.1]\n- Update Oracle Linux certificates (Kevin Lyons)\n- Disable signing for aarch64 (Ilya Okomin)\n- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]\n- Update x509.genkey [Orabug: 24817676]\n- Conflict with shim-ia32 and shim-x64 = 15.3-1.0.3\n- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]\n- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985772]\n\n[4.18.0-553.104.1]\n- Revert 'audit: Avoid excessive dput/dget in audit_context setup and reset paths' (Alexandra Hajkova) [RHEL-145856]\n\n[4.18.0-553.103.1]\n- ext4: fix use-after-free in ext4_orphan_cleanup (CKI Backport Bot) [RHEL-136000] {CVE-2022-50673}\n- ext4: lost matching-pair of trace in ext4_truncate (CKI Backport Bot) [RHEL-136000] {CVE-2022-50673}\n- ALSA: usb-audio: Fix potential overflow of PCM transfer buffer (CKI Backport Bot) [RHEL-136904] {CVE-2025-40269}\n\n[4.18.0-553.102.1]\n- nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec (CKI Backport Bot) [RHEL-144327] {CVE-2026-22998}\n- NFSv4: ensure the open stateid seqid doesn't go backwards (Scott Mayhew) [RHEL-121683]\n- audit: Avoid excessive dput/dget in audit_context setup and reset paths (Waiman Long) [RHEL-140776]\n- lockref: remove lockref_put_not_zero (Waiman Long) [RHEL-140776]\n- lockref: stop doing cpu_relax in the cmpxchg loop (Waiman Long) [RHEL-140776]\n- lockref: remove unused 'lockref_get_or_lock()' function (Waiman Long) [RHEL-140776]\n- lockref: Limit number of cmpxchg loop retries (Waiman Long) [RHEL-140776]\n- net: use dst_dev_rcu() in sk_setup_caps() (Hangbin Liu) [RHEL-129079] {CVE-2025-40170}\n- ipv6: use RCU in ip6_xmit() (Hangbin Liu) [RHEL-129004] {CVE-2025-40135}\n- ipv6: use RCU in ip6_output() (Hangbin Liu) [RHEL-128966] {CVE-2025-40158}\n- net: dst: introduce dst-dev_rcu (Hangbin Liu) [RHEL-128966]\n- net: Add locking to protect skb-dev access in ip_output (Hangbin Liu) [RHEL-128966]\n- net: dst: add four helpers to annotate data-races around dst-dev (Hangbin Liu) [RHEL-128966]\n- ipv4: use RCU protection in __ip_rt_update_pmtu() (Hangbin Liu) [RHEL-128966] {CVE-2025-21766}\n- net: gain ipv4 mtu when mtu is not locked (Hangbin Liu) [RHEL-128966]\n- ipv4: use RCU protection in ip_dst_mtu_maybe_forward() (Hangbin Liu) [RHEL-128966]\n- ipv4: add RCU protection to ip4_dst_hoplimit() (Hangbin Liu) [RHEL-128966]\n\n[4.18.0-553.101.1]\n- i40e: avoid redundant VF link state updates (CKI Backport Bot) [RHEL-141878]\n- NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid (CKI Backport Bot) [RHEL-140255] {CVE-2025-68349}\n- vsock/vmci: Clear the vmci transport packet properly when initializing it (CKI Backport Bot) [RHEL-137692] {CVE-2025-38403}\n- sched: Fix stop_one_cpu_nowait() vs hotplug (Herton R. Krzesinski) [RHEL-85625]","id":"ELSA-2026-2264","ovalId":"oval:com.oracle.elsa:def:20262264","source":"oracle_linux","title":"ELSA-2026-2264:  kernel security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-2264.html"}