{
  "cves": [
    "CVE-2022-50673",
    "CVE-2025-38403",
    "CVE-2025-40135",
    "CVE-2025-40158",
    "CVE-2025-40170",
    "CVE-2025-40269",
    "CVE-2025-68349",
    "CVE-2026-22998"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[4.18.0-553.104.1]\n- Update Oracle Linux certificates (Kevin Lyons)\n- Disable signing for aarch64 (Ilya Okomin)\n- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]\n- Update x509.genkey [Orabug: 24817676]\n- Conflict with shim-ia32 and shim-x64 = 15.3-1.0.3\n- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]\n- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985772]\n\n[4.18.0-553.104.1]\n- Revert 'audit: Avoid excessive dput/dget in audit_context setup and reset paths' (Alexandra Hajkova) [RHEL-145856]\n\n[4.18.0-553.103.1]\n- ext4: fix use-after-free in ext4_orphan_cleanup (CKI Backport Bot) [RHEL-136000] {CVE-2022-50673}\n- ext4: lost matching-pair of trace in ext4_truncate (CKI Backport Bot) [RHEL-136000] {CVE-2022-50673}\n- ALSA: usb-audio: Fix potential overflow of PCM transfer buffer (CKI Backport Bot) [RHEL-136904] {CVE-2025-40269}\n\n[4.18.0-553.102.1]\n- nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec (CKI Backport Bot) [RHEL-144327] {CVE-2026-22998}\n- NFSv4: ensure the open stateid seqid doesn't go backwards (Scott Mayhew) [RHEL-121683]\n- audit: Avoid excessive dput/dget in audit_context setup and reset paths (Waiman Long) [RHEL-140776]\n- lockref: remove lockref_put_not_zero (Waiman Long) [RHEL-140776]\n- lockref: stop doing cpu_relax in the cmpxchg loop (Waiman Long) [RHEL-140776]\n- lockref: remove unused 'lockref_get_or_lock()' function (Waiman Long) [RHEL-140776]\n- lockref: Limit number of cmpxchg loop retries (Waiman Long) [RHEL-140776]\n- net: use dst_dev_rcu() in sk_setup_caps() (Hangbin Liu) [RHEL-129079] {CVE-2025-40170}\n- ipv6: use RCU in ip6_xmit() (Hangbin Liu) [RHEL-129004] {CVE-2025-40135}\n- ipv6: use RCU in ip6_output() (Hangbin Liu) [RHEL-128966] {CVE-2025-40158}\n- net: dst: introduce dst-dev_rcu (Hangbin Liu) [RHEL-128966]\n- net: Add locking to protect skb-dev access in ip_output (Hangbin Liu) [RHEL-128966]\n- net: dst: add four helpers to annotate data-races around dst-dev (Hangbin Liu) [RHEL-128966]\n- ipv4: use RCU protection in __ip_rt_update_pmtu() (Hangbin Liu) [RHEL-128966] {CVE-2025-21766}\n- net: gain ipv4 mtu when mtu is not locked (Hangbin Liu) [RHEL-128966]\n- ipv4: use RCU protection in ip_dst_mtu_maybe_forward() (Hangbin Liu) [RHEL-128966]\n- ipv4: add RCU protection to ip4_dst_hoplimit() (Hangbin Liu) [RHEL-128966]\n\n[4.18.0-553.101.1]\n- i40e: avoid redundant VF link state updates (CKI Backport Bot) [RHEL-141878]\n- NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid (CKI Backport Bot) [RHEL-140255] {CVE-2025-68349}\n- vsock/vmci: Clear the vmci transport packet properly when initializing it (CKI Backport Bot) [RHEL-137692] {CVE-2025-38403}\n- sched: Fix stop_one_cpu_nowait() vs hotplug (Herton R. Krzesinski) [RHEL-85625]",
  "id": "ELSA-2026-2264",
  "ovalId": "oval:com.oracle.elsa:def:20262264",
  "source": "oracle_linux",
  "title": "ELSA-2026-2264:  kernel security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-2264.html"
}