{"cves":["CVE-2025-38085","CVE-2025-38678","CVE-2025-39810","CVE-2025-40248","CVE-2025-40250","CVE-2025-40271","CVE-2025-40280"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[5.15.0-316.196.4.1]\n- tipc: Fix use-after-free in tipc_mon_reinit_self(). (Kuniyuki Iwashima)  [Orabug: 38788585]  {CVE-2025-40280}\n- fs/proc: fix uaf in proc_readdir_de() (Wei Yang)  [Orabug: 38788587]  {CVE-2025-40271}\n- vsock: Ignore signal/timeout on connect() if already established (Michal Luczaj)  [Orabug: 38788594]  {CVE-2025-40248}\n\n[5.15.0-316.196.4]\n- vhost_scsi: Sync up cmd completion locking with upstream (Mike Christie)  [Orabug: 38545946]\n- vhost_scsi: add support for worker ioctls (Mike Christie)  [Orabug: 38545946]\n- vhost: Limit access to vhost worker ioctls (Mike Christie)  [Orabug: 38545946]\n- vhost: allow userspace to create workers (Mike Christie)  [Orabug: 38545946]\n- vhost: replace single worker pointer with xarray (Mike Christie)  [Orabug: 38545946]\n- vhost: add helper to parse userspace vring state/file (Mike Christie)  [Orabug: 38545946]\n- vhost: remove vhost_work_queue (Mike Christie)  [Orabug: 38545946]\n- vhost_scsi: flush IO vqs then send TMF rsp (Mike Christie)  [Orabug: 38545946]\n- vhost_scsi: convert to vhost_vq_work_queue (Mike Christie)  [Orabug: 38545946]\n- vhost_scsi: make SCSI cmd completion per vq (Mike Christie)  [Orabug: 38545946]\n- vhost_sock: convert to vhost_vq_work_queue (Mike Christie)  [Orabug: 38545946]\n- vhost: convert poll work to be vq based (Mike Christie)  [Orabug: 38545946]\n- vhost: take worker or vq for flushing (Mike Christie)  [Orabug: 38545946]\n- vhost: take worker or vq instead of dev for queueing (Mike Christie)  [Orabug: 38545946]\n- vhost, vhost_net: add helper to check if vq has work (Mike Christie)  [Orabug: 38545946]\n- vhost: add vhost_worker pointer to vhost_virtqueue (Mike Christie)  [Orabug: 38545946]\n- vhost: dynamically allocate vhost_worker (Mike Christie)  [Orabug: 38545946]\n- vhost: create worker at end of vhost_dev_set_owner (Mike Christie)  [Orabug: 38545946]\n- vhost-scsi: Fix crash during LUN unmapping (Mike Christie)  [Orabug: 38545946]\n- vhost: move worker thread fields to new struct (Mike Christie)  [Orabug: 38545946]\n- vhost: Fix livepatch timeouts in vhost_worker() (Josh Poimboeuf)  [Orabug: 38545946]\n- vhost: rename vhost_work_dev_flush (Mike Christie)  [Orabug: 38545946]\n- vhost-test: drop flush after vhost_dev_cleanup (Mike Christie)  [Orabug: 38545946]\n- vhost/test: fix memory leak of vhost virtqueues (Xianting Tian)  [Orabug: 38545946]\n- vhost-scsi: drop flush after vhost_dev_cleanup (Mike Christie)  [Orabug: 38545946]\n- vhost_vsock: simplify vhost_vsock_flush() (Andrey Ryabinin)  [Orabug: 38545946]\n- vhost_test: remove vhost_test_flush_vq() (Andrey Ryabinin)  [Orabug: 38545946]\n- vhost_net: get rid of vhost_net_flush_vq() and extra flush calls (Andrey Ryabinin)  [Orabug: 38545946]\n- vhost: flush dev once during vhost_dev_stop (Mike Christie)  [Orabug: 38545946]\n- vhost: get rid of vhost_poll_flush() wrapper (Andrey Ryabinin)  [Orabug: 38545946]\n- net/mlx5e: Add a miss level for ipsec crypto offload (Lama Kayal)  [Orabug: 38600056]\n- net/mlx5e: Add new prio for promiscuous mode (Jianbo Liu)  [Orabug: 38600056]\n- mm/hugetlb: add option to allows disabling CVE-2025-38085 mitigation (Joe Jin)  [Orabug: 38728358]\n- uek-rpm: Replace check-kabi tool with kabi (Yifei Liu)  [Orabug: 38673381]\n- uek-rpm: Introduce check function for uek-rpm/tools/kabi (Yifei Liu)  [Orabug: 38673381]\n- rtc: expose RTC_FEATURE_UPDATE_INTERRUPT (Alexandre Belloni)  [Orabug: 38708842]\n- Reapply 'cpuidle: menu: Avoid discarding useful information' (Harshvardhan Jha)  [Orabug: 38710346]\n- netfilter: nf_tables: reject duplicate device on updates (Pablo Neira Ayuso)  [Orabug: 38389767]  {CVE-2025-38678}\n- HID: quirks: work around VID/PID conflict for 0x4c4a/0x4155 (Zhang Heng)\n- mptcp: pm: in-kernel: C-flag: handle late ADD_ADDR (Matthieu Baerts (NGI0))\n- USB: storage: Remove subclass and protocol overrides from Novatek quirk (Alan Stern)\n- most: usb: fix double free on late probe failure (Johan Hovold)\n- uio_hv_generic: Set event for all channels on the device (Long Li)\n- regmap: slimbus: fix bus_context pointer in regmap init calls (Alexey Klimov)\n- usb: typec: ucsi: psy: Set max current to zero when disconnected (Jameson Thies)\n- ata: libata-scsi: Fix system suspend for a security locked drive (Niklas Cassel)\n- MIPS: mm: Prevent a TLB shutdown on initial uniquification (Maciej W. Rozycki)\n\n[5.15.0-316.196.3]\n- rds: Add smp_rmb before reading c_destroy_in_prog (Hakon Bugge) [Orabug: 38352484]\n- Revert 'block: don't add or resize partition on the disk with GENHD_FL_NO_PART' (Gulam Mohamed) [Orabug: 38652797]\n- Revert 'block: Move checking GENHD_FL_NO_PART to bdev_add_partition()' (Gulam Mohamed) [Orabug: 38652797]\n\n[5.15.0-316.196.2]\n- net/mlx5: Clean up only new IRQ glue on request_irq() failure (Pradyumn Rahar) [Orabug: 37961220,38730620] {CVE-2025-40250}\n\n[5.15.0-316.196.1]\n- uek-rpm: kabi: Remove the kabi protection for debug kernels (Yifei Liu) [Orabug: 38609547]\n- bnxt_en: Fix memory corruption when FW resources change during ifdown (Sreekanth Reddy) [Orabug: 38440240] {CVE-2025-39810}\n- selftests/proc: add PROCMAP_QUERY ioctl tests (Andrii Nakryiko) [Orabug: 38410775]\n- tools: sync uapi/linux/fs.h header into tools subdir (Andrii Nakryiko) [Orabug: 38410775]\n- docs/procfs: call out ioctl()-based PROCMAP_QUERY command existence (Andrii Nakryiko) [Orabug: 38410775]\n- fs/procfs: add build ID fetching to PROCMAP_QUERY API (Andrii Nakryiko) [Orabug: 38410775]\n- fs/procfs: implement efficient VMA querying API for /proc/pid/maps (Andrii Nakryiko) [Orabug: 38410775]\n- fs/procfs: extract logic for getting VMA name constituents (Andrii Nakryiko) [Orabug: 38410775]\n- fs: create helper file_user_path() for user displayed mapped file path (Amir Goldstein) [Orabug: 38410775]\n- mm: factor out VMA stack and heap checks (Kefeng Wang) [Orabug: 38410775]","id":"ELSA-2026-50007","ovalId":"oval:com.oracle.elsa:def:202650007","source":"oracle_linux","title":"ELSA-2026-50007: Unbreakable Enterprise kernel security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-50007.html"}