{"cves":["CVE-2025-10263"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[6.12.0-203.76.7.3]\n- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland)  [Orabug: 39017589]  {CVE-2025-10263}\n- arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland)  [Orabug: 39017589] \n- arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland)  [Orabug: 39017589] \n- arm64: cputype: Add C1-Premium definitions (Mark Rutland)  [Orabug: 39017589] \n- arm64: cputype: Add C1-Ultra definitions (Mark Rutland)  [Orabug: 39017589]\n\n[6.12.0-203.76.7.2]\n- kabi: update FIPS kABI files (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- KEYS: Reserve key usage values (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: keep FIPS MPI helpers private (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: keep FIPS compression helpers private (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: keep FIPS helper library symbols private (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: tcrypt - clamp num_mb to avoid divide-by-zero (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: tcrypt - stop ahash speed tests when setkey fails (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: add x86 GHASH CLMUL to FIPS module (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: add fixed-time AES to FIPS module (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- fips: add scatterwalk to FIPS module (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: avoid auto-load for arch specific impls (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- arm64/crypto: wire up FIPS aliases and helpers (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: share alg registry between FIPS and base kernel (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: keep crypto_user out of the FIPS module (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: tcrypt - skip retest in FIPS mode (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: skip redundant FIPS self-module signature check (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- scripts: fail cleanly on arm64 boot image formats (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto/hkdf: Skip tests with keys too short in FIPS mode (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- uek-rpm: build module symvers before fips140.ko (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: add crc64_rocksoft_generic to the FIPS module (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: add keywrap to the FIPS module (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: add cts to the FIPS module (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: convert kdf_sp800108 to CRYPTO_API() (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- fips: drop ansi_cprng and revert ansi_cprng FIPS hooks (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto/testmgr: mark xxhash64 as fips disallowed (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- Revert 'fips: add xxhash64-generic to FIPS module' (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- asm-generic/vmlinux.lds.h: remove unreachable FIPS140 branch (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- btrfs: switch to library APIs for checksums (Eric Biggers)  [Orabug: 39489008]\n- lib/crypto: blake2b: Add BLAKE2b library functions (Eric Biggers)  [Orabug: 39489008]\n- byteorder: Add le64_to_cpu_array() and cpu_to_le64_array() (Eric Biggers)  [Orabug: 39489008]","id":"ELSA-2026-50304","ovalId":"oval:com.oracle.elsa:def:202650304","source":"oracle_linux","title":"ELSA-2026-50304: Unbreakable Enterprise kernel security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-50304.html"}