{"cves":["CVE-2024-56602","CVE-2026-46120","CVE-2026-52991","CVE-2026-53189","CVE-2026-63887","CVE-2026-63888","CVE-2026-64048","CVE-2026-64379","CVE-2026-68388"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[4.18.0-553.157.1]\n- Update Oracle Linux certificates (Kevin Lyons)\n- Disable signing for aarch64 (Ilya Okomin)\n- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]\n- Update x509.genkey [Orabug: 24817676]\n- Conflict with shim-ia32 and shim-x64 = 15.3-1.0.3\n- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]\n- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985772]\n\n[4.18.0-553.157.1]\n- smb/client: handle overlapping allocated ranges in fallocate (CKI Backport Bot) [RHEL-236195] {CVE-2026-68388}\n- mm, page_alloc: skip -waternark_boost for atomic order-0 allocations (Jay Shin) [RHEL-219767]\n- mm, page_alloc: reset the zone-watermark_boost early (Jay Shin) [RHEL-219767]\n- scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (Maurizio Lombardi) [RHEL-213227] {CVE-2026-63888}\n- net: ieee802154: do not leave a dangling sk pointer in ieee802154_create() (Abhishek Rawal) [RHEL-224189] {CVE-2024-56602}\n- cgroup/psi: Set of-priv to NULL upon file release (Waiman Long) [RHEL-232546]\n- sched/psi: Create the psimon kthread outside of cgroup_mutex (Waiman Long) [RHEL-232546]\n- sched/psi: fix race between file release and pressure write (Waiman Long) [RHEL-232546] {CVE-2026-52991}\n- sched/psi: Remove unused parameter nbytes of psi_trigger_create() (Waiman Long) [RHEL-232546]\n- psi: fix 'no previous prototype' warnings when CONFIG_CGROUPS=n (Waiman Long) [RHEL-232546]\n- smb: client: mask server-provided mode to 07777 in modefromsid (CKI Backport Bot) [RHEL-234516] {CVE-2026-64379}\n- mm/huge_memory: update file PMD counter before folio_put() (Luiz Capitulino) [RHEL-231209] {CVE-2026-53189}\n- net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (CKI Backport Bot) [RHEL-230094] {CVE-2026-64048}\n- scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (CKI Backport Bot) [RHEL-213200] {CVE-2026-63887}\n- ip6_gre: Use cached t-net in ip6erspan_changelink(). (CKI Backport Bot) [RHEL-180148] {CVE-2026-46120}","id":"ELSA-2026-57253","ovalId":"oval:com.oracle.elsa:def:202657253","source":"oracle_linux","title":"ELSA-2026-57253:  kernel security, bug fix, and enhancement update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-57253.html"}