elsa-2025-13598

oracle_linux
Description

[6.12.0-55.27.1.0.1] - nvme-pci: remove two deallocate zeroes quirks [Orabug: 37756650] - Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782] - Disable UKI signing [Orabug: 36571828] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64 = 15.3-1.0.5.el9 - Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535] - Add Oracle Linux IMA certificates - Update module name for cryptographic module [Orabug: 37400433] * Thu Aug 14 2025 Alex Burmashev alexander.burmashev@oracle.com [6.12.0-55.27.1] - Bump internal version to 55.27.1 - Fix includes for mm: fix copy_vma() error handling for hugetlb mappings - Revert sch_htb: make htb_qlen_notify() idempotent - Revert sch_drr: make drr_qlen_notify() idempotent - Revert sch_qfq: make qfq_qlen_notify() idempotent - Revert codel: remove sch-q.qlen check before qdisc_tree_reduce_backlog() - Revert sch_htb: make htb_deactivate() idempotent - Revert net/sched: Always pass notifications when child class becomes empty - wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds - CVE-2025-38159 - Documentation: Fix pci=config_acs= example - PCI/ACS: Fix 'pci=config_acs=' parameter - Revert 'smb: client: fix TCP timers deadlock after rmmod' - CVE-2025-22077 - Revert smb: client: Fix netns refcount imbalance causing leaks and use-after-free - smb: client: Fix netns refcount imbalance causing leaks and use-after-free - wifi: ath12k: fix invalid access to memory - CVE-2025-38292 - x86/CPU/AMD: Terminate the erratum_1386_microcode array - CVE-2024-56721 - crypto: algif_hash - fix double free in hash_accept - CVE-2025-38079 - net/sched: Always pass notifications when child class becomes empty - CVE-2025-38350 - sch_htb: make htb_deactivate() idempotent - CVE-2025-38350 - codel: remove sch-q.qlen check before qdisc_tree_reduce_backlog() - CVE-2025-38350 - sch_qfq: make qfq_qlen_notify() idempotent - CVE-2025-38350 - sch_drr: make drr_qlen_notify() idempotent - CVE-2025-38350 - sch_htb: make htb_qlen_notify() idempotent - CVE-2025-38350 - mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race - CVE-2025-38085 - mm/hugetlb: unshare page tables during VMA split, not before - CVE-2025-38084 - tools/testing/vma: add missing function stub - mm: fix copy_vma() error handling for hugetlb mappings - PCI: Use downstream bridges for distributing resources - PCI/pwrctrl: Cancel outstanding rescan work when unregistering - CVE-2025-38137 - bnxt_en: Skip MAC loopback selftest if it is unsupported by FW - bnxt_en: Skip PHY loopback ethtool selftest if unsupported by FW

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2025-38292",
    "CVE-2025-38079",
    "CVE-2025-38085",
    "CVE-2025-38137",
    "CVE-2024-56721",
    "CVE-2025-38159",
    "CVE-2025-38084"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "MODERATE"
  },
  "description": "[6.12.0-55.27.1.0.1]\n- nvme-pci: remove two deallocate zeroes quirks [Orabug: 37756650]\n- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]\n- Disable UKI signing [Orabug: 36571828]\n- Update Oracle Linux certificates (Kevin Lyons)\n- Disable signing for aarch64 (Ilya Okomin)\n- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]\n- Update x509.genkey [Orabug: 24817676]\n- Conflict with shim-ia32 and shim-x64 = 15.3-1.0.5.el9\n- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]\n- Add Oracle Linux IMA certificates\n- Update module name for cryptographic module [Orabug: 37400433]\n\n* Thu Aug 14 2025 Alex Burmashev alexander.burmashev@oracle.com [6.12.0-55.27.1]\n- Bump internal version to 55.27.1\n- Fix includes for mm: fix copy_vma() error handling for hugetlb mappings\n- Revert sch_htb: make htb_qlen_notify() idempotent\n- Revert sch_drr: make drr_qlen_notify() idempotent\n- Revert sch_qfq: make qfq_qlen_notify() idempotent\n- Revert codel: remove sch-q.qlen check before qdisc_tree_reduce_backlog()\n- Revert sch_htb: make htb_deactivate() idempotent\n- Revert net/sched: Always pass notifications when child class becomes empty\n- wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds - CVE-2025-38159\n- Documentation: Fix pci=config_acs= example\n- PCI/ACS: Fix 'pci=config_acs=' parameter\n- Revert 'smb: client: fix TCP timers deadlock after rmmod' - CVE-2025-22077\n- Revert smb: client: Fix netns refcount imbalance causing leaks and use-after-free \n- smb: client: Fix netns refcount imbalance causing leaks and use-after-free\n- wifi: ath12k: fix invalid access to memory - CVE-2025-38292\n- x86/CPU/AMD: Terminate the erratum_1386_microcode array - CVE-2024-56721\n- crypto: algif_hash - fix double free in hash_accept - CVE-2025-38079\n- net/sched: Always pass notifications when child class becomes empty - CVE-2025-38350\n- sch_htb: make htb_deactivate() idempotent - CVE-2025-38350\n- codel: remove sch-q.qlen check before qdisc_tree_reduce_backlog() - CVE-2025-38350\n- sch_qfq: make qfq_qlen_notify() idempotent - CVE-2025-38350\n- sch_drr: make drr_qlen_notify() idempotent - CVE-2025-38350\n- sch_htb: make htb_qlen_notify() idempotent - CVE-2025-38350\n- mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race - CVE-2025-38085\n- mm/hugetlb: unshare page tables during VMA split, not before - CVE-2025-38084\n- tools/testing/vma: add missing function stub\n- mm: fix copy_vma() error handling for hugetlb mappings\n- PCI: Use downstream bridges for distributing resources\n- PCI/pwrctrl: Cancel outstanding rescan work when unregistering - CVE-2025-38137\n- bnxt_en: Skip MAC loopback selftest if it is unsupported by FW\n- bnxt_en: Skip PHY loopback ethtool selftest if unsupported by FW",
  "id": "ELSA-2025-13598",
  "ovalId": "oval:com.oracle.elsa:def:202513598",
  "source": "oracle_linux",
  "title": "ELSA-2025-13598:  kernel security update (MODERATE)",
  "url": "https://linux.oracle.com/errata/ELSA-2025-13598.html"
}
View JSON API Download JSON