elsa-2026-50304

oracle_linux
Description

[6.12.0-203.76.7.3] - arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39017589] {CVE-2025-10263} - arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland) [Orabug: 39017589] - arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland) [Orabug: 39017589] - arm64: cputype: Add C1-Premium definitions (Mark Rutland) [Orabug: 39017589] - arm64: cputype: Add C1-Ultra definitions (Mark Rutland) [Orabug: 39017589] [6.12.0-203.76.7.2] - kabi: update FIPS kABI files (Saeed Mirzamohammadi) [Orabug: 39489008] - KEYS: Reserve key usage values (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto: keep FIPS MPI helpers private (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto: keep FIPS compression helpers private (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto: keep FIPS helper library symbols private (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto: tcrypt - clamp num_mb to avoid divide-by-zero (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto: tcrypt - stop ahash speed tests when setkey fails (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto: add x86 GHASH CLMUL to FIPS module (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto: add fixed-time AES to FIPS module (Saeed Mirzamohammadi) [Orabug: 39489008] - fips: add scatterwalk to FIPS module (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto: avoid auto-load for arch specific impls (Saeed Mirzamohammadi) [Orabug: 39489008] - arm64/crypto: wire up FIPS aliases and helpers (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto: share alg registry between FIPS and base kernel (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto: keep crypto_user out of the FIPS module (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto: tcrypt - skip retest in FIPS mode (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto: skip redundant FIPS self-module signature check (Saeed Mirzamohammadi) [Orabug: 39489008] - scripts: fail cleanly on arm64 boot image formats (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto/hkdf: Skip tests with keys too short in FIPS mode (Saeed Mirzamohammadi) [Orabug: 39489008] - uek-rpm: build module symvers before fips140.ko (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto: add crc64_rocksoft_generic to the FIPS module (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto: add keywrap to the FIPS module (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto: add cts to the FIPS module (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto: convert kdf_sp800108 to CRYPTO_API() (Saeed Mirzamohammadi) [Orabug: 39489008] - fips: drop ansi_cprng and revert ansi_cprng FIPS hooks (Saeed Mirzamohammadi) [Orabug: 39489008] - crypto/testmgr: mark xxhash64 as fips disallowed (Saeed Mirzamohammadi) [Orabug: 39489008] - Revert 'fips: add xxhash64-generic to FIPS module' (Saeed Mirzamohammadi) [Orabug: 39489008] - asm-generic/vmlinux.lds.h: remove unreachable FIPS140 branch (Saeed Mirzamohammadi) [Orabug: 39489008] - btrfs: switch to library APIs for checksums (Eric Biggers) [Orabug: 39489008] - lib/crypto: blake2b: Add BLAKE2b library functions (Eric Biggers) [Orabug: 39489008] - byteorder: Add le64_to_cpu_array() and cpu_to_le64_array() (Eric Biggers) [Orabug: 39489008]

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2025-10263"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[6.12.0-203.76.7.3]\n- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland)  [Orabug: 39017589]  {CVE-2025-10263}\n- arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland)  [Orabug: 39017589] \n- arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland)  [Orabug: 39017589] \n- arm64: cputype: Add C1-Premium definitions (Mark Rutland)  [Orabug: 39017589] \n- arm64: cputype: Add C1-Ultra definitions (Mark Rutland)  [Orabug: 39017589]\n\n[6.12.0-203.76.7.2]\n- kabi: update FIPS kABI files (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- KEYS: Reserve key usage values (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: keep FIPS MPI helpers private (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: keep FIPS compression helpers private (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: keep FIPS helper library symbols private (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: tcrypt - clamp num_mb to avoid divide-by-zero (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: tcrypt - stop ahash speed tests when setkey fails (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: add x86 GHASH CLMUL to FIPS module (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: add fixed-time AES to FIPS module (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- fips: add scatterwalk to FIPS module (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: avoid auto-load for arch specific impls (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- arm64/crypto: wire up FIPS aliases and helpers (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: share alg registry between FIPS and base kernel (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: keep crypto_user out of the FIPS module (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: tcrypt - skip retest in FIPS mode (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: skip redundant FIPS self-module signature check (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- scripts: fail cleanly on arm64 boot image formats (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto/hkdf: Skip tests with keys too short in FIPS mode (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- uek-rpm: build module symvers before fips140.ko (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: add crc64_rocksoft_generic to the FIPS module (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: add keywrap to the FIPS module (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: add cts to the FIPS module (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto: convert kdf_sp800108 to CRYPTO_API() (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- fips: drop ansi_cprng and revert ansi_cprng FIPS hooks (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- crypto/testmgr: mark xxhash64 as fips disallowed (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- Revert 'fips: add xxhash64-generic to FIPS module' (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- asm-generic/vmlinux.lds.h: remove unreachable FIPS140 branch (Saeed Mirzamohammadi)  [Orabug: 39489008]\n- btrfs: switch to library APIs for checksums (Eric Biggers)  [Orabug: 39489008]\n- lib/crypto: blake2b: Add BLAKE2b library functions (Eric Biggers)  [Orabug: 39489008]\n- byteorder: Add le64_to_cpu_array() and cpu_to_le64_array() (Eric Biggers)  [Orabug: 39489008]",
  "id": "ELSA-2026-50304",
  "ovalId": "oval:com.oracle.elsa:def:202650304",
  "source": "oracle_linux",
  "title": "ELSA-2026-50304: Unbreakable Enterprise kernel security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-50304.html"
}
View JSON API Download JSON