elsa-2026-50374

oracle_linux
Description

[5.4.17-2136.357.3.1] - KVM: x86: Fix shadow paging use-after-free due to unexpected role (Paolo Bonzini) [Orabug: 39673892] - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (Sean Christopherson) [Orabug: 39673892] - KVM: x86/MMU: Recursively zap nested TDP SPs when zapping last/only parent (Ben Gardon) [Orabug: 39673892] - KVM: x86/mmu: Move flush logic from mmu_page_zap_pte() to FNAME(invlpg) (Sean Christopherson) [Orabug: 39673892] - KVM: x86/mmu: pull call to drop_large_spte() into __link_shadow_page() (Paolo Bonzini) [Orabug: 39673892] - KVM: x86/mmu: Passing up the error state of mmu_alloc_shadow_roots() (Like Xu) [Orabug: 39673892] - KVM: MMU: load PDPTRs outside mmu_lock (Paolo Bonzini) [Orabug: 39673892] - KVM: x86/mmu: Check PDPTRs before allocating PAE roots (Sean Christopherson) [Orabug: 39673892] - KVM: x86/mmu: Always pass 0 for @quadrant when gptes are 8 bytes (David Matlack) [Orabug: 39673892] - KVM: x86/mmu: Derive shadow MMU page role from parent (David Matlack) [Orabug: 39673892] - KVM: X86: Remove useless code to set role.gpte_is_8_bytes when role.direct (Lai Jiangshan) [Orabug: 39673892] - KVM: X86: Synchronize the shadow pagetable before link it (Lai Jiangshan) [Orabug: 39673892] - KVM: X86: Fix missed remote tlb flush in rmap_write_protect() (Lai Jiangshan) [Orabug: 39673892] - KVM: x86/mmu: Refactor shadow walk in __direct_map() to reduce indentation (Sean Christopherson) [Orabug: 39673892] - KVM: x86/mmu: Stop passing 'direct' to mmu_alloc_root() (David Matlack) [Orabug: 39673892] - KVM: x86/mmu: Use a bool for direct (David Matlack) [Orabug: 39673892] - kvm: mmu: Replace unsigned with unsigned int for PTE access (Ben Gardon) [Orabug: 39673892] - KVM: x86/mmu: Ensure MMU pages are available when allocating roots (Sean Christopherson) [Orabug: 39673892] - KVM: x86/mmu: Allocate pae_root and lm_root pages in dedicated helper (Sean Christopherson) [Orabug: 39673892] - KVM: x86/mmu: Allocate the lm_root before allocating PAE roots (Sean Christopherson) [Orabug: 39673892] - KVM: x86/mmu: Capture 'mmu' in a local variable when allocating roots (Sean Christopherson) [Orabug: 39673892] - KVM: x86/mmu: Alloc page for PDPTEs when shadowing 32-bit NPT with 64-bit (Sean Christopherson) [Orabug: 39673892] - KVM: x86/mmu: Stash 'kvm' in a local variable in kvm_mmu_free_roots() (Sean Christopherson) [Orabug: 39673892] - KVM: x86/mmu: Add a helper to consolidate root sp allocation (Sean Christopherson) [Orabug: 39673892] - net/sched: act_pedit: fix action bind logic (Pedro Tammela) [Orabug: 39680880] - net/sched: act_pedit: free pedit keys on bail from offset check (Pedro Tammela) [Orabug: 39680880] - net/sched: fix pedit partial COW leading to page cache corruption (Rajat Gupta) [Orabug: 39680880] {CVE-2026-46331} - net/sched: act_pedit: Parse L3 Header for L4 offset (Max Tottenham) [Orabug: 39680880] - net/sched: act_pedit: rate limit datapath messages (Pedro Tammela) [Orabug: 39680880] - net/sched: act_pedit: check static offsets a priori (Pedro Tammela) [Orabug: 39680880] - net/sched: act_pedit: remove extra check for key type (Pedro Tammela) [Orabug: 39680880] - net/sched: simplify tcf_pedit_act (Pedro Tammela) [Orabug: 39680880] - net/sched: transition act_pedit to rcu and percpu stats (Pedro Tammela) [Orabug: 39680880] - net/sched: act_pedit: use NLA_POLICY for parsing 'ex' keys (Pedro Tammela) [Orabug: 39680880] [5.4.17-2136.357.3] - net: skbuff: fix missing zerocopy reference in pskb_carve helpers (Minh Nguyen) [Orabug: 39619389] {CVE-2026-52943} [5.4.17-2136.357.2] - net: fix fanout UAF in packet_release() via NETDEV_UP race (Yochai Eisenrich) [Orabug: 39250953] {CVE-2026-31504} - x86/kaslr: Recognize all ZONE_DEVICE users as physaddr consumers (Dan Williams) [Orabug: 39429802] - x86/kaslr: Reduce KASLR entropy on most x86 systems (Balbir Singh) [Orabug: 39429802] - net: tap: NULL pointer derefence in dev_parse_header_protocol when skb-dev is null (Cezar Bulinaru) [Orabug: 39526882] {CVE-2022-50073} - arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39548666] {CVE-2025-10263} - arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland) [Orabug: 39548666] - ARM: uek: Disable CONFIG_QCOM_FALKOR_ERRATUM_1003 (Boris Ostrovsky) [Orabug: 39548666] - arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland) [Orabug: 39548666] - arm64: cputype: Add C1-Premium definitions (Mark Rutland) [Orabug: 39548666] - arm64: cputype: Add C1-Ultra definitions (Mark Rutland) [Orabug: 39548666] - ip6_tunnel: clear skb2-cb[] in ip4ip6_err() (Eric Dumazet) [Orabug: 39300926] {CVE-2026-43037} [5.4.17-2136.357.1] - batman-adv: hold claim backbone gateways by reference (Haoze Xie) [Orabug: 39262375] {CVE-2026-31657} - scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (Michael Bommarito) [Orabug: 39446045] - scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (Michael Bommarito) [Orabug: 39446045] - scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (Michael Bommarito) [Orabug: 39446045] - rds: Drop rds conn in connect worker if not in down state. (Rohit Nair) [Orabug: 39152239] [5.4.17-2136.356.4.1] - smb: client: reject userspace cifs.spnego descriptions (Asim Viladi Oglu Manizada) [Orabug: 39463669] {CVE-2026-46243} [5.4.17-2136.356.4] - tun: free page on build_skb failure in tun_xdp_one() (Weiming Shi) [Orabug: 39429147] - tap: free page on error paths in tap_get_user_xdp() (Weiming Shi) [Orabug: 39429147] - tun: free page on short-frame rejection in tun_xdp_one() (Weiming Shi) [Orabug: 39429147] [5.4.17-2136.356.3] - ptrace: slightly saner 'get_dumpable()' logic (Linus Torvalds) [Orabug: 39384275,39391459] {CVE-2026-46333} - net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim) [Orabug: 39368828,39441326] {CVE-2026-43503,CVE-2026-46300} - net: skbuff: preserve shared-frag marker during coalescing (William Bowling) [Orabug: 39368828] {CVE-2026-46300} [5.4.17-2136.356.2] - nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (Jeff Layton) [Orabug: 39167617,39368718] {CVE-2026-31402} - scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() (Maurizio Lombardi) [Orabug: 38985173,39368732] {CVE-2026-23216} - scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() (Maurizio Lombardi) [Orabug: 38970455,39368774] {CVE-2026-23193} - xfrm: esp: avoid in-place decrypt on shared skb frags (Kuan-Ting Chen) [Orabug: 39334580,39367147] {CVE-2026-43284} - x86/CPU/AMD: Add a fix for AMD-SB-7052 (Prathyushi Nangia) [Orabug: 39218897] {CVE-2025-54518} [5.4.17-2136.356.1] - arm64/kvm: Include linux/random.h in trng.c (Siddh Raman Pant) [Orabug: 39327096] - i2c: designware: Disable TX_EMPTY irq while waiting for block length byte (Tam Nguyen) [Orabug: 39174662] - i2c: designware: Handle invalid SMBus block data response length value (Tam Nguyen) [Orabug: 39174662] - i2c: designware: fix __i2c_dw_disable() in case master is holding SCL low (Yann Sionneau) [Orabug: 39174662] [5.4.17-2136.355.3] - crypto: algif_aead - Fix minimum RX size check for decryption (Herbert Xu) [Orabug: 39250687,39331106] {CVE-2026-43077} - crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl (Herbert Xu) [Orabug: 39250687,39331111] {CVE-2026-43078} - crypto: authencesn - Fix src offset when decrypting in-place (Herbert Xu) [Orabug: 39250687] - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (Herbert Xu) [Orabug: 39250687,39300911] {CVE-2026-43033} - crypto: authenc - use memcpy_sglist() instead of null skcipher (Eric Biggers) [Orabug: 39250687] - crypto: algif_aead - snapshot IV for async AEAD requests (Douya Le) [Orabug: 39250687,39452217] {CVE-2026-46028} - crypto: algif_aead - Revert to operating out-of-place (Herbert Xu) [Orabug: 39250687,39283868,39292250] {CVE-2026-31431} - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (Eric Biggers) [Orabug: 39250687] {CVE-2026-31431} - crypto: scatterwalk - Backport memcpy_sglist() (Eric Biggers) [Orabug: 39250687] - crypto: doc - fix kernel-doc notation in chacha.c and af_alg.c (Randy Dunlap) [Orabug: 39250687]

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2022-50073",
    "CVE-2025-10263",
    "CVE-2026-31504",
    "CVE-2026-31657",
    "CVE-2026-43037",
    "CVE-2026-46331",
    "CVE-2026-52943",
    "CVE-2026-53359"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[5.4.17-2136.357.3.1]\n- KVM: x86: Fix shadow paging use-after-free due to unexpected role (Paolo Bonzini)  [Orabug: 39673892] \n- KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (Sean Christopherson)  [Orabug: 39673892] \n- KVM: x86/MMU: Recursively zap nested TDP SPs when zapping last/only parent (Ben Gardon)  [Orabug: 39673892] \n- KVM: x86/mmu: Move flush logic from mmu_page_zap_pte() to FNAME(invlpg) (Sean Christopherson)  [Orabug: 39673892] \n- KVM: x86/mmu: pull call to drop_large_spte() into __link_shadow_page() (Paolo Bonzini)  [Orabug: 39673892] \n- KVM: x86/mmu: Passing up the error state of mmu_alloc_shadow_roots() (Like Xu)  [Orabug: 39673892] \n- KVM: MMU: load PDPTRs outside mmu_lock (Paolo Bonzini)  [Orabug: 39673892] \n- KVM: x86/mmu: Check PDPTRs before allocating PAE roots (Sean Christopherson)  [Orabug: 39673892] \n- KVM: x86/mmu: Always pass 0 for @quadrant when gptes are 8 bytes (David Matlack)  [Orabug: 39673892] \n- KVM: x86/mmu: Derive shadow MMU page role from parent (David Matlack)  [Orabug: 39673892] \n- KVM: X86: Remove useless code to set role.gpte_is_8_bytes when role.direct (Lai Jiangshan)  [Orabug: 39673892] \n- KVM: X86: Synchronize the shadow pagetable before link it (Lai Jiangshan)  [Orabug: 39673892] \n- KVM: X86: Fix missed remote tlb flush in rmap_write_protect() (Lai Jiangshan)  [Orabug: 39673892] \n- KVM: x86/mmu: Refactor shadow walk in __direct_map() to reduce indentation (Sean Christopherson)  [Orabug: 39673892] \n- KVM: x86/mmu: Stop passing 'direct' to mmu_alloc_root() (David Matlack)  [Orabug: 39673892] \n- KVM: x86/mmu: Use a bool for direct (David Matlack)  [Orabug: 39673892] \n- kvm: mmu: Replace unsigned with unsigned int for PTE access (Ben Gardon)  [Orabug: 39673892] \n- KVM: x86/mmu: Ensure MMU pages are available when allocating roots (Sean Christopherson)  [Orabug: 39673892] \n- KVM: x86/mmu: Allocate pae_root and lm_root pages in dedicated helper (Sean Christopherson)  [Orabug: 39673892] \n- KVM: x86/mmu: Allocate the lm_root before allocating PAE roots (Sean Christopherson)  [Orabug: 39673892] \n- KVM: x86/mmu: Capture 'mmu' in a local variable when allocating roots (Sean Christopherson)  [Orabug: 39673892] \n- KVM: x86/mmu: Alloc page for PDPTEs when shadowing 32-bit NPT with 64-bit (Sean Christopherson)  [Orabug: 39673892] \n- KVM: x86/mmu: Stash 'kvm' in a local variable in kvm_mmu_free_roots() (Sean Christopherson)  [Orabug: 39673892] \n- KVM: x86/mmu: Add a helper to consolidate root sp allocation (Sean Christopherson)  [Orabug: 39673892] \n- net/sched: act_pedit: fix action bind logic (Pedro Tammela)  [Orabug: 39680880] \n- net/sched: act_pedit: free pedit keys on bail from offset check (Pedro Tammela)  [Orabug: 39680880] \n- net/sched: fix pedit partial COW leading to page cache corruption (Rajat Gupta)  [Orabug: 39680880]  {CVE-2026-46331}\n- net/sched: act_pedit: Parse L3 Header for L4 offset (Max Tottenham)  [Orabug: 39680880] \n- net/sched: act_pedit: rate limit datapath messages (Pedro Tammela)  [Orabug: 39680880] \n- net/sched: act_pedit: check static offsets a priori (Pedro Tammela)  [Orabug: 39680880] \n- net/sched: act_pedit: remove extra check for key type (Pedro Tammela)  [Orabug: 39680880] \n- net/sched: simplify tcf_pedit_act (Pedro Tammela)  [Orabug: 39680880] \n- net/sched: transition act_pedit to rcu and percpu stats (Pedro Tammela)  [Orabug: 39680880] \n- net/sched: act_pedit: use NLA_POLICY for parsing 'ex' keys (Pedro Tammela)  [Orabug: 39680880]\n\n[5.4.17-2136.357.3]\n- net: skbuff: fix missing zerocopy reference in pskb_carve helpers (Minh Nguyen)  [Orabug: 39619389]  {CVE-2026-52943}\n\n[5.4.17-2136.357.2]\n- net: fix fanout UAF in packet_release() via NETDEV_UP race (Yochai Eisenrich)  [Orabug: 39250953]  {CVE-2026-31504}\n- x86/kaslr: Recognize all ZONE_DEVICE users as physaddr consumers (Dan Williams)  [Orabug: 39429802]\n- x86/kaslr: Reduce KASLR entropy on most x86 systems (Balbir Singh)  [Orabug: 39429802]\n- net: tap: NULL pointer derefence in dev_parse_header_protocol when skb-dev is null (Cezar Bulinaru)  [Orabug: 39526882]  {CVE-2022-50073}\n- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland)  [Orabug: 39548666]  {CVE-2025-10263}\n- arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland)  [Orabug: 39548666]\n- ARM: uek: Disable CONFIG_QCOM_FALKOR_ERRATUM_1003 (Boris Ostrovsky)  [Orabug: 39548666]\n- arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland)  [Orabug: 39548666]\n- arm64: cputype: Add C1-Premium definitions (Mark Rutland)  [Orabug: 39548666]\n- arm64: cputype: Add C1-Ultra definitions (Mark Rutland)  [Orabug: 39548666]\n- ip6_tunnel: clear skb2-cb[] in ip4ip6_err() (Eric Dumazet)  [Orabug: 39300926]  {CVE-2026-43037}\n\n[5.4.17-2136.357.1]\n- batman-adv: hold claim backbone gateways by reference (Haoze Xie)  [Orabug: 39262375]  {CVE-2026-31657}\n- scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (Michael Bommarito)  [Orabug: 39446045]\n- scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (Michael Bommarito)  [Orabug: 39446045]\n- scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (Michael Bommarito)  [Orabug: 39446045]\n- rds: Drop rds conn in connect worker if not in down state. (Rohit Nair)  [Orabug: 39152239]\n\n[5.4.17-2136.356.4.1]\n- smb: client: reject userspace cifs.spnego descriptions (Asim Viladi Oglu Manizada)  [Orabug: 39463669] {CVE-2026-46243}\n\n[5.4.17-2136.356.4]\n- tun: free page on build_skb failure in tun_xdp_one() (Weiming Shi) [Orabug: 39429147]\n- tap: free page on error paths in tap_get_user_xdp() (Weiming Shi) [Orabug: 39429147]\n- tun: free page on short-frame rejection in tun_xdp_one() (Weiming Shi) [Orabug: 39429147]\n\n[5.4.17-2136.356.3]\n- ptrace: slightly saner 'get_dumpable()' logic (Linus Torvalds) [Orabug: 39384275,39391459] {CVE-2026-46333}\n- net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim) [Orabug: 39368828,39441326] {CVE-2026-43503,CVE-2026-46300}\n- net: skbuff: preserve shared-frag marker during coalescing (William Bowling) [Orabug: 39368828] {CVE-2026-46300}\n\n[5.4.17-2136.356.2]\n- nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (Jeff Layton) [Orabug: 39167617,39368718] {CVE-2026-31402}\n- scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() (Maurizio Lombardi) [Orabug: 38985173,39368732] {CVE-2026-23216}\n- scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() (Maurizio Lombardi) [Orabug: 38970455,39368774] {CVE-2026-23193}\n- xfrm: esp: avoid in-place decrypt on shared skb frags (Kuan-Ting Chen) [Orabug: 39334580,39367147] {CVE-2026-43284}\n- x86/CPU/AMD: Add a fix for AMD-SB-7052 (Prathyushi Nangia) [Orabug: 39218897] {CVE-2025-54518}\n\n[5.4.17-2136.356.1]\n- arm64/kvm: Include linux/random.h in trng.c (Siddh Raman Pant) [Orabug: 39327096]\n- i2c: designware: Disable TX_EMPTY irq while waiting for block length byte (Tam Nguyen) [Orabug: 39174662]\n- i2c: designware: Handle invalid SMBus block data response length value (Tam Nguyen) [Orabug: 39174662]\n- i2c: designware: fix __i2c_dw_disable() in case master is holding SCL low (Yann Sionneau) [Orabug: 39174662]\n\n[5.4.17-2136.355.3]\n- crypto: algif_aead - Fix minimum RX size check for decryption (Herbert Xu) [Orabug: 39250687,39331106] {CVE-2026-43077}\n- crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl (Herbert Xu) [Orabug: 39250687,39331111] {CVE-2026-43078}\n- crypto: authencesn - Fix src offset when decrypting in-place (Herbert Xu) [Orabug: 39250687]\n- crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (Herbert Xu) [Orabug: 39250687,39300911] {CVE-2026-43033}\n- crypto: authenc - use memcpy_sglist() instead of null skcipher (Eric Biggers) [Orabug: 39250687]\n- crypto: algif_aead - snapshot IV for async AEAD requests (Douya Le) [Orabug: 39250687,39452217] {CVE-2026-46028}\n- crypto: algif_aead - Revert to operating out-of-place (Herbert Xu) [Orabug: 39250687,39283868,39292250] {CVE-2026-31431}\n- crypto: algif_aead - use memcpy_sglist() instead of null skcipher (Eric Biggers) [Orabug: 39250687] {CVE-2026-31431}\n- crypto: scatterwalk - Backport memcpy_sglist() (Eric Biggers) [Orabug: 39250687]\n- crypto: doc - fix kernel-doc notation in chacha.c and af_alg.c (Randy Dunlap) [Orabug: 39250687]",
  "id": "ELSA-2026-50374",
  "ovalId": "oval:com.oracle.elsa:def:202650374",
  "source": "oracle_linux",
  "title": "ELSA-2026-50374: Unbreakable Enterprise kernel security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-50374.html"
}
View JSON API Download JSON