elsa-2026-59821

oracle_linux
Description

[4.18.0-553.158.1] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64 = 15.3-1.0.3 - Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652] - Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985772] [4.18.0-553.158.1] - nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (Maurizio Lombardi) [RHEL-219613] {CVE-2026-64320} - selinux: check connect-related permissions on TCP Fast Open (Ondrej Mosnacek) [RHEL-222800] - i2c: stub: Reject I2C block transfers with invalid length (CKI Backport Bot) [RHEL-232120] {CVE-2026-64191} - scsi: target: Fix hexadecimal CHAP_I handling (CKI Backport Bot) [RHEL-231660] {CVE-2026-63886} - scsi: target: iscsi: Validate CHAP_R length before base64 decode (CKI Backport Bot) [RHEL-231660] {CVE-2026-63886} - Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (CKI Backport Bot) [RHEL-231447] {CVE-2026-64277} - Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (CKI Backport Bot) [RHEL-230251] {CVE-2026-64276} - netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check (CKI Backport Bot) [RHEL-229797] {CVE-2026-63913} - netfilter: ipset: fix race between dump and ip_set_list resize (CKI Backport Bot) [RHEL-227676] {CVE-2026-64189} - sctp: hold socket lock when dumping endpoints in sctp_diag (Jamie Bainbridge) [RHEL-212400] - sctp: Hold sock lock while iterating over address list (Jamie Bainbridge) [RHEL-212400] - sctp: Prevent TOCTOU out-of-bounds write (Jamie Bainbridge) [RHEL-212400] - sctp: Hold RCU read lock while iterating over address list (Jamie Bainbridge) [RHEL-212400] - usb: hub: Make usb_hub_wq type depend on isolcpus/nohz_full setting (Waiman Long) [RHEL-178088] - sctp: purge outqueue on stale COOKIE-ECHO handling (CKI Backport Bot) [RHEL-188193] {CVE-2026-52924}

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2026-52924",
    "CVE-2026-63886",
    "CVE-2026-63913",
    "CVE-2026-64189",
    "CVE-2026-64191",
    "CVE-2026-64276",
    "CVE-2026-64277",
    "CVE-2026-64320"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[4.18.0-553.158.1]\n- Update Oracle Linux certificates (Kevin Lyons)\n- Disable signing for aarch64 (Ilya Okomin)\n- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]\n- Update x509.genkey [Orabug: 24817676]\n- Conflict with shim-ia32 and shim-x64 = 15.3-1.0.3\n- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]\n- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985772]\n\n[4.18.0-553.158.1]\n- nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (Maurizio Lombardi) [RHEL-219613] {CVE-2026-64320}\n- selinux: check connect-related permissions on TCP Fast Open (Ondrej Mosnacek) [RHEL-222800]\n- i2c: stub: Reject I2C block transfers with invalid length (CKI Backport Bot) [RHEL-232120] {CVE-2026-64191}\n- scsi: target: Fix hexadecimal CHAP_I handling (CKI Backport Bot) [RHEL-231660] {CVE-2026-63886}\n- scsi: target: iscsi: Validate CHAP_R length before base64 decode (CKI Backport Bot) [RHEL-231660] {CVE-2026-63886}\n- Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (CKI Backport Bot) [RHEL-231447] {CVE-2026-64277}\n- Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (CKI Backport Bot) [RHEL-230251] {CVE-2026-64276}\n- netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check (CKI Backport Bot) [RHEL-229797] {CVE-2026-63913}\n- netfilter: ipset: fix race between dump and ip_set_list resize (CKI Backport Bot) [RHEL-227676] {CVE-2026-64189}\n- sctp: hold socket lock when dumping endpoints in sctp_diag (Jamie Bainbridge) [RHEL-212400]\n- sctp: Hold sock lock while iterating over address list (Jamie Bainbridge) [RHEL-212400]\n- sctp: Prevent TOCTOU out-of-bounds write (Jamie Bainbridge) [RHEL-212400]\n- sctp: Hold RCU read lock while iterating over address list (Jamie Bainbridge) [RHEL-212400]\n- usb: hub: Make usb_hub_wq type depend on isolcpus/nohz_full setting (Waiman Long) [RHEL-178088]\n- sctp: purge outqueue on stale COOKIE-ECHO handling (CKI Backport Bot) [RHEL-188193] {CVE-2026-52924}",
  "id": "ELSA-2026-59821",
  "ovalId": "oval:com.oracle.elsa:def:202659821",
  "source": "oracle_linux",
  "title": "ELSA-2026-59821:  kernel security, bug fix, and enhancement update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-59821.html"
}
View JSON API Download JSON