ELBA-2025-13589-1

ELBA-2025-13589-1 - kernel bug fix update

Type:BUG
Impact:NA
Release Date:2025-08-12

Description


[4.18.0-553.69.1.0.1.el8_10.OL8]
- scsi: core: Restrict legal sdev_state transitions via sysfs (Uday Shankar) [Orabug: 37778230]

[4.18.0-553.69.1.el8_10.OL8]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.3
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985772]

[4.18.0-553.69.1.el8_10]
- Revert 'sch_htb: make htb_qlen_notify() idempotent' (Denys Vlasenko) [RHEL-108140]
- Revert 'sch_drr: make drr_qlen_notify() idempotent' (Denys Vlasenko) [RHEL-108140]
- Revert 'sch_qfq: make qfq_qlen_notify() idempotent' (Denys Vlasenko) [RHEL-108140]
- Revert 'codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog()' (Denys Vlasenko) [RHEL-108140]
- Revert 'sch_htb: make htb_deactivate() idempotent' (Denys Vlasenko) [RHEL-108140]
- Revert 'net/sched: Always pass notifications when child class becomes empty' (Denys Vlasenko) [RHEL-108140]
- Revert 'sch_cbq: make cbq_qlen_notify() idempotent' (Denys Vlasenko) [RHEL-108140]

[4.18.0-553.68.1.el8_10]
- ipv6: mcast: extend RCU protection in igmp6_send() (Hangbin Liu) [RHEL-102392] {CVE-2025-21759}
- md/md-bitmap: move bitmap_{start, end}write to md upper layer (Nigel Croxon) [RHEL-57991]
- md/raid5: implement pers->bitmap_sector() (Nigel Croxon) [RHEL-57991]
- md: add a new callback pers->bitmap_sector() (Nigel Croxon) [RHEL-57991]
- md/md-bitmap: remove the last parameter for bimtap_ops->endwrite() (Nigel Croxon) [RHEL-57991]
- md/md-bitmap: factor behind write counters out from bitmap_{start/end}write() (Nigel Croxon) [RHEL-57991]
- md/raid5: recheck if reshape has finished with device_lock held (Nigel Croxon) [RHEL-57991]
- md/md-linear: enable io accounting (Nigel Croxon) [RHEL-59928]
- md/md-multipath: enable io accounting (Nigel Croxon) [RHEL-59928]
- md/raid10: switch to use md_account_bio() for io accounting (Nigel Croxon) [RHEL-59928]
- md/raid1: switch to use md_account_bio() for io accounting (Nigel Croxon) [RHEL-59928]
- raid5: fix missing io accounting in raid5_align_endio() (Nigel Croxon) [RHEL-59928]
- md: also clone new io if io accounting is disabled (Nigel Croxon) [RHEL-59928]
- sch_cbq: make cbq_qlen_notify() idempotent (Ivan Vecera) [RHEL-93376]
- net/sched: Always pass notifications when child class becomes empty (CKI Backport Bot) [RHEL-93376] {CVE-2025-38350}
- sch_htb: make htb_deactivate() idempotent (CKI Backport Bot) [RHEL-93376] {CVE-2025-38350}
- codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog() (CKI Backport Bot) [RHEL-93376] {CVE-2025-38350}
- sch_qfq: make qfq_qlen_notify() idempotent (CKI Backport Bot) [RHEL-93376] {CVE-2025-38350}
- sch_drr: make drr_qlen_notify() idempotent (CKI Backport Bot) [RHEL-93376] {CVE-2025-38350}
- sch_htb: make htb_qlen_notify() idempotent (CKI Backport Bot) [RHEL-93376] {CVE-2025-38350}
- can: peak_usb: fix use after free bugs (CKI Backport Bot) [RHEL-99447] {CVE-2021-47670}
- wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds (CKI Backport Bot) [RHEL-103141] {CVE-2025-38159}
- net/ipv6: release expired exception dst cached in socket (Guillaume Nault) [RHEL-105794] {CVE-2024-56644}

[4.18.0-553.67.1.el8_10]
- mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race (Rafael Aquini) [RHEL-101233] {CVE-2025-38085}
- mm/khugepaged: fix collapse_pte_mapped_thp() to allow anon_vma (Rafael Aquini) [RHEL-101233] {CVE-2025-38085}
- mm/khugepaged: fix GUP-fast interaction by sending IPI (Rafael Aquini) [RHEL-101233] {CVE-2025-38085}
- mm/khugepaged: take the right locks for page table retraction (Rafael Aquini) [RHEL-101233] {CVE-2025-38085}
- mm/khugepaged: unify collapse pmd clear, flush and free (Rafael Aquini) [RHEL-101233] {CVE-2025-38085}
- padata: fix UAF in padata_reorder (Waiman Long) [RHEL-101398] {CVE-2025-21727}
- redhat: update BUILD_TARGET to rhel-8.10.0-z-test-pesign (Jan Stancek)
- ftrace: Clean up hash direct_functions on register failures (Gregory Bell) [RHEL-103912]




Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (x86_64) kernel-4.18.0-553.69.1.0.1.el8_10.src.rpmc29e5f5c5a6af385254542c91f7db24f02265b97b4008ecc81b2ab652e54f5ce-ol8_x86_64_MODRHCK
bpftool-4.18.0-553.69.1.0.1.el8_10.x86_64.rpm3637f895352d17601d795b53667c80d3e2e13ac655d7d2b03048bf314cb4cd4e-ol8_x86_64_MODRHCK
kernel-4.18.0-553.69.1.0.1.el8_10.x86_64.rpm648d5bd3653f8181172ffb7f8a70dac7a5477ebba6dd40159e5b5809f22f3002-ol8_x86_64_MODRHCK
kernel-abi-stablelists-4.18.0-553.69.1.0.1.el8_10.noarch.rpmf71a5b91b83d1f6db2235caba85a5baf6ca61eaadd18cafa1935a1e6881d5298-ol8_x86_64_MODRHCK
kernel-core-4.18.0-553.69.1.0.1.el8_10.x86_64.rpm88bb56a72dbfa87b73f6b876e68d1ced0d9cc3edc9352696af2c6931309735cb-ol8_x86_64_MODRHCK
kernel-cross-headers-4.18.0-553.69.1.0.1.el8_10.x86_64.rpm2d2dce5ee01c2edcd47528c64a918970fbcfe5c09104f3205a39c56f62dd7d5d-ol8_x86_64_MODRHCK
kernel-debug-4.18.0-553.69.1.0.1.el8_10.x86_64.rpm28c42e93fe38a39d416f48c4f378e7cbeca59f6785860e46f5061ec75949be80-ol8_x86_64_MODRHCK
kernel-debug-core-4.18.0-553.69.1.0.1.el8_10.x86_64.rpmb783b1c0059eceac22698e9253583e0e8b48157735b4c71012bc0889a399cb0f-ol8_x86_64_MODRHCK
kernel-debug-devel-4.18.0-553.69.1.0.1.el8_10.x86_64.rpm9be2be1547458523c17973300401ea1801f5f0ff201f6c530006909ca57ce803-ol8_x86_64_MODRHCK
kernel-debug-modules-4.18.0-553.69.1.0.1.el8_10.x86_64.rpm4c84d6219230bc0fb7cacbe20c095fab5a1c23552f62ce55821b0e571c0a6066-ol8_x86_64_MODRHCK
kernel-debug-modules-extra-4.18.0-553.69.1.0.1.el8_10.x86_64.rpm14b0df6095cb65ce60883cd14a7515582d8d4485d981f7422175327d58067528-ol8_x86_64_MODRHCK
kernel-devel-4.18.0-553.69.1.0.1.el8_10.x86_64.rpm42bb0ed19a80fabdc1d7f9769f1ef39bcca7544cda0fbd2c48f2d0b021e8c3b1-ol8_x86_64_MODRHCK
kernel-doc-4.18.0-553.69.1.0.1.el8_10.noarch.rpm182468d0f50f5685b9369dd20aef0400c450e31250a1af446408474f66fcde08-ol8_x86_64_MODRHCK
kernel-headers-4.18.0-553.69.1.0.1.el8_10.x86_64.rpmd1d7a2c4384e5376551e781744c19a2588f66a0242c25e724f4dbc48b5dbe4a2-ol8_x86_64_MODRHCK
kernel-modules-4.18.0-553.69.1.0.1.el8_10.x86_64.rpm5f0ca966d7cbd244f8499f493dc5ccaea3b94d1f3572aa13b613f458da692023-ol8_x86_64_MODRHCK
kernel-modules-extra-4.18.0-553.69.1.0.1.el8_10.x86_64.rpme34fce40cc86b44d674e562d5a399be23a3e9ed13dd78b5dbbefc5c8486e4f57-ol8_x86_64_MODRHCK
kernel-tools-4.18.0-553.69.1.0.1.el8_10.x86_64.rpm08ba6a5915583da393cba457e3a4bae92d9b796c648dfae60cfd9004532a05fe-ol8_x86_64_MODRHCK
kernel-tools-libs-4.18.0-553.69.1.0.1.el8_10.x86_64.rpma445052a7225a8cfbbd16b5d10ce6b61830e85aec842907a9856792b34bef4f2-ol8_x86_64_MODRHCK
kernel-tools-libs-devel-4.18.0-553.69.1.0.1.el8_10.x86_64.rpm2584a3f10285584d09f2508bc663e6ce1157d0bd894be23430792f4d282c1af9-ol8_x86_64_MODRHCK
perf-4.18.0-553.69.1.0.1.el8_10.x86_64.rpmd27ee128b1ccfdbc291e6923ee77ea6c2a9e5b1de801a5bf361f75e233661a1b-ol8_x86_64_MODRHCK
python3-perf-4.18.0-553.69.1.0.1.el8_10.x86_64.rpmd6c050f3c3937eeed6b3605f2029be19d472bddfd1c725bc1643346461e48bf7-ol8_x86_64_MODRHCK



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete