ELSA-2025-12752

ELSA-2025-12752 - kernel security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2025-08-05

Description


[4.18.0-553.66.1_10.OL8]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.3
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985772]

[4.18.0-553.66.1_10]
- net_sched: hfsc: Address reentrant enqueue adding class to eltree twice (Xin Long) [RHEL-105415] {CVE-2025-38001}
- sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() (Xin Long) [RHEL-105415] {CVE-2025-38000}
- net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc (CKI Backport Bot) [RHEL-105415] {CVE-2025-37890}
- sch_hfsc: make hfsc_qlen_notify() idempotent (Xin Long) [RHEL-105415]
- crypto: algif_hash - fix double free in hash_accept (CKI Backport Bot) [RHEL-102223] {CVE-2025-38079}
- Revert 'smb: client: fix TCP timers deadlock after rmmod' (Paulo Alcantara) [RHEL-100698] {CVE-2025-22077}
- Revert 'smb: client: Fix netns refcount imbalance causing leaks and use-after-free' (Paulo Alcantara) [RHEL-100698]
- smb: client: Fix netns refcount imbalance causing leaks and use-after-free (Paulo Alcantara) [RHEL-100698]
- smb: client: fix TCP timers deadlock after rmmod (Paulo Alcantara) [RHEL-100698] {CVE-2024-54680}
- smb: client: Fix use-after-free of network namespace. (Paulo Alcantara) [RHEL-100698] {CVE-2024-53095}
- smb: client: fix warning in generic_ip_connect() (Paulo Alcantara) [RHEL-100698]
- net: tipc: fix refcount warning in tipc_aead_encrypt (Xin Long) [RHEL-103079]
- net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done (CKI Backport Bot) [RHEL-103079] {CVE-2025-38052}
- memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove (CKI Backport Bot) [RHEL-99013] {CVE-2025-22020}
- HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() (CKI Backport Bot) [RHEL-98837] {CVE-2025-21928}

[4.18.0-553.65.1_10]
- x86/alternatives: avoid mapping FIX_TEXT_POKE1 page when it is not required (Rafael Aquini) [RHEL-95422]
- ext4: avoid resizing to a partial cluster size (CKI Backport Bot) [RHEL-101423] {CVE-2022-50020}


Related CVEs


CVE-2025-38052
CVE-2025-21928
CVE-2025-22020
CVE-2025-37890
CVE-2022-50020
CVE-2025-38079

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) kernel-4.18.0-553.66.1.el8_10.src.rpm97254c7a3aa17c24af7c917b43a51473afd5635e3949408f010162173feaf453-ol8_aarch64_baseos_latest
kernel-4.18.0-553.66.1.el8_10.src.rpm97254c7a3aa17c24af7c917b43a51473afd5635e3949408f010162173feaf453-ol8_aarch64_codeready_builder
kernel-4.18.0-553.66.1.el8_10.src.rpm97254c7a3aa17c24af7c917b43a51473afd5635e3949408f010162173feaf453-ol8_aarch64_u10_baseos_patch
Oracle Linux 8 (x86_64) kernel-4.18.0-553.66.1.el8_10.src.rpm97254c7a3aa17c24af7c917b43a51473afd5635e3949408f010162173feaf453-ol8_x86_64_baseos_latest
kernel-4.18.0-553.66.1.el8_10.src.rpm97254c7a3aa17c24af7c917b43a51473afd5635e3949408f010162173feaf453-ol8_x86_64_codeready_builder
kernel-4.18.0-553.66.1.el8_10.src.rpm97254c7a3aa17c24af7c917b43a51473afd5635e3949408f010162173feaf453-ol8_x86_64_u10_baseos_patch
bpftool-4.18.0-553.66.1.el8_10.x86_64.rpmbbdbdad08f0bda27a329ea31eaa1dcb9552dac9c8ec8fc4c1b7f66f4e732f2f3-ol8_x86_64_baseos_latest
bpftool-4.18.0-553.66.1.el8_10.x86_64.rpmbbdbdad08f0bda27a329ea31eaa1dcb9552dac9c8ec8fc4c1b7f66f4e732f2f3-ol8_x86_64_u10_baseos_patch
kernel-4.18.0-553.66.1.el8_10.x86_64.rpma5f6ea80ece4e9a4b8d9ab5dfdf7600bd7112be3dbfedeb422f30c4230067303-ol8_x86_64_baseos_latest
kernel-4.18.0-553.66.1.el8_10.x86_64.rpma5f6ea80ece4e9a4b8d9ab5dfdf7600bd7112be3dbfedeb422f30c4230067303-ol8_x86_64_u10_baseos_patch
kernel-abi-stablelists-4.18.0-553.66.1.el8_10.noarch.rpmea12807f70296af97c293865f44a23a6c30c5ae9ba6096e3b5ca86d4dd39433b-ol8_x86_64_baseos_latest
kernel-abi-stablelists-4.18.0-553.66.1.el8_10.noarch.rpmea12807f70296af97c293865f44a23a6c30c5ae9ba6096e3b5ca86d4dd39433b-ol8_x86_64_u10_baseos_patch
kernel-core-4.18.0-553.66.1.el8_10.x86_64.rpm310e6befba5ce68c3c7459df21501ec54ec84816d78c49c5355e87f0d27fbc2a-ol8_x86_64_baseos_latest
kernel-core-4.18.0-553.66.1.el8_10.x86_64.rpm310e6befba5ce68c3c7459df21501ec54ec84816d78c49c5355e87f0d27fbc2a-ol8_x86_64_u10_baseos_patch
kernel-cross-headers-4.18.0-553.66.1.el8_10.x86_64.rpm36b070cfacd84fda7a9ff749be61a1ebe56c44e87fe6a370d396df577454453d-ol8_x86_64_baseos_latest
kernel-cross-headers-4.18.0-553.66.1.el8_10.x86_64.rpm36b070cfacd84fda7a9ff749be61a1ebe56c44e87fe6a370d396df577454453d-ol8_x86_64_u10_baseos_patch
kernel-debug-4.18.0-553.66.1.el8_10.x86_64.rpm6412499456fa7de42e5804efe6c9d17462164495d90bdf7bbab9567abc361de7-ol8_x86_64_baseos_latest
kernel-debug-4.18.0-553.66.1.el8_10.x86_64.rpm6412499456fa7de42e5804efe6c9d17462164495d90bdf7bbab9567abc361de7-ol8_x86_64_u10_baseos_patch
kernel-debug-core-4.18.0-553.66.1.el8_10.x86_64.rpme050f8e3946f86758f0613b286ea2757246662262271e2d53f7f5b125db658da-ol8_x86_64_baseos_latest
kernel-debug-core-4.18.0-553.66.1.el8_10.x86_64.rpme050f8e3946f86758f0613b286ea2757246662262271e2d53f7f5b125db658da-ol8_x86_64_u10_baseos_patch
kernel-debug-devel-4.18.0-553.66.1.el8_10.x86_64.rpme2e3c67c77a140ca5ce1871641cb9c0f7452116016645a577f1b9cf77840a0e4-ol8_x86_64_baseos_latest
kernel-debug-devel-4.18.0-553.66.1.el8_10.x86_64.rpme2e3c67c77a140ca5ce1871641cb9c0f7452116016645a577f1b9cf77840a0e4-ol8_x86_64_u10_baseos_patch
kernel-debug-modules-4.18.0-553.66.1.el8_10.x86_64.rpmd60546b72ac91aa1930977360a5ec05f2934e7c3cce593e2bc558872a8c12df2-ol8_x86_64_baseos_latest
kernel-debug-modules-4.18.0-553.66.1.el8_10.x86_64.rpmd60546b72ac91aa1930977360a5ec05f2934e7c3cce593e2bc558872a8c12df2-ol8_x86_64_u10_baseos_patch
kernel-debug-modules-extra-4.18.0-553.66.1.el8_10.x86_64.rpm050e9781cbcb72c83c83ef392466cd0ac24a0e4d8fe52d1663f1fcc5562d914a-ol8_x86_64_baseos_latest
kernel-debug-modules-extra-4.18.0-553.66.1.el8_10.x86_64.rpm050e9781cbcb72c83c83ef392466cd0ac24a0e4d8fe52d1663f1fcc5562d914a-ol8_x86_64_u10_baseos_patch
kernel-devel-4.18.0-553.66.1.el8_10.x86_64.rpm0cd97a8e453048319dc04c0ac7f4bada9dcc9998ae10df28a47a6c8283ccea3d-ol8_x86_64_baseos_latest
kernel-devel-4.18.0-553.66.1.el8_10.x86_64.rpm0cd97a8e453048319dc04c0ac7f4bada9dcc9998ae10df28a47a6c8283ccea3d-ol8_x86_64_u10_baseos_patch
kernel-doc-4.18.0-553.66.1.el8_10.noarch.rpm8297d506666f75fc23118457f1659da94f3bce95d28858385ebe1a44075ff57b-ol8_x86_64_baseos_latest
kernel-doc-4.18.0-553.66.1.el8_10.noarch.rpm8297d506666f75fc23118457f1659da94f3bce95d28858385ebe1a44075ff57b-ol8_x86_64_u10_baseos_patch
kernel-headers-4.18.0-553.66.1.el8_10.x86_64.rpm5e793f759b6e7a49db245f70a248ba563deda520614742f6d67fabbc43a865de-ol8_x86_64_baseos_latest
kernel-headers-4.18.0-553.66.1.el8_10.x86_64.rpm5e793f759b6e7a49db245f70a248ba563deda520614742f6d67fabbc43a865de-ol8_x86_64_u10_baseos_patch
kernel-modules-4.18.0-553.66.1.el8_10.x86_64.rpm29426e4b97e49ab646e7b2a5aa47d9e8550cc250e81cf064052894fcbce70bb3-ol8_x86_64_baseos_latest
kernel-modules-4.18.0-553.66.1.el8_10.x86_64.rpm29426e4b97e49ab646e7b2a5aa47d9e8550cc250e81cf064052894fcbce70bb3-ol8_x86_64_u10_baseos_patch
kernel-modules-extra-4.18.0-553.66.1.el8_10.x86_64.rpm38c55978e0ac1e072bc05466939a4fa2c8282ecf3f471b25e11b261f829962aa-ol8_x86_64_baseos_latest
kernel-modules-extra-4.18.0-553.66.1.el8_10.x86_64.rpm38c55978e0ac1e072bc05466939a4fa2c8282ecf3f471b25e11b261f829962aa-ol8_x86_64_u10_baseos_patch
kernel-tools-4.18.0-553.66.1.el8_10.x86_64.rpmd25f5064802553584bacd9a9847618ad7579e9a37284c02ffa450a3501dd63ef-ol8_x86_64_baseos_latest
kernel-tools-4.18.0-553.66.1.el8_10.x86_64.rpmd25f5064802553584bacd9a9847618ad7579e9a37284c02ffa450a3501dd63ef-ol8_x86_64_u10_baseos_patch
kernel-tools-libs-4.18.0-553.66.1.el8_10.x86_64.rpm410bacc9dc5abd0caeb2a4cf92e707fe53001d3534f7c725cfe7bca8883d15d5-ol8_x86_64_baseos_latest
kernel-tools-libs-4.18.0-553.66.1.el8_10.x86_64.rpm410bacc9dc5abd0caeb2a4cf92e707fe53001d3534f7c725cfe7bca8883d15d5-ol8_x86_64_u10_baseos_patch
kernel-tools-libs-devel-4.18.0-553.66.1.el8_10.x86_64.rpmdfb8c8ca36ff1d1b6229a5809193ad3f298fea4e9bc798a95caedafc8b4e7e2c-ol8_x86_64_codeready_builder
perf-4.18.0-553.66.1.el8_10.x86_64.rpm42d2c69186f2dd91ab664351b071a7e2899fbb9bfdab307e56cc6fa0ec53e33a-ol8_x86_64_baseos_latest
perf-4.18.0-553.66.1.el8_10.x86_64.rpm42d2c69186f2dd91ab664351b071a7e2899fbb9bfdab307e56cc6fa0ec53e33a-ol8_x86_64_u10_baseos_patch
python3-perf-4.18.0-553.66.1.el8_10.x86_64.rpmd935ae53cb568ffab6c132715425884f1e3fc9821f3c3c0724483754d99e7176-ol8_x86_64_baseos_latest
python3-perf-4.18.0-553.66.1.el8_10.x86_64.rpmd935ae53cb568ffab6c132715425884f1e3fc9821f3c3c0724483754d99e7176-ol8_x86_64_u10_baseos_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete