ELSA-2025-21063

ELSA-2025-21063 - kernel security update

Type:SECURITY
Impact:MODERATE
Release Date:2025-12-16

Description


[3.10.0-1160.119.1.0.14]
- HID: core: fix shift-out-of-bounds in hid_report_raw_event {CVE-2022-48978} [Orabug: 38644370]
- crypto: seqiv - Handle EBUSY correctly {CVE-2023-53373} [Orabug: 38644370]
- nfsd: don't ignore the return code of svc_proc_register() {CVE-2025-22026} [Orabug: 38644370]
- net_sched: hfsc: Fix a UAF vulnerability in class handling {CVE-2025-37797} [Orabug: 38644370]
- HID: core: Harden s32ton() against conversion to 0 bits {CVE-2025-38556} [Orabug: 38644370]
- ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control {CVE-2025-39751} [Orabug: 38644370]

[3.10.0-1160.119.1.0.13]
- ALSA: usb-audio: Fix an out-of-bounds bug in __snd_usb_parse_audio_interface() {CVE-2022-48701} [Orabug: 38493400]
- md-raid10: fix KASAN warning {CVE-2022-50211} [Orabug: 38493400]
- ALSA: bcd2000: Fix a UAF bug on the error path of probing {CVE-2022-50229} [Orabug: 38493400]
- net: usb: smsc75xx: Limit packet length to skb->len {CVE-2023-53125} [Orabug: 38493400]
- i40e: fix MMIO write access to an invalid page in i40e_clear_hw {CVE-2025-38200} [Orabug: 38493400]
- net/sched: sch_qfq: Fix race condition on qfq_aggregate {CVE-2025-38477} [Orabug: 38493400]

[3.10.0-1160.119.1.0.12]
- scsi: lpfc: Use memcpy() for BIOS version (CVE-2025-38332) [Orabug: 38414589]
- posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() (CVE-2025-38352) [Orabug: 38414589]

[3.10.0-1160.119.1.0.11]
- kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)
- kernel: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() (CVE-2025-21928)
- kernel: ext4: fix off-by-one error in do_split (CVE-2025-23150)
- kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() (CVE-2022-49788)
- kernel: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() (CVE-2025-38000)
- kernel: ext4: avoid resizing to a partial cluster size (CVE-2022-50020)
- kernel: drivers:md:fix a potential use-after-free bug (CVE-2022-50022)
- kernel: sch_hfsc: make hfsc_qlen_notify() idempotent (CVE-2025-38177)
- kernel: net/sched: Always pass notifications when child class becomes empty (CVE-2025-38350)
- crypto: algif_hash - fix double free in hash_accept (CVE-2025-38079)

[3.10.0-1160.119.1.0.10]
- net: atlantic: fix aq_vec index out of range error (Chia-Lin Kao) {CVE-2022-50066} [Orabug: 38201271]
- net: atm: fix use after free in lec_send() (Dan Carpenter) {CVE-2025-22004} [Orabug: 38201271]

[3.10.0-1160.119.1.0.9]
- netfilter: ipset: add missing range check in bitmap_ip_uadt (Jeongjun Park) {CVE-2024-53141} [Orabug: 37964173]
- Update OL SB certificates
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985797]

[3.10.0-1160.119.1.0.8]
- ALSA: usb-audio: Fix out of bounds reads when finding clock sources (Takashi Iwai) {CVE-2024-53150} [Orabug: 37830084]

[3.10.0-1160.119.1.0.7]
- ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices (Benoit Sevens) {CVE-2024-53197} [Orabug: 37686305]
- can: bcm: Fix UAF in bcm_proc_show() (YueHaibing) {CVE-2023-52922} [Orabug: 37686305]
- HID: core: zero-initialize the report buffer (Benoit Sevens) {CVE-2024-50302} [Orabug: 37686305]

[3.10.0-1160.119.1.0.6]
- media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format (Benoit Sevens) {CVE-2024-53104} [Orabug: 37584712]


Related CVEs


CVE-2022-48978
CVE-2023-53373
CVE-2025-22026
CVE-2025-37797
CVE-2025-38556
CVE-2025-39751

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 7 (x86_64) kernel-3.10.0-1160.119.1.0.14.el7.src.rpme1cd2928994b3c2d0736ddaed0126f773fe629f2e039399a770575f4bed10229-ol7_x86_64_latest_ELS
bpftool-3.10.0-1160.119.1.0.14.el7.x86_64.rpmf2aa0abb9eec373088bd18cd2aa8e8d5b62f726ecd03bb2a1f1f171e81697d86-ol7_x86_64_latest_ELS
kernel-3.10.0-1160.119.1.0.14.el7.x86_64.rpm1bb249daa6c498590e5be7af1217b9e63c02e1f39c617efdc873ddf582dbe93a-ol7_x86_64_latest_ELS
kernel-abi-whitelists-3.10.0-1160.119.1.0.14.el7.noarch.rpmec993ba00f8fe7fbb6f49db5a82b3e83f5e2461a133ee5ac07ebc3ac1c3a6cb7-ol7_x86_64_latest_ELS
kernel-debug-3.10.0-1160.119.1.0.14.el7.x86_64.rpm1b59cb7b097f9d6d4bd8fd6e0ad9d67afb5a70220d7f08888dd6decc312bf43f-ol7_x86_64_latest_ELS
kernel-debug-devel-3.10.0-1160.119.1.0.14.el7.x86_64.rpm98c38bf93fb50a469148fad45f18f2de75705bcda7fc9bfc204d4b7e07e0f870-ol7_x86_64_latest_ELS
kernel-devel-3.10.0-1160.119.1.0.14.el7.x86_64.rpm703fdb02dd578d7e35f2cc9bac8d61a253190aca7f89074688cb8d981b1f5336-ol7_x86_64_latest_ELS
kernel-doc-3.10.0-1160.119.1.0.14.el7.noarch.rpm60c37d886a9085ecabe2a4f7604ee5154a168f69e5fbd40ee6b00d0b82f54cb9-ol7_x86_64_latest_ELS
kernel-headers-3.10.0-1160.119.1.0.14.el7.x86_64.rpm5955dd4cfa222dc99ab4433cbb2a523d3d3b76ffb17127ecbbdb96731f368ec0-ol7_x86_64_latest_ELS
kernel-tools-3.10.0-1160.119.1.0.14.el7.x86_64.rpm27322e9769ef78f5e2734e7c0d4bc027d91db0a4026ea6ceceb1a250a614fe5f-ol7_x86_64_latest_ELS
kernel-tools-libs-3.10.0-1160.119.1.0.14.el7.x86_64.rpm4bea6bc0b6628f17e05fd6d7c32b1496b6c9ab65d64c1c402ff8bdcee15a6faa-ol7_x86_64_latest_ELS
kernel-tools-libs-devel-3.10.0-1160.119.1.0.14.el7.x86_64.rpm0aa9d1d77c5eaf139314a4a9fa36e26bd739d8d99153231d341682ebdf4eb9d7-ol7_x86_64_latest_ELS
perf-3.10.0-1160.119.1.0.14.el7.x86_64.rpm788c1a57e3d5e929cda7b2db5cedb06ca62def9e9284c7f0f49d30dd86ad0932-ol7_x86_64_latest_ELS
python-perf-3.10.0-1160.119.1.0.14.el7.x86_64.rpm796e4d052621bf3e8c57e08e11b9a4afc6ac1ab29a2b4db0c8239661dbcfe46e-ol7_x86_64_latest_ELS



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete