ELSA-2026-500121

ELSA-2026-500121 - Unbreakable Enterprise kernel security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-08-03

Description


[5.4.17-2136.358.2]
- xfs: resample the data fork mapping after cycling ILOCK (Darrick J. Wong) [Orabug: 39776792] {CVE-2026-64600}
- net: Work around Marvell NIC TX stalls (Venkat Venkatsubra) [Orabug: 39765820]

[5.4.17-2136.358.1]
- KVM: x86: Fix shadow paging use-after-free due to unexpected role (Paolo Bonzini) [Orabug: 39673871]
- KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/MMU: Recursively zap nested TDP SPs when zapping last/only parent (Ben Gardon) [Orabug: 39673871]
- KVM: x86/mmu: Move flush logic from mmu_page_zap_pte() to FNAME(invlpg) (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: pull call to drop_large_spte() into __link_shadow_page() (Paolo Bonzini) [Orabug: 39673871]
- KVM: x86/mmu: Passing up the error state of mmu_alloc_shadow_roots() (Like Xu) [Orabug: 39673871]
- KVM: MMU: load PDPTRs outside mmu_lock (Paolo Bonzini) [Orabug: 39673871]
- KVM: x86/mmu: Check PDPTRs before allocating PAE roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Always pass 0 for @quadrant when gptes are 8 bytes (David Matlack) [Orabug: 39673871]
- KVM: x86/mmu: Derive shadow MMU page role from parent (David Matlack) [Orabug: 39673871]
- KVM: X86: Remove useless code to set role.gpte_is_8_bytes when role.direct (Lai Jiangshan) [Orabug: 39673871]
- KVM: X86: Synchronize the shadow pagetable before link it (Lai Jiangshan) [Orabug: 39673871]
- KVM: X86: Fix missed remote tlb flush in rmap_write_protect() (Lai Jiangshan) [Orabug: 39673871]
- KVM: x86/mmu: Refactor shadow walk in __direct_map() to reduce indentation (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Stop passing 'direct' to mmu_alloc_root() (David Matlack) [Orabug: 39673871]
- KVM: x86/mmu: Use a bool for direct (David Matlack) [Orabug: 39673871]
- kvm: mmu: Replace unsigned with unsigned int for PTE access (Ben Gardon) [Orabug: 39673871]
- KVM: x86/mmu: Ensure MMU pages are available when allocating roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Allocate pae_root and lm_root pages in dedicated helper (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Allocate the lm_root before allocating PAE roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Capture 'mmu' in a local variable when allocating roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Alloc page for PDPTEs when shadowing 32-bit NPT with 64-bit (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Stash 'kvm' in a local variable in kvm_mmu_free_roots() (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Add a helper to consolidate root sp allocation (Sean Christopherson) [Orabug: 39673871]
- Revert 'net/rds: poll eq during user-reset' (Praveen Kumar Kannoju) [Orabug: 39659401]
- net/sched: act_pedit: fix action bind logic (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: free pedit keys on bail from offset check (Pedro Tammela) [Orabug: 39567287]
- net/sched: fix pedit partial COW leading to page cache corruption (Rajat Gupta) [Orabug: 39567287] {CVE-2026-46331}
- net/sched: act_pedit: Parse L3 Header for L4 offset (Max Tottenham) [Orabug: 39567287]
- net/sched: act_pedit: rate limit datapath messages (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: check static offsets a priori (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: remove extra check for key type (Pedro Tammela) [Orabug: 39567287]
- net/sched: simplify tcf_pedit_act (Pedro Tammela) [Orabug: 39567287]
- net/sched: transition act_pedit to rcu and percpu stats (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: use NLA_POLICY for parsing 'ex' keys (Pedro Tammela) [Orabug: 39567287]
- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (hkbinbin) [Orabug: 39452261] {CVE-2026-46043}
- locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (Davidlohr Bueso) [Orabug: 39426001]
- rtmutex: Use waiter::task instead of current in remove_waiter() (Keenan Dong) [Orabug: 39426001] {CVE-2026-43499}
- ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (Eric Dumazet) [Orabug: 39300930] {CVE-2026-43038}
- tracing/events: Expand global buffer for in-kernel event enables (Manjunath Patil) [Orabug: 38790406]
- net/mlx5: poll mlx5 eq during irq migration (Praveen Kumar Kannoju) [Orabug: 38776184]

[5.4.17-2136.357.3]
- net: skbuff: fix missing zerocopy reference in pskb_carve helpers (Minh Nguyen) [Orabug: 39619389] {CVE-2026-52943}

[5.4.17-2136.357.2]
- net: fix fanout UAF in packet_release() via NETDEV_UP race (Yochai Eisenrich) [Orabug: 39250953] {CVE-2026-31504}
- x86/kaslr: Recognize all ZONE_DEVICE users as physaddr consumers (Dan Williams) [Orabug: 39429802]
- x86/kaslr: Reduce KASLR entropy on most x86 systems (Balbir Singh) [Orabug: 39429802]
- net: tap: NULL pointer derefence in dev_parse_header_protocol when skb->dev is null (Cezar Bulinaru) [Orabug: 39526882] {CVE-2022-50073}
- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39548666] {CVE-2025-10263}
- arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland) [Orabug: 39548666]
- ARM: uek: Disable CONFIG_QCOM_FALKOR_ERRATUM_1003 (Boris Ostrovsky) [Orabug: 39548666]
- arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland) [Orabug: 39548666]
- arm64: cputype: Add C1-Premium definitions (Mark Rutland) [Orabug: 39548666]
- arm64: cputype: Add C1-Ultra definitions (Mark Rutland) [Orabug: 39548666]
- ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (Eric Dumazet) [Orabug: 39300926] {CVE-2026-43037}

[5.4.17-2136.357.1]
- batman-adv: hold claim backbone gateways by reference (Haoze Xie) [Orabug: 39262375] {CVE-2026-31657}
- scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (Michael Bommarito) [Orabug: 39446045]
- scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (Michael Bommarito) [Orabug: 39446045]
- scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (Michael Bommarito) [Orabug: 39446045]
- rds: Drop rds conn in connect worker if not in down state. (Rohit Nair) [Orabug: 39152239]

[5.4.17-2136.356.4.1]
- smb: client: reject userspace cifs.spnego descriptions (Asim Viladi Oglu Manizada) [Orabug: 39463669] {CVE-2026-46243}

[5.4.17-2136.356.4]
- tun: free page on build_skb failure in tun_xdp_one() (Weiming Shi) [Orabug: 39429147]
- tap: free page on error paths in tap_get_user_xdp() (Weiming Shi) [Orabug: 39429147]
- tun: free page on short-frame rejection in tun_xdp_one() (Weiming Shi) [Orabug: 39429147]

[5.4.17-2136.356.3]
- ptrace: slightly saner 'get_dumpable()' logic (Linus Torvalds) [Orabug: 39384275,39391459] {CVE-2026-46333}
- net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim) [Orabug: 39368828,39441326] {CVE-2026-43503,CVE-2026-46300}
- net: skbuff: preserve shared-frag marker during coalescing (William Bowling) [Orabug: 39368828] {CVE-2026-46300}

[5.4.17-2136.356.2]
- nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (Jeff Layton) [Orabug: 39167617,39368718] {CVE-2026-31402}
- scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() (Maurizio Lombardi) [Orabug: 38985173,39368732] {CVE-2026-23216}
- scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() (Maurizio Lombardi) [Orabug: 38970455,39368774] {CVE-2026-23193}
- xfrm: esp: avoid in-place decrypt on shared skb frags (Kuan-Ting Chen) [Orabug: 39334580,39367147] {CVE-2026-43284}
- x86/CPU/AMD: Add a fix for AMD-SB-7052 (Prathyushi Nangia) [Orabug: 39218897] {CVE-2025-54518}

[5.4.17-2136.356.1]
- arm64/kvm: Include linux/random.h in trng.c (Siddh Raman Pant) [Orabug: 39327096]
- i2c: designware: Disable TX_EMPTY irq while waiting for block length byte (Tam Nguyen) [Orabug: 39174662]
- i2c: designware: Handle invalid SMBus block data response length value (Tam Nguyen) [Orabug: 39174662]
- i2c: designware: fix __i2c_dw_disable() in case master is holding SCL low (Yann Sionneau) [Orabug: 39174662]


Related CVEs


CVE-2026-43038
CVE-2026-43499
CVE-2026-46043
CVE-2026-46331
CVE-2026-64600

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) kernel-uek-5.4.17-2136.358.2.el8uek.src.rpm83961f8060f7b1e3a2bbd031bf0ea9655e7945768b6b367fc102286dc3223458-ol8_aarch64_baseos_latest
kernel-uek-5.4.17-2136.358.2.el8uek.src.rpm83961f8060f7b1e3a2bbd031bf0ea9655e7945768b6b367fc102286dc3223458-ol8_aarch64_u10_baseos_patch
kernel-uek-5.4.17-2136.358.2.el8uek.aarch64.rpmcf18306a6058af9f2c520d1a291491cdb46d2f676bdf73d77a6a474dedb2d07e-ol8_aarch64_baseos_latest
kernel-uek-5.4.17-2136.358.2.el8uek.aarch64.rpmcf18306a6058af9f2c520d1a291491cdb46d2f676bdf73d77a6a474dedb2d07e-ol8_aarch64_u10_baseos_patch
kernel-uek-debug-5.4.17-2136.358.2.el8uek.aarch64.rpm4c14a24bf472919497ec5789c0441f985bc099dada49845b5eaad89e798a11b0-ol8_aarch64_baseos_latest
kernel-uek-debug-5.4.17-2136.358.2.el8uek.aarch64.rpm4c14a24bf472919497ec5789c0441f985bc099dada49845b5eaad89e798a11b0-ol8_aarch64_u10_baseos_patch
kernel-uek-debug-devel-5.4.17-2136.358.2.el8uek.aarch64.rpm2cacb945b4e94ca580687663eeeab587b7914d7733171916e5e0f12769b80f27-ol8_aarch64_baseos_latest
kernel-uek-debug-devel-5.4.17-2136.358.2.el8uek.aarch64.rpm2cacb945b4e94ca580687663eeeab587b7914d7733171916e5e0f12769b80f27-ol8_aarch64_u10_baseos_patch
kernel-uek-devel-5.4.17-2136.358.2.el8uek.aarch64.rpm9464e4a0eb7fdf72e526aae41db0286f8b9cff14c44afb5e75e3ccedb93d4fae-ol8_aarch64_baseos_latest
kernel-uek-devel-5.4.17-2136.358.2.el8uek.aarch64.rpm9464e4a0eb7fdf72e526aae41db0286f8b9cff14c44afb5e75e3ccedb93d4fae-ol8_aarch64_u10_baseos_patch
kernel-uek-doc-5.4.17-2136.358.2.el8uek.noarch.rpm7c793a4e7b71569987da1e8fe265d81c61fbe9f123aadbbd9955c9e409acad2b-ol8_aarch64_baseos_latest
kernel-uek-doc-5.4.17-2136.358.2.el8uek.noarch.rpm7c793a4e7b71569987da1e8fe265d81c61fbe9f123aadbbd9955c9e409acad2b-ol8_aarch64_u10_baseos_patch
Oracle Linux 8 (x86_64) kernel-uek-5.4.17-2136.358.2.el8uek.src.rpm83961f8060f7b1e3a2bbd031bf0ea9655e7945768b6b367fc102286dc3223458-ol8_x86_64_UEKR6
kernel-uek-5.4.17-2136.358.2.el8uek.x86_64.rpmb73459b780e5eb10ad67b3d9c7045ed5f0e09587285c58c5e94e53578b84327c-ol8_x86_64_UEKR6
kernel-uek-container-5.4.17-2136.358.2.el8uek.x86_64.rpm28ac446b9d3acc9f0961f311c01d00bc001a9684dc55acabf25f70d2182ff169-ol8_x86_64_UEKR6
kernel-uek-container-debug-5.4.17-2136.358.2.el8uek.x86_64.rpm275d947fe396c3254f8e6cadb5c0d70a273844c0a0898a15b61966c29685e6e9-ol8_x86_64_UEKR6
kernel-uek-debug-5.4.17-2136.358.2.el8uek.x86_64.rpmb07ff4367875ac9dadfc2bd7efabc37c857022a6e135eeeccea11e8e3d9d0f7d-ol8_x86_64_UEKR6
kernel-uek-debug-devel-5.4.17-2136.358.2.el8uek.x86_64.rpm6eb3d6806f34767e345b39f0f460eba63d1aea32a324548e20f53d79c2dc80f0-ol8_x86_64_UEKR6
kernel-uek-devel-5.4.17-2136.358.2.el8uek.x86_64.rpmae48f001fa3ce958bfc26340ed45a13b8f285ade1c553e1be682725ce09c5753-ol8_x86_64_UEKR6
kernel-uek-doc-5.4.17-2136.358.2.el8uek.noarch.rpm7c793a4e7b71569987da1e8fe265d81c61fbe9f123aadbbd9955c9e409acad2b-ol8_x86_64_UEKR6



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete