Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 510
Alerts This Week
Warning Icon 1 510

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
217

Oracle Linux 9 ELSA-2026-50352 Kernel Important CVE-2026-52943

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-50352 http://linux.oracle.com/errata/ELSA-2026-50352.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: aarch64: bpftool-5.15.0-321.202.5.3.el9uek.aarch64.rpm kernel-uek-5.15.0-321.202.5.3.el9uek.aarch64.rpm kernel-uek-container-5.15.0-321.202.5.3.el9uek.aarch64.rpm kernel-uek-container-debug-5.15.0-321.202.5.3.el9uek.aarch64.rpm kernel-uek-core-5.15.0-321.202.5.3.el9uek.aarch64.rpm kernel-uek-debug-5.15.0-321.202.5.3.el9uek.aarch64.rpm kernel-uek-debug-core-5.15.0-321.202.5.3.el9uek.aarch64.rpm kernel-uek-debug-devel-5.15.0-321.202.5.3.el9uek.aarch64.rpm kernel-uek-debug-modules-5.15.0-321.202.5.3.el9uek.aarch64.rpm kernel-uek-debug-modules-extra-5.15.0-321.202.5.3.el9uek.aarch64.rpm kernel-uek-devel-5.15.0-321.202.5.3.el9uek.aarch64.rpm kernel-uek-doc-5.15.0-321.202.5.3.el9uek.noarch.rpm kernel-uek-modules-5.15.0-321.202.5.3.el9uek.aarch64.rpm kernel-uek-modules-extra-5.15.0-321.202.5.3.el9uek.aarch64.rpm kernel-uek64k-5.15.0-321.202.5.3.el9uek.aarch64.rpm kernel-uek64k-core-5.15.0-321.202.5.3.el9uek.aarch64.rpm kernel-uek64k-devel-5.15.0-321.202.5.3.el9uek.aarch64.rpm kernel-uek64k-modules-5.15.0-321.202.5.3.el9uek.aarch64.rpm kernel-uek64k-modules-extra-5.15.0-321.202.5.3.el9uek.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/kernel-uek-5.15.0-321.202.5.3.el9uek.src.rpm Related CVEs: CVE-2026-52943 Description of changes: [5.15.0-321.202.5.3] - net: skbuff: fix missing zerocopy reference in pskb_carve helpers (Minh Nguyen) [Orabug: 39639981] {CVE-2026-52943} [5.15.0-321.202.5.2] - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (Muhammad Alifa Ramdhan) [Orabug: 39543209] {CVE-2026-31533} - net: fix fanout UAF in packet_release() via NETDEV_UP race (Yochai Eisenrich) [Orabug: 39543208] {CVE-2026-31504} - net: tap: NULL pointer derefence in dev_parse_header_protocolwhen skb-> dev is null (Cezar Bulinaru) [Orabug: 39543201] {CVE-2022-50073} - mptcp: fix slab-use-after-free in __inet_lookup_established (Jiayuan Chen) [Orabug: 39543200] {CVE-2026-31669} - batman-adv: hold claim backbone gateways by reference (Haoze Xie) [Orabug: 39543197] {CVE-2026-31657} - arm64: dts: pensando: drop elba penfw firmware node (Tom Saeger) [Orabug: 39543196] [5.15.0-321.202.5.1] - arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39017590] {CVE-2025-10263} - arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland) [Orabug: 39017590] - ARM: uek: Disable CONFIG_NVIDIA_CARMEL_CNP_ERRATUM (Boris Ostrovsky) [Orabug: 39017590] - arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland) [Orabug: 39017590] - arm64: cputype: Add C1-Premium definitions (Mark Rutland) [Orabug: 39017590] - arm64: cputype: Add C1-Ultra definitions (Mark Rutland) [Orabug: 39017590] [5.15.0-321.202.5] - Revert "ip6_tunnel: Fix usage of skb_vlan_inet_prepare()" (Harshit Mogalapalli) [Orabug: 39476647] - smb: client: reject userspace cifs.spnego descriptions (Asim Viladi Oglu Manizada) [Orabug: 39463672] [5.15.0-321.202.4] - tun: free page on build_skb failure in tun_xdp_one() (Weiming Shi) [Orabug: 39429143] - tap: free page on error paths in tap_get_user_xdp() (Weiming Shi) [Orabug: 39429143] - tun: free page on short-frame rejection in tun_xdp_one() (Weiming Shi) [Orabug: 39429143] [5.15.0-321.202.3] - net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim) [Orabug: 39368827] {CVE-2026-46300} - net: skbuff: preserve shared-frag marker during coalescing (William Bowling) [Orabug: 39368827] - ptrace: slightly saner 'get_dumpable()' logic (Linus Torvalds) [Orabug: 39384274] {CVE-2026-46333} - mm/hugetlb: fix excessive IPI broadcasts when unsharing PMD tables using mmu_gather (David Hildenbrand (Red Hat)) [Orabug: 38474901] - Revert "mm/hugetlb: add option to allows disabling CVE-2025-38085 mitigation" (Samasth Norway Ananda) [Orabug: 38474901] - mm/rmap: fix two comments related to huge_pmd_unshare() (David Hildenbrand (Red Hat)) [Orabug: 38474901] - mm/hugetlb: fix two comments related to huge_pmd_unshare() (David Hildenbrand (Red Hat)) [Orabug: 38474901] - mm/hugetlb: fix hugetlb_pmd_shared() (David Hildenbrand (Red Hat)) [Orabug: 38474901] [5.15.0-321.202.2] - dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler (Guenter Roeck) - Revert "arm64: dts: qcom: sdm845-oneplus: Mark l14a regulator as boot-on" (Sasha Levin) - ip6_tunnel: Fix usage of skb_vlan_inet_prepare() (Ben Hutchings) - hwmon: (max16065) Use READ/WRITE_ONCE to avoid compiler optimization induced race (Gui-Dong Han) - wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom (Guenter Roeck) - sched: idle: Make skipping governor callbacks more consistent (Rafael J. Wysocki) - nvmet-tcp: fix use-before-check of sg in bounds validation (Cengiz Can) - remoteproc: mediatek: Unprepare SCP clock during system suspend (Tzung-Bi Shih) - net: openvswitch: Avoid releasing netdev before teardown completes (Toke Høiland-Jørgensen) - ACPI: processor: Fix previous acpi_processor_errata_piix4() fix (Rafael J. Wysocki) - net: hsr: fix VLAN add unwind on slave errors (Luka Gejak) - x86/CPU/AMD: Add a fix for AMD-SB-7052 (Prathyushi Nangia) [Orabug: 39327141] {CVE-2025-54518} - xfrm: esp: ipv4: fix up flags setting (Greg Kroah-Hartman) [Orabug: 39342679] {CVE-2026-43284} - xfrm: esp: avoid in-place decrypt on shared skb frags (Kuan-Ting Chen) [Orabug: 39342679] {CVE-2026-43284} - KVM: x86: disable preemption around the call to kvm_arch_vcpu_{un|}blocking (Maxim Levitsky) [Orabug: 39334996] - KVM: Don't block+unblock when halt-polling is successful (Sean Christopherson) [Orabug: 39334996] - nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (Jeff Layton) [Orabug: 39167616] {CVE-2026-31402} - net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks (Victor Nogueira) [Orabug: 39103230] {CVE-2026-23270} - exadata: tools: perf: update column to comm_nodigit (Stephen Brennan) [Orabug: 39327019] - perf report: Add comm_nodigit sort key (Stephen Brennan) [Orabug: 39327019] - Revert "tools: perf: add comm_ignore_digit column" (Stephen Brennan) [Orabug: 39327019] [5.15.0-321.202.1] - virtio-net: add cond_resched() to the command waiting loop (Jason Wang) [Orabug: 39291988] - virtio-net: convert rx mode setting to use workqueue (Jason Wang) [Orabug: 39291988] - x86: KVM: Add common feature flag for AMD's PSFD (Sean Christopherson) [Orabug: 35586248] - KVM: x86: Insert "AMD" in KVM_X86_FEATURE_PSFD (Jim Mattson) [Orabug: 35586248] - KVM: x86: Expose Predictive Store Forwarding Disable (Babu Moger) [Orabug: 35586248] - i2c: designware: fix __i2c_dw_disable() in case master is holding SCL low (Yann Sionneau) [Orabug: 39174661] [5.15.0-320.202.8] - iommu/arm-smmu-v3: Handle zeroed A4-2C HTTU override settings (Joao Martins) [Orabug: 39186453] - iommu: Move IOMMU_DIRTY_NO_CLEAR define (Shameer Kolothum) [Orabug: 39186453] - iommu/arm-smmu-v3: Enable HTTU for stage1 with io-pgtable mapping (Kunkun Jiang) [Orabug: 39186453] - iommu/arm-smmu-v3: Add support for dirty tracking in domain alloc (Joao Martins) [Orabug: 39186453] - iommu/io-pgtable-arm: Add read_and_clear_dirty() support (Shameer Kolothum) [Orabug: 39186453] - iommu/arm-smmu-v3: Add feature detection for HTTU (Jean-Philippe Brucker) [Orabug: 39186453] [5.15.0-320.202.7] - crypto: algif_aead - Fix minimum RX size check for decryption (Herbert Xu) [Orabug: 39250686,39331104] {CVE-2026-43077} - crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl (Herbert Xu) [Orabug: 39250686,39331109] {CVE-2026-43078} - crypto: authencesn - Fix src offset when decrypting in-place (Herbert Xu) [Orabug: 39250686] - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (Herbert Xu) [Orabug: 39250686,39300910] {CVE-2026-43033} - crypto: authenc - use memcpy_sglist() instead of null skcipher (Eric Biggers) [Orabug:39250686] - crypto: algif_aead - snapshot IV for async AEAD requests (Douya Le) [Orabug: 39250686] - crypto: algif_aead - Revert to operating out-of-place (Herbert Xu) [Orabug: 39250686,39283867,39291961] {CVE-2026-31431} - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (Eric Biggers) [Orabug: 39250686] {CVE-2026-31431} - crypto: scatterwalk - Backport memcpy_sglist() (Eric Biggers) [Orabug: 39250686] - uek-rpm: Enable FWCTL for aarch64 (Dave Kleikamp) [Orabug: 39252913] _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux has released an important advisory for kernel with CVE-2026-52943 highlighting critical updates for security.. Oracle Linux kernel advisory updates CVE issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 01, 2026 Important Oracle
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200