Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-500004 http://linux.oracle.com/errata/ELSA-2026-500004.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: kernel-uek-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-core-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-debug-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-debug-core-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-debug-devel-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-debug-modules-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-debug-modules-core-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-debug-modules-deprecated-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-debug-modules-desktop-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-debug-modules-extra-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-debug-modules-extra-netfilter-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-debug-modules-usb-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-debug-modules-wireless-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-devel-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-doc-6.12.0-204.92.4.3.el9uek.noarch.rpm kernel-uek-modules-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-modules-core-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-modules-deprecated-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-modules-desktop-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-modules-extra-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-modules-extra-netfilter-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-modules-usb-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-modules-wireless-6.12.0-204.92.4.3.el9uek.x86_64.rpm kernel-uek-tools-6.12.0-204.92.4.3.el9uek.x86_64.rpm aarch64: kernel-uek-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-core-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-debug-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-debug-core-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-debug-devel-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-debug-modules-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-debug-modules-core-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-debug-modules-deprecated-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-debug-modules-desktop-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-debug-modules-extra-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-debug-modules-extra-netfilter-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-debug-modules-usb-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-debug-modules-wireless-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-devel-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-doc-6.12.0-204.92.4.3.el9uek.noarch.rpm kernel-uek-modules-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-modules-extra-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-modules-core-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-modules-deprecated-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-modules-desktop-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-modules-extra-netfilter-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-modules-usb-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-modules-wireless-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek-tools-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek64k-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek64k-core-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek64k-devel-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek64k-modules-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek64k-modules-core-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek64k-modules-deprecated-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek64k-modules-desktop-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek64k-modules-extra-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek64k-modules-extra-netfilter-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek64k-modules-usb-6.12.0-204.92.4.3.el9uek.aarch64.rpm kernel-uek64k-modules-wireless-6.12.0-204.92.4.3.el9uek.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/kernel-uek-6.12.0-204.92.4.3.el9uek.src.rpm Related CVEs: CVE-2026-31663 CVE-2026-46316 CVE-2026-53362 Description of changes: [6.12.0-204.92.4.3] - xfrm: hold dev ref until after transport_finish NF_HOOK (Qi Tang) [Orabug: 39727259] {CVE-2026-31663} - xfrm: hold device only for the asynchronous decryption (Jianbo Liu) [Orabug: 39727259] - KVM:arm64: vgic-its: Drop the translation cache reference only for the erased entry (Hyunwoo Kim) [Orabug: 39727258] {CVE-2026-46316} - ipv6: account for fraggap on the paged allocation path (Wongi Lee) [Orabug: 39727239] {CVE-2026-53362} _______________________________________________ El-errata mailing list
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:21692-1 Release Date: 2026-05-14T07:20:11Z Rating: important References: * bsc#1264459 Cross-References: * CVE-2026-43284 CVSS scores: * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes one security issue The following security issue was fixed: * CVE-2026-43284: xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-421=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-39-default-5-1.1 * kernel-livepatch-MICRO-6-0_Update_16-debugsource-5-1.1 * kernel-livepatch-6_4_0-39-default-debuginfo-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43284.html * https://bugzilla.suse.com/show_bug.cgi?id=1264459 . Update for SUSE Linux Kernel to fix CVE-2026-43284 addressing important security risk.. SUSE Linux Update, Kernel Security Fix, CVE-2026-43284, Live Patch, Linux Security. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:21695-1 Release Date: 2026-05-14T07:20:59Z Rating: important References: * bsc#1264459 Cross-References: * CVE-2026-43284 CVSS scores: * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes one security issue The following security issue was fixed: * CVE-2026-43284: xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-422=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-40-default-4-1.1 * kernel-livepatch-6_4_0-40-default-debuginfo-4-1.1 * kernel-livepatch-MICRO-6-0_Update_17-debugsource-4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43284.html * https://bugzilla.suse.com/show_bug.cgi?id=1264459 . SUSE Linux Enterprise Micro 6.0 update addresses important kernel security issue with CVE-2026-43284.. SUSE Linux, Live Patch, Kernel Update, Security Advisory, CVE Threats. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:21697-1 Release Date: 2026-05-14T07:21:37Z Rating: important References: * bsc#1264459 Cross-References: * CVE-2026-43284 CVSS scores: * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-35.1 fixes one security issue The following security issue was fixed: * CVE-2026-43284: xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-419=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-35-default-10-1.1 * kernel-livepatch-MICRO-6-0_Update_12-debugsource-10-1.1 * kernel-livepatch-6_4_0-35-default-debuginfo-10-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43284.html * https://bugzilla.suse.com/show_bug.cgi?id=1264459 . Important security update for SUSE Linux Micro addresses a critical kernel issue. Install patch to enhance system protection.. SUSE Linux Micro, kernel security, important update. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:21701-1 Release Date: 2026-05-14T07:46:08Z Rating: important References: * bsc#1264459 Cross-References: * CVE-2026-43284 CVSS scores: * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes one security issue The following security issue was fixed: * CVE-2026-43284: xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-423=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-41-default-debuginfo-3-1.1 * kernel-livepatch-6_4_0-41-default-3-1.1 * kernel-livepatch-MICRO-6-0_Update_18-debugsource-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43284.html * https://bugzilla.suse.com/show_bug.cgi?id=1264459 . Stay informed about the important kernel update for SUSE Linux Enterprise Micro 6.0 that addresses CVE-2026-43284.. SUSE Linux Kernel Update, CVE-2026-43284, kernel security patch. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:21702-1 Release Date: 2026-05-14T07:54:43Z Rating: important References: * bsc#1264459 Cross-References: * CVE-2026-43284 CVSS scores: * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-30.1 fixes one security issue The following security issue was fixed: * CVE-2026-43284: xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-425=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-30-default-17-1.2 * kernel-livepatch-6_4_0-30-default-debuginfo-17-1.2 * kernel-livepatch-MICRO-6-0_Update_8-debugsource-17-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-43284.html * https://bugzilla.suse.com/show_bug.cgi?id=1264459 . An important security advisory detailing an update for SUSE Linux Micro addressing a critical buffer overflow issue.. SUSE Linux Kernel Update, Security Advisory, Kernel Live Patch. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel RT (Live Patch 6 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:21707-1 Release Date: 2026-05-14T06:30:06Z Rating: important References: * bsc#1264459 Cross-References: * CVE-2026-43284 CVSS scores: * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-28.1 fixes one security issue The following security issue was fixed: * CVE-2026-43284: xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-401=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-28-rt-18-3.1 * kernel-livepatch-MICRO-6-0-RT_Update_6-debugsource-18-3.1 * kernel-livepatch-6_4_0-28-rt-debuginfo-18-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43284.html * https://bugzilla.suse.com/show_bug.cgi?id=1264459 . SUSE Linux Kernel RT update addresses important issues related to CVE-2026-43284 and enhances system security.. SUSE Linux Micro 6.1, kernel live patch, CVE-2026-43284. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel RT (Live Patch 7 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:21708-1 Release Date: 2026-05-14T06:30:06Z Rating: important References: * bsc#1264459 Cross-References: * CVE-2026-43284 CVSS scores: * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-30.1 fixes one security issue The following security issue was fixed: * CVE-2026-43284: xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264459). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-402=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-30-rt-18-1.3 * kernel-livepatch-MICRO-6-0-RT_Update_7-debugsource-18-1.3 * kernel-livepatch-6_4_0-30-rt-debuginfo-18-1.3 ## References: * https://www.suse.com/security/cve/CVE-2026-43284.html * https://bugzilla.suse.com/show_bug.cgi?id=1264459 . Important update for SUSE Linux Micro 6.0 addresses critical kernel security issue with CVE-2026-43284 for safe operations.. SUSE Linux Micro kernel security update CVE-2026-43284 important patch. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.