Oracle Linux 6497 Published by

Oracle Linux administrators managing UEKR7 version 5.15.0 on OL8 and OL9 can now deploy essential kernel patches through Ksplice Uptrack to resolve several critical vulnerabilities. The ELSA-2026-50294 advisory specifically targets dangerous flaws such as null pointer dereferences in the NVMe TCP subsystem, overly permissive Kerberos SPNEGO privilege checks, and persistent memory leaks in network drivers. Users with automatic installation enabled will receive these fixes immediately while others can manually trigger the process using a straightforward terminal command. Meanwhile the ELBA-2026-50317 release requires no attention whatsoever since it introduces changes that do not impact live production environments.

New Ksplice updates for UEKR7 5.15.0 on OL8 and OL9 (ELSA-2026-50294)
ELBA-2026-50317 does not affect running systems




New Ksplice updates for UEKR7 5.15.0 on OL8 and OL9 (ELSA-2026-50294)


Synopsis: ELSA-2026-50294 can now be patched using Ksplice
CVEs: CVE-2026-23112 CVE-2026-31508 CVE-2026-46243

Users with Oracle Linux Premier Support can now use Ksplice to patch
against the latest Oracle Linux Security Advisory, ELSA-2026-50294.
More information about this errata can be found at
https://linux.oracle.com/errata/ELSA-2026-50294.html

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack running UEKR7 5.15.0 on
OL8 and OL9 install these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y

DESCRIPTION

* CVE-2026-23112: Null pointer dereference in NVMe/TCP target subsystem.

* CVE-2026-31508: Kernel oops in Open vSwitch driver.

* CVE-2026-46243: Overly permissive privilege checks in Kerberos/SPNEGO driver.

Orabug: 39463672

* Memory leak in TUN/TAP device driver.

Orabug: 39429143

* Missing AMD PSFD feature in KVM.

Orabug: 35586248

SUPPORT

Ksplice support is available at ksplice-support_ww@oracle.com.



ELBA-2026-50317 does not affect running systems


Synopsis: ELBA-2026-50317 does not affect running systems

The recently released RHCK 7, ELBA-2026-50317, does not fix any
security problems relevant to already running systems. You do not need
to take any action to update your systems.

SUPPORT

Ksplice support is available at ksplice-support_ww@oracle.com.