-
Fri Jul 31 2026 EL Errata <el-errata_ww@oracle.com> [6.12.0-211.42.1.el10_2.OL10]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5.el9
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Update module name for cryptographic module [Orabug: 37400433]
- Clean git history at setup stage
-
Wed Jul 29 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.42.1.el10_2]
- net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (CKI Backport Bot) [RHEL-214082] {CVE-2026-64530}
- ksm: use range-walk function to jump over holes in scan_get_next_rmap_item (Rafael Aquini) [RHEL-189554] {CVE-2025-68211}
- isofs: validate Rock Ridge CE continuation extent against volume size (CKI Backport Bot) [RHEL-187415] {CVE-2026-46303}
-
Tue Jul 28 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.41.1.el10_2]
- dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() (CKI Backport Bot) [RHEL-212063]
- ASoC: Intel: sof_sdw: append dai type to dai link name unconditionally (CKI Backport Bot) [RHEL-185669]
-
Mon Jul 27 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.40.1.el10_2]
- ipv6: fix possible UAF in icmpv6_rcv() (CKI Backport Bot) [RHEL-192215] {CVE-2026-53006}
- tipc: fix double-free in tipc_buf_append() (CKI Backport Bot) [RHEL-192181] {CVE-2026-52993}
- iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (Eder Zulian) [RHEL-190344] {CVE-2026-53281}
- iommu/vt-d: Fix oops due to out of scope access (Eder Zulian) [RHEL-190344]
- net: bridge: use a stable FDB dst snapshot in RCU readers (Mohammad Heib) [RHEL-179338] {CVE-2026-46086}
- rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc (Marc Dionne) [RHEL-178254]
- rxrpc: Fix the ACK parser to extract the SACK table for parsing (Marc Dionne) [RHEL-178254]
- rxrpc: Fix RESPONSE packet verification to extract skb to a linear buffer (Marc Dionne) [RHEL-178254]
- rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg (Marc Dionne) [RHEL-178254]
- crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks (Marc Dionne) [RHEL-178254]
- rxrpc: fix oversized RESPONSE authenticator length check (Marc Dionne) [RHEL-178254] {CVE-2026-31635}
- rxrpc: Fix integer overflow in rxgk_verify_response() (Marc Dionne) [RHEL-178254] {CVE-2026-31633}
- rxrpc: Fix leak of rxgk context in rxgk_verify_response() (Marc Dionne) [RHEL-178254] {CVE-2026-31632}
- rxrpc: Fix buffer overread in rxgk_do_verify_authenticator() (Marc Dionne) [RHEL-178254] {CVE-2026-31631}
- rxgk: Fix potential integer overflow in length check (Marc Dionne) [RHEL-178254]
- rxrpc: Fix rxkad crypto unalignment handling (Marc Dionne) [RHEL-178254]
- rxrpc: Fix memory leaks in rxkad_verify_response() (Marc Dionne) [RHEL-178254]
- rxrpc: Fix missing error checks for rxkad encryption/decryption failure (Marc Dionne) [RHEL-178254]
- rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present (Marc Dionne) [RHEL-178254] {CVE-2026-43500}
- rxrpc: Fix conn-level packet handling to unshare RESPONSE packets (Marc Dionne) [RHEL-178254]
- rxrpc: only handle RESPONSE during service challenge (Marc Dionne) [RHEL-178254] {CVE-2026-31676}
-
Thu Jul 23 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.39.1.el10_2]
- futex: Drop CLONE_THREAD requirement for private default hash alloc (Audra Mitchell) [RHEL-193518] {CVE-2026-52973}
- net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (Antoine Tenart) [RHEL-179299] {CVE-2026-46099}
- scsi: core: Wake up the error handler when final completions race against each other (CKI Backport Bot) [RHEL-189651] {CVE-2026-23110}
- dm log: fix out-of-bounds write due to region_count overflow (CKI Backport Bot) [RHEL-188547] {CVE-2026-53059}
- rtnetlink: add missing netlink_ns_capable() check for peer netns (Guillaume Nault) [RHEL-172537] {CVE-2026-31692}
- rtnetlink: Try the outer netns attribute in rtnl_get_peer_net(). (Guillaume Nault) [RHEL-172537] {CVE-2026-31692}
- rtnetlink: fix double call of rtnl_link_get_net_ifla() (Guillaume Nault) [RHEL-172537] {CVE-2026-31692}
- netkit: Set IFLA_NETKIT_PEER_INFO to netkit_link_ops.peer_type. (Guillaume Nault) [RHEL-172537] {CVE-2026-31692}
- vxcan: Set VXCAN_INFO_PEER to vxcan_link_ops.peer_type. (Guillaume Nault) [RHEL-172537] {CVE-2026-31692}
- veth: Set VETH_INFO_PEER to veth_link_ops.peer_type. (Guillaume Nault) [RHEL-172537] {CVE-2026-31692}
- rtnetlink: Add peer_type in struct rtnl_link_ops. (Guillaume Nault) [RHEL-172537] {CVE-2026-31692}
- fs/notify: call exportfs_encode_fid with s_umount (Jay Shin) [RHEL-169188] {CVE-2025-40237}
- fs: relax assertions on failure to encode file handles (Jay Shin) [RHEL-169188]
-
Wed Jul 22 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.38.1.el10_2]
- net: gro: don't merge zcopy skbs (CKI Backport Bot) [RHEL-177856] {CVE-2026-46323}
-
Tue Jul 21 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.37.1.el10_2]
- can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (CKI Backport Bot) [RHEL-212681]
- fanotify: fix false positive on permission events (CKI Backport Bot) [RHEL-180076] {CVE-2026-46150}
-
Mon Jul 20 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.36.1.el10_2]
- ice: fix double-free of tx_buf skb (Jakub Ramaseuski) [RHEL-191324 RHEL-192200] {CVE-2026-53009}
- ice: fix double free in ice_sf_eth_activate() error path (Jakub Ramaseuski) [RHEL-191324] {CVE-2026-46162}
- ice: update PCS latency settings for E825 10G/25Gb modes (Jakub Ramaseuski) [RHEL-191324]
- ice: fix 'adjust' timer programming for E830 devices (Jakub Ramaseuski) [RHEL-191324]
- ice: use bitmap_empty() in ice_vf_has_no_qs_ena (Jakub Ramaseuski) [RHEL-191324]
- ice: use bitmap_weighted_xor() in ice_find_free_recp_res_idx() (Jakub Ramaseuski) [RHEL-191324]
- ice: Make name member of struct ice_cgu_pin_desc const (Jakub Ramaseuski) [RHEL-191324]
- ice: fix PTP timestamping broken by SyncE code on E825C (Jakub Ramaseuski) [RHEL-191324]
- ice: ptp: don't WARN when controlling PF is unavailable (Jakub Ramaseuski) [RHEL-191324] {CVE-2026-43346}
- ice: use ice_update_eth_stats() for representor stats (Jakub Ramaseuski) [RHEL-191324]
- ice: fix inverted ready check for VF representors (Jakub Ramaseuski) [RHEL-191324]
- drivers: net: ice: fix devlink parameters get without irdma (Jakub Ramaseuski) [RHEL-191324]
- ice: fix rxq info registering in mbuf packets (Jakub Ramaseuski) [RHEL-191324]
- ice: fix retry for AQ command 0x06EE (Jakub Ramaseuski) [RHEL-191324]
- ice: reintroduce retry mechanism for indirect AQ (Jakub Ramaseuski) [RHEL-191324]
- ice: fix adding AQ LLDP filter for VF (Jakub Ramaseuski) [RHEL-191324]
- ice: recap the VSI and QoS info after rebuild (Jakub Ramaseuski) [RHEL-191324]
- ice: fix missing TX timestamps interrupts on E825 devices (Jakub Ramaseuski) [RHEL-191324]
- ice: stop counting UDP csum mismatch as rx_errors (Jakub Ramaseuski) [RHEL-191324]
- ice: reshuffle and group Rx and Tx queue fields by cachelines (Jakub Ramaseuski) [RHEL-191324]
- ice: convert all ring stats to u64_stats_t (Jakub Ramaseuski) [RHEL-191324]
- ice: shorten ring stat names and add accessors (Jakub Ramaseuski) [RHEL-191324]
- ice: use u64_stats API to access pkts/bytes in dim sample (Jakub Ramaseuski) [RHEL-191324]
- ice: remove ice_q_stats struct and use struct_group (Jakub Ramaseuski) [RHEL-191324]
- ice: pass pointer to ice_fetch_u64_stats_per_ring (Jakub Ramaseuski) [RHEL-191324]
- ice: unify PHY FW loading status handler for E800 devices (Jakub Ramaseuski) [RHEL-191324]
- ice: Fix NULL pointer dereference in ice_vsi_set_napi_queues (Jakub Ramaseuski) [RHEL-191324] {CVE-2026-23166}
- bitmap: introduce bitmap_weighted_xor() (Jakub Ramaseuski) [RHEL-191324]
- bitmap: add test_zero_nbits() (Jakub Ramaseuski) [RHEL-191324]
- bitmap: exclude nbits == 0 cases from bitmap test (Jakub Ramaseuski) [RHEL-191324]
- bitmap: test bitmap_weight() for more (Jakub Ramaseuski) [RHEL-191324]
- bitmap: add bitmap_weight_from() (Jakub Ramaseuski) [RHEL-191324]
- bitmap: align test_bitmap output (Jakub Ramaseuski) [RHEL-191324]
- bitmap: switch test to scnprintf("%*pbl") (Jakub Ramaseuski) [RHEL-191324]
- bitmap: Add test for out-of-boundary modifications for scatter & gather (Jakub Ramaseuski) [RHEL-191324]
- cpumask: Introduce cpumask_weighted_or() (Jakub Ramaseuski) [RHEL-191324]
- bitmap: Align documentation between bitmap_gather() and bitmap_scatter() (Jakub Ramaseuski) [RHEL-191324]
- bitmap: remove _check_eq_u32_array (Jakub Ramaseuski) [RHEL-191324]
- include: update references to include/asm-<arch> (Jakub Ramaseuski) [RHEL-191324]
- KEYS: trusted: Fix a memory leak in tpm2_load_cmd (CKI Backport Bot) [RHEL-189604] {CVE-2025-71147}
- crypto: af_alg - zero initialize memory allocated via sock_kmalloc (CKI Backport Bot) [RHEL-189576] {CVE-2025-71113}
- drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (CKI Backport Bot) [RHEL-188644] {CVE-2026-52976}
- xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (Sabrina Dubroca) [RHEL-180167] {CVE-2026-46116}
-
Thu Jul 16 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.35.1.el10_2]
- drm/xe/dma-buf: fix UAF with retry loop (Karol Herbst) [RHEL-192232] {CVE-2026-52950}
- drm/xe/dma-buf: handle empty bo and UAF races (Karol Herbst) [RHEL-192232]
- drm/xe: Fix bo leak in xe_dma_buf_init_obj() on allocation failure (Karol Herbst) [RHEL-192232]
- drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (Karol Herbst) [RHEL-192232]
- nfsd: cancel async COPY operations when admin revokes filesystem state (Olga Kornievskaia) [RHEL-173103]
- nfsd: use correct loop termination in nfsd4_revoke_states() (Olga Kornievskaia) [RHEL-173103]
- nfsd: check that server is running in unlock_filesystem (Olga Kornievskaia) [RHEL-173103]
- drm/gem: Try to fix change_handle ioctl, attempt 4 (Jocelyn Falempe) [RHEL-179887]
- drm/gem: fix race between change_handle and handle_delete (Jocelyn Falempe) [RHEL-179887]
- drm: Replace old pointer to new idr (Jocelyn Falempe) [RHEL-179887]
- drm: Set old handle to NULL before prime swap in change_handle (Jocelyn Falempe) [RHEL-179887] {CVE-2026-46215}
- drm: Do not allow userspace to trigger kernel warnings in drm_gem_change_handle_ioctl() (Jocelyn Falempe) [RHEL-179887]
- cxl/port: Fix use after free of parent_port in cxl_detach_ep() (Myron Stowe) [RHEL-180697] {CVE-2026-31530}
- flex_proportions: make fprop_new_period() hardirq safe (CKI Backport Bot) [RHEL-189658] {CVE-2026-23168}
- Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CKI Backport Bot) [RHEL-188331] {CVE-2026-53071}
- redhat/configs: disable CONFIG_PT_RECLAIM (Luiz Capitulino) [RHEL-186311]
- libperf build: Always place libperf includes first (Michael Petlan) [RHEL-183975]
-
Tue Jul 14 2026 Jan Stancek <jstancek@redhat.com> [6.12.0-211.34.1.el10_2]
- crypto: ccp - copy IV using skcipher ivsize (CKI Backport Bot) [RHEL-188463] {CVE-2026-53016}
- xfs: resample the data fork mapping after cycling ILOCK (Carlos Maiolino) [RHEL-193945]
- xfrm: esp: restore combined single-frag length gate (CKI Backport Bot) [RHEL-178326]