-
Mon Sep 28 2026 EL Errata <el-errata_ww@oracle.com> [4.18.0-553.168.1.el8_10.OL8]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.3
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985772]
-
Wed Sep 23 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [4.18.0-553.168.1.el8_10]
- pppoe: reload header pointer after dev_hard_header() (Guillaume Nault) [RHEL-237293] {CVE-2026-68121}
- nvme-tcp: reject a read that transferred too few bytes (CKI Backport Bot) [RHEL-263345] {CVE-2026-89480}
- nvme: rename and document nvme_end_request (CKI Backport Bot) [RHEL-263345] {CVE-2026-89480}
- ipvs: do not propagate one-packet flag to synced conns (CKI Backport Bot) [RHEL-255839] {CVE-2026-80714}
- netfilter: nf_queue: hold bridge skb->dev while queued (CKI Backport Bot) [RHEL-231233] {CVE-2026-52912}
- drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CKI Backport Bot) [RHEL-221269] {CVE-2026-31566}
-
Tue Sep 22 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [4.18.0-553.167.1.el8_10]
- net: tun: bound receive headroom (CKI Backport Bot) [RHEL-264385] {CVE-2026-81000}
- xfrm: ah6: validate routing header segments_left (CKI Backport Bot) [RHEL-264314] {CVE-2026-80844}
- scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (CKI Backport Bot) [RHEL-262571] {CVE-2026-89846}
- ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (CKI Backport Bot) [RHEL-243620] {CVE-2026-72261}
- mac802154: llsec: add skb_cow_data() before in-place crypto (Abhishek Rawal) [RHEL-231030] {CVE-2026-63831}
- sctp: don't free the ASCONF's own transport in DEL-IP processing (CKI Backport Bot) [RHEL-234282] {CVE-2026-64564}
- drm/amdgpu: Fix use-after-free race in VM acquire (CKI Backport Bot) [RHEL-222381] {CVE-2026-43370}
- sctp: prevent peer transport count overflow (Xin Long) [RHEL-216297]
-
Mon Sep 21 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [4.18.0-553.166.1.el8_10]
- crypto: af_alg - Fix incorrect boolean values in af_alg_ctx (CKI Backport Bot) [RHEL-264205] {CVE-2025-39964}
- crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CKI Backport Bot) [RHEL-264205] {CVE-2025-39964}
-
Mon Sep 21 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [4.18.0-553.165.1.el8_10]
- nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (CKI Backport Bot) [RHEL-260522] {CVE-2026-64534}
- nvmet-tcp: pass iov_len instead of sg->length to bvec_set_page() (Chris Leech) [RHEL-260522] {CVE-2026-64534}
- nvmet-tcp: remove nvmet_tcp_finish_cmd (CKI Backport Bot) [RHEL-260522] {CVE-2026-64534}
- nvmet-tcp: fix NULL pointer dereference during release (Chris Leech) [RHEL-260522] {CVE-2026-64534}
- nvmet-tcp: don't map pages which can't come from HIGHMEM (CKI Backport Bot) [RHEL-260522] {CVE-2026-64534}
- xfs: do not allocate the entire delalloc extent in xfs_bmapi_write (Lukas Herbolt) [RHEL-251578]
- xfs: fix xfs_bmap_add_extent_delay_real for partial conversions (Lukas Herbolt) [RHEL-251578]
- xfs: remove the xfs_iext_peek_prev_extent call in xfs_bmapi_allocate (Lukas Herbolt) [RHEL-251578]
- xfs: pass the actual offset and len to allocate to xfs_bmapi_allocate (Lukas Herbolt) [RHEL-251578]
- xfs: don't open code XFS_FILBLKS_MIN in xfs_bmapi_write (Lukas Herbolt) [RHEL-251578]
- xfs: lift a xfs_valid_startblock into xfs_bmapi_allocate (Lukas Herbolt) [RHEL-251578]
- xfs: remove the unusued tmp_logflags variable in xfs_bmapi_allocate (Lukas Herbolt) [RHEL-251578]
- keys: Pin request_key_auth payload in instantiate paths (Bruno Meneguele) [RHEL-225491] {CVE-2026-63823}
- iommu/vt-d: Remove unnecessary locking in intel_irq_remapping_alloc() (Jakub Brnak) [RHEL-243217]
- iommu/vt-d: Clear Present bit before tearing down PASID entry (Eder Zulian) [RHEL-228475] {CVE-2026-45894}
- iommu/amd: Fix clone_alias() to use the original device's devid (Eder Zulian) [RHEL-227450] {CVE-2026-53053}
- Bluetooth: RFCOMM: Fix session UAF in set_termios (CKI Backport Bot) [RHEL-237326] {CVE-2026-68188}
- net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (CKI Backport Bot) [RHEL-236787] {CVE-2026-68293}
- RDMA/rxe: Fix a use-after-free problem in rxe_mmap (Kamal Heib) [RHEL-233821] {CVE-2026-64582}
- RDMA/rxe: Reject unknown opcodes before ICRC processing (Kamal Heib) [RHEL-226871] {CVE-2026-46133}
- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (Kamal Heib) [RHEL-228181] {CVE-2026-46043}
- dm cache policy smq: check allocation under invalidate lock (CKI Backport Bot) [RHEL-231810] {CVE-2026-53062}
- dm cache policy smq: fix missing locks in invalidating cache blocks (CKI Backport Bot) [RHEL-231810] {CVE-2026-53062}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231060] {CVE-2026-63947}
- Bluetooth: L2CAP: Fix potential user-after-free (CKI Backport Bot) [RHEL-229428] {CVE-2023-54214}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228747] {CVE-2026-63975}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227528] {CVE-2026-43334}
- Bluetooth: Fix race condition in hidp_session_thread (CKI Backport Bot) [RHEL-227382] {CVE-2023-54120}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225633] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225571] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225535] {CVE-2026-52918}
- Bluetooth: btusb: revert use of devm_kzalloc in btusb (CKI Backport Bot) [RHEL-225154] {CVE-2025-71082}
-
Wed Sep 16 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [4.18.0-553.164.1.el8_10]
- net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() (Izabela Bakollari) [RHEL-244096] {CVE-2026-72298}
- ipv6: sit: reload inner IPv6 header after GSO offloads (Jamie Bainbridge) [RHEL-225905] {CVE-2026-53228}
- ipvlan: Make the addrs_lock be per port (Jamie Bainbridge) [RHEL-229962] {CVE-2026-23103}
- xfrm: Fix dev use-after-free in xfrm async resumption (Sabrina Dubroca) [RHEL-232949] {CVE-2026-31663}
- xfrm: hold dev ref until after transport_finish NF_HOOK (Sabrina Dubroca) [RHEL-232949] {CVE-2026-31663}
- xfrm: hold device only for the asynchronous decryption (Sabrina Dubroca) [RHEL-232949] {CVE-2026-31663}
- xfrm: input: hold netns during deferred transport reinjection (Sabrina Dubroca) [RHEL-227504] {CVE-2026-63919}
- xfrm: fix stale skb->prev after async crypto steals a GSO segment (Sabrina Dubroca) [RHEL-236099] {CVE-2026-68426}
- xfrm: propagate -EINPROGRESS from validate_xmit_xfrm() (Sabrina Dubroca) [RHEL-236099] {CVE-2026-68426}
- xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (Sabrina Dubroca) [RHEL-227976] {CVE-2026-53239}
- ip6: vti: Use ip6_tnl.net in vti6_changelink(). (Sabrina Dubroca) [RHEL-231741] {CVE-2026-63917}
- ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). (Sabrina Dubroca) [RHEL-228934] {CVE-2026-63921}
- inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (Jamie Bainbridge) [RHEL-226122] {CVE-2026-46266}
- ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (Jamie Bainbridge) [RHEL-227265] {CVE-2026-64002}
- ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (Jamie Bainbridge) [RHEL-227981] {CVE-2026-53075}
- ipv6: mcast: Fix use-after-free when processing MLD queries (Jamie Bainbridge) [RHEL-226057] {CVE-2026-53275}
- net: guard timestamp cmsgs to real error queue skbs (Jamie Bainbridge) [RHEL-225848] {CVE-2026-53223}
- flow_dissector: do not dissect PPPoE PFC frames (Jamie Bainbridge) [RHEL-232609] {CVE-2026-46306}
- ipv6: prevent possible UaF in addrconf_permanent_addr() (Jamie Bainbridge) [RHEL-225595] {CVE-2026-43339}
- net: slip: serialize receive against buffer reallocation (Michal Schmidt) [RHEL-237390] {CVE-2026-68143}
- slip: not call free_netdev before rtnl_unlock in slip_open (Michal Schmidt) [RHEL-237390]
- slip: Fix use-after-free Read in slip_open (Michal Schmidt) [RHEL-237390]
- slip: Fix memory leak in slip_open error path (Michal Schmidt) [RHEL-237390]
- netfilter: require Ethernet MAC header before using eth_hdr() (CKI Backport Bot) [RHEL-230663] {CVE-2026-53131}
- netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (CKI Backport Bot) [RHEL-230607] {CVE-2026-43233}
- ALSA: timer: Fix UAF at snd_timer_user_params() (CKI Backport Bot) [RHEL-228683] {CVE-2026-53192}
- netfilter: xt_policy: fix strict mode inbound policy matching (CKI Backport Bot) [RHEL-228832] {CVE-2026-52920}
- netfilter: conntrack_irc: fix possible out-of-bounds read (CKI Backport Bot) [RHEL-225240] {CVE-2026-53268}
- IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (CKI Backport Bot) [RHEL-191599] {CVE-2026-53176}
-
Mon Sep 14 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [4.18.0-553.163.1.el8_10]
- EDAC/bluefield: Fix potential integer overflow (Joel Savitz) [RHEL-234337] {CVE-2024-53161}
- scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (CKI Backport Bot) [RHEL-254583] {CVE-2026-74556}
- blk-cgroup: fix UAF in __blkcg_rstat_flush() (Jeff Moyer) [RHEL-230276] {CVE-2026-63802}
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244942] {CVE-2026-72098}
- net: qrtr: restrict socket creation to the initial network namespace (Jose Ignacio Tornos Martinez) [RHEL-239090] {CVE-2026-68294}
- wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (Jose Ignacio Tornos Martinez) [RHEL-237990] {CVE-2026-68363}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb (Jose Ignacio Tornos Martinez) [RHEL-231677] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231677] {CVE-2026-64117}
- wifi: mac80211: Discard Beacon frames to non-broadcast address (Jose Ignacio Tornos Martinez) [RHEL-230705] {CVE-2025-71127}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230593] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229715] {CVE-2026-52947}
- scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (CKI Backport Bot) [RHEL-228708] {CVE-2026-63889}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189455] {CVE-2026-43133}
-
Wed Sep 09 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [4.18.0-553.162.1.el8_10]
- scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers (Laurence Oberman) [RHEL-194117]
- tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (Xin Long) [RHEL-228877] {CVE-2026-63801}
- tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (Xin Long) [RHEL-238050] {CVE-2026-68117}
- sctp: fix race between sctp_wait_for_connect and peeloff (Xin Long) [RHEL-229464] {CVE-2026-63971}
- sctp: diag: reject stale associations in dump_one path (Xin Long) [RHEL-231561] {CVE-2026-52917}
- sctp: validate stream count in sctp_process_strreset_inreq() (Xin Long) [RHEL-236135] {CVE-2026-68315}
- sctp: fix auth_hmacs array size in struct sctp_cookie (Xin Long) [RHEL-237394] {CVE-2026-68376}
- sctp: auth: verify auth requirement when auth_chunk is NULL (Xin Long) [RHEL-237088] {CVE-2026-68300}
- gfs2: harden gfs2_glock_hold (Andreas Gruenbacher) [RHEL-240340]
- gfs2: gfs2_glock_hold cleanup (Andreas Gruenbacher) [RHEL-240340]
- sctp: validate embedded INIT chunk and address list lengths in cookie (Xin Long) [RHEL-190202]
- sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (Xin Long) [RHEL-190202] {CVE-2026-53246}
- netfilter: nf_log: validate MAC header was set before dumping it (CKI Backport Bot) [RHEL-232055] {CVE-2026-52942}
- netfilter: nf_conntrack_sip: don't use simple_strtoul (CKI Backport Bot) [RHEL-232024] {CVE-2026-52986}
- scsi: qla2xxx: Clear cmds after chip reset (CKI Backport Bot) [RHEL-230822] {CVE-2025-68745}
- scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CKI Backport Bot) [RHEL-225791] {CVE-2026-46149}
-
Mon Sep 07 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [4.18.0-553.161.1.el8_10]
- security/keys: fix missed RCU read section on lookup (Bruno Meneguele) [RHEL-225679] {CVE-2026-64015}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227760] {CVE-2026-64113}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: use qdisc_pkt_len_segs_init() in sch_handle_ingress() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)->pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: init shinfo->gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: add more sanity checks to qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)->pkt_segs (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- sch_cake: do not use skb_mac_header() in cake_overhead() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: do not use skb_mac_header() in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
- net: Skip GSO length estimation if transport header is not set (Ivan Vecera) [RHEL-188227] {CVE-2026-53091}
-
Thu Sep 03 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [4.18.0-553.160.1.el8_10]
- rhashtable: clear stale iter->p on table restart (CKI Backport Bot) [RHEL-248433] {CVE-2026-64563}
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246938] {CVE-2026-74480}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244910] {CVE-2026-72129}
- crypto: pcrypt - Fix handling of MAY_BACKLOG requests (Ricardo Robaina) [RHEL-226702] {CVE-2026-43493}
- crypto: pcrypt - Delay write to padata->info (Ricardo Robaina) [RHEL-226702] {CVE-2026-43493}
- crypto: pcrypt - Do not clear MAY_SLEEP flag in original request (Ricardo Robaina) [RHEL-226702] {CVE-2026-43493}
- smb: client: validate DFS referral PathConsumed (CKI Backport Bot) [RHEL-237655] {CVE-2026-68343}
- netfilter: synproxy: refresh tcphdr after skb_ensure_writable (CKI Backport Bot) [RHEL-228903] {CVE-2026-64007}
- netfilter: conntrack: remove sprintf usage (CKI Backport Bot) [RHEL-224448] {CVE-2026-53002}