Skip to content
Critical Oracle Linux Kernel Vulnerabilities Expose Admin Control Risks

Critical Oracle Linux Kernel Vulnerabilities Expose Admin Control Risks

First seen 14 Sep 2026, 12:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 13:48 UTC
  • Chained vulnerabilities in Oracle Linux allow admin control.
  • Patches released for Oracle Linux 8 and 9; immediate updates recommended.
  • Affected versions include kernel 4.18.0-553.162.1 and 5.14.0-687.46.1.

Multiple vulnerabilities in Oracle Linux kernels (versions 4.18 and 5.14) have been identified, allowing attackers to gain administrative control through chained exploits. The vulnerabilities are linked to CVE-2026-46015 and CVE-2025-38004, with patches released for Oracle Linux 8 and 9. Affected systems include Oracle Linux 8 and 9, with specific kernel versions being 4.18.0-553.162.1 and 5.14.0-687.46.1. The vulnerabilities were disclosed recently, with the potential for exploitation confirmed. Administrators are urged to update their systems immediately to mitigate risks. The updates include disabling UKI signing and updating Oracle Linux certificates. The situation is critical due to the potential for mass exploitation if not addressed promptly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-06-08
CVE-2025-38004 published
A vulnerability allowing admin control was disclosed, affecting Oracle Linux.
Linuxsecurity
2025-12-24
CVE-2025-68745 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-06
CVE-2026-43133 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-08
CVE-2026-43339 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-19
CVE-2026-43493 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-27
CVE-2026-46015 published
A critical kernel vulnerability was disclosed, enabling potential admin access.
Linuxsecurity
2026-05-28
CVE-2026-46149 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-03
CVE-2026-46266 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-08
CVE-2026-46306 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-09
CVE-2026-46330 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (3)

Following this threat?

Track CVE-2025-38004 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed