Linuxsecurity Oracle Linux Kernel Security Updates Address Multiple Vulnerabilities
Article Content
- •Oracle Linux kernel updates released on June 23, 2026, addressing multiple CVEs.
- •Critical vulnerabilities include use-after-free and denial of service issues.
- •Users are urged to apply patches immediately to mitigate risks.
On June 23, 2026, Oracle released significant kernel security updates for Oracle Linux, addressing multiple vulnerabilities, including CVE-2026-23272, CVE-2026-31419, CVE-2026-31533, CVE-2026-31657, CVE-2026-31669, and CVE-2026-43074. These vulnerabilities include use-after-free issues and potential denial of service conditions affecting various components of the Linux kernel. The updates are crucial for users of Oracle Linux 9 and earlier versions, as they mitigate risks associated with these vulnerabilities. The updates include kernel packages such as kernel-uek and kernel-uek-core. Users are advised to apply the patches immediately to safeguard their systems against potential exploitation. The vulnerabilities were disclosed between March and May 2026, with some having known exploits. The updates are available for download from Oracle's advisory pages.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-23272 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…