Oracle Linux Kernel Vulnerabilities Addressed in Recent Updates

Oracle Linux Kernel Vulnerabilities Addressed in Recent Updates

First seen 19 Mar 2026, 17:44 UTC Linuxsecurity 45.8

Article Content

Browse articles
ThreatCluster

Oracle has released updates for Oracle Linux 10 and Oracle Linux 9 to address moderate security vulnerabilities. The updates include the addition of new driver signing certificates and the disabling of UKI signing. Notably, CVE-2026-23010, a use-after-free vulnerability in the IPv6 subsystem, was patched in Oracle Linux 10. The updates also address issues related to aarch64 signing and conflicts with shim versions. The vulnerabilities could potentially lead to denial of service (DoS) attacks. Affected systems include those running the specified versions of Oracle Linux. The updates were published on March 17 and March 19, 2026. Users are advised to apply the patches to mitigate risks associated with these vulnerabilities.

Key Points: • Oracle Linux 10 and 9 received updates to address moderate security vulnerabilities. • CVE-2026-23010, a use-after-free vulnerability, was patched in Oracle Linux 10. • Updates include disabling UKI signing and adding new driver signing certificates.

Timeline

2026-01-25
CVE-2026-23010 published
2026-03-17
Oracle Linux 10 update released addressing vulnerabilities
2026-03-19
Oracle Linux 9 update released addressing vulnerabilities