Linuxsecurity Oracle Linux Kernel Vulnerabilities Addressed in Recent Updates
Article Content
- •Oracle Linux 10 and 9 received updates to address moderate security vulnerabilities.
- •CVE-2026-23010, a use-after-free vulnerability, was patched in Oracle Linux 10.
- •Updates include disabling UKI signing and adding new driver signing certificates.
Oracle has released updates for Oracle Linux 10 and Oracle Linux 9 to address moderate security vulnerabilities. The updates include the addition of new driver signing certificates and the disabling of UKI signing. Notably, CVE-2026-23010, a use-after-free vulnerability in the IPv6 subsystem, was patched in Oracle Linux 10. The updates also address issues related to aarch64 signing and conflicts with shim versions. The vulnerabilities could potentially lead to denial of service (DoS) attacks. Affected systems include those running the specified versions of Oracle Linux. The updates were published on March 17 and March 19, 2026. Users are advised to apply the patches to mitigate risks associated with these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-23010 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…