CVE-2026-68480
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-68480 is a vulnerability in the Linux kernel affecting Oracle Linux systems. It was reserved by a CNA with a release date of 2026-08-06 and carries a preliminary CVSS v3.1 base score of 5.5 (Moderate) (Oracle ULN). The affected platforms include Oracle Linux version 8 and 9 (kernel-uek), addressed via errata ELSA-2026-500135 and ELSA-2026-500137 released on 2026-08-06 (Oracle ULN). Full technical details remain limited as this CVE has only been reserved and not yet fully published by MITRE or NIST NVD.

Technical details

Full technical details for CVE-2026-68480 have not yet been publicly disclosed, as the CVE ID has been reserved by a CNA but not fully populated in MITRE or NIST NVD databases (Oracle ULN). The preliminary CVSS v3.1 metrics indicate a local attack vector with low attack complexity, low privileges required, no user interaction, and no confidentiality, integrity, or availability impact — suggesting the scoring may be incomplete or placeholder (Oracle ULN). No CWE classification, root cause analysis, or PoC code is currently available.

Impact

Based on the available preliminary information, the confidentiality, integrity, and availability impacts are all listed as None in the current CVSS scoring, though Oracle has classified the overall impact as Moderate (Oracle ULN). This discrepancy suggests the CVSS metrics are preliminary and subject to revision. The affected scope is limited to Oracle Linux 8 and 9 systems running the kernel-uek package.

Exploitability

No information is currently available regarding in-the-wild exploitation, PoC availability, exploit kits, threat actor attribution, EPSS score, or CISA KEV catalog status for CVE-2026-68480. The CVE was only recently reserved and has not been fully disclosed (Oracle ULN).

Mitigation and workarounds

Oracle has released kernel-uek updates for Oracle Linux 8 and 9 to address CVE-2026-68480. Affected systems should be updated using the following errata: ELSA-2026-500137 (Oracle Linux 8 and 9) and ELSA-2026-500135 (Oracle Linux 9), both released on 2026-08-06 (Oracle ULN). Administrators should apply the available kernel-uek updates through standard Oracle Linux patching mechanisms (e.g., yum update kernel-uek) and reboot affected systems to load the patched kernel.

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64597CRITICAL9.8
  • Linux Kernel logoLinux Kernel
  • linux-aws-5.4
NoYesAug 06, 2026
CVE-2026-68480HIGH8.8
  • Linux Kernel logoLinux Kernel
  • kernel-modules-partner
NoYesAug 06, 2026
CVE-2026-64598HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.8
NoYesAug 06, 2026
CVE-2026-64604HIGH7.7
  • Linux Kernel logoLinux Kernel
  • linux-riscv-5.15
NoYesAug 06, 2026
CVE-2026-64603NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-intel-iotg-5.15
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management