Dear AlmaLinux experts,
according to this page:
kernel-5.14.0-687.24.1.el9_8 has the fix for GhostLock but CVE-2026-43499 does not appear in the changelog:
$ rpm -qp --changelog kernel-5.14.0-687.24.1.el9_8.x86_64.rpm | grep -i cve
- KVM: x86: Fix shadow paging use-after-free due to unexpected role (Paolo Bonzini) [RHEL-192400] {CVE-2026-53359}
- KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (CKI Backport Bot) [RHEL-186702] {CVE-2026-46113}
- net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change (CKI Backport Bot) [RHEL-183004] {CVE-2025-71066}
Is that due to an oversight in the machinery? If so, could that be improved for future cases?
Thanks!