Kernel-5.14.0-687.24.1.el9_8 vs. GhostLock

Dear AlmaLinux experts,

according to this page:

kernel-5.14.0-687.24.1.el9_8 has the fix for GhostLock but CVE-2026-43499 does not appear in the changelog:

$ rpm -qp --changelog kernel-5.14.0-687.24.1.el9_8.x86_64.rpm | grep -i cve

  • KVM: x86: Fix shadow paging use-after-free due to unexpected role (Paolo Bonzini) [RHEL-192400] {CVE-2026-53359}
  • KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (CKI Backport Bot) [RHEL-186702] {CVE-2026-46113}
  • net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change (CKI Backport Bot) [RHEL-183004] {CVE-2025-71066}

Is that due to an oversight in the machinery? If so, could that be improved for future cases?

Thanks!

Hello,

I’ve shared this post in the security channel:

I am just a volunteer.
Thanks.