Oracle Linux 6523 Published by

Oracle Linux released multiple security advisories for version 10 that update core system packages including the Unbreakable Enterprise kernel, golang, openssl, podman, nginx, freerdp, libreswan, and mariadb-connector-c across x86_64 and aarch64 architectures. These patches resolve dozens of assigned CVEs covering memory corruption flaws, arbitrary code execution risks, and denial-of-service vulnerabilities alongside specific driver regressions in the arm64 ACPI subsystem and virtio_pci networking stack. Oracle Linux Premier Support subscribers can use Ksplice to patch out-of-bounds memory access flaws in the IPv6 networking stack and RDMA RXE driver on OL7 and OL8 systems without restarting their servers.

ELSA-2026-43505 Important: Oracle Linux 10 mariadb-connector-c security update
ELBA-2026-500062 Unbreakable Enterprise kernel bug fix update
ELSA-2026-46398 Important: Oracle Linux 10 libreswan security update
New Ksplice updates for UEKR6 5.4.17 on OL7 and OL8
ELSA-2026-29980 Moderate: Oracle Linux 10 golang security, bug fix, and enhancement update
ELBA-2026-39326 Oracle Linux 10 openssl bug fix and enhancement update
ELSA-2026-24386 Important: Oracle Linux 10 podman security update
ELSA-2026-18289 Important: Oracle Linux 10 podman security update
ELSA-2026-19142 Moderate: Oracle Linux 10 freerdp security update
ELSA-2026-29874 Important: Oracle Linux 10 nginx security update
ELBA-2026-500086 xfsprogs bug fix update
ELSA-2026-46394 Important: Oracle Linux 10 go-fdo-client security update
ELSA-2026-37072 Important: Oracle Linux 10 podman security, bug fix, and enhancement update




ELSA-2026-43505 Important: Oracle Linux 10 mariadb-connector-c security update


Oracle Linux Security Advisory ELSA-2026-43505

http://linux.oracle.com/errata/ELSA-2026-43505.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
mariadb-connector-c-3.4.4-2.el10_2.x86_64.rpm
mariadb-connector-c-config-3.4.4-2.el10_2.noarch.rpm
mariadb-connector-c-devel-3.4.4-2.el10_2.x86_64.rpm
mariadb-connector-c-doc-3.4.4-2.el10_2.noarch.rpm
mariadb-connector-c-test-3.4.4-2.el10_2.x86_64.rpm

aarch64:
mariadb-connector-c-3.4.4-2.el10_2.aarch64.rpm
mariadb-connector-c-config-3.4.4-2.el10_2.noarch.rpm
mariadb-connector-c-devel-3.4.4-2.el10_2.aarch64.rpm
mariadb-connector-c-doc-3.4.4-2.el10_2.noarch.rpm
mariadb-connector-c-test-3.4.4-2.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/mariadb-connector-c-3.4.4-2.el10_2.src.rpm

Related CVEs:

CVE-2026-44172

Description of changes:

[3.4.4-2]
- CVE-2026-44172 fix



ELBA-2026-500062 Unbreakable Enterprise kernel bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-500062

http://linux.oracle.com/errata/ELBA-2026-500062.html

The following updated rpms for have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-uek-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-core-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-devel-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-doc-6.12.0-204.92.4.4.el10uek.noarch.rpm
kernel-uek-modules-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-modules-core-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-modules-deprecated-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-modules-desktop-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-modules-extra-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-modules-extra-netfilter-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-modules-usb-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-modules-wireless-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-tools-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-core-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-devel-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-modules-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-modules-core-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-modules-deprecated-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-modules-desktop-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-modules-extra-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-modules-extra-netfilter-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-modules-usb-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-modules-wireless-6.12.0-204.92.4.4.el10uek.x86_64.rpm

aarch64:
kernel-uek-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-core-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-devel-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-doc-6.12.0-204.92.4.4.el10uek.noarch.rpm
kernel-uek-modules-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-modules-core-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-modules-deprecated-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-modules-desktop-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-modules-extra-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-modules-extra-netfilter-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-modules-usb-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-modules-wireless-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-tools-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-core-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-devel-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-modules-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-modules-core-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-modules-deprecated-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-modules-desktop-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-modules-extra-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-modules-extra-netfilter-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-modules-usb-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-modules-wireless-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-core-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-devel-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-modules-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-modules-core-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-modules-deprecated-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-modules-desktop-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-modules-extra-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-modules-extra-netfilter-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-modules-usb-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-modules-wireless-6.12.0-204.92.4.4.el10uek.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/kernel-uek-6.12.0-204.92.4.4.el10uek.src.rpm

Description of changes:

[6.12.0-204.92.4.4]
- Revert "arm64: acpi: Enable ACPI CCEL support" (Will Deacon) [Orabug: 39772225]
- virtio_pci: fix vq info pointer lookup via wrong index (Ammar Faizi) [Orabug: 39772224]



ELSA-2026-46398 Important: Oracle Linux 10 libreswan security update


Oracle Linux Security Advisory ELSA-2026-46398

http://linux.oracle.com/errata/ELSA-2026-46398.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
libreswan-5.3.2-1.el10_2.x86_64.rpm
libreswan-minimal-5.3.2-1.el10_2.x86_64.rpm

aarch64:
libreswan-5.3.2-1.el10_2.aarch64.rpm
libreswan-minimal-5.3.2-1.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/libreswan-5.3.2-1.el10_2.src.rpm

Related CVEs:

CVE-2026-12413
CVE-2026-14957
CVE-2026-50721
CVE-2026-50722

Description of changes:

[5.3.2-1.0.1]
- Add libreswan-oracle.patch to detect Oracle Linux distro

[5.3.2-1]
- Update to libreswan-5.3.2

[5.3.1-1]
- Update to libreswan-5.3.1



Synopsis: Following CVEs can now be patched using Ksplice
CVEs: CVE-2026-43038 CVE-2026-46043 CVE-2026-64600

Users with Oracle Linux Premier Support can now use Ksplice to patch
against the latest CVE fixes.

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack running UEKR6 5.4.17 on
OL7 and OL8 install these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y

DESCRIPTION

* CVE-2026-43038: Out-of-bounds memory access in IPv6 networking stack.

Orabug: 39300930

* CVE-2026-46043: Out-of-bounds memory access in RDMA RXE driver.

Orabug: 39452261

SUPPORT

Ksplice support is available at ksplice-support_ww@oracle.com.

ELSA-2026-29980 Moderate: Oracle Linux 10 golang security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-29980

http://linux.oracle.com/errata/ELSA-2026-29980.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
go-toolset-1.26.5-1.0.1.el10_2.x86_64.rpm
golang-1.26.5-1.0.1.el10_2.x86_64.rpm
golang-bin-1.26.5-1.0.1.el10_2.x86_64.rpm
golang-docs-1.26.5-1.0.1.el10_2.noarch.rpm
golang-misc-1.26.5-1.0.1.el10_2.noarch.rpm
golang-race-1.26.5-1.0.1.el10_2.x86_64.rpm
golang-src-1.26.5-1.0.1.el10_2.noarch.rpm
golang-tests-1.26.5-1.0.1.el10_2.noarch.rpm

aarch64:
go-toolset-1.26.5-1.0.1.el10_2.aarch64.rpm
golang-1.26.5-1.0.1.el10_2.aarch64.rpm
golang-bin-1.26.5-1.0.1.el10_2.aarch64.rpm
golang-docs-1.26.5-1.0.1.el10_2.noarch.rpm
golang-misc-1.26.5-1.0.1.el10_2.noarch.rpm
golang-race-1.26.5-1.0.1.el10_2.aarch64.rpm
golang-src-1.26.5-1.0.1.el10_2.noarch.rpm
golang-tests-1.26.5-1.0.1.el10_2.noarch.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/golang-1.26.5-1.0.1.el10_2.src.rpm

Related CVEs:

CVE-2026-42507

Description of changes:

[1.26.5-1.0.1]
- EXPERIMENTAL: Introduce fipsnoenforceems GODEBUG var

[1.26.5-1]
- Update to Go 1.26.5 (fips-1)

[1.25.7-1]
- Update to Go 1.25.7 (fips-1)

[1.25.5-1]
- Update to Go 1.25.5 (fips-1)

[1.25.3-5]
- gating.yaml: Add tier1 s390x tests

[1.25.3-4]
- Cleanup lib/ ownership
- Remove legacy logic forcing lib/ into golang-tests
- Move lib/wasm, lib/fips140, and lib/time to main golang package
- Fixes go_js_wasm_exec availability

[1.25.3-3]
- plans/tier0.fmf: Import plan

[1.25.3-2]
- rpminspect.yaml: Add testdata to annocheck ignore

[1.25.3-1]
- Update to Go 1.25.3

[1.25.1-1]
- Update to Go1.25.1 -Resolves: RHEL-116849



ELBA-2026-39326 Oracle Linux 10 openssl bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2026-39326

http://linux.oracle.com/errata/ELBA-2026-39326.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
openssl-3.5.5-5.0.1.el10_2.x86_64.rpm
openssl-devel-3.5.5-5.0.1.el10_2.x86_64.rpm
openssl-libs-3.5.5-5.0.1.el10_2.x86_64.rpm
openssl-perl-3.5.5-5.0.1.el10_2.x86_64.rpm

aarch64:
openssl-3.5.5-5.0.1.el10_2.aarch64.rpm
openssl-devel-3.5.5-5.0.1.el10_2.aarch64.rpm
openssl-libs-3.5.5-5.0.1.el10_2.aarch64.rpm
openssl-perl-3.5.5-5.0.1.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/openssl-3.5.5-5.0.1.el10_2.src.rpm

Description of changes:

[3.5.5-5.0.1]
- Replace upstream references [Orabug: 34340177]
- Update FIPS provider name [Orabug: 35824276]

[1:3.5.5-5]
- Patch asn1_d2i_read_bio to read headers without blocking
Resolves: RHEL-169991

[1:3.5.5-4]
- Fix CVE-2026-7383, CVE-2026-9076, CVE-2026-34180, CVE-2026-34181,
CVE-2026-34183, CVE-2026-42764, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768,
CVE-2026-42769, CVE-2026-42770, CVE-2026-45445, CVE-2026-45446, CVE-2026-45447,
CVE-2026-34182.
Resolves: RHEL-179267
Resolves: RHEL-179281
Resolves: RHEL-179537
Resolves: RHEL-179542
Resolves: RHEL-179545
Resolves: RHEL-179550
Resolves: RHEL-179553
Resolves: RHEL-179626
Resolves: RHEL-179658
Resolves: RHEL-179675
Resolves: RHEL-179682
Resolves: RHEL-179685
Resolves: RHEL-179689
Resolves: RHEL-179693
Resolves: RHEL-179697

[1:3.5.5-3]
- Fix CVE-2026-28390
Resolves: RHEL-165705



ELSA-2026-24386 Important: Oracle Linux 10 podman security update


Oracle Linux Security Advisory ELSA-2026-24386

http://linux.oracle.com/errata/ELSA-2026-24386.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
podman-5.8.2-5.0.1.el10_2.x86_64.rpm
podman-docker-5.8.2-5.0.1.el10_2.noarch.rpm
podman-remote-5.8.2-5.0.1.el10_2.x86_64.rpm
podman-tests-5.8.2-5.0.1.el10_2.x86_64.rpm

aarch64:
podman-5.8.2-5.0.1.el10_2.aarch64.rpm
podman-docker-5.8.2-5.0.1.el10_2.noarch.rpm
podman-remote-5.8.2-5.0.1.el10_2.aarch64.rpm
podman-tests-5.8.2-5.0.1.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/podman-5.8.2-5.0.1.el10_2.src.rpm

Related CVEs:

CVE-2026-25679

Description of changes:

[5.8.2-5.0.1]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404]

[7:5.8.2-5]
- rebuild for CVE-2026-39822
- Resolves: RHEL-193642

[7:5.8.2-4]
- update to the latest state of the sustaining branch
- fixes CVE-2026-42508 CVE-2026-39829 CVE-2026-39830 CVE-2026-39832 CVE-2026-39835
- fixes CVE-2026-57231 CVE-2026-25681 CVE-2026-27136
- Resolves: RHEL-173842 RHEL-185604 RHEL-185920 RHEL-186263 RHEL-188713 RHEL-190073 RHEL-190857 RHEL-191095 RHEL-191546 RHEL-192440

[7:5.8.2-3]
- Rebuild for CVE-2026-32283
- Resolves: RHEL-167501

[7:5.8.2-2]
- Rebuild for CVE-2026-25679
- Resolves: RHEL-158493



ELSA-2026-18289 Important: Oracle Linux 10 podman security update


Oracle Linux Security Advisory ELSA-2026-18289

http://linux.oracle.com/errata/ELSA-2026-18289.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
podman-5.8.2-5.0.1.el10_2.x86_64.rpm
podman-docker-5.8.2-5.0.1.el10_2.noarch.rpm
podman-remote-5.8.2-5.0.1.el10_2.x86_64.rpm
podman-tests-5.8.2-5.0.1.el10_2.x86_64.rpm

aarch64:
podman-5.8.2-5.0.1.el10_2.aarch64.rpm
podman-docker-5.8.2-5.0.1.el10_2.noarch.rpm
podman-remote-5.8.2-5.0.1.el10_2.aarch64.rpm
podman-tests-5.8.2-5.0.1.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/podman-5.8.2-5.0.1.el10_2.src.rpm

Related CVEs:

CVE-2025-9566

Description of changes:

[5.8.2-5.0.1]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404]

[7:5.8.2-5]
- rebuild for CVE-2026-39822
- Resolves: RHEL-193642

[7:5.8.2-4]
- update to the latest state of the sustaining branch
- fixes CVE-2026-42508 CVE-2026-39829 CVE-2026-39830 CVE-2026-39832 CVE-2026-39835
- fixes CVE-2026-57231 CVE-2026-25681 CVE-2026-27136
- Resolves: RHEL-173842 RHEL-185604 RHEL-185920 RHEL-186263 RHEL-188713 RHEL-190073 RHEL-190857 RHEL-191095 RHEL-191546 RHEL-192440

[7:5.8.2-3]
- Rebuild for CVE-2026-32283
- Resolves: RHEL-167501

[7:5.8.2-2]
- Rebuild for CVE-2026-25679
- Resolves: RHEL-158493



ELSA-2026-19142 Moderate: Oracle Linux 10 freerdp security update


Oracle Linux Security Advisory ELSA-2026-19142

http://linux.oracle.com/errata/ELSA-2026-19142.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
freerdp-3.10.3-12.el10_2.6.x86_64.rpm
freerdp-devel-3.10.3-12.el10_2.6.x86_64.rpm
freerdp-libs-3.10.3-12.el10_2.6.x86_64.rpm
freerdp-server-3.10.3-12.el10_2.6.x86_64.rpm
libwinpr-3.10.3-12.el10_2.6.x86_64.rpm
libwinpr-devel-3.10.3-12.el10_2.6.x86_64.rpm

aarch64:
freerdp-3.10.3-12.el10_2.6.aarch64.rpm
freerdp-devel-3.10.3-12.el10_2.6.aarch64.rpm
freerdp-libs-3.10.3-12.el10_2.6.aarch64.rpm
freerdp-server-3.10.3-12.el10_2.6.aarch64.rpm
libwinpr-3.10.3-12.el10_2.6.aarch64.rpm
libwinpr-devel-3.10.3-12.el10_2.6.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/freerdp-3.10.3-12.el10_2.6.src.rpm

Related CVEs:

CVE-2026-25952
CVE-2026-25997
CVE-2026-26986
CVE-2026-29775
CVE-2026-31883
CVE-2026-31884
CVE-2026-31885
CVE-2026-33982
CVE-2026-33985
CVE-2026-33987

Description of changes:

[2:3.10.3-12.6]
- Backport several CVE fixes (CVE-2026-40033, CVE-2026-44420, CVE-2026-44421,
CVE-2026-44422, CVE-2026-45700)
Resolves: RHEL-186978, RHEL-186967, RHEL-186958, RHEL-186950, RHEL-186093

[2:3.10.3-12.5]
- Lock appWindow to fix use-after-free in RAIL mode (CVE-2026-25952)
Resolves: RHEL-159848

[2:3.10.3-12.4]
- Fix double free in xf_rail_window_common cleanup (CVE-2026-26986)
- Fix clipboard use-after-free during auto-reconnect (CVE-2026-25997)
- Fix heap-buffer-overflow in bitmap_cache_put (CVE-2026-29775)
- Add DSP format checks (CVE-2026-31884)
- Fix DSP array bounds checks (CVE-2026-31883)
- Fix DSP array bounds checks (CVE-2026-31885)
- Update PERSISTENT_CACHE_ENTRY::size after realloc (CVE-2026-33987)
- Update CLEAR_GLYPH_ENTRY::count after alloc (CVE-2026-33985)
- Use winpr_aligned_calloc in persistent cache (CVE-2026-33982)
Resolves: RHEL-159804, RHEL-159660, RHEL-161034, RHEL-161469
Resolves: RHEL-161505, RHEL-161072, RHEL-163654, RHEL-168462, RHEL-162931



ELSA-2026-29874 Important: Oracle Linux 10 nginx security update


Oracle Linux Security Advisory ELSA-2026-29874

http://linux.oracle.com/errata/ELSA-2026-29874.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
nginx-1.26.3-6.0.1.el10_2.5.x86_64.rpm
nginx-all-modules-1.26.3-6.0.1.el10_2.5.noarch.rpm
nginx-core-1.26.3-6.0.1.el10_2.5.x86_64.rpm
nginx-filesystem-1.26.3-6.0.1.el10_2.5.noarch.rpm
nginx-mod-devel-1.26.3-6.0.1.el10_2.5.x86_64.rpm
nginx-mod-http-image-filter-1.26.3-6.0.1.el10_2.5.x86_64.rpm
nginx-mod-http-perl-1.26.3-6.0.1.el10_2.5.x86_64.rpm
nginx-mod-http-xslt-filter-1.26.3-6.0.1.el10_2.5.x86_64.rpm
nginx-mod-mail-1.26.3-6.0.1.el10_2.5.x86_64.rpm
nginx-mod-stream-1.26.3-6.0.1.el10_2.5.x86_64.rpm

aarch64:
nginx-1.26.3-6.0.1.el10_2.5.aarch64.rpm
nginx-all-modules-1.26.3-6.0.1.el10_2.5.noarch.rpm
nginx-core-1.26.3-6.0.1.el10_2.5.aarch64.rpm
nginx-filesystem-1.26.3-6.0.1.el10_2.5.noarch.rpm
nginx-mod-devel-1.26.3-6.0.1.el10_2.5.aarch64.rpm
nginx-mod-http-image-filter-1.26.3-6.0.1.el10_2.5.aarch64.rpm
nginx-mod-http-perl-1.26.3-6.0.1.el10_2.5.aarch64.rpm
nginx-mod-http-xslt-filter-1.26.3-6.0.1.el10_2.5.aarch64.rpm
nginx-mod-mail-1.26.3-6.0.1.el10_2.5.aarch64.rpm
nginx-mod-stream-1.26.3-6.0.1.el10_2.5.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/nginx-1.26.3-6.0.1.el10_2.5.src.rpm

Related CVEs:

CVE-2026-9256

Description of changes:

[1.26.3-6.0.1.el10_2.5]
- Reference oracle-indexhtml within Requires [Orabug: 33802044]

[2:1.26.3-6.5]
- Resolves: RHEL-191778 - nginx: "HTTP/2 bomb" nginx fix breaks module ABI
causing crashes
- Resolves: RHEL-188402 - nginx: NGINX: Arbitrary code execution or.
Denial of Service via heap-based buffer overflow with crafted HTTP/2
headers (CVE-2026-42055)

[2:1.26.3-6.4]
- Resolves: RHEL-178669 - nginx: code execution and denial of
service (CVE-2026-9256)
- Resolves: RHEL-182544 - nginx: HTTP/2: Remote Denial of Service via
compression bomb and Slowloris-style attack

[2:1.26.3-6.3]
- Resolves: RHEL-176231 - nginx: NGINX: Arbitrary Code Execution
Vulnerability (CVE-2026-42945)

[2:1.26.3-6.2]
- rebuild for the right candidate tag

[2:1.26.3-6.1]
- RHEL-159547 CVE-2026-27654 nginx: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module
- RHEL-159526 CVE-2026-27784 nginx: NGINX: Denial of Service due to memory corruption via crafted MP4 file
- RHEL-159434 CVE-2026-27651 nginx: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled
- RHEL-157875 CVE-2026-32647 nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files



ELBA-2026-500086 xfsprogs bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-500086

http://linux.oracle.com/errata/ELBA-2026-500086.html

The following updated rpms for have been uploaded to the Unbreakable Linux Network:

x86_64:
xfsprogs-devel-6.18.0-1.0.3.el10.x86_64.rpm
xfsprogs-6.18.0-1.0.3.el10.x86_64.rpm
xfsprogs-xfs_scrub-6.18.0-1.0.3.el10.x86_64.rpm

aarch64:
xfsprogs-devel-6.18.0-1.0.3.el10.aarch64.rpm
xfsprogs-6.18.0-1.0.3.el10.aarch64.rpm
xfsprogs-xfs_scrub-6.18.0-1.0.3.el10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/xfsprogs-6.18.0-1.0.3.el10.src.rpm

Description of changes:

[6.18.0-1.0.3]
- Re-apply missing patch to increase min log size to 100MiB.



ELSA-2026-46394 Important: Oracle Linux 10 go-fdo-client security update


Oracle Linux Security Advisory ELSA-2026-46394

http://linux.oracle.com/errata/ELSA-2026-46394.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
go-fdo-client-1.0.0-4.el10_2.5.x86_64.rpm

aarch64:
go-fdo-client-1.0.0-4.el10_2.5.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/go-fdo-client-1.0.0-4.el10_2.5.src.rpm

Related CVEs:

CVE-2026-27145

Description of changes:

[1.0.0-5]
- Rebuild against updated golang



ELSA-2026-37072 Important: Oracle Linux 10 podman security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-37072

http://linux.oracle.com/errata/ELSA-2026-37072.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
podman-5.8.2-5.0.1.el10_2.x86_64.rpm
podman-docker-5.8.2-5.0.1.el10_2.noarch.rpm
podman-remote-5.8.2-5.0.1.el10_2.x86_64.rpm
podman-tests-5.8.2-5.0.1.el10_2.x86_64.rpm

aarch64:
podman-5.8.2-5.0.1.el10_2.aarch64.rpm
podman-docker-5.8.2-5.0.1.el10_2.noarch.rpm
podman-remote-5.8.2-5.0.1.el10_2.aarch64.rpm
podman-tests-5.8.2-5.0.1.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/podman-5.8.2-5.0.1.el10_2.src.rpm

Related CVEs:

CVE-2026-25681
CVE-2026-27136
CVE-2026-39829
CVE-2026-39830
CVE-2026-39832
CVE-2026-39835
CVE-2026-42508
CVE-2026-57231

Description of changes:

[5.8.2-5.0.1]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404]

[7:5.8.2-5]
- rebuild for CVE-2026-39822
- Resolves: RHEL-193642

[7:5.8.2-4]
- update to the latest state of the sustaining branch
- fixes CVE-2026-42508 CVE-2026-39829 CVE-2026-39830 CVE-2026-39832 CVE-2026-39835
- fixes CVE-2026-57231 CVE-2026-25681 CVE-2026-27136
- Resolves: RHEL-173842 RHEL-185604 RHEL-185920 RHEL-186263 RHEL-188713 RHEL-190073 RHEL-190857 RHEL-191095 RHEL-191546 RHEL-192440

[7:5.8.2-3]
- Rebuild for CVE-2026-32283
- Resolves: RHEL-167501

[7:5.8.2-2]
- Rebuild for CVE-2026-25679
- Resolves: RHEL-158493