ELSA-2026-43505 Important: Oracle Linux 10 mariadb-connector-c security update
ELBA-2026-500062 Unbreakable Enterprise kernel bug fix update
ELSA-2026-46398 Important: Oracle Linux 10 libreswan security update
New Ksplice updates for UEKR6 5.4.17 on OL7 and OL8
ELSA-2026-29980 Moderate: Oracle Linux 10 golang security, bug fix, and enhancement update
ELBA-2026-39326 Oracle Linux 10 openssl bug fix and enhancement update
ELSA-2026-24386 Important: Oracle Linux 10 podman security update
ELSA-2026-18289 Important: Oracle Linux 10 podman security update
ELSA-2026-19142 Moderate: Oracle Linux 10 freerdp security update
ELSA-2026-29874 Important: Oracle Linux 10 nginx security update
ELBA-2026-500086 xfsprogs bug fix update
ELSA-2026-46394 Important: Oracle Linux 10 go-fdo-client security update
ELSA-2026-37072 Important: Oracle Linux 10 podman security, bug fix, and enhancement update
ELSA-2026-43505 Important: Oracle Linux 10 mariadb-connector-c security update
Oracle Linux Security Advisory ELSA-2026-43505
http://linux.oracle.com/errata/ELSA-2026-43505.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
mariadb-connector-c-3.4.4-2.el10_2.x86_64.rpm
mariadb-connector-c-config-3.4.4-2.el10_2.noarch.rpm
mariadb-connector-c-devel-3.4.4-2.el10_2.x86_64.rpm
mariadb-connector-c-doc-3.4.4-2.el10_2.noarch.rpm
mariadb-connector-c-test-3.4.4-2.el10_2.x86_64.rpm
aarch64:
mariadb-connector-c-3.4.4-2.el10_2.aarch64.rpm
mariadb-connector-c-config-3.4.4-2.el10_2.noarch.rpm
mariadb-connector-c-devel-3.4.4-2.el10_2.aarch64.rpm
mariadb-connector-c-doc-3.4.4-2.el10_2.noarch.rpm
mariadb-connector-c-test-3.4.4-2.el10_2.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/mariadb-connector-c-3.4.4-2.el10_2.src.rpm
Related CVEs:
CVE-2026-44172
Description of changes:
[3.4.4-2]
- CVE-2026-44172 fix
ELBA-2026-500062 Unbreakable Enterprise kernel bug fix update
Oracle Linux Bug Fix Advisory ELBA-2026-500062
http://linux.oracle.com/errata/ELBA-2026-500062.html
The following updated rpms for have been uploaded to the Unbreakable Linux Network:
x86_64:
kernel-uek-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-core-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-devel-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-doc-6.12.0-204.92.4.4.el10uek.noarch.rpm
kernel-uek-modules-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-modules-core-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-modules-deprecated-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-modules-desktop-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-modules-extra-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-modules-extra-netfilter-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-modules-usb-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-modules-wireless-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-tools-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-core-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-devel-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-modules-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-modules-core-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-modules-deprecated-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-modules-desktop-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-modules-extra-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-modules-extra-netfilter-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-modules-usb-6.12.0-204.92.4.4.el10uek.x86_64.rpm
kernel-uek-debug-modules-wireless-6.12.0-204.92.4.4.el10uek.x86_64.rpm
aarch64:
kernel-uek-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-core-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-devel-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-doc-6.12.0-204.92.4.4.el10uek.noarch.rpm
kernel-uek-modules-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-modules-core-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-modules-deprecated-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-modules-desktop-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-modules-extra-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-modules-extra-netfilter-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-modules-usb-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-modules-wireless-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-tools-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-core-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-devel-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-modules-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-modules-core-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-modules-deprecated-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-modules-desktop-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-modules-extra-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-modules-extra-netfilter-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-modules-usb-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek-debug-modules-wireless-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-core-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-devel-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-modules-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-modules-core-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-modules-deprecated-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-modules-desktop-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-modules-extra-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-modules-extra-netfilter-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-modules-usb-6.12.0-204.92.4.4.el10uek.aarch64.rpm
kernel-uek64k-modules-wireless-6.12.0-204.92.4.4.el10uek.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/kernel-uek-6.12.0-204.92.4.4.el10uek.src.rpm
Description of changes:
[6.12.0-204.92.4.4]
- Revert "arm64: acpi: Enable ACPI CCEL support" (Will Deacon) [Orabug: 39772225]
- virtio_pci: fix vq info pointer lookup via wrong index (Ammar Faizi) [Orabug: 39772224]
ELSA-2026-46398 Important: Oracle Linux 10 libreswan security update
Oracle Linux Security Advisory ELSA-2026-46398
http://linux.oracle.com/errata/ELSA-2026-46398.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
libreswan-5.3.2-1.el10_2.x86_64.rpm
libreswan-minimal-5.3.2-1.el10_2.x86_64.rpm
aarch64:
libreswan-5.3.2-1.el10_2.aarch64.rpm
libreswan-minimal-5.3.2-1.el10_2.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/libreswan-5.3.2-1.el10_2.src.rpm
Related CVEs:
CVE-2026-12413
CVE-2026-14957
CVE-2026-50721
CVE-2026-50722
Description of changes:
[5.3.2-1.0.1]
- Add libreswan-oracle.patch to detect Oracle Linux distro
[5.3.2-1]
- Update to libreswan-5.3.2
[5.3.1-1]
- Update to libreswan-5.3.1
Synopsis: Following CVEs can now be patched using Ksplice
CVEs: CVE-2026-43038 CVE-2026-46043 CVE-2026-64600
Users with Oracle Linux Premier Support can now use Ksplice to patch
against the latest CVE fixes.
INSTALLING THE UPDATES
We recommend that all users of Ksplice Uptrack running UEKR6 5.4.17 on
OL7 and OL8 install these updates.
On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.
Alternatively, you can install these updates by running:
# /usr/sbin/uptrack-upgrade -y
DESCRIPTION
* CVE-2026-43038: Out-of-bounds memory access in IPv6 networking stack.
Orabug: 39300930
* CVE-2026-46043: Out-of-bounds memory access in RDMA RXE driver.
Orabug: 39452261
SUPPORT
Ksplice support is available at ksplice-support_ww@oracle.com.
ELSA-2026-29980 Moderate: Oracle Linux 10 golang security, bug fix, and enhancement update
Oracle Linux Security Advisory ELSA-2026-29980
http://linux.oracle.com/errata/ELSA-2026-29980.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
go-toolset-1.26.5-1.0.1.el10_2.x86_64.rpm
golang-1.26.5-1.0.1.el10_2.x86_64.rpm
golang-bin-1.26.5-1.0.1.el10_2.x86_64.rpm
golang-docs-1.26.5-1.0.1.el10_2.noarch.rpm
golang-misc-1.26.5-1.0.1.el10_2.noarch.rpm
golang-race-1.26.5-1.0.1.el10_2.x86_64.rpm
golang-src-1.26.5-1.0.1.el10_2.noarch.rpm
golang-tests-1.26.5-1.0.1.el10_2.noarch.rpm
aarch64:
go-toolset-1.26.5-1.0.1.el10_2.aarch64.rpm
golang-1.26.5-1.0.1.el10_2.aarch64.rpm
golang-bin-1.26.5-1.0.1.el10_2.aarch64.rpm
golang-docs-1.26.5-1.0.1.el10_2.noarch.rpm
golang-misc-1.26.5-1.0.1.el10_2.noarch.rpm
golang-race-1.26.5-1.0.1.el10_2.aarch64.rpm
golang-src-1.26.5-1.0.1.el10_2.noarch.rpm
golang-tests-1.26.5-1.0.1.el10_2.noarch.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/golang-1.26.5-1.0.1.el10_2.src.rpm
Related CVEs:
CVE-2026-42507
Description of changes:
[1.26.5-1.0.1]
- EXPERIMENTAL: Introduce fipsnoenforceems GODEBUG var
[1.26.5-1]
- Update to Go 1.26.5 (fips-1)
[1.25.7-1]
- Update to Go 1.25.7 (fips-1)
[1.25.5-1]
- Update to Go 1.25.5 (fips-1)
[1.25.3-5]
- gating.yaml: Add tier1 s390x tests
[1.25.3-4]
- Cleanup lib/ ownership
- Remove legacy logic forcing lib/ into golang-tests
- Move lib/wasm, lib/fips140, and lib/time to main golang package
- Fixes go_js_wasm_exec availability
[1.25.3-3]
- plans/tier0.fmf: Import plan
[1.25.3-2]
- rpminspect.yaml: Add testdata to annocheck ignore
[1.25.3-1]
- Update to Go 1.25.3
[1.25.1-1]
- Update to Go1.25.1 -Resolves: RHEL-116849
ELBA-2026-39326 Oracle Linux 10 openssl bug fix and enhancement update
Oracle Linux Bug Fix Advisory ELBA-2026-39326
http://linux.oracle.com/errata/ELBA-2026-39326.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
openssl-3.5.5-5.0.1.el10_2.x86_64.rpm
openssl-devel-3.5.5-5.0.1.el10_2.x86_64.rpm
openssl-libs-3.5.5-5.0.1.el10_2.x86_64.rpm
openssl-perl-3.5.5-5.0.1.el10_2.x86_64.rpm
aarch64:
openssl-3.5.5-5.0.1.el10_2.aarch64.rpm
openssl-devel-3.5.5-5.0.1.el10_2.aarch64.rpm
openssl-libs-3.5.5-5.0.1.el10_2.aarch64.rpm
openssl-perl-3.5.5-5.0.1.el10_2.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/openssl-3.5.5-5.0.1.el10_2.src.rpm
Description of changes:
[3.5.5-5.0.1]
- Replace upstream references [Orabug: 34340177]
- Update FIPS provider name [Orabug: 35824276]
[1:3.5.5-5]
- Patch asn1_d2i_read_bio to read headers without blocking
Resolves: RHEL-169991
[1:3.5.5-4]
- Fix CVE-2026-7383, CVE-2026-9076, CVE-2026-34180, CVE-2026-34181,
CVE-2026-34183, CVE-2026-42764, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768,
CVE-2026-42769, CVE-2026-42770, CVE-2026-45445, CVE-2026-45446, CVE-2026-45447,
CVE-2026-34182.
Resolves: RHEL-179267
Resolves: RHEL-179281
Resolves: RHEL-179537
Resolves: RHEL-179542
Resolves: RHEL-179545
Resolves: RHEL-179550
Resolves: RHEL-179553
Resolves: RHEL-179626
Resolves: RHEL-179658
Resolves: RHEL-179675
Resolves: RHEL-179682
Resolves: RHEL-179685
Resolves: RHEL-179689
Resolves: RHEL-179693
Resolves: RHEL-179697
[1:3.5.5-3]
- Fix CVE-2026-28390
Resolves: RHEL-165705
ELSA-2026-24386 Important: Oracle Linux 10 podman security update
Oracle Linux Security Advisory ELSA-2026-24386
http://linux.oracle.com/errata/ELSA-2026-24386.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
podman-5.8.2-5.0.1.el10_2.x86_64.rpm
podman-docker-5.8.2-5.0.1.el10_2.noarch.rpm
podman-remote-5.8.2-5.0.1.el10_2.x86_64.rpm
podman-tests-5.8.2-5.0.1.el10_2.x86_64.rpm
aarch64:
podman-5.8.2-5.0.1.el10_2.aarch64.rpm
podman-docker-5.8.2-5.0.1.el10_2.noarch.rpm
podman-remote-5.8.2-5.0.1.el10_2.aarch64.rpm
podman-tests-5.8.2-5.0.1.el10_2.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/podman-5.8.2-5.0.1.el10_2.src.rpm
Related CVEs:
CVE-2026-25679
Description of changes:
[5.8.2-5.0.1]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404]
[7:5.8.2-5]
- rebuild for CVE-2026-39822
- Resolves: RHEL-193642
[7:5.8.2-4]
- update to the latest state of the sustaining branch
- fixes CVE-2026-42508 CVE-2026-39829 CVE-2026-39830 CVE-2026-39832 CVE-2026-39835
- fixes CVE-2026-57231 CVE-2026-25681 CVE-2026-27136
- Resolves: RHEL-173842 RHEL-185604 RHEL-185920 RHEL-186263 RHEL-188713 RHEL-190073 RHEL-190857 RHEL-191095 RHEL-191546 RHEL-192440
[7:5.8.2-3]
- Rebuild for CVE-2026-32283
- Resolves: RHEL-167501
[7:5.8.2-2]
- Rebuild for CVE-2026-25679
- Resolves: RHEL-158493
ELSA-2026-18289 Important: Oracle Linux 10 podman security update
Oracle Linux Security Advisory ELSA-2026-18289
http://linux.oracle.com/errata/ELSA-2026-18289.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
podman-5.8.2-5.0.1.el10_2.x86_64.rpm
podman-docker-5.8.2-5.0.1.el10_2.noarch.rpm
podman-remote-5.8.2-5.0.1.el10_2.x86_64.rpm
podman-tests-5.8.2-5.0.1.el10_2.x86_64.rpm
aarch64:
podman-5.8.2-5.0.1.el10_2.aarch64.rpm
podman-docker-5.8.2-5.0.1.el10_2.noarch.rpm
podman-remote-5.8.2-5.0.1.el10_2.aarch64.rpm
podman-tests-5.8.2-5.0.1.el10_2.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/podman-5.8.2-5.0.1.el10_2.src.rpm
Related CVEs:
CVE-2025-9566
Description of changes:
[5.8.2-5.0.1]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404]
[7:5.8.2-5]
- rebuild for CVE-2026-39822
- Resolves: RHEL-193642
[7:5.8.2-4]
- update to the latest state of the sustaining branch
- fixes CVE-2026-42508 CVE-2026-39829 CVE-2026-39830 CVE-2026-39832 CVE-2026-39835
- fixes CVE-2026-57231 CVE-2026-25681 CVE-2026-27136
- Resolves: RHEL-173842 RHEL-185604 RHEL-185920 RHEL-186263 RHEL-188713 RHEL-190073 RHEL-190857 RHEL-191095 RHEL-191546 RHEL-192440
[7:5.8.2-3]
- Rebuild for CVE-2026-32283
- Resolves: RHEL-167501
[7:5.8.2-2]
- Rebuild for CVE-2026-25679
- Resolves: RHEL-158493
ELSA-2026-19142 Moderate: Oracle Linux 10 freerdp security update
Oracle Linux Security Advisory ELSA-2026-19142
http://linux.oracle.com/errata/ELSA-2026-19142.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
freerdp-3.10.3-12.el10_2.6.x86_64.rpm
freerdp-devel-3.10.3-12.el10_2.6.x86_64.rpm
freerdp-libs-3.10.3-12.el10_2.6.x86_64.rpm
freerdp-server-3.10.3-12.el10_2.6.x86_64.rpm
libwinpr-3.10.3-12.el10_2.6.x86_64.rpm
libwinpr-devel-3.10.3-12.el10_2.6.x86_64.rpm
aarch64:
freerdp-3.10.3-12.el10_2.6.aarch64.rpm
freerdp-devel-3.10.3-12.el10_2.6.aarch64.rpm
freerdp-libs-3.10.3-12.el10_2.6.aarch64.rpm
freerdp-server-3.10.3-12.el10_2.6.aarch64.rpm
libwinpr-3.10.3-12.el10_2.6.aarch64.rpm
libwinpr-devel-3.10.3-12.el10_2.6.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/freerdp-3.10.3-12.el10_2.6.src.rpm
Related CVEs:
CVE-2026-25952
CVE-2026-25997
CVE-2026-26986
CVE-2026-29775
CVE-2026-31883
CVE-2026-31884
CVE-2026-31885
CVE-2026-33982
CVE-2026-33985
CVE-2026-33987
Description of changes:
[2:3.10.3-12.6]
- Backport several CVE fixes (CVE-2026-40033, CVE-2026-44420, CVE-2026-44421,
CVE-2026-44422, CVE-2026-45700)
Resolves: RHEL-186978, RHEL-186967, RHEL-186958, RHEL-186950, RHEL-186093
[2:3.10.3-12.5]
- Lock appWindow to fix use-after-free in RAIL mode (CVE-2026-25952)
Resolves: RHEL-159848
[2:3.10.3-12.4]
- Fix double free in xf_rail_window_common cleanup (CVE-2026-26986)
- Fix clipboard use-after-free during auto-reconnect (CVE-2026-25997)
- Fix heap-buffer-overflow in bitmap_cache_put (CVE-2026-29775)
- Add DSP format checks (CVE-2026-31884)
- Fix DSP array bounds checks (CVE-2026-31883)
- Fix DSP array bounds checks (CVE-2026-31885)
- Update PERSISTENT_CACHE_ENTRY::size after realloc (CVE-2026-33987)
- Update CLEAR_GLYPH_ENTRY::count after alloc (CVE-2026-33985)
- Use winpr_aligned_calloc in persistent cache (CVE-2026-33982)
Resolves: RHEL-159804, RHEL-159660, RHEL-161034, RHEL-161469
Resolves: RHEL-161505, RHEL-161072, RHEL-163654, RHEL-168462, RHEL-162931
ELSA-2026-29874 Important: Oracle Linux 10 nginx security update
Oracle Linux Security Advisory ELSA-2026-29874
http://linux.oracle.com/errata/ELSA-2026-29874.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
nginx-1.26.3-6.0.1.el10_2.5.x86_64.rpm
nginx-all-modules-1.26.3-6.0.1.el10_2.5.noarch.rpm
nginx-core-1.26.3-6.0.1.el10_2.5.x86_64.rpm
nginx-filesystem-1.26.3-6.0.1.el10_2.5.noarch.rpm
nginx-mod-devel-1.26.3-6.0.1.el10_2.5.x86_64.rpm
nginx-mod-http-image-filter-1.26.3-6.0.1.el10_2.5.x86_64.rpm
nginx-mod-http-perl-1.26.3-6.0.1.el10_2.5.x86_64.rpm
nginx-mod-http-xslt-filter-1.26.3-6.0.1.el10_2.5.x86_64.rpm
nginx-mod-mail-1.26.3-6.0.1.el10_2.5.x86_64.rpm
nginx-mod-stream-1.26.3-6.0.1.el10_2.5.x86_64.rpm
aarch64:
nginx-1.26.3-6.0.1.el10_2.5.aarch64.rpm
nginx-all-modules-1.26.3-6.0.1.el10_2.5.noarch.rpm
nginx-core-1.26.3-6.0.1.el10_2.5.aarch64.rpm
nginx-filesystem-1.26.3-6.0.1.el10_2.5.noarch.rpm
nginx-mod-devel-1.26.3-6.0.1.el10_2.5.aarch64.rpm
nginx-mod-http-image-filter-1.26.3-6.0.1.el10_2.5.aarch64.rpm
nginx-mod-http-perl-1.26.3-6.0.1.el10_2.5.aarch64.rpm
nginx-mod-http-xslt-filter-1.26.3-6.0.1.el10_2.5.aarch64.rpm
nginx-mod-mail-1.26.3-6.0.1.el10_2.5.aarch64.rpm
nginx-mod-stream-1.26.3-6.0.1.el10_2.5.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/nginx-1.26.3-6.0.1.el10_2.5.src.rpm
Related CVEs:
CVE-2026-9256
Description of changes:
[1.26.3-6.0.1.el10_2.5]
- Reference oracle-indexhtml within Requires [Orabug: 33802044]
[2:1.26.3-6.5]
- Resolves: RHEL-191778 - nginx: "HTTP/2 bomb" nginx fix breaks module ABI
causing crashes
- Resolves: RHEL-188402 - nginx: NGINX: Arbitrary code execution or.
Denial of Service via heap-based buffer overflow with crafted HTTP/2
headers (CVE-2026-42055)
[2:1.26.3-6.4]
- Resolves: RHEL-178669 - nginx: code execution and denial of
service (CVE-2026-9256)
- Resolves: RHEL-182544 - nginx: HTTP/2: Remote Denial of Service via
compression bomb and Slowloris-style attack
[2:1.26.3-6.3]
- Resolves: RHEL-176231 - nginx: NGINX: Arbitrary Code Execution
Vulnerability (CVE-2026-42945)
[2:1.26.3-6.2]
- rebuild for the right candidate tag
[2:1.26.3-6.1]
- RHEL-159547 CVE-2026-27654 nginx: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module
- RHEL-159526 CVE-2026-27784 nginx: NGINX: Denial of Service due to memory corruption via crafted MP4 file
- RHEL-159434 CVE-2026-27651 nginx: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled
- RHEL-157875 CVE-2026-32647 nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files
ELBA-2026-500086 xfsprogs bug fix update
Oracle Linux Bug Fix Advisory ELBA-2026-500086
http://linux.oracle.com/errata/ELBA-2026-500086.html
The following updated rpms for have been uploaded to the Unbreakable Linux Network:
x86_64:
xfsprogs-devel-6.18.0-1.0.3.el10.x86_64.rpm
xfsprogs-6.18.0-1.0.3.el10.x86_64.rpm
xfsprogs-xfs_scrub-6.18.0-1.0.3.el10.x86_64.rpm
aarch64:
xfsprogs-devel-6.18.0-1.0.3.el10.aarch64.rpm
xfsprogs-6.18.0-1.0.3.el10.aarch64.rpm
xfsprogs-xfs_scrub-6.18.0-1.0.3.el10.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/xfsprogs-6.18.0-1.0.3.el10.src.rpm
Description of changes:
[6.18.0-1.0.3]
- Re-apply missing patch to increase min log size to 100MiB.
ELSA-2026-46394 Important: Oracle Linux 10 go-fdo-client security update
Oracle Linux Security Advisory ELSA-2026-46394
http://linux.oracle.com/errata/ELSA-2026-46394.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
go-fdo-client-1.0.0-4.el10_2.5.x86_64.rpm
aarch64:
go-fdo-client-1.0.0-4.el10_2.5.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/go-fdo-client-1.0.0-4.el10_2.5.src.rpm
Related CVEs:
CVE-2026-27145
Description of changes:
[1.0.0-5]
- Rebuild against updated golang
ELSA-2026-37072 Important: Oracle Linux 10 podman security, bug fix, and enhancement update
Oracle Linux Security Advisory ELSA-2026-37072
http://linux.oracle.com/errata/ELSA-2026-37072.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
podman-5.8.2-5.0.1.el10_2.x86_64.rpm
podman-docker-5.8.2-5.0.1.el10_2.noarch.rpm
podman-remote-5.8.2-5.0.1.el10_2.x86_64.rpm
podman-tests-5.8.2-5.0.1.el10_2.x86_64.rpm
aarch64:
podman-5.8.2-5.0.1.el10_2.aarch64.rpm
podman-docker-5.8.2-5.0.1.el10_2.noarch.rpm
podman-remote-5.8.2-5.0.1.el10_2.aarch64.rpm
podman-tests-5.8.2-5.0.1.el10_2.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/podman-5.8.2-5.0.1.el10_2.src.rpm
Related CVEs:
CVE-2026-25681
CVE-2026-27136
CVE-2026-39829
CVE-2026-39830
CVE-2026-39832
CVE-2026-39835
CVE-2026-42508
CVE-2026-57231
Description of changes:
[5.8.2-5.0.1]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404]
[7:5.8.2-5]
- rebuild for CVE-2026-39822
- Resolves: RHEL-193642
[7:5.8.2-4]
- update to the latest state of the sustaining branch
- fixes CVE-2026-42508 CVE-2026-39829 CVE-2026-39830 CVE-2026-39832 CVE-2026-39835
- fixes CVE-2026-57231 CVE-2026-25681 CVE-2026-27136
- Resolves: RHEL-173842 RHEL-185604 RHEL-185920 RHEL-186263 RHEL-188713 RHEL-190073 RHEL-190857 RHEL-191095 RHEL-191546 RHEL-192440
[7:5.8.2-3]
- Rebuild for CVE-2026-32283
- Resolves: RHEL-167501
[7:5.8.2-2]
- Rebuild for CVE-2026-25679
- Resolves: RHEL-158493