Oracle Linux 6531 Published by

Oracle Linux just released a broad batch of errata covering versions seven through ten, delivering security patches and routine maintenance across the operating system. The updates touch core infrastructure, including the mainline and Unbreakable Enterprise kernels, Ruby, PHP, Node.js, libpng12, timezone databases, and SELinux policy sets. Security researchers should prioritize the fixes for dozens of tracked vulnerabilities that affect KVM virtualization, the IPv6 networking stack, cryptographic routines, and USB device handling.

ELBA-2026-47011-1 Oracle Linux 8 kernel bug fix update
ELSA-2026-43702 Moderate: Oracle Linux 7 libpng12 security update
ELBA-2026-51070 Oracle Linux 7 tzdata bug fix and enhancement update
ELSA-2026-33685 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
ELSA-2026-52841 Important: Oracle Linux 10 nodejs-nodemon security update
ELBA-2026-50154-0 Oracle Linux 10 linux-firmware bug fix and enhancement update
ELBA-2026-50146-0 Oracle Linux 10 selinux-policy bug fix and enhancement update
ELSA-2026-51295 Moderate: Oracle Linux 10 kernel security, bug fix, and enhancement update
ELBA-2026-500139 Oracle Linux 10 nodejs22 bug fix update
ELSA-2026-52675 Moderate: Oracle Linux 10 libarchive security update
ELBA-2026-500144 Oracle Linux 10 nodejs24 bug fix update
ELSA-2026-500150 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
ELBA-2026-500147 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
ELSA-2026-50828 Important: Oracle Linux 9 ruby:3.3 security, bug fix, and enhancement update
ELBA-2026-500147 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
ELSA-2026-50827 Important: Oracle Linux 9 ruby:4.0 security, bug fix, and enhancement update
ELSA-2026-48197 Low: Oracle Linux 9 php:8.3 security, bug fix, and enhancement update
ELSA-2026-51153 Important: Oracle Linux 9 gpsd-minimal security update
ELBA-2026-500152 Oracle Linux 9 xfsprogs bug fix update
ELBA-2026-500120 Oracle Linux 9 leapp-repository bug fix update
ELBA-2026-49214-1 Oracle Linux 8 kernel bug fix update
ELBA-2026-47121 Oracle Linux 8 linux-firmware bug fix and enhancement update




ELBA-2026-47011-1 Oracle Linux 8 kernel bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-47011-1

http://linux.oracle.com/errata/ELBA-2026-47011-1.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
bpftool-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm
kernel-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm
kernel-abi-stablelists-4.18.0-553.148.1.0.1.el8_10.noarch.rpm
kernel-core-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm
kernel-cross-headers-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm
kernel-debug-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm
kernel-debug-core-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm
kernel-debug-devel-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm
kernel-debug-modules-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm
kernel-debug-modules-extra-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm
kernel-devel-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm
kernel-doc-4.18.0-553.148.1.0.1.el8_10.noarch.rpm
kernel-headers-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm
kernel-modules-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm
kernel-modules-extra-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm
kernel-tools-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm
kernel-tools-libs-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm
kernel-tools-libs-devel-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm
perf-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm
python3-perf-4.18.0-553.148.1.0.1.el8_10.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/kernel-4.18.0-553.148.1.0.1.el8_10.src.rpm

Description of changes:

[4.18.0-553.148.1.0.1]
- scsi: core: Restrict legal sdev_state transitions via sysfs (Uday Shankar) [Orabug: 37778230]

[4.18.0-553.148.1]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 arch.pio* (Aidan Wallace) [RHEL-211228]
- KVM: x86: move all vcpu->arch.pio* setup in emulator_pio_in_out() (Aidan Wallace) [RHEL-211228]
- KVM: x86: drop PIO from unregistered devices (Aidan Wallace) [RHEL-211228]
- KVM: x86: inline kernel_pio into its sole caller (Aidan Wallace) [RHEL-211228]
- serial: 8250_mid: Disable DMA for selected platforms (Mark Salter) [RHEL-190191]
- tipc: fix double-free in tipc_buf_append() (CKI Backport Bot) [RHEL-192178] {CVE-2026-52993}
- xfrm: esp: restore combined single-frag length gate (CKI Backport Bot) [RHEL-178324]
- dm log: fix out-of-bounds write due to region_count overflow (CKI Backport Bot) [RHEL-188543] {CVE-2026-53059}
- xfs: Use xarray to track SB UUIDs instead of plain array. (Lukas Herbolt) [RHEL-127174]
- selftests: kvm: try getting XFD and XSAVE state out of sync (Paolo Bonzini) [RHEL-166738]
- selftests: kvm: replace numbering of sync points with actions (Paolo Bonzini) [RHEL-166738]
- x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state whenever XFD[i]=1 (Paolo Bonzini) [RHEL-166738]
- mount: Retest MNT_LOCKED in do_umount (Ian Kent) [RHEL-152655]
- mount: Don't allow copying MNT_UNBINDABLE|MNT_LOCKED mounts (Ian Kent) [RHEL-152655]
- mount: Prevent MNT_DETACH from disconnecting locked mounts (Ian Kent) [RHEL-152655]



ELSA-2026-43702 Moderate: Oracle Linux 7 libpng12 security update


Oracle Linux Security Advisory ELSA-2026-43702

http://linux.oracle.com/errata/ELSA-2026-43702.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
libpng12-1.2.50-10.0.3.el7.i686.rpm
libpng12-1.2.50-10.0.3.el7.x86_64.rpm
libpng12-devel-1.2.50-10.0.3.el7.i686.rpm
libpng12-devel-1.2.50-10.0.3.el7.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/libpng12-1.2.50-10.0.3.el7.src.rpm

Related CVEs:

CVE-2026-33416

Description of changes:

[1.2.50-10.0.3]
- Fix CVE-2026-33416: use-after-free via pointer aliasing in png_set_tRNS and
png_set_PLTE [Orabug: 39771480]

[1.2.50-10.0.1]
- Fix CVE-2026-25646: heap buffer overflow in png_set_quantize [Orabug: 39183864]



ELBA-2026-51070 Oracle Linux 7 tzdata bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2026-51070

http://linux.oracle.com/errata/ELBA-2026-51070.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
tzdata-2026c-1.el7.noarch.rpm
tzdata-java-2026c-1.el7.noarch.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/tzdata-2026c-1.el7.src.rpm

Description of changes:

[2026c-1]
- Update to tzdata-2026c (RHEL-194104)
- Alberta moved to permanent -06 on 2026-06-18.
- Morocco moves to permanent +00 on 2026-09-20.

[2026b-1]
- Update to tzdata-2026b (RHEL-170797)
- British Columbia’s 2026-03-08 spring forward is expected
to be its last transition as it moves to permanent -07.

[2026a-1]
- Update to tzdata-2026a (RHEL-154033)
- Correct the transition times for Moldova.
- The POSIXRULES option is now obsolete.

[2025c-1]
- Update to tzdata-2025c (RHEL-135159)
- Update leap seconds file expiration date

[2025b-2]
- Included NEWS file with docs. (RHEL-102379)

[2025b-1]
- Update to tzdata-2025b (RHEL-84741)
- Chile's Aysén Region moves from -04/-03
to -03 year-round, diverging from America/Santiago and
creating a new zone America/Coyhaique.

[2025a-1]
Update to tzdata-2025a (RHEL-74308)
- Paraguay is now permanently at -03. This impacts timestamps
starting on 2025-03-22.
- Includes improvements to pre-1991 data for the Philippines.
- Etc/Unknown is now reserved.



ELSA-2026-33685 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-33685

http://linux.oracle.com/errata/ELSA-2026-33685.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-abi-stablelists-6.12.0-211.34.1.el10_2.noarch.rpm
kernel-core-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-cross-headers-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-core-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-devel-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-devel-matched-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-modules-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-modules-core-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-modules-extra-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-uki-virt-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-devel-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-devel-matched-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-doc-6.12.0-211.34.1.el10_2.noarch.rpm
kernel-headers-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-modules-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-modules-core-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-modules-extra-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-modules-extra-matched-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-tools-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-tools-libs-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-tools-libs-devel-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-uki-virt-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-uki-virt-addons-6.12.0-211.34.1.el10_2.x86_64.rpm
libperf-6.12.0-211.34.1.el10_2.x86_64.rpm
perf-6.12.0-211.34.1.el10_2.x86_64.rpm
python3-perf-6.12.0-211.34.1.el10_2.x86_64.rpm
rtla-6.12.0-211.34.1.el10_2.x86_64.rpm
rv-6.12.0-211.34.1.el10_2.x86_64.rpm

aarch64:
kernel-cross-headers-6.12.0-211.34.1.el10_2.aarch64.rpm
kernel-headers-6.12.0-211.34.1.el10_2.aarch64.rpm
kernel-tools-6.12.0-211.34.1.el10_2.aarch64.rpm
kernel-tools-libs-6.12.0-211.34.1.el10_2.aarch64.rpm
kernel-tools-libs-devel-6.12.0-211.34.1.el10_2.aarch64.rpm
libperf-6.12.0-211.34.1.el10_2.aarch64.rpm
perf-6.12.0-211.34.1.el10_2.aarch64.rpm
python3-perf-6.12.0-211.34.1.el10_2.aarch64.rpm
rtla-6.12.0-211.34.1.el10_2.aarch64.rpm
rv-6.12.0-211.34.1.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/kernel-6.12.0-211.34.1.el10_2.src.rpm

Related CVEs:

CVE-2026-43279
CVE-2026-46090
CVE-2026-46176
CVE-2026-46189

Description of changes:

[6.12.0-211.34.1]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64