Oracle Linux 6522 Published by

Oracle Linux published a wide range of security advisories across operating system versions 7 through 10 to address dozens of publicly disclosed vulnerabilities in core infrastructure components. The patches deliver updated kernels for both mainline and Unbreakable Enterprise distributions alongside critical fixes for OpenSSL, glibc, Tomcat, Node.js, Python 3.14, and SSSD. Engineers will resolve heap-based buffer overflows, use-after-free errors, certificate revocation bypasses, and command injection flaws across services like Apache HTTP Server and Samba. Routine maintenance releases for Podman, Buildah, Cloud-init, and Ignition round out the advisory set by tightening container runtime security and stabilizing cloud provisioning workflows.

ELSA-2026-46395 Important: Oracle Linux 10 go-fdo-server security update
ELSA-2026-43400 Important: Oracle Linux 10 dogtag-pki security update
ELSA-2026-44391 Important: Oracle Linux 10 libpq security update
ELSA-2026-42919 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
ELSA-2026-44270 Important: Oracle Linux 10 kernel security update
ELSA-2026-42096 Important: Oracle Linux 10 c-ares security update
ELSA-2026-30855 Important: Oracle Linux 10 git-lfs security update
ELSA-2026-29195 Important: Oracle Linux 10 buildah security update
ELSA-2026-24470 Important: Oracle Linux 10 podman security update
ELSA-2026-28210 Moderate: Oracle Linux 10 vim security update
ELSA-2026-25341 Important: Oracle Linux 10 tomcat9 update
ELSA-2026-22314 Moderate: Oracle Linux 10 openssl security update
ELSA-2026-22120 Important: Oracle Linux 10 golang security update
ELSA-2026-21286 Important: Oracle Linux 10 .NET 8.0 security update
ELSA-2026-20693 Moderate: Oracle Linux 10 mysql8.4 security update
ELSA-2026-18537 Important: Oracle Linux 10 tomcat security update
ELSA-2026-19126 Important: Oracle Linux 10 yggdrasil security update
ELSA-2026-19569 Important: Oracle Linux 10 kernel security update
ELSA-2026-18320 Moderate: Oracle Linux 10 edk2 security update
ELBA-2026-500089 Oracle Linux 10 ignition bug fix update
ELBA-2026-25086 Oracle Linux 10 cloud-init bug fix and enhancement update
ELBA-2026-500050 Oracle Linux 10 fips-provider-next bug fix update
ELBA-2026-500087 Oracle Linux 9 xfsprogs bug fix update
ELBA-2026-500062 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
ELBA-2026-500088 Oracle Linux 9 xfsprogs bug fix update
ELSA-2026-44308 Important: Oracle Linux 9 libpq security update
ELSA-2026-43307 Important: Oracle Linux 9 kernel security, bug fix, and enhancement update
ELSA-2026-42122 Important: Oracle Linux 9 sssd security update
ELSA-2026-44438 Important: Oracle Linux 9 compat-openssl11 security update
ELSA-2026-42952 Moderate: Oracle Linux 9 glibc security update
ELSA-2026-41949 Important: Oracle Linux 9 python3.14 security update
ELSA-2026-40895 Important: Oracle Linux 9 jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update
ELSA-2026-19345 Important: Oracle Linux 9 LibRaw security update
ELBA-2026-500052 Oracle Linux 9 NetworkManager bug fix update
ELBA-2026-500061 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
ELBA-2026-42552-1 Oracle Linux 8 kernel bug fix update
ELSA-2026-43420 Important: Oracle Linux 8 acl security update
ELSA-2026-42828 Important: Oracle Linux 8 httpd:2.4 security, bug fix, and enhancement update
ELSA-2026-42552 Important: Oracle Linux 8 kernel security, bug fix, and enhancement update
ELSA-2026-41947 Important: Oracle Linux 8 nodejs:22 security, bug fix, and enhancement update
ELSA-2026-40841 Important: Oracle Linux 8 maven:3.8 security update
ELSA-2026-39868 Important: Oracle Linux 8 nodejs:24 security, bug fix, and enhancement update
ELBA-2026-500061 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
ELBA-2026-500061 Oracle Linux 7 Unbreakable Enterprise kernel bug fix update
ELSA-2026-30044 Important: Oracle Linux 7 poppler security update
ELSA-2026-29952 Important: Oracle Linux 7 compat-poppler022 security update
ELSA-2026-28132 Important: Oracle Linux 7 samba security update




ELSA-2026-46395 Important: Oracle Linux 10 go-fdo-server security update


Oracle Linux Security Advisory ELSA-2026-46395

http://linux.oracle.com/errata/ELSA-2026-46395.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
go-fdo-server-1.0.1-2.el10_2.3.x86_64.rpm
go-fdo-server-manufacturer-1.0.1-2.el10_2.3.noarch.rpm
go-fdo-server-owner-1.0.1-2.el10_2.3.noarch.rpm
go-fdo-server-rendezvous-1.0.1-2.el10_2.3.noarch.rpm

aarch64:
go-fdo-server-1.0.1-2.el10_2.3.aarch64.rpm
go-fdo-server-manufacturer-1.0.1-2.el10_2.3.noarch.rpm
go-fdo-server-owner-1.0.1-2.el10_2.3.noarch.rpm
go-fdo-server-rendezvous-1.0.1-2.el10_2.3.noarch.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/go-fdo-server-1.0.1-2.el10_2.3.src.rpm

Related CVEs:

CVE-2026-27145
CVE-2026-39821

Description of changes:

[1.0.1-3]
- Rebuild against updated golang



ELSA-2026-43400 Important: Oracle Linux 10 dogtag-pki security update


Oracle Linux Security Advisory ELSA-2026-43400

http://linux.oracle.com/errata/ELSA-2026-43400.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
idm-pki-acme-11.9.0-4.0.1.el10_2.noarch.rpm
idm-pki-base-11.9.0-4.0.1.el10_2.noarch.rpm
idm-pki-ca-11.9.0-4.0.1.el10_2.noarch.rpm
idm-pki-java-11.9.0-4.0.1.el10_2.noarch.rpm
idm-pki-kra-11.9.0-4.0.1.el10_2.noarch.rpm
idm-pki-server-11.9.0-4.0.1.el10_2.noarch.rpm
idm-pki-tools-11.9.0-4.0.1.el10_2.x86_64.rpm
python3-idm-pki-11.9.0-4.0.1.el10_2.noarch.rpm

aarch64:
idm-pki-acme-11.9.0-4.0.1.el10_2.noarch.rpm
idm-pki-base-11.9.0-4.0.1.el10_2.noarch.rpm
idm-pki-ca-11.9.0-4.0.1.el10_2.noarch.rpm
idm-pki-java-11.9.0-4.0.1.el10_2.noarch.rpm
idm-pki-kra-11.9.0-4.0.1.el10_2.noarch.rpm
idm-pki-server-11.9.0-4.0.1.el10_2.noarch.rpm
idm-pki-tools-11.9.0-4.0.1.el10_2.aarch64.rpm
python3-idm-pki-11.9.0-4.0.1.el10_2.noarch.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/dogtag-pki-11.9.0-4.0.1.el10_2.src.rpm

Related CVEs:

CVE-2026-54512
CVE-2026-54513

Description of changes:

[11.9.0-4.0.1]
- Treat Oracle Linux the same as RHEL when selecting the Tomcat app server version.

[11.9.0-4]
- Update jackson bundled to 2.21.4
- Resolves: RHEL-188290
- Resolves: RHEL-190906



ELSA-2026-44391 Important: Oracle Linux 10 libpq security update


Oracle Linux Security Advisory ELSA-2026-44391

http://linux.oracle.com/errata/ELSA-2026-44391.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
libpq-16.14-1.el10_2.x86_64.rpm
libpq-devel-16.14-1.el10_2.x86_64.rpm

aarch64:
libpq-16.14-1.el10_2.aarch64.rpm
libpq-devel-16.14-1.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/libpq-16.14-1.el10_2.src.rpm

Related CVEs:

CVE-2026-6477

Description of changes:

[16.14-1]
- Rebase to upstream release 16.14
- Resolves: RHEL-192240



ELSA-2026-42919 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-42919

http://linux.oracle.com/errata/ELSA-2026-42919.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-abi-stablelists-6.12.0-211.37.1.el10_2.noarch.rpm
kernel-core-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-cross-headers-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-debug-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-debug-core-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-debug-devel-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-debug-devel-matched-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-debug-modules-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-debug-modules-core-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-debug-modules-extra-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-debug-uki-virt-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-devel-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-devel-matched-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-doc-6.12.0-211.37.1.el10_2.noarch.rpm
kernel-headers-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-modules-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-modules-core-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-modules-extra-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-modules-extra-matched-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-tools-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-tools-libs-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-tools-libs-devel-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-uki-virt-6.12.0-211.37.1.el10_2.x86_64.rpm
kernel-uki-virt-addons-6.12.0-211.37.1.el10_2.x86_64.rpm
libperf-6.12.0-211.37.1.el10_2.x86_64.rpm
perf-6.12.0-211.37.1.el10_2.x86_64.rpm
python3-perf-6.12.0-211.37.1.el10_2.x86_64.rpm
rtla-6.12.0-211.37.1.el10_2.x86_64.rpm
rv-6.12.0-211.37.1.el10_2.x86_64.rpm

aarch64:
kernel-cross-headers-6.12.0-211.37.1.el10_2.aarch64.rpm
kernel-headers-6.12.0-211.37.1.el10_2.aarch64.rpm
kernel-tools-6.12.0-211.37.1.el10_2.aarch64.rpm
kernel-tools-libs-6.12.0-211.37.1.el10_2.aarch64.rpm
kernel-tools-libs-devel-6.12.0-211.37.1.el10_2.aarch64.rpm
libperf-6.12.0-211.37.1.el10_2.aarch64.rpm
perf-6.12.0-211.37.1.el10_2.aarch64.rpm
python3-perf-6.12.0-211.37.1.el10_2.aarch64.rpm
rtla-6.12.0-211.37.1.el10_2.aarch64.rpm
rv-6.12.0-211.37.1.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/kernel-6.12.0-211.37.1.el10_2.src.rpm

Related CVEs:

CVE-2025-71113
CVE-2025-71147
CVE-2026-23168
CVE-2026-31530
CVE-2026-46116
CVE-2026-46150
CVE-2026-46215
CVE-2026-52950
CVE-2026-52976
CVE-2026-53009
CVE-2026-53071

Description of changes:

[6.12.0-211.37.1]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64