Oracle Linux 6528 Published by

Oracle Linux distributed a batch of security and maintenance advisories across versions 7 through 10, addressing dozens of CVEs across core system libraries and applications. The updates upgrade Thunderbird to version 140.13.0 ESR, refresh Java 25 OpenJDK and Node.js 24 to patch browser and package manager vulnerabilities, and fix PHP 8.4 alongside several kernel revisions for both mainline and Unbreakable Enterprise configurations. Additional packages received targeted fixes, including DNS validation improvements in ldns, certificate handling adjustments in glibc and frr10, and authentication bypass corrections in GDM.

ELSA-2026-49838 Important: Oracle Linux 9 osbuild-composer security, bug fix, and enhancement update
ELSA-2026-50108-0 Important: Oracle Linux 9 ldns security update
ELSA-2026-49214 Important: Oracle Linux 8 kernel security update
ELSA-2026-49921 Important: Oracle Linux 9 thunderbird security update
ELSA-2026-500121 Important: Oracle Linux 7 Unbreakable Enterprise kernel security update
ELSA-2026-49520 Important: Oracle Linux 8 ldns security update
ELSA-2026-49927 Moderate: Oracle Linux 8 fence-agents security update
ELSA-2026-49512 Important: Oracle Linux 8 mingw-glib2 security update
ELSA-2026-49922 Important: Oracle Linux 8 thunderbird security update
ELBA-2026-48843 Oracle Linux 8 fwupd bug fix and enhancement update
ELBA-2026-48830 Oracle Linux 8 libxmlb bug fix and enhancement update
ELSA-2026-50141-0 Important: Oracle Linux 9 sg3_utils security, bug fix, and enhancement update
ELSA-2026-49667 Moderate: Oracle Linux 9 p11-kit security update
ELSA-2026-500121 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
ELSA-2026-50147-0 Moderate: Oracle Linux 9 libgcrypt security update
ELSA-2026-50317-0 Important: Oracle Linux 9 fence-agents security update
ELBA-2026-50153-0 Oracle Linux 10 rust-bootupd bug fix and enhancement update
ELBA-2026-500126 Oracle Linux 10 kdump-utils bug fix update
ELBA-2026-50138-0 Oracle Linux 9 conmon bug fix and enhancement update
ELBA-2026-500128 Oracle Linux 10 osbuild bug fix update
ELBA-2026-26196 Oracle Linux 9 openscap bug fix and enhancement update
ELSA-2026-49211 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
ELBA-2026-50135-0 Oracle Linux 10 policycoreutils bug fix and enhancement update
ELBA-2026-500091 Oracle Linux 9 oracle-database-preinstall-19c bug fix update
ELBA-2026-50166-0 Oracle Linux 9 linuxptp bug fix and enhancement update
ELSA-2026-50142-0 Important: Oracle Linux 10 sg3_utils security, bug fix, and enhancement update
ELSA-2026-49607 Important: Oracle Linux 9 frr10 security, bug fix, and enhancement update
ELSA-2026-49212 Important: Oracle Linux 9 kernel security update
ELSA-2026-42899 Important: Oracle Linux 9 java-25-openjdk security update
ELBA-2026-50136-0 Oracle Linux 9 gnutls bug fix and enhancement update
ELBA-2026-50150-0 Oracle Linux 9 rust-bootupd bug fix and enhancement update
ELBA-2026-50159-0 Oracle Linux 9 keylime bug fix and enhancement update
ELSA-2026-49836 Important: Oracle Linux 10 ldns security update
ELBA-2026-49518 Oracle Linux 9 glibc bug fix and enhancement update
ELBA-2026-50133-0 Oracle Linux 9 autofs bug fix and enhancement update
ELBA-2026-50171-0 Oracle Linux 10 gdm bug fix and enhancement update
ELSA-2026-48034 Important: Oracle Linux 10 nodejs24 security update
ELSA-2026-50144-0 Moderate: Oracle Linux 10 libgcrypt security update
ELSA-2026-49914 Low: Oracle Linux 10 php8.4 security, bug fix, and enhancement update




ELSA-2026-49838 Important: Oracle Linux 9 osbuild-composer security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-49838

http://linux.oracle.com/errata/ELSA-2026-49838.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
osbuild-composer-175-1.0.1.el9_8.x86_64.rpm
osbuild-composer-core-175-1.0.1.el9_8.x86_64.rpm
osbuild-composer-worker-175-1.0.1.el9_8.x86_64.rpm

aarch64:
osbuild-composer-175-1.0.1.el9_8.aarch64.rpm
osbuild-composer-core-175-1.0.1.el9_8.aarch64.rpm
osbuild-composer-worker-175-1.0.1.el9_8.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/osbuild-composer-175-1.0.1.el9_8.src.rpm

Related CVEs:

CVE-2026-32280
CVE-2026-32281

Description of changes:

[175-1.0.1]
- Track github upstream



ELSA-2026-50108-0 Important: Oracle Linux 9 ldns security update


Oracle Linux Security Advisory ELSA-2026-50108-0

http://linux.oracle.com/errata/ELSA-2026-50108-0.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
ldns-1.7.1-12.el9_8.1.i686.rpm
ldns-1.7.1-12.el9_8.1.x86_64.rpm
ldns-devel-1.7.1-12.el9_8.1.x86_64.rpm
ldns-doc-1.7.1-12.el9_8.1.noarch.rpm
ldns-utils-1.7.1-12.el9_8.1.x86_64.rpm
perl-ldns-1.7.1-12.el9_8.1.x86_64.rpm
python3-ldns-1.7.1-12.el9_8.1.x86_64.rpm

aarch64:
ldns-1.7.1-12.el9_8.1.aarch64.rpm
ldns-devel-1.7.1-12.el9_8.1.aarch64.rpm
ldns-doc-1.7.1-12.el9_8.1.noarch.rpm
ldns-utils-1.7.1-12.el9_8.1.aarch64.rpm
perl-ldns-1.7.1-12.el9_8.1.aarch64.rpm
python3-ldns-1.7.1-12.el9_8.1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/ldns-1.7.1-12.el9_8.1.src.rpm

Related CVEs:

CVE-2026-10846

Description of changes:

[1.7.1-12.1]
- Fix CVE-2026-10846: DNS response spoofing via missing
address/port/TXID and question section validation (RHEL-210701)



ELSA-2026-49214 Important: Oracle Linux 8 kernel security update


Oracle Linux Security Advisory ELSA-2026-49214

http://linux.oracle.com/errata/ELSA-2026-49214.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
bpftool-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-abi-stablelists-4.18.0-553.150.1.el8_10.noarch.rpm
kernel-core-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-cross-headers-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-debug-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-debug-core-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-debug-devel-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-debug-modules-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-debug-modules-extra-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-devel-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-doc-4.18.0-553.150.1.el8_10.noarch.rpm
kernel-headers-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-modules-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-modules-extra-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-tools-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-tools-libs-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-tools-libs-devel-4.18.0-553.150.1.el8_10.x86_64.rpm
perf-4.18.0-553.150.1.el8_10.x86_64.rpm
python3-perf-4.18.0-553.150.1.el8_10.x86_64.rpm

aarch64:
bpftool-4.18.0-553.150.1.el8_10.aarch64.rpm
kernel-cross-headers-4.18.0-553.150.1.el8_10.aarch64.rpm
kernel-headers-4.18.0-553.150.1.el8_10.aarch64.rpm
kernel-tools-4.18.0-553.150.1.el8_10.aarch64.rpm
kernel-tools-libs-4.18.0-553.150.1.el8_10.aarch64.rpm
kernel-tools-libs-devel-4.18.0-553.150.1.el8_10.aarch64.rpm
perf-4.18.0-553.150.1.el8_10.aarch64.rpm
python3-perf-4.18.0-553.150.1.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/kernel-4.18.0-553.150.1.el8_10.src.rpm

Related CVEs:

CVE-2026-31692
CVE-2026-43116
CVE-2026-46150
CVE-2026-64530

Description of changes:

[4.18.0-553.150.1]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 cb[] in ip6_err_gen_icmpv6_unreach() (Eric Dumazet) [Orabug: 39300930] {CVE-2026-43038}
- tracing/events: Expand global buffer for in-kernel event enables (Manjunath Patil) [Orabug: 38790406]
- net/mlx5: poll mlx5 eq during irq migration (Praveen Kumar Kannoju) [Orabug: 38776184]

[5.4.17-2136.357.3]
- net: skbuff: fix missing zerocopy reference in pskb_carve helpers (Minh Nguyen) [Orabug: 39619389] {CVE-2026-52943}

[5.4.17-2136.357.2]
- net: fix fanout UAF in packet_release() via NETDEV_UP race (Yochai Eisenrich) [Orabug: 39250953] {CVE-2026-31504}
- x86/kaslr: Recognize all ZONE_DEVICE users as physaddr consumers (Dan Williams) [Orabug: 39429802]
- x86/kaslr: Reduce KASLR entropy on most x86 systems (Balbir Singh) [Orabug: 39429802]
- net: tap: NULL pointer derefence in dev_parse_header_protocol when skb->dev is null (Cezar Bulinaru) [Orabug: 39526882] {CVE-2022-50073}
- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39548666] {CVE-2025-10263}
- arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland) [Orabug: 39548666]
- ARM: uek: Disable CONFIG_QCOM_FALKOR_ERRATUM_1003 (Boris Ostrovsky) [Orabug: 39548666]
- arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland) [Orabug: 39548666]
- arm64: cputype: Add C1-Premium definitions (Mark Rutland) [Orabug: 39548666]
- arm64: cputype: Add C1-Ultra definitions (Mark Rutland) [Orabug: 39548666]
- ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (Eric Dumazet) [Orabug: 39300926] {CVE-2026-43037}

[5.4.17-2136.357.1]
- batman-adv: hold claim backbone gateways by reference (Haoze Xie) [Orabug: 39262375] {CVE-2026-31657}
- scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (Michael Bommarito) [Orabug: 39446045]
- scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (Michael Bommarito) [Orabug: 39446045]
- scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (Michael Bommarito) [Orabug: 39446045]
- rds: Drop rds conn in connect worker if not in down state. (Rohit Nair) [Orabug: 39152239]

[5.4.17-2136.356.4.1]
- smb: client: reject userspace cifs.spnego descriptions (Asim Viladi Oglu Manizada) [Orabug: 39463669] {CVE-2026-46243}

[5.4.17-2136.356.4]
- tun: free page on build_skb failure in tun_xdp_one() (Weiming Shi) [Orabug: 39429147]
- tap: free page on error paths in tap_get_user_xdp() (Weiming Shi) [Orabug: 39429147]
- tun: free page on short-frame rejection in tun_xdp_one() (Weiming Shi) [Orabug: 39429147]

[5.4.17-2136.356.3]
- ptrace: slightly saner 'get_dumpable()' logic (Linus Torvalds) [Orabug: 39384275,39391459] {CVE-2026-46333}
- net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim) [Orabug: 39368828,39441326] {CVE-2026-43503,CVE-2026-46300}
- net: skbuff: preserve shared-frag marker during coalescing (William Bowling) [Orabug: 39368828] {CVE-2026-46300}

[5.4.17-2136.356.2]
- nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (Jeff Layton) [Orabug: 39167617,39368718] {CVE-2026-31402}
- scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() (Maurizio Lombardi) [Orabug: 38985173,39368732] {CVE-2026-23216}
- scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() (Maurizio Lombardi) [Orabug: 38970455,39368774] {CVE-2026-23193}
- xfrm: esp: avoid in-place decrypt on shared skb frags (Kuan-Ting Chen) [Orabug: 39334580,39367147] {CVE-2026-43284}
- x86/CPU/AMD: Add a fix for AMD-SB-7052 (Prathyushi Nangia) [Orabug: 39218897] {CVE-2025-54518}

[5.4.17-2136.356.1]
- arm64/kvm: Include linux/random.h in trng.c (Siddh Raman Pant) [Orabug: 39327096]
- i2c: designware: Disable TX_EMPTY irq while waiting for block length byte (Tam Nguyen) [Orabug: 39174662]
- i2c: designware: Handle invalid SMBus block data response length value (Tam Nguyen) [Orabug: 39174662]
- i2c: designware: fix __i2c_dw_disable() in case master is holding SCL low (Yann Sionneau) [Orabug: 39174662]



ELSA-2026-49520 Important: Oracle Linux 8 ldns security update


Oracle Linux Security Advisory ELSA-2026-49520

http://linux.oracle.com/errata/ELSA-2026-49520.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
ldns-1.7.0-23.el8_10.i686.rpm
ldns-1.7.0-23.el8_10.x86_64.rpm
ldns-devel-1.7.0-23.el8_10.i686.rpm
ldns-devel-1.7.0-23.el8_10.x86_64.rpm
ldns-doc-1.7.0-23.el8_10.noarch.rpm
ldns-utils-1.7.0-23.el8_10.x86_64.rpm
perl-ldns-1.7.0-23.el8_10.x86_64.rpm
python3-ldns-1.7.0-23.el8_10.x86_64.rpm

aarch64:
ldns-1.7.0-23.el8_10.aarch64.rpm
ldns-devel-1.7.0-23.el8_10.aarch64.rpm
ldns-doc-1.7.0-23.el8_10.noarch.rpm
ldns-utils-1.7.0-23.el8_10.aarch64.rpm
perl-ldns-1.7.0-23.el8_10.aarch64.rpm
python3-ldns-1.7.0-23.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/ldns-1.7.0-23.el8_10.src.rpm

Related CVEs:

CVE-2026-10846

Description of changes:

[1.7.0-23]
- Fix CVE-2026-10846: validate DNS response source address, transaction
ID, and query section matching
- Resolves: RHEL-210700



ELSA-2026-49927 Moderate: Oracle Linux 8 fence-agents security update


Oracle Linux Security Advisory ELSA-2026-49927

http://linux.oracle.com/errata/ELSA-2026-49927.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
fence-agents-all-4.2.1-129.el8_10.28.x86_64.rpm
fence-agents-amt-ws-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-apc-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-apc-snmp-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-bladecenter-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-brocade-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-cisco-mds-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-cisco-ucs-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-common-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-compute-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-drac5-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-eaton-snmp-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-emerson-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-eps-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-heuristics-ping-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-hpblade-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ibm-powervs-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ibm-vpc-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ibmblade-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ifmib-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ilo-moonshot-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ilo-mp-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ilo-ssh-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ilo2-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-intelmodular-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ipdu-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ipmilan-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-kdump-4.2.1-129.el8_10.28.x86_64.rpm
fence-agents-kubevirt-4.2.1-129.el8_10.28.x86_64.rpm
fence-agents-lpar-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-mpath-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-nutanix-ahv-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-redfish-4.2.1-129.el8_10.28.x86_64.rpm
fence-agents-rhevm-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-rsa-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-rsb-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-sbd-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-scsi-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-virsh-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-vmware-rest-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-vmware-soap-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-wti-4.2.1-129.el8_10.28.noarch.rpm

aarch64:
fence-agents-all-4.2.1-129.el8_10.28.aarch64.rpm
fence-agents-amt-ws-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-apc-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-apc-snmp-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-bladecenter-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-brocade-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-cisco-mds-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-cisco-ucs-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-common-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-compute-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-drac5-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-eaton-snmp-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-emerson-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-eps-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-heuristics-ping-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-hpblade-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ibm-powervs-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ibm-vpc-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ibmblade-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ifmib-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ilo-moonshot-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ilo-mp-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ilo-ssh-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ilo2-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-intelmodular-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ipdu-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ipmilan-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-kdump-4.2.1-129.el8_10.28.aarch64.rpm
fence-agents-kubevirt-4.2.1-129.el8_10.28.aarch64.rpm
fence-agents-mpath-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-nutanix-ahv-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-redfish-4.2.1-129.el8_10.28.aarch64.rpm
fence-agents-rhevm-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-rsa-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-rsb-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-sbd-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-scsi-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-virsh-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-vmware-rest-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-vmware-soap-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-wti-4.2.1-129.el8_10.28.noarch.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/fence-agents-4.2.1-129.el8_10.28.src.rpm

Related CVEs:

CVE-2026-44431

Description of changes:

[4.2.1-129.28]
- bundled urllib3: fix CVE-2026-44431
Resolves: RHEL-178594



ELSA-2026-49512 Important: Oracle Linux 8 mingw-glib2 security update


Oracle Linux Security Advisory ELSA-2026-49512

http://linux.oracle.com/errata/ELSA-2026-49512.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
mingw32-glib2-2.70.1-9.el8_10.noarch.rpm
mingw32-glib2-static-2.70.1-9.el8_10.noarch.rpm
mingw64-glib2-2.70.1-9.el8_10.noarch.rpm
mingw64-glib2-static-2.70.1-9.el8_10.noarch.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/mingw-glib2-2.70.1-9.el8_10.src.rpm

Related CVEs:

CVE-2025-14087
CVE-2026-58010
CVE-2026-58011
CVE-2026-58012
CVE-2026-58013
CVE-2026-58014
CVE-2026-58015
CVE-2026-58016

Description of changes:

[2.70.1-9]
- Fix CVE-2026-58010: off-by-one error in gvs_tuple_is_normal()
Resolves: RHEL-212164

[2.70.1-8]
- Fix CVE-2026-58011: g_date_time_add_full() range validation
Resolves: RHEL-212184

[2.70.1-7]
- Fix CVE-2026-58013: memcmp buffer over-read in giochannel
Resolves: RHEL-212234

[2.70.1-6]
- Fix CVE-2026-58012: buffer overflow in gregex substitutions
Resolves: RHEL-212200

[2.70.1-5]
- Fix CVE-2025-14087: integer overflow in GVariant parser
Resolves: RHEL-154707

[2.70.1-4]
- Fix CVE-2026-58016: D-Bus introspection XML node nesting check
Resolves: RHEL-190617

[2.70.1-3]
- Fix CVE-2026-58014: one-byte heap under-read in mingw-glib2
Resolves: RHEL-190609

[2.70.1-2]
- Fix CVE-2026-58015: D-Bus cookie context path traversal
Resolves: RHEL-212246



ELSA-2026-49922 Important: Oracle Linux 8 thunderbird security update


Oracle Linux Security Advisory ELSA-2026-49922

http://linux.oracle.com/errata/ELSA-2026-49922.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
thunderbird-140.13.0-1.0.1.el8_10.x86_64.rpm

aarch64:
thunderbird-140.13.0-1.0.1.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/thunderbird-140.13.0-1.0.1.el8_10.src.rpm

Related CVEs:

CVE-2026-14899
CVE-2026-15718
CVE-2026-15719
CVE-2026-16349
CVE-2026-16350
CVE-2026-16351
CVE-2026-16352
CVE-2026-16353
CVE-2026-16354
CVE-2026-16355
CVE-2026-16356
CVE-2026-16357
CVE-2026-16358
CVE-2026-16359
CVE-2026-16360
CVE-2026-16361
CVE-2026-16362
CVE-2026-16363
CVE-2026-16368
CVE-2026-16369
CVE-2026-16371
CVE-2026-16374
CVE-2026-16375
CVE-2026-16377
CVE-2026-16379
CVE-2026-16381
CVE-2026-16383
CVE-2026-16387
CVE-2026-16390
CVE-2026-16391
CVE-2026-16396
CVE-2026-16405
CVE-2026-16412

Description of changes:

[140.13.0-1.0.1]
- Fix prefs for new nss [Orabug: 37079820]
- Add Oracle prefs file

[140.13.0]
- Add OpenELA debranding

[140.13.0-1]
- Update to 140.13.0 ESR



ELBA-2026-48843 Oracle Linux 8 fwupd bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2026-48843

http://linux.oracle.com/errata/ELBA-2026-48843.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
fwupd-2.1.6-1.0.1.el8_10.x86_64.rpm
fwupd-devel-2.1.6-1.0.1.el8_10.x86_64.rpm

aarch64:
fwupd-2.1.6-1.0.1.el8_10.aarch64.rpm
fwupd-devel-2.1.6-1.0.1.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/fwupd-2.1.6-1.0.1.el8_10.src.rpm

Description of changes:

[2.1.6-1.0.1]
- Align sections to 512 bytes [Orabug: 35265981]
- Use objcopy to build arm/aarch64 binaries if binutils 2.30-113.0.3 or newer [Orabug: 35265981]
- Enabled signing for aarch64 [Orabug: 35265981]
- Modify meson.build for fwupd-efi [Orabug: 35265981]
- Update SBAT data to include Oracle [Oracle: 33072886]
- Build with the updated Oracle certificate
- Use oraclesecureboot301 as certdir [Orabug: 29881368]
- Use new signing certificate (Alex Burmashev)

[2.1.6-1]
- Rebase to a new version.
- Resolves: RHEL-185615



ELBA-2026-48830 Oracle Linux 8 libxmlb bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2026-48830

http://linux.oracle.com/errata/ELBA-2026-48830.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
libxmlb-0.3.28-1.el8_10.i686.rpm
libxmlb-0.3.28-1.el8_10.x86_64.rpm
libxmlb-devel-0.3.28-1.el8_10.i686.rpm
libxmlb-devel-0.3.28-1.el8_10.x86_64.rpm

aarch64:
libxmlb-0.3.28-1.el8_10.aarch64.rpm
libxmlb-devel-0.3.28-1.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/libxmlb-0.3.28-1.el8_10.src.rpm

Description of changes:

[0.3.28-1]
- New upstream release for fwupd backport
- Resolves: RHEL-190658



ELSA-2026-50141-0 Important: Oracle Linux 9 sg3_utils security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-50141-0

http://linux.oracle.com/errata/ELSA-2026-50141-0.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
sg3_utils-1.47-10.el9_8.1.x86_64.rpm
sg3_utils-devel-1.47-10.el9_8.1.i686.rpm
sg3_utils-devel-1.47-10.el9_8.1.x86_64.rpm
sg3_utils-libs-1.47-10.el9_8.1.i686.rpm
sg3_utils-libs-1.47-10.el9_8.1.x86_64.rpm

aarch64:
sg3_utils-1.47-10.el9_8.1.aarch64.rpm
sg3_utils-devel-1.47-10.el9_8.1.aarch64.rpm
sg3_utils-libs-1.47-10.el9_8.1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/sg3_utils-1.47-10.el9_8.1.src.rpm

Related CVEs:

CVE-2026-16313

Description of changes:

[1.47-10.1]
- sg_inq output conformance for SCSI name string and ATA fields (RHEL-188130)



ELSA-2026-49667 Moderate: Oracle Linux 9 p11-kit security update


Oracle Linux Security Advisory ELSA-2026-49667

http://linux.oracle.com/errata/ELSA-2026-49667.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
p11-kit-0.26.4-1.el9_8.i686.rpm
p11-kit-0.26.4-1.el9_8.x86_64.rpm
p11-kit-client-0.26.4-1.el9_8.x86_64.rpm
p11-kit-devel-0.26.4-1.el9_8.i686.rpm
p11-kit-devel-0.26.4-1.el9_8.x86_64.rpm
p11-kit-server-0.26.4-1.el9_8.x86_64.rpm
p11-kit-trust-0.26.4-1.el9_8.i686.rpm
p11-kit-trust-0.26.4-1.el9_8.x86_64.rpm

aarch64:
p11-kit-0.26.4-1.el9_8.aarch64.rpm
p11-kit-client-0.26.4-1.el9_8.aarch64.rpm
p11-kit-devel-0.26.4-1.el9_8.aarch64.rpm
p11-kit-server-0.26.4-1.el9_8.aarch64.rpm
p11-kit-trust-0.26.4-1.el9_8.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/p11-kit-0.26.4-1.el9_8.src.rpm

Related CVEs:

CVE-2026-13757

Description of changes:

[0.26.2-1]
- Rebase to 0.26.2
Resolves: RHEL-147825

[0.26.1-1]
- Rebase to 0.26.1
Resolves: RHEL-139075, RHEL-118361, RHEL-126132

[0.25.10-1]
- Update to new upstream release 0.25.10
Resolves: RHEL-115453

[0.25.3-3]
- Fix regression in trust where file creation fails for long cert labels
Resolves: RHEL-58899
- Fix usage message in p11-kit list-tokens command
Resolves: RHEL-31810



ELSA-2026-500121 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update


Oracle Linux Security Advisory ELSA-2026-500121

http://linux.oracle.com/errata/ELSA-2026-500121.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

aarch64:
kernel-uek-5.4.17-2136.358.2.el8uek.aarch64.rpm
kernel-uek-debug-5.4.17-2136.358.2.el8uek.aarch64.rpm
kernel-uek-debug-devel-5.4.17-2136.358.2.el8uek.aarch64.rpm
kernel-uek-devel-5.4.17-2136.358.2.el8uek.aarch64.rpm
kernel-uek-doc-5.4.17-2136.358.2.el8uek.noarch.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/kernel-uek-5.4.17-2136.358.2.el8uek.src.rpm

Related CVEs:

CVE-2026-43038
CVE-2026-43499
CVE-2026-46043
CVE-2026-46331
CVE-2026-64600

Description of changes:

[5.4.17-2136.358.2]
- xfs: resample the data fork mapping after cycling ILOCK (Darrick J. Wong) [Orabug: 39776792] {CVE-2026-64600}
- net: Work around Marvell NIC TX stalls (Venkat Venkatsubra) [Orabug: 39765820]

[5.4.17-2136.358.1]
- KVM: x86: Fix shadow paging use-after-free due to unexpected role (Paolo Bonzini) [Orabug: 39673871]
- KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/MMU: Recursively zap nested TDP SPs when zapping last/only parent (Ben Gardon) [Orabug: 39673871]
- KVM: x86/mmu: Move flush logic from mmu_page_zap_pte() to FNAME(invlpg) (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: pull call to drop_large_spte() into __link_shadow_page() (Paolo Bonzini) [Orabug: 39673871]
- KVM: x86/mmu: Passing up the error state of mmu_alloc_shadow_roots() (Like Xu) [Orabug: 39673871]
- KVM: MMU: load PDPTRs outside mmu_lock (Paolo Bonzini) [Orabug: 39673871]
- KVM: x86/mmu: Check PDPTRs before allocating PAE roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Always pass 0 for @quadrant when gptes are 8 bytes (David Matlack) [Orabug: 39673871]
- KVM: x86/mmu: Derive shadow MMU page role from parent (David Matlack) [Orabug: 39673871]
- KVM: X86: Remove useless code to set role.gpte_is_8_bytes when role.direct (Lai Jiangshan) [Orabug: 39673871]
- KVM: X86: Synchronize the shadow pagetable before link it (Lai Jiangshan) [Orabug: 39673871]
- KVM: X86: Fix missed remote tlb flush in rmap_write_protect() (Lai Jiangshan) [Orabug: 39673871]
- KVM: x86/mmu: Refactor shadow walk in __direct_map() to reduce indentation (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Stop passing "direct" to mmu_alloc_root() (David Matlack) [Orabug: 39673871]
- KVM: x86/mmu: Use a bool for direct (David Matlack) [Orabug: 39673871]
- kvm: mmu: Replace unsigned with unsigned int for PTE access (Ben Gardon) [Orabug: 39673871]
- KVM: x86/mmu: Ensure MMU pages are available when allocating roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Allocate pae_root and lm_root pages in dedicated helper (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Allocate the lm_root before allocating PAE roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Capture 'mmu' in a local variable when allocating roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Alloc page for PDPTEs when shadowing 32-bit NPT with 64-bit (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Stash 'kvm' in a local variable in kvm_mmu_free_roots() (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Add a helper to consolidate root sp allocation (Sean Christopherson) [Orabug: 39673871]
- Revert "net/rds: poll eq during user-reset" (Praveen Kumar Kannoju) [Orabug: 39659401]
- net/sched: act_pedit: fix action bind logic (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: free pedit keys on bail from offset check (Pedro Tammela) [Orabug: 39567287]
- net/sched: fix pedit partial COW leading to page cache corruption (Rajat Gupta) [Orabug: 39567287] {CVE-2026-46331}
- net/sched: act_pedit: Parse L3 Header for L4 offset (Max Tottenham) [Orabug: 39567287]
- net/sched: act_pedit: rate limit datapath messages (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: check static offsets a priori (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: remove extra check for key type (Pedro Tammela) [Orabug: 39567287]
- net/sched: simplify tcf_pedit_act (Pedro Tammela) [Orabug: 39567287]
- net/sched: transition act_pedit to rcu and percpu stats (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: use NLA_POLICY for parsing 'ex' keys (Pedro Tammela) [Orabug: 39567287]
- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (hkbinbin) [Orabug: 39452261] {CVE-2026-46043}
- locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (Davidlohr Bueso) [Orabug: 39426001]
- rtmutex: Use waiter::task instead of current in remove_waiter() (Keenan Dong) [Orabug: 39426001] {CVE-2026-43499}
- ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (Eric Dumazet) [Orabug: 39300930] {CVE-2026-43038}
- tracing/events: Expand global buffer for in-kernel event enables (Manjunath Patil) [Orabug: 38790406]
- net/mlx5: poll mlx5 eq during irq migration (Praveen Kumar Kannoju) [Orabug: 38776184]

[5.4.17-2136.357.3]
- net: skbuff: fix missing zerocopy reference in pskb_carve helpers (Minh Nguyen) [Orabug: 39619389] {CVE-2026-52943}

[5.4.17-2136.357.2]
- net: fix fanout UAF in packet_release() via NETDEV_UP race (Yochai Eisenrich) [Orabug: 39250953] {CVE-2026-31504}
- x86/kaslr: Recognize all ZONE_DEVICE users as physaddr consumers (Dan Williams) [Orabug: 39429802]
- x86/kaslr: Reduce KASLR entropy on most x86 systems (Balbir Singh) [Orabug: 39429802]
- net: tap: NULL pointer derefence in dev_parse_header_protocol when skb->dev is null (Cezar Bulinaru) [Orabug: 39526882] {CVE-2022-50073}
- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39548666] {CVE-2025-10263}
- arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland) [Orabug: 39548666]
- ARM: uek: Disable CONFIG_QCOM_FALKOR_ERRATUM_1003 (Boris Ostrovsky) [Orabug: 39548666]
- arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland) [Orabug: 39548666]
- arm64: cputype: Add C1-Premium definitions (Mark Rutland) [Orabug: 39548666]
- arm64: cputype: Add C1-Ultra definitions (Mark Rutland) [Orabug: 39548666]
- ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (Eric Dumazet) [Orabug: 39300926] {CVE-2026-43037}

[5.4.17-2136.357.1]
- batman-adv: hold claim backbone gateways by reference (Haoze Xie) [Orabug: 39262375] {CVE-2026-31657}
- scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (Michael Bommarito) [Orabug: 39446045]
- scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (Michael Bommarito) [Orabug: 39446045]
- scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (Michael Bommarito) [Orabug: 39446045]
- rds: Drop rds conn in connect worker if not in down state. (Rohit Nair) [Orabug: 39152239]

[5.4.17-2136.356.4.1]
- smb: client: reject userspace cifs.spnego descriptions (Asim Viladi Oglu Manizada) [Orabug: 39463669] {CVE-2026-46243}

[5.4.17-2136.356.4]
- tun: free page on build_skb failure in tun_xdp_one() (Weiming Shi) [Orabug: 39429147]
- tap: free page on error paths in tap_get_user_xdp() (Weiming Shi) [Orabug: 39429147]
- tun: free page on short-frame rejection in tun_xdp_one() (Weiming Shi) [Orabug: 39429147]

[5.4.17-2136.356.3]
- ptrace: slightly saner 'get_dumpable()' logic (Linus Torvalds) [Orabug: 39384275,39391459] {CVE-2026-46333}
- net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim) [Orabug: 39368828,39441326] {CVE-2026-43503,CVE-2026-46300}
- net: skbuff: preserve shared-frag marker during coalescing (William Bowling) [Orabug: 39368828] {CVE-2026-46300}

[5.4.17-2136.356.2]
- nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (Jeff Layton) [Orabug: 39167617,39368718] {CVE-2026-31402}
- scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() (Maurizio Lombardi) [Orabug: 38985173,39368732] {CVE-2026-23216}
- scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() (Maurizio Lombardi) [Orabug: 38970455,39368774] {CVE-2026-23193}
- xfrm: esp: avoid in-place decrypt on shared skb frags (Kuan-Ting Chen) [Orabug: 39334580,39367147] {CVE-2026-43284}
- x86/CPU/AMD: Add a fix for AMD-SB-7052 (Prathyushi Nangia) [Orabug: 39218897] {CVE-2025-54518}

[5.4.17-2136.356.1]
- arm64/kvm: Include linux/random.h in trng.c (Siddh Raman Pant) [Orabug: 39327096]
- i2c: designware: Disable TX_EMPTY irq while waiting for block length byte (Tam Nguyen) [Orabug: 39174662]
- i2c: designware: Handle invalid SMBus block data response length value (Tam Nguyen) [Orabug: 39174662]
- i2c: designware: fix __i2c_dw_disable() in case master is holding SCL low (Yann Sionneau) [Orabug: 39174662]



ELSA-2026-50147-0 Moderate: Oracle Linux 9 libgcrypt security update


Oracle Linux Security Advisory ELSA-2026-50147-0

http://linux.oracle.com/errata/ELSA-2026-50147-0.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
libgcrypt-1.10.0-13.el9_8.i686.rpm
libgcrypt-1.10.0-13.el9_8.x86_64.rpm
libgcrypt-devel-1.10.0-13.el9_8.i686.rpm
libgcrypt-devel-1.10.0-13.el9_8.x86_64.rpm

aarch64:
libgcrypt-1.10.0-13.el9_8.aarch64.rpm
libgcrypt-devel-1.10.0-13.el9_8.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/libgcrypt-1.10.0-13.el9_8.src.rpm

Related CVEs:

CVE-2026-41989

Description of changes:

[1.10.0-13]
- Bump version to fix wrong build target.

[1.10.0.12]
- Fix CVE-2026-41989: Denial of Service and buffer overflow via crafted ECDH ciphertext



ELSA-2026-50317-0 Important: Oracle Linux 9 fence-agents security update


Oracle Linux Security Advisory ELSA-2026-50317-0

http://linux.oracle.com/errata/ELSA-2026-50317-0.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
fence-agents-aliyun-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-all-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-amt-ws-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-apc-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-apc-snmp-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-aws-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-azure-arm-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-bladecenter-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-brocade-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-cisco-mds-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-cisco-ucs-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-common-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-compute-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-drac5-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-eaton-snmp-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-emerson-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-eps-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-gce-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-heuristics-ping-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-hpblade-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ibm-powervs-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ibm-vpc-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ibmblade-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ifmib-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ilo-moonshot-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ilo-mp-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ilo-ssh-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ilo2-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-intelmodular-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ipdu-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ipmilan-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-kdump-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-kubevirt-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-lpar-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-mpath-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-nutanix-ahv-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-openstack-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-redfish-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-rhevm-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-rsa-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-rsb-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-sbd-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-scsi-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-virsh-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-vmware-rest-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-vmware-soap-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-wti-4.10.0-110.el9_8.5.noarch.rpm
fence-virt-4.10.0-110.el9_8.5.x86_64.rpm
fence-virtd-4.10.0-110.el9_8.5.x86_64.rpm
fence-virtd-cpg-4.10.0-110.el9_8.5.x86_64.rpm
fence-virtd-libvirt-4.10.0-110.el9_8.5.x86_64.rpm
fence-virtd-multicast-4.10.0-110.el9_8.5.x86_64.rpm
fence-virtd-serial-4.10.0-110.el9_8.5.x86_64.rpm
fence-virtd-tcp-4.10.0-110.el9_8.5.x86_64.rpm
ha-cloud-support-4.10.0-110.el9_8.5.x86_64.rpm

aarch64:
fence-agents-all-4.10.0-110.el9_8.5.aarch64.rpm
fence-agents-amt-ws-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-apc-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-apc-snmp-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-bladecenter-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-brocade-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-cisco-mds-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-cisco-ucs-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-common-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-drac5-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-eaton-snmp-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-emerson-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-eps-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-heuristics-ping-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-hpblade-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ibm-powervs-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ibm-vpc-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ibmblade-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ifmib-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ilo-moonshot-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ilo-mp-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ilo-ssh-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ilo2-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-intelmodular-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ipdu-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ipmilan-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-kdump-4.10.0-110.el9_8.5.aarch64.rpm
fence-agents-kubevirt-4.10.0-110.el9_8.5.aarch64.rpm
fence-agents-lpar-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-mpath-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-nutanix-ahv-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-redfish-4.10.0-110.el9_8.5.aarch64.rpm
fence-agents-rhevm-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-rsa-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-rsb-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-sbd-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-scsi-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-virsh-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-vmware-rest-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-vmware-soap-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-wti-4.10.0-110.el9_8.5.noarch.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/fence-agents-4.10.0-110.el9_8.5.src.rpm

Related CVEs:

CVE-2026-59939

Description of changes:

[4.10.0-110.5]
- bundled httplib2: upgrade to v0.32.0 to fix CVE-2026-59939
Resolves: RHEL-193808

[4.10.0-110.4]
- fence_openstack: fix list-action to avoid timeout when
there are 100+ VMs on the hypervisor
Resolves: RHEL-186320



ELBA-2026-50153-0 Oracle Linux 10 rust-bootupd bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2026-50153-0

http://linux.oracle.com/errata/ELBA-2026-50153-0.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
bootupd-0.2.35-1.el10_2.x86_64.rpm

aarch64:
bootupd-0.2.35-1.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/rust-bootupd-0.2.35-1.el10_2.src.rpm

Description of changes:

[0.2.35-1]
- Update to v0.2.35



ELBA-2026-500126 Oracle Linux 10 kdump-utils bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-500126

http://linux.oracle.com/errata/ELBA-2026-500126.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
kdump-utils-1.0.58-15.0.2.el10.x86_64.rpm

aarch64:
kdump-utils-1.0.58-15.0.2.el10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/kdump-utils-1.0.58-15.0.2.el10.src.rpm

Description of changes:

[1.0.58-15.0.2]
- kdump: add iSCSI driver injection for iSCSI boot setups [Orabug: 38989420]

[1.0.58-15.0.1]
- Disable transparent_hugepage for aarch64 [Orabug: 37867172]
- Do not use squash-erofs on UEK kernels [Orabug: 37737510]
- Port OL9 patches to OL10 [Orabug: 37600072]
arm64: skip memory integrity checks in purgatory [Orabug: 30822387]
disable iommu for kdump [Orabug: 30832988]
append no_timer_check for xen guest kdump [Orabug: 30928441]
kdump: Skip LVM private devices [Orabug: 33822070]
Update UEK reserved sizes [Orabug: 34663083]
handle xen_netfront in dracut module setup [Orabug: 35615400]
kdumpctl: check if FIPS is enabled [Orabug: 35982140]
- Include support for virt-what [Orabug: 36517679]
- Fix syntax error in patch [Orabug: 39009351]

[1.0.58-15]
- kdump-lib: use EFI var to find UKI

[1.0.58-14]
- spec: Add the missing 20th patch

[1.0.58-13]
- kdump-lib: always disable systemd-gpt-auto-generator

[1.0.58-12]
- spec: drop dependency for binutils

[1.0.58-11]
- spec: drop dependency for binutils

[1.0.58-10]
- sysconfig: use initramfs_options to reduce memory usage

[1.0.58-9]
- kdump-lib-initramfs: Fix performance regression in kdump_get_conf_val

[1.0.58-8]
- kexec-kdump-howto.txt: update paragraphs related to disable_cpu_apicid



ELBA-2026-50138-0 Oracle Linux 9 conmon bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2026-50138-0

http://linux.oracle.com/errata/ELBA-2026-50138-0.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
conmon-2.2.1-2.el9_8.x86_64.rpm

aarch64:
conmon-2.2.1-2.el9_8.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/conmon-2.2.1-2.el9_8.src.rpm

Description of changes:

[3:2.2.1-2]
- reset create_pid after waitpid to prevent signaling unrelated processes
- Resolves: RHEL-180615



ELBA-2026-500128 Oracle Linux 10 osbuild bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-500128

http://linux.oracle.com/errata/ELBA-2026-500128.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
osbuild-185-1.0.1.el10.x86_64.rpm
osbuild-container-selinux-185-1.0.1.el10.x86_64.rpm
osbuild-depsolve-dnf-185-1.0.1.el10.x86_64.rpm
osbuild-initrd-185-1.0.1.el10.x86_64.rpm
osbuild-luks2-185-1.0.1.el10.x86_64.rpm
osbuild-lvm2-185-1.0.1.el10.x86_64.rpm
osbuild-ostree-185-1.0.1.el10.x86_64.rpm
osbuild-selinux-185-1.0.1.el10.x86_64.rpm
osbuild-tools-185-1.0.1.el10.x86_64.rpm
osbuild-virt-deps-185-1.0.1.el10.x86_64.rpm
python3-osbuild-185-1.0.1.el10.x86_64.rpm

aarch64:
osbuild-185-1.0.1.el10.aarch64.rpm
osbuild-container-selinux-185-1.0.1.el10.aarch64.rpm
osbuild-depsolve-dnf-185-1.0.1.el10.aarch64.rpm
osbuild-initrd-185-1.0.1.el10.aarch64.rpm
osbuild-luks2-185-1.0.1.el10.aarch64.rpm
osbuild-lvm2-185-1.0.1.el10.aarch64.rpm
osbuild-ostree-185-1.0.1.el10.aarch64.rpm
osbuild-tools-185-1.0.1.el10.aarch64.rpm
osbuild-virt-deps-185-1.0.1.el10.aarch64.rpm
osbuild-selinux-185-1.0.1.el10.aarch64.rpm
python3-osbuild-185-1.0.1.el10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/osbuild-185-1.0.1.el10.src.rpm

Description of changes:

[185-1.0.1]
- Bump to v185 [Orabug: 39666639]
- Oracle Linux support was merged upstream in osbuild PR 2476, adding the OL runner symlink



ELBA-2026-26196 Oracle Linux 9 openscap bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2026-26196

http://linux.oracle.com/errata/ELBA-2026-26196.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
openscap-1.3.14-1.0.1.el9_8.i686.rpm
openscap-1.3.14-1.0.1.el9_8.x86_64.rpm
openscap-devel-1.3.14-1.0.1.el9_8.i686.rpm
openscap-devel-1.3.14-1.0.1.el9_8.x86_64.rpm
openscap-engine-sce-1.3.14-1.0.1.el9_8.i686.rpm
openscap-engine-sce-1.3.14-1.0.1.el9_8.x86_64.rpm
openscap-engine-sce-devel-1.3.14-1.0.1.el9_8.i686.rpm
openscap-engine-sce-devel-1.3.14-1.0.1.el9_8.x86_64.rpm
openscap-python3-1.3.14-1.0.1.el9_8.x86_64.rpm
openscap-scanner-1.3.14-1.0.1.el9_8.x86_64.rpm
openscap-utils-1.3.14-1.0.1.el9_8.x86_64.rpm

aarch64:
openscap-1.3.14-1.0.1.el9_8.aarch64.rpm
openscap-devel-1.3.14-1.0.1.el9_8.aarch64.rpm
openscap-engine-sce-1.3.14-1.0.1.el9_8.aarch64.rpm
openscap-engine-sce-devel-1.3.14-1.0.1.el9_8.aarch64.rpm
openscap-python3-1.3.14-1.0.1.el9_8.aarch64.rpm
openscap-scanner-1.3.14-1.0.1.el9_8.aarch64.rpm
openscap-utils-1.3.14-1.0.1.el9_8.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/openscap-1.3.14-1.0.1.el9_8.src.rpm

Description of changes:

[1.3.14-1.0.1]
- Restore original version
- Drop OpenELA branding

[1.3.14.openela.1.0]
- Add OpenELA to openscap

[1:1.3.14-1]
- Upgrade to the latest upstream release (RHEL-167949)



ELSA-2026-49211 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-49211

http://linux.oracle.com/errata/ELSA-2026-49211.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-abi-stablelists-6.12.0-211.42.1.el10_2.noarch.rpm
kernel-core-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-cross-headers-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-debug-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-debug-core-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-debug-devel-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-debug-devel-matched-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-debug-modules-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-debug-modules-core-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-debug-modules-extra-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-debug-uki-virt-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-devel-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-devel-matched-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-doc-6.12.0-211.42.1.el10_2.noarch.rpm
kernel-headers-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-modules-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-modules-core-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-modules-extra-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-modules-extra-matched-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-tools-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-tools-libs-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-tools-libs-devel-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-uki-virt-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-uki-virt-addons-6.12.0-211.42.1.el10_2.x86_64.rpm
libperf-6.12.0-211.42.1.el10_2.x86_64.rpm
perf-6.12.0-211.42.1.el10_2.x86_64.rpm
python3-perf-6.12.0-211.42.1.el10_2.x86_64.rpm
rtla-6.12.0-211.42.1.el10_2.x86_64.rpm
rv-6.12.0-211.42.1.el10_2.x86_64.rpm

aarch64:
kernel-cross-headers-6.12.0-211.42.1.el10_2.aarch64.rpm
kernel-headers-6.12.0-211.42.1.el10_2.aarch64.rpm
kernel-tools-6.12.0-211.42.1.el10_2.aarch64.rpm
kernel-tools-libs-6.12.0-211.42.1.el10_2.aarch64.rpm
kernel-tools-libs-devel-6.12.0-211.42.1.el10_2.aarch64.rpm
libperf-6.12.0-211.42.1.el10_2.aarch64.rpm
perf-6.12.0-211.42.1.el10_2.aarch64.rpm
python3-perf-6.12.0-211.42.1.el10_2.aarch64.rpm
rtla-6.12.0-211.42.1.el10_2.aarch64.rpm
rv-6.12.0-211.42.1.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/kernel-6.12.0-211.42.1.el10_2.src.rpm

Related CVEs:

CVE-2025-68211
CVE-2026-46303
CVE-2026-64530

Description of changes:

[6.12.0-211.42.1]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64