ELSA-2026-49838 Important: Oracle Linux 9 osbuild-composer security, bug fix, and enhancement update
ELSA-2026-50108-0 Important: Oracle Linux 9 ldns security update
ELSA-2026-49214 Important: Oracle Linux 8 kernel security update
ELSA-2026-49921 Important: Oracle Linux 9 thunderbird security update
ELSA-2026-500121 Important: Oracle Linux 7 Unbreakable Enterprise kernel security update
ELSA-2026-49520 Important: Oracle Linux 8 ldns security update
ELSA-2026-49927 Moderate: Oracle Linux 8 fence-agents security update
ELSA-2026-49512 Important: Oracle Linux 8 mingw-glib2 security update
ELSA-2026-49922 Important: Oracle Linux 8 thunderbird security update
ELBA-2026-48843 Oracle Linux 8 fwupd bug fix and enhancement update
ELBA-2026-48830 Oracle Linux 8 libxmlb bug fix and enhancement update
ELSA-2026-50141-0 Important: Oracle Linux 9 sg3_utils security, bug fix, and enhancement update
ELSA-2026-49667 Moderate: Oracle Linux 9 p11-kit security update
ELSA-2026-500121 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
ELSA-2026-50147-0 Moderate: Oracle Linux 9 libgcrypt security update
ELSA-2026-50317-0 Important: Oracle Linux 9 fence-agents security update
ELBA-2026-50153-0 Oracle Linux 10 rust-bootupd bug fix and enhancement update
ELBA-2026-500126 Oracle Linux 10 kdump-utils bug fix update
ELBA-2026-50138-0 Oracle Linux 9 conmon bug fix and enhancement update
ELBA-2026-500128 Oracle Linux 10 osbuild bug fix update
ELBA-2026-26196 Oracle Linux 9 openscap bug fix and enhancement update
ELSA-2026-49211 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
ELBA-2026-50135-0 Oracle Linux 10 policycoreutils bug fix and enhancement update
ELBA-2026-500091 Oracle Linux 9 oracle-database-preinstall-19c bug fix update
ELBA-2026-50166-0 Oracle Linux 9 linuxptp bug fix and enhancement update
ELSA-2026-50142-0 Important: Oracle Linux 10 sg3_utils security, bug fix, and enhancement update
ELSA-2026-49607 Important: Oracle Linux 9 frr10 security, bug fix, and enhancement update
ELSA-2026-49212 Important: Oracle Linux 9 kernel security update
ELSA-2026-42899 Important: Oracle Linux 9 java-25-openjdk security update
ELBA-2026-50136-0 Oracle Linux 9 gnutls bug fix and enhancement update
ELBA-2026-50150-0 Oracle Linux 9 rust-bootupd bug fix and enhancement update
ELBA-2026-50159-0 Oracle Linux 9 keylime bug fix and enhancement update
ELSA-2026-49836 Important: Oracle Linux 10 ldns security update
ELBA-2026-49518 Oracle Linux 9 glibc bug fix and enhancement update
ELBA-2026-50133-0 Oracle Linux 9 autofs bug fix and enhancement update
ELBA-2026-50171-0 Oracle Linux 10 gdm bug fix and enhancement update
ELSA-2026-48034 Important: Oracle Linux 10 nodejs24 security update
ELSA-2026-50144-0 Moderate: Oracle Linux 10 libgcrypt security update
ELSA-2026-49914 Low: Oracle Linux 10 php8.4 security, bug fix, and enhancement update
ELSA-2026-49838 Important: Oracle Linux 9 osbuild-composer security, bug fix, and enhancement update
Oracle Linux Security Advisory ELSA-2026-49838
http://linux.oracle.com/errata/ELSA-2026-49838.html
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
x86_64:
osbuild-composer-175-1.0.1.el9_8.x86_64.rpm
osbuild-composer-core-175-1.0.1.el9_8.x86_64.rpm
osbuild-composer-worker-175-1.0.1.el9_8.x86_64.rpm
aarch64:
osbuild-composer-175-1.0.1.el9_8.aarch64.rpm
osbuild-composer-core-175-1.0.1.el9_8.aarch64.rpm
osbuild-composer-worker-175-1.0.1.el9_8.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/osbuild-composer-175-1.0.1.el9_8.src.rpm
Related CVEs:
CVE-2026-32280
CVE-2026-32281
Description of changes:
[175-1.0.1]
- Track github upstream
ELSA-2026-50108-0 Important: Oracle Linux 9 ldns security update
Oracle Linux Security Advisory ELSA-2026-50108-0
http://linux.oracle.com/errata/ELSA-2026-50108-0.html
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
x86_64:
ldns-1.7.1-12.el9_8.1.i686.rpm
ldns-1.7.1-12.el9_8.1.x86_64.rpm
ldns-devel-1.7.1-12.el9_8.1.x86_64.rpm
ldns-doc-1.7.1-12.el9_8.1.noarch.rpm
ldns-utils-1.7.1-12.el9_8.1.x86_64.rpm
perl-ldns-1.7.1-12.el9_8.1.x86_64.rpm
python3-ldns-1.7.1-12.el9_8.1.x86_64.rpm
aarch64:
ldns-1.7.1-12.el9_8.1.aarch64.rpm
ldns-devel-1.7.1-12.el9_8.1.aarch64.rpm
ldns-doc-1.7.1-12.el9_8.1.noarch.rpm
ldns-utils-1.7.1-12.el9_8.1.aarch64.rpm
perl-ldns-1.7.1-12.el9_8.1.aarch64.rpm
python3-ldns-1.7.1-12.el9_8.1.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/ldns-1.7.1-12.el9_8.1.src.rpm
Related CVEs:
CVE-2026-10846
Description of changes:
[1.7.1-12.1]
- Fix CVE-2026-10846: DNS response spoofing via missing
address/port/TXID and question section validation (RHEL-210701)
ELSA-2026-49214 Important: Oracle Linux 8 kernel security update
Oracle Linux Security Advisory ELSA-2026-49214
http://linux.oracle.com/errata/ELSA-2026-49214.html
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
x86_64:
bpftool-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-abi-stablelists-4.18.0-553.150.1.el8_10.noarch.rpm
kernel-core-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-cross-headers-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-debug-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-debug-core-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-debug-devel-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-debug-modules-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-debug-modules-extra-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-devel-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-doc-4.18.0-553.150.1.el8_10.noarch.rpm
kernel-headers-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-modules-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-modules-extra-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-tools-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-tools-libs-4.18.0-553.150.1.el8_10.x86_64.rpm
kernel-tools-libs-devel-4.18.0-553.150.1.el8_10.x86_64.rpm
perf-4.18.0-553.150.1.el8_10.x86_64.rpm
python3-perf-4.18.0-553.150.1.el8_10.x86_64.rpm
aarch64:
bpftool-4.18.0-553.150.1.el8_10.aarch64.rpm
kernel-cross-headers-4.18.0-553.150.1.el8_10.aarch64.rpm
kernel-headers-4.18.0-553.150.1.el8_10.aarch64.rpm
kernel-tools-4.18.0-553.150.1.el8_10.aarch64.rpm
kernel-tools-libs-4.18.0-553.150.1.el8_10.aarch64.rpm
kernel-tools-libs-devel-4.18.0-553.150.1.el8_10.aarch64.rpm
perf-4.18.0-553.150.1.el8_10.aarch64.rpm
python3-perf-4.18.0-553.150.1.el8_10.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/kernel-4.18.0-553.150.1.el8_10.src.rpm
Related CVEs:
CVE-2026-31692
CVE-2026-43116
CVE-2026-46150
CVE-2026-64530
Description of changes:
[4.18.0-553.150.1]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 cb[] in ip6_err_gen_icmpv6_unreach() (Eric Dumazet) [Orabug: 39300930] {CVE-2026-43038}
- tracing/events: Expand global buffer for in-kernel event enables (Manjunath Patil) [Orabug: 38790406]
- net/mlx5: poll mlx5 eq during irq migration (Praveen Kumar Kannoju) [Orabug: 38776184]
[5.4.17-2136.357.3]
- net: skbuff: fix missing zerocopy reference in pskb_carve helpers (Minh Nguyen) [Orabug: 39619389] {CVE-2026-52943}
[5.4.17-2136.357.2]
- net: fix fanout UAF in packet_release() via NETDEV_UP race (Yochai Eisenrich) [Orabug: 39250953] {CVE-2026-31504}
- x86/kaslr: Recognize all ZONE_DEVICE users as physaddr consumers (Dan Williams) [Orabug: 39429802]
- x86/kaslr: Reduce KASLR entropy on most x86 systems (Balbir Singh) [Orabug: 39429802]
- net: tap: NULL pointer derefence in dev_parse_header_protocol when skb->dev is null (Cezar Bulinaru) [Orabug: 39526882] {CVE-2022-50073}
- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39548666] {CVE-2025-10263}
- arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland) [Orabug: 39548666]
- ARM: uek: Disable CONFIG_QCOM_FALKOR_ERRATUM_1003 (Boris Ostrovsky) [Orabug: 39548666]
- arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland) [Orabug: 39548666]
- arm64: cputype: Add C1-Premium definitions (Mark Rutland) [Orabug: 39548666]
- arm64: cputype: Add C1-Ultra definitions (Mark Rutland) [Orabug: 39548666]
- ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (Eric Dumazet) [Orabug: 39300926] {CVE-2026-43037}
[5.4.17-2136.357.1]
- batman-adv: hold claim backbone gateways by reference (Haoze Xie) [Orabug: 39262375] {CVE-2026-31657}
- scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (Michael Bommarito) [Orabug: 39446045]
- scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (Michael Bommarito) [Orabug: 39446045]
- scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (Michael Bommarito) [Orabug: 39446045]
- rds: Drop rds conn in connect worker if not in down state. (Rohit Nair) [Orabug: 39152239]
[5.4.17-2136.356.4.1]
- smb: client: reject userspace cifs.spnego descriptions (Asim Viladi Oglu Manizada) [Orabug: 39463669] {CVE-2026-46243}
[5.4.17-2136.356.4]
- tun: free page on build_skb failure in tun_xdp_one() (Weiming Shi) [Orabug: 39429147]
- tap: free page on error paths in tap_get_user_xdp() (Weiming Shi) [Orabug: 39429147]
- tun: free page on short-frame rejection in tun_xdp_one() (Weiming Shi) [Orabug: 39429147]
[5.4.17-2136.356.3]
- ptrace: slightly saner 'get_dumpable()' logic (Linus Torvalds) [Orabug: 39384275,39391459] {CVE-2026-46333}
- net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim) [Orabug: 39368828,39441326] {CVE-2026-43503,CVE-2026-46300}
- net: skbuff: preserve shared-frag marker during coalescing (William Bowling) [Orabug: 39368828] {CVE-2026-46300}
[5.4.17-2136.356.2]
- nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (Jeff Layton) [Orabug: 39167617,39368718] {CVE-2026-31402}
- scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() (Maurizio Lombardi) [Orabug: 38985173,39368732] {CVE-2026-23216}
- scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() (Maurizio Lombardi) [Orabug: 38970455,39368774] {CVE-2026-23193}
- xfrm: esp: avoid in-place decrypt on shared skb frags (Kuan-Ting Chen) [Orabug: 39334580,39367147] {CVE-2026-43284}
- x86/CPU/AMD: Add a fix for AMD-SB-7052 (Prathyushi Nangia) [Orabug: 39218897] {CVE-2025-54518}
[5.4.17-2136.356.1]
- arm64/kvm: Include linux/random.h in trng.c (Siddh Raman Pant) [Orabug: 39327096]
- i2c: designware: Disable TX_EMPTY irq while waiting for block length byte (Tam Nguyen) [Orabug: 39174662]
- i2c: designware: Handle invalid SMBus block data response length value (Tam Nguyen) [Orabug: 39174662]
- i2c: designware: fix __i2c_dw_disable() in case master is holding SCL low (Yann Sionneau) [Orabug: 39174662]
ELSA-2026-49520 Important: Oracle Linux 8 ldns security update
Oracle Linux Security Advisory ELSA-2026-49520
http://linux.oracle.com/errata/ELSA-2026-49520.html
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
x86_64:
ldns-1.7.0-23.el8_10.i686.rpm
ldns-1.7.0-23.el8_10.x86_64.rpm
ldns-devel-1.7.0-23.el8_10.i686.rpm
ldns-devel-1.7.0-23.el8_10.x86_64.rpm
ldns-doc-1.7.0-23.el8_10.noarch.rpm
ldns-utils-1.7.0-23.el8_10.x86_64.rpm
perl-ldns-1.7.0-23.el8_10.x86_64.rpm
python3-ldns-1.7.0-23.el8_10.x86_64.rpm
aarch64:
ldns-1.7.0-23.el8_10.aarch64.rpm
ldns-devel-1.7.0-23.el8_10.aarch64.rpm
ldns-doc-1.7.0-23.el8_10.noarch.rpm
ldns-utils-1.7.0-23.el8_10.aarch64.rpm
perl-ldns-1.7.0-23.el8_10.aarch64.rpm
python3-ldns-1.7.0-23.el8_10.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/ldns-1.7.0-23.el8_10.src.rpm
Related CVEs:
CVE-2026-10846
Description of changes:
[1.7.0-23]
- Fix CVE-2026-10846: validate DNS response source address, transaction
ID, and query section matching
- Resolves: RHEL-210700
ELSA-2026-49927 Moderate: Oracle Linux 8 fence-agents security update
Oracle Linux Security Advisory ELSA-2026-49927
http://linux.oracle.com/errata/ELSA-2026-49927.html
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
x86_64:
fence-agents-all-4.2.1-129.el8_10.28.x86_64.rpm
fence-agents-amt-ws-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-apc-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-apc-snmp-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-bladecenter-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-brocade-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-cisco-mds-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-cisco-ucs-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-common-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-compute-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-drac5-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-eaton-snmp-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-emerson-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-eps-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-heuristics-ping-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-hpblade-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ibm-powervs-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ibm-vpc-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ibmblade-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ifmib-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ilo-moonshot-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ilo-mp-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ilo-ssh-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ilo2-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-intelmodular-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ipdu-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ipmilan-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-kdump-4.2.1-129.el8_10.28.x86_64.rpm
fence-agents-kubevirt-4.2.1-129.el8_10.28.x86_64.rpm
fence-agents-lpar-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-mpath-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-nutanix-ahv-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-redfish-4.2.1-129.el8_10.28.x86_64.rpm
fence-agents-rhevm-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-rsa-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-rsb-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-sbd-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-scsi-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-virsh-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-vmware-rest-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-vmware-soap-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-wti-4.2.1-129.el8_10.28.noarch.rpm
aarch64:
fence-agents-all-4.2.1-129.el8_10.28.aarch64.rpm
fence-agents-amt-ws-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-apc-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-apc-snmp-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-bladecenter-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-brocade-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-cisco-mds-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-cisco-ucs-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-common-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-compute-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-drac5-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-eaton-snmp-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-emerson-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-eps-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-heuristics-ping-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-hpblade-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ibm-powervs-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ibm-vpc-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ibmblade-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ifmib-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ilo-moonshot-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ilo-mp-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ilo-ssh-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ilo2-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-intelmodular-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ipdu-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-ipmilan-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-kdump-4.2.1-129.el8_10.28.aarch64.rpm
fence-agents-kubevirt-4.2.1-129.el8_10.28.aarch64.rpm
fence-agents-mpath-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-nutanix-ahv-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-redfish-4.2.1-129.el8_10.28.aarch64.rpm
fence-agents-rhevm-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-rsa-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-rsb-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-sbd-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-scsi-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-virsh-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-vmware-rest-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-vmware-soap-4.2.1-129.el8_10.28.noarch.rpm
fence-agents-wti-4.2.1-129.el8_10.28.noarch.rpm
SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/fence-agents-4.2.1-129.el8_10.28.src.rpm
Related CVEs:
CVE-2026-44431
Description of changes:
[4.2.1-129.28]
- bundled urllib3: fix CVE-2026-44431
Resolves: RHEL-178594
ELSA-2026-49512 Important: Oracle Linux 8 mingw-glib2 security update
Oracle Linux Security Advisory ELSA-2026-49512
http://linux.oracle.com/errata/ELSA-2026-49512.html
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
x86_64:
mingw32-glib2-2.70.1-9.el8_10.noarch.rpm
mingw32-glib2-static-2.70.1-9.el8_10.noarch.rpm
mingw64-glib2-2.70.1-9.el8_10.noarch.rpm
mingw64-glib2-static-2.70.1-9.el8_10.noarch.rpm
SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/mingw-glib2-2.70.1-9.el8_10.src.rpm
Related CVEs:
CVE-2025-14087
CVE-2026-58010
CVE-2026-58011
CVE-2026-58012
CVE-2026-58013
CVE-2026-58014
CVE-2026-58015
CVE-2026-58016
Description of changes:
[2.70.1-9]
- Fix CVE-2026-58010: off-by-one error in gvs_tuple_is_normal()
Resolves: RHEL-212164
[2.70.1-8]
- Fix CVE-2026-58011: g_date_time_add_full() range validation
Resolves: RHEL-212184
[2.70.1-7]
- Fix CVE-2026-58013: memcmp buffer over-read in giochannel
Resolves: RHEL-212234
[2.70.1-6]
- Fix CVE-2026-58012: buffer overflow in gregex substitutions
Resolves: RHEL-212200
[2.70.1-5]
- Fix CVE-2025-14087: integer overflow in GVariant parser
Resolves: RHEL-154707
[2.70.1-4]
- Fix CVE-2026-58016: D-Bus introspection XML node nesting check
Resolves: RHEL-190617
[2.70.1-3]
- Fix CVE-2026-58014: one-byte heap under-read in mingw-glib2
Resolves: RHEL-190609
[2.70.1-2]
- Fix CVE-2026-58015: D-Bus cookie context path traversal
Resolves: RHEL-212246
ELSA-2026-49922 Important: Oracle Linux 8 thunderbird security update
Oracle Linux Security Advisory ELSA-2026-49922
http://linux.oracle.com/errata/ELSA-2026-49922.html
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
x86_64:
thunderbird-140.13.0-1.0.1.el8_10.x86_64.rpm
aarch64:
thunderbird-140.13.0-1.0.1.el8_10.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/thunderbird-140.13.0-1.0.1.el8_10.src.rpm
Related CVEs:
CVE-2026-14899
CVE-2026-15718
CVE-2026-15719
CVE-2026-16349
CVE-2026-16350
CVE-2026-16351
CVE-2026-16352
CVE-2026-16353
CVE-2026-16354
CVE-2026-16355
CVE-2026-16356
CVE-2026-16357
CVE-2026-16358
CVE-2026-16359
CVE-2026-16360
CVE-2026-16361
CVE-2026-16362
CVE-2026-16363
CVE-2026-16368
CVE-2026-16369
CVE-2026-16371
CVE-2026-16374
CVE-2026-16375
CVE-2026-16377
CVE-2026-16379
CVE-2026-16381
CVE-2026-16383
CVE-2026-16387
CVE-2026-16390
CVE-2026-16391
CVE-2026-16396
CVE-2026-16405
CVE-2026-16412
Description of changes:
[140.13.0-1.0.1]
- Fix prefs for new nss [Orabug: 37079820]
- Add Oracle prefs file
[140.13.0]
- Add OpenELA debranding
[140.13.0-1]
- Update to 140.13.0 ESR
ELBA-2026-48843 Oracle Linux 8 fwupd bug fix and enhancement update
Oracle Linux Bug Fix Advisory ELBA-2026-48843
http://linux.oracle.com/errata/ELBA-2026-48843.html
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
x86_64:
fwupd-2.1.6-1.0.1.el8_10.x86_64.rpm
fwupd-devel-2.1.6-1.0.1.el8_10.x86_64.rpm
aarch64:
fwupd-2.1.6-1.0.1.el8_10.aarch64.rpm
fwupd-devel-2.1.6-1.0.1.el8_10.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/fwupd-2.1.6-1.0.1.el8_10.src.rpm
Description of changes:
[2.1.6-1.0.1]
- Align sections to 512 bytes [Orabug: 35265981]
- Use objcopy to build arm/aarch64 binaries if binutils 2.30-113.0.3 or newer [Orabug: 35265981]
- Enabled signing for aarch64 [Orabug: 35265981]
- Modify meson.build for fwupd-efi [Orabug: 35265981]
- Update SBAT data to include Oracle [Oracle: 33072886]
- Build with the updated Oracle certificate
- Use oraclesecureboot301 as certdir [Orabug: 29881368]
- Use new signing certificate (Alex Burmashev)
[2.1.6-1]
- Rebase to a new version.
- Resolves: RHEL-185615
ELBA-2026-48830 Oracle Linux 8 libxmlb bug fix and enhancement update
Oracle Linux Bug Fix Advisory ELBA-2026-48830
http://linux.oracle.com/errata/ELBA-2026-48830.html
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
x86_64:
libxmlb-0.3.28-1.el8_10.i686.rpm
libxmlb-0.3.28-1.el8_10.x86_64.rpm
libxmlb-devel-0.3.28-1.el8_10.i686.rpm
libxmlb-devel-0.3.28-1.el8_10.x86_64.rpm
aarch64:
libxmlb-0.3.28-1.el8_10.aarch64.rpm
libxmlb-devel-0.3.28-1.el8_10.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/libxmlb-0.3.28-1.el8_10.src.rpm
Description of changes:
[0.3.28-1]
- New upstream release for fwupd backport
- Resolves: RHEL-190658
ELSA-2026-50141-0 Important: Oracle Linux 9 sg3_utils security, bug fix, and enhancement update
Oracle Linux Security Advisory ELSA-2026-50141-0
http://linux.oracle.com/errata/ELSA-2026-50141-0.html
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
x86_64:
sg3_utils-1.47-10.el9_8.1.x86_64.rpm
sg3_utils-devel-1.47-10.el9_8.1.i686.rpm
sg3_utils-devel-1.47-10.el9_8.1.x86_64.rpm
sg3_utils-libs-1.47-10.el9_8.1.i686.rpm
sg3_utils-libs-1.47-10.el9_8.1.x86_64.rpm
aarch64:
sg3_utils-1.47-10.el9_8.1.aarch64.rpm
sg3_utils-devel-1.47-10.el9_8.1.aarch64.rpm
sg3_utils-libs-1.47-10.el9_8.1.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/sg3_utils-1.47-10.el9_8.1.src.rpm
Related CVEs:
CVE-2026-16313
Description of changes:
[1.47-10.1]
- sg_inq output conformance for SCSI name string and ATA fields (RHEL-188130)
ELSA-2026-49667 Moderate: Oracle Linux 9 p11-kit security update
Oracle Linux Security Advisory ELSA-2026-49667
http://linux.oracle.com/errata/ELSA-2026-49667.html
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
x86_64:
p11-kit-0.26.4-1.el9_8.i686.rpm
p11-kit-0.26.4-1.el9_8.x86_64.rpm
p11-kit-client-0.26.4-1.el9_8.x86_64.rpm
p11-kit-devel-0.26.4-1.el9_8.i686.rpm
p11-kit-devel-0.26.4-1.el9_8.x86_64.rpm
p11-kit-server-0.26.4-1.el9_8.x86_64.rpm
p11-kit-trust-0.26.4-1.el9_8.i686.rpm
p11-kit-trust-0.26.4-1.el9_8.x86_64.rpm
aarch64:
p11-kit-0.26.4-1.el9_8.aarch64.rpm
p11-kit-client-0.26.4-1.el9_8.aarch64.rpm
p11-kit-devel-0.26.4-1.el9_8.aarch64.rpm
p11-kit-server-0.26.4-1.el9_8.aarch64.rpm
p11-kit-trust-0.26.4-1.el9_8.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/p11-kit-0.26.4-1.el9_8.src.rpm
Related CVEs:
CVE-2026-13757
Description of changes:
[0.26.2-1]
- Rebase to 0.26.2
Resolves: RHEL-147825
[0.26.1-1]
- Rebase to 0.26.1
Resolves: RHEL-139075, RHEL-118361, RHEL-126132
[0.25.10-1]
- Update to new upstream release 0.25.10
Resolves: RHEL-115453
[0.25.3-3]
- Fix regression in trust where file creation fails for long cert labels
Resolves: RHEL-58899
- Fix usage message in p11-kit list-tokens command
Resolves: RHEL-31810
ELSA-2026-500121 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
Oracle Linux Security Advisory ELSA-2026-500121
http://linux.oracle.com/errata/ELSA-2026-500121.html
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
aarch64:
kernel-uek-5.4.17-2136.358.2.el8uek.aarch64.rpm
kernel-uek-debug-5.4.17-2136.358.2.el8uek.aarch64.rpm
kernel-uek-debug-devel-5.4.17-2136.358.2.el8uek.aarch64.rpm
kernel-uek-devel-5.4.17-2136.358.2.el8uek.aarch64.rpm
kernel-uek-doc-5.4.17-2136.358.2.el8uek.noarch.rpm
SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/kernel-uek-5.4.17-2136.358.2.el8uek.src.rpm
Related CVEs:
CVE-2026-43038
CVE-2026-43499
CVE-2026-46043
CVE-2026-46331
CVE-2026-64600
Description of changes:
[5.4.17-2136.358.2]
- xfs: resample the data fork mapping after cycling ILOCK (Darrick J. Wong) [Orabug: 39776792] {CVE-2026-64600}
- net: Work around Marvell NIC TX stalls (Venkat Venkatsubra) [Orabug: 39765820]
[5.4.17-2136.358.1]
- KVM: x86: Fix shadow paging use-after-free due to unexpected role (Paolo Bonzini) [Orabug: 39673871]
- KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/MMU: Recursively zap nested TDP SPs when zapping last/only parent (Ben Gardon) [Orabug: 39673871]
- KVM: x86/mmu: Move flush logic from mmu_page_zap_pte() to FNAME(invlpg) (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: pull call to drop_large_spte() into __link_shadow_page() (Paolo Bonzini) [Orabug: 39673871]
- KVM: x86/mmu: Passing up the error state of mmu_alloc_shadow_roots() (Like Xu) [Orabug: 39673871]
- KVM: MMU: load PDPTRs outside mmu_lock (Paolo Bonzini) [Orabug: 39673871]
- KVM: x86/mmu: Check PDPTRs before allocating PAE roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Always pass 0 for @quadrant when gptes are 8 bytes (David Matlack) [Orabug: 39673871]
- KVM: x86/mmu: Derive shadow MMU page role from parent (David Matlack) [Orabug: 39673871]
- KVM: X86: Remove useless code to set role.gpte_is_8_bytes when role.direct (Lai Jiangshan) [Orabug: 39673871]
- KVM: X86: Synchronize the shadow pagetable before link it (Lai Jiangshan) [Orabug: 39673871]
- KVM: X86: Fix missed remote tlb flush in rmap_write_protect() (Lai Jiangshan) [Orabug: 39673871]
- KVM: x86/mmu: Refactor shadow walk in __direct_map() to reduce indentation (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Stop passing "direct" to mmu_alloc_root() (David Matlack) [Orabug: 39673871]
- KVM: x86/mmu: Use a bool for direct (David Matlack) [Orabug: 39673871]
- kvm: mmu: Replace unsigned with unsigned int for PTE access (Ben Gardon) [Orabug: 39673871]
- KVM: x86/mmu: Ensure MMU pages are available when allocating roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Allocate pae_root and lm_root pages in dedicated helper (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Allocate the lm_root before allocating PAE roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Capture 'mmu' in a local variable when allocating roots (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Alloc page for PDPTEs when shadowing 32-bit NPT with 64-bit (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Stash 'kvm' in a local variable in kvm_mmu_free_roots() (Sean Christopherson) [Orabug: 39673871]
- KVM: x86/mmu: Add a helper to consolidate root sp allocation (Sean Christopherson) [Orabug: 39673871]
- Revert "net/rds: poll eq during user-reset" (Praveen Kumar Kannoju) [Orabug: 39659401]
- net/sched: act_pedit: fix action bind logic (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: free pedit keys on bail from offset check (Pedro Tammela) [Orabug: 39567287]
- net/sched: fix pedit partial COW leading to page cache corruption (Rajat Gupta) [Orabug: 39567287] {CVE-2026-46331}
- net/sched: act_pedit: Parse L3 Header for L4 offset (Max Tottenham) [Orabug: 39567287]
- net/sched: act_pedit: rate limit datapath messages (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: check static offsets a priori (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: remove extra check for key type (Pedro Tammela) [Orabug: 39567287]
- net/sched: simplify tcf_pedit_act (Pedro Tammela) [Orabug: 39567287]
- net/sched: transition act_pedit to rcu and percpu stats (Pedro Tammela) [Orabug: 39567287]
- net/sched: act_pedit: use NLA_POLICY for parsing 'ex' keys (Pedro Tammela) [Orabug: 39567287]
- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (hkbinbin) [Orabug: 39452261] {CVE-2026-46043}
- locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (Davidlohr Bueso) [Orabug: 39426001]
- rtmutex: Use waiter::task instead of current in remove_waiter() (Keenan Dong) [Orabug: 39426001] {CVE-2026-43499}
- ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (Eric Dumazet) [Orabug: 39300930] {CVE-2026-43038}
- tracing/events: Expand global buffer for in-kernel event enables (Manjunath Patil) [Orabug: 38790406]
- net/mlx5: poll mlx5 eq during irq migration (Praveen Kumar Kannoju) [Orabug: 38776184]
[5.4.17-2136.357.3]
- net: skbuff: fix missing zerocopy reference in pskb_carve helpers (Minh Nguyen) [Orabug: 39619389] {CVE-2026-52943}
[5.4.17-2136.357.2]
- net: fix fanout UAF in packet_release() via NETDEV_UP race (Yochai Eisenrich) [Orabug: 39250953] {CVE-2026-31504}
- x86/kaslr: Recognize all ZONE_DEVICE users as physaddr consumers (Dan Williams) [Orabug: 39429802]
- x86/kaslr: Reduce KASLR entropy on most x86 systems (Balbir Singh) [Orabug: 39429802]
- net: tap: NULL pointer derefence in dev_parse_header_protocol when skb->dev is null (Cezar Bulinaru) [Orabug: 39526882] {CVE-2022-50073}
- arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39548666] {CVE-2025-10263}
- arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland) [Orabug: 39548666]
- ARM: uek: Disable CONFIG_QCOM_FALKOR_ERRATUM_1003 (Boris Ostrovsky) [Orabug: 39548666]
- arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland) [Orabug: 39548666]
- arm64: cputype: Add C1-Premium definitions (Mark Rutland) [Orabug: 39548666]
- arm64: cputype: Add C1-Ultra definitions (Mark Rutland) [Orabug: 39548666]
- ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (Eric Dumazet) [Orabug: 39300926] {CVE-2026-43037}
[5.4.17-2136.357.1]
- batman-adv: hold claim backbone gateways by reference (Haoze Xie) [Orabug: 39262375] {CVE-2026-31657}
- scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (Michael Bommarito) [Orabug: 39446045]
- scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (Michael Bommarito) [Orabug: 39446045]
- scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (Michael Bommarito) [Orabug: 39446045]
- rds: Drop rds conn in connect worker if not in down state. (Rohit Nair) [Orabug: 39152239]
[5.4.17-2136.356.4.1]
- smb: client: reject userspace cifs.spnego descriptions (Asim Viladi Oglu Manizada) [Orabug: 39463669] {CVE-2026-46243}
[5.4.17-2136.356.4]
- tun: free page on build_skb failure in tun_xdp_one() (Weiming Shi) [Orabug: 39429147]
- tap: free page on error paths in tap_get_user_xdp() (Weiming Shi) [Orabug: 39429147]
- tun: free page on short-frame rejection in tun_xdp_one() (Weiming Shi) [Orabug: 39429147]
[5.4.17-2136.356.3]
- ptrace: slightly saner 'get_dumpable()' logic (Linus Torvalds) [Orabug: 39384275,39391459] {CVE-2026-46333}
- net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim) [Orabug: 39368828,39441326] {CVE-2026-43503,CVE-2026-46300}
- net: skbuff: preserve shared-frag marker during coalescing (William Bowling) [Orabug: 39368828] {CVE-2026-46300}
[5.4.17-2136.356.2]
- nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (Jeff Layton) [Orabug: 39167617,39368718] {CVE-2026-31402}
- scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() (Maurizio Lombardi) [Orabug: 38985173,39368732] {CVE-2026-23216}
- scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() (Maurizio Lombardi) [Orabug: 38970455,39368774] {CVE-2026-23193}
- xfrm: esp: avoid in-place decrypt on shared skb frags (Kuan-Ting Chen) [Orabug: 39334580,39367147] {CVE-2026-43284}
- x86/CPU/AMD: Add a fix for AMD-SB-7052 (Prathyushi Nangia) [Orabug: 39218897] {CVE-2025-54518}
[5.4.17-2136.356.1]
- arm64/kvm: Include linux/random.h in trng.c (Siddh Raman Pant) [Orabug: 39327096]
- i2c: designware: Disable TX_EMPTY irq while waiting for block length byte (Tam Nguyen) [Orabug: 39174662]
- i2c: designware: Handle invalid SMBus block data response length value (Tam Nguyen) [Orabug: 39174662]
- i2c: designware: fix __i2c_dw_disable() in case master is holding SCL low (Yann Sionneau) [Orabug: 39174662]
ELSA-2026-50147-0 Moderate: Oracle Linux 9 libgcrypt security update
Oracle Linux Security Advisory ELSA-2026-50147-0
http://linux.oracle.com/errata/ELSA-2026-50147-0.html
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
x86_64:
libgcrypt-1.10.0-13.el9_8.i686.rpm
libgcrypt-1.10.0-13.el9_8.x86_64.rpm
libgcrypt-devel-1.10.0-13.el9_8.i686.rpm
libgcrypt-devel-1.10.0-13.el9_8.x86_64.rpm
aarch64:
libgcrypt-1.10.0-13.el9_8.aarch64.rpm
libgcrypt-devel-1.10.0-13.el9_8.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/libgcrypt-1.10.0-13.el9_8.src.rpm
Related CVEs:
CVE-2026-41989
Description of changes:
[1.10.0-13]
- Bump version to fix wrong build target.
[1.10.0.12]
- Fix CVE-2026-41989: Denial of Service and buffer overflow via crafted ECDH ciphertext
ELSA-2026-50317-0 Important: Oracle Linux 9 fence-agents security update
Oracle Linux Security Advisory ELSA-2026-50317-0
http://linux.oracle.com/errata/ELSA-2026-50317-0.html
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
x86_64:
fence-agents-aliyun-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-all-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-amt-ws-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-apc-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-apc-snmp-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-aws-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-azure-arm-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-bladecenter-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-brocade-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-cisco-mds-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-cisco-ucs-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-common-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-compute-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-drac5-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-eaton-snmp-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-emerson-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-eps-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-gce-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-heuristics-ping-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-hpblade-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ibm-powervs-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ibm-vpc-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ibmblade-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ifmib-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ilo-moonshot-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ilo-mp-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ilo-ssh-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ilo2-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-intelmodular-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ipdu-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ipmilan-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-kdump-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-kubevirt-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-lpar-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-mpath-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-nutanix-ahv-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-openstack-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-redfish-4.10.0-110.el9_8.5.x86_64.rpm
fence-agents-rhevm-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-rsa-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-rsb-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-sbd-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-scsi-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-virsh-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-vmware-rest-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-vmware-soap-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-wti-4.10.0-110.el9_8.5.noarch.rpm
fence-virt-4.10.0-110.el9_8.5.x86_64.rpm
fence-virtd-4.10.0-110.el9_8.5.x86_64.rpm
fence-virtd-cpg-4.10.0-110.el9_8.5.x86_64.rpm
fence-virtd-libvirt-4.10.0-110.el9_8.5.x86_64.rpm
fence-virtd-multicast-4.10.0-110.el9_8.5.x86_64.rpm
fence-virtd-serial-4.10.0-110.el9_8.5.x86_64.rpm
fence-virtd-tcp-4.10.0-110.el9_8.5.x86_64.rpm
ha-cloud-support-4.10.0-110.el9_8.5.x86_64.rpm
aarch64:
fence-agents-all-4.10.0-110.el9_8.5.aarch64.rpm
fence-agents-amt-ws-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-apc-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-apc-snmp-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-bladecenter-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-brocade-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-cisco-mds-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-cisco-ucs-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-common-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-drac5-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-eaton-snmp-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-emerson-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-eps-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-heuristics-ping-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-hpblade-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ibm-powervs-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ibm-vpc-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ibmblade-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ifmib-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ilo-moonshot-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ilo-mp-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ilo-ssh-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ilo2-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-intelmodular-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ipdu-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-ipmilan-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-kdump-4.10.0-110.el9_8.5.aarch64.rpm
fence-agents-kubevirt-4.10.0-110.el9_8.5.aarch64.rpm
fence-agents-lpar-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-mpath-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-nutanix-ahv-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-redfish-4.10.0-110.el9_8.5.aarch64.rpm
fence-agents-rhevm-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-rsa-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-rsb-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-sbd-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-scsi-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-virsh-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-vmware-rest-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-vmware-soap-4.10.0-110.el9_8.5.noarch.rpm
fence-agents-wti-4.10.0-110.el9_8.5.noarch.rpm
SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/fence-agents-4.10.0-110.el9_8.5.src.rpm
Related CVEs:
CVE-2026-59939
Description of changes:
[4.10.0-110.5]
- bundled httplib2: upgrade to v0.32.0 to fix CVE-2026-59939
Resolves: RHEL-193808
[4.10.0-110.4]
- fence_openstack: fix list-action to avoid timeout when
there are 100+ VMs on the hypervisor
Resolves: RHEL-186320
ELBA-2026-50153-0 Oracle Linux 10 rust-bootupd bug fix and enhancement update
Oracle Linux Bug Fix Advisory ELBA-2026-50153-0
http://linux.oracle.com/errata/ELBA-2026-50153-0.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
bootupd-0.2.35-1.el10_2.x86_64.rpm
aarch64:
bootupd-0.2.35-1.el10_2.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/rust-bootupd-0.2.35-1.el10_2.src.rpm
Description of changes:
[0.2.35-1]
- Update to v0.2.35
ELBA-2026-500126 Oracle Linux 10 kdump-utils bug fix update
Oracle Linux Bug Fix Advisory ELBA-2026-500126
http://linux.oracle.com/errata/ELBA-2026-500126.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
kdump-utils-1.0.58-15.0.2.el10.x86_64.rpm
aarch64:
kdump-utils-1.0.58-15.0.2.el10.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/kdump-utils-1.0.58-15.0.2.el10.src.rpm
Description of changes:
[1.0.58-15.0.2]
- kdump: add iSCSI driver injection for iSCSI boot setups [Orabug: 38989420]
[1.0.58-15.0.1]
- Disable transparent_hugepage for aarch64 [Orabug: 37867172]
- Do not use squash-erofs on UEK kernels [Orabug: 37737510]
- Port OL9 patches to OL10 [Orabug: 37600072]
arm64: skip memory integrity checks in purgatory [Orabug: 30822387]
disable iommu for kdump [Orabug: 30832988]
append no_timer_check for xen guest kdump [Orabug: 30928441]
kdump: Skip LVM private devices [Orabug: 33822070]
Update UEK reserved sizes [Orabug: 34663083]
handle xen_netfront in dracut module setup [Orabug: 35615400]
kdumpctl: check if FIPS is enabled [Orabug: 35982140]
- Include support for virt-what [Orabug: 36517679]
- Fix syntax error in patch [Orabug: 39009351]
[1.0.58-15]
- kdump-lib: use EFI var to find UKI
[1.0.58-14]
- spec: Add the missing 20th patch
[1.0.58-13]
- kdump-lib: always disable systemd-gpt-auto-generator
[1.0.58-12]
- spec: drop dependency for binutils
[1.0.58-11]
- spec: drop dependency for binutils
[1.0.58-10]
- sysconfig: use initramfs_options to reduce memory usage
[1.0.58-9]
- kdump-lib-initramfs: Fix performance regression in kdump_get_conf_val
[1.0.58-8]
- kexec-kdump-howto.txt: update paragraphs related to disable_cpu_apicid
ELBA-2026-50138-0 Oracle Linux 9 conmon bug fix and enhancement update
Oracle Linux Bug Fix Advisory ELBA-2026-50138-0
http://linux.oracle.com/errata/ELBA-2026-50138-0.html
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
x86_64:
conmon-2.2.1-2.el9_8.x86_64.rpm
aarch64:
conmon-2.2.1-2.el9_8.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/conmon-2.2.1-2.el9_8.src.rpm
Description of changes:
[3:2.2.1-2]
- reset create_pid after waitpid to prevent signaling unrelated processes
- Resolves: RHEL-180615
ELBA-2026-500128 Oracle Linux 10 osbuild bug fix update
Oracle Linux Bug Fix Advisory ELBA-2026-500128
http://linux.oracle.com/errata/ELBA-2026-500128.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
osbuild-185-1.0.1.el10.x86_64.rpm
osbuild-container-selinux-185-1.0.1.el10.x86_64.rpm
osbuild-depsolve-dnf-185-1.0.1.el10.x86_64.rpm
osbuild-initrd-185-1.0.1.el10.x86_64.rpm
osbuild-luks2-185-1.0.1.el10.x86_64.rpm
osbuild-lvm2-185-1.0.1.el10.x86_64.rpm
osbuild-ostree-185-1.0.1.el10.x86_64.rpm
osbuild-selinux-185-1.0.1.el10.x86_64.rpm
osbuild-tools-185-1.0.1.el10.x86_64.rpm
osbuild-virt-deps-185-1.0.1.el10.x86_64.rpm
python3-osbuild-185-1.0.1.el10.x86_64.rpm
aarch64:
osbuild-185-1.0.1.el10.aarch64.rpm
osbuild-container-selinux-185-1.0.1.el10.aarch64.rpm
osbuild-depsolve-dnf-185-1.0.1.el10.aarch64.rpm
osbuild-initrd-185-1.0.1.el10.aarch64.rpm
osbuild-luks2-185-1.0.1.el10.aarch64.rpm
osbuild-lvm2-185-1.0.1.el10.aarch64.rpm
osbuild-ostree-185-1.0.1.el10.aarch64.rpm
osbuild-tools-185-1.0.1.el10.aarch64.rpm
osbuild-virt-deps-185-1.0.1.el10.aarch64.rpm
osbuild-selinux-185-1.0.1.el10.aarch64.rpm
python3-osbuild-185-1.0.1.el10.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/osbuild-185-1.0.1.el10.src.rpm
Description of changes:
[185-1.0.1]
- Bump to v185 [Orabug: 39666639]
- Oracle Linux support was merged upstream in osbuild PR 2476, adding the OL runner symlink
ELBA-2026-26196 Oracle Linux 9 openscap bug fix and enhancement update
Oracle Linux Bug Fix Advisory ELBA-2026-26196
http://linux.oracle.com/errata/ELBA-2026-26196.html
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
x86_64:
openscap-1.3.14-1.0.1.el9_8.i686.rpm
openscap-1.3.14-1.0.1.el9_8.x86_64.rpm
openscap-devel-1.3.14-1.0.1.el9_8.i686.rpm
openscap-devel-1.3.14-1.0.1.el9_8.x86_64.rpm
openscap-engine-sce-1.3.14-1.0.1.el9_8.i686.rpm
openscap-engine-sce-1.3.14-1.0.1.el9_8.x86_64.rpm
openscap-engine-sce-devel-1.3.14-1.0.1.el9_8.i686.rpm
openscap-engine-sce-devel-1.3.14-1.0.1.el9_8.x86_64.rpm
openscap-python3-1.3.14-1.0.1.el9_8.x86_64.rpm
openscap-scanner-1.3.14-1.0.1.el9_8.x86_64.rpm
openscap-utils-1.3.14-1.0.1.el9_8.x86_64.rpm
aarch64:
openscap-1.3.14-1.0.1.el9_8.aarch64.rpm
openscap-devel-1.3.14-1.0.1.el9_8.aarch64.rpm
openscap-engine-sce-1.3.14-1.0.1.el9_8.aarch64.rpm
openscap-engine-sce-devel-1.3.14-1.0.1.el9_8.aarch64.rpm
openscap-python3-1.3.14-1.0.1.el9_8.aarch64.rpm
openscap-scanner-1.3.14-1.0.1.el9_8.aarch64.rpm
openscap-utils-1.3.14-1.0.1.el9_8.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/openscap-1.3.14-1.0.1.el9_8.src.rpm
Description of changes:
[1.3.14-1.0.1]
- Restore original version
- Drop OpenELA branding
[1.3.14.openela.1.0]
- Add OpenELA to openscap
[1:1.3.14-1]
- Upgrade to the latest upstream release (RHEL-167949)
ELSA-2026-49211 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
Oracle Linux Security Advisory ELSA-2026-49211
http://linux.oracle.com/errata/ELSA-2026-49211.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
kernel-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-abi-stablelists-6.12.0-211.42.1.el10_2.noarch.rpm
kernel-core-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-cross-headers-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-debug-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-debug-core-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-debug-devel-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-debug-devel-matched-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-debug-modules-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-debug-modules-core-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-debug-modules-extra-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-debug-uki-virt-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-devel-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-devel-matched-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-doc-6.12.0-211.42.1.el10_2.noarch.rpm
kernel-headers-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-modules-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-modules-core-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-modules-extra-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-modules-extra-matched-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-tools-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-tools-libs-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-tools-libs-devel-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-uki-virt-6.12.0-211.42.1.el10_2.x86_64.rpm
kernel-uki-virt-addons-6.12.0-211.42.1.el10_2.x86_64.rpm
libperf-6.12.0-211.42.1.el10_2.x86_64.rpm
perf-6.12.0-211.42.1.el10_2.x86_64.rpm
python3-perf-6.12.0-211.42.1.el10_2.x86_64.rpm
rtla-6.12.0-211.42.1.el10_2.x86_64.rpm
rv-6.12.0-211.42.1.el10_2.x86_64.rpm
aarch64:
kernel-cross-headers-6.12.0-211.42.1.el10_2.aarch64.rpm
kernel-headers-6.12.0-211.42.1.el10_2.aarch64.rpm
kernel-tools-6.12.0-211.42.1.el10_2.aarch64.rpm
kernel-tools-libs-6.12.0-211.42.1.el10_2.aarch64.rpm
kernel-tools-libs-devel-6.12.0-211.42.1.el10_2.aarch64.rpm
libperf-6.12.0-211.42.1.el10_2.aarch64.rpm
perf-6.12.0-211.42.1.el10_2.aarch64.rpm
python3-perf-6.12.0-211.42.1.el10_2.aarch64.rpm
rtla-6.12.0-211.42.1.el10_2.aarch64.rpm
rv-6.12.0-211.42.1.el10_2.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/kernel-6.12.0-211.42.1.el10_2.src.rpm
Related CVEs:
CVE-2025-68211
CVE-2026-46303
CVE-2026-64530
Description of changes:
[6.12.0-211.42.1]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64