Oracle Linux 6535 Published by

Oracle Linux published a comprehensive set of security and bug fix advisories for operating system versions 8, 9, and 10 that resolve numerous vulnerabilities across core infrastructure packages. System administrators can apply kernel and dracut updates, alongside version upgrades for .NET 8.0 through 10.0, Ruby 3.3 and 4.0, and Node.js:24. Remote access and monitoring tools also received security hardening, with patched releases for OpenSSH, BIND DNS, Grafana, and Python idna. On-site virtualization environments should install the oVirt 4.5 engine release to gain stability improvements and refreshed Java library dependencies.

New Ksplice updates for UEKR6 5.4.17 on OL7 and OL8
ELSA-2026-54542 Important: Oracle Linux 8 .NET 10.0 security, bug fix, and enhancement update
ELSA-2026-54538 Important: Oracle Linux 8 .NET 8.0 security, bug fix, and enhancement update
ELSA-2026-54484 Moderate: Oracle Linux 9 python-idna security update
ELSA-2026-54443 Important: Oracle Linux 9 kernel security, bug fix, and enhancement update
ELSA-2026-54571 Important: Oracle Linux 9 dracut security update
ELSA-2026-54184 Important: Oracle Linux 9 grafana security update
ELSA-2026-53844 Important: Oracle Linux 9 iscsi-initiator-utils security, bug fix, and enhancement update
ELSA-2026-47756 Important: Oracle Linux 9 openssh security update
ELBA-2026-500143 Oracle Linux 9 oracle-ovirt-release-45-el9 bug fix update
ELSA-2026-54654 Important: Oracle Linux 8 bind security update
ELSA-2026-54576 Important: Oracle Linux 10 dracut security update
ELSA-2026-54343 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
ELSA-2026-54210 Moderate: Oracle Linux 10 dhcpcd security update
ELSA-2026-53845 Important: Oracle Linux 10 iscsi-initiator-utils security, bug fix, and enhancement update
ELSA-2026-50778 Important: Oracle Linux 10 ruby security, bug fix, and enhancement update
ELSA-2026-50773 Important: Oracle Linux 10 ruby4.0 security, bug fix, and enhancement update
ELSA-2026-36956 Important: Oracle Linux 10 kernel security update
ELSA-2026-22450 Important: Oracle Linux 10 osbuild-composer security update
ELBA-2026-500142 Oracle Linux 9 oVirt 4.5 OLVM Engine Release for OL9
ELBA-2026-500141 Oracle Linux 9 oVirt 4.5 OLVM Engine Release for OL9
ELSA-2026-54575 Important: Oracle Linux 8 dracut security update
ELSA-2026-54550 Important: Oracle Linux 8 .NET 9.0 security, bug fix, and enhancement update
ELSA-2026-54371 Important: Oracle Linux 8 nodejs:24 security update




Synopsis: The following CVEs can now be patched using Ksplice
CVEs: CVE-2026-31598 CVE-2026-46116 CVE-2026-52995

Users with Oracle Linux Premier Support can now use Ksplice to patch
against the latest CVE fixes.

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack running UEKR6 5.4.17 on
OL7 and OL8 install these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y

DESCRIPTION

* CVE-2026-31598: Kernel deadlock in OCFS2 filesystem.

Orabug: 39273589

* CVE-2026-46116: Use-after-free in XFRM.

Orabug: 39460235

* CVE-2026-52995: Information leak in RDS connection information.

Orabug: 39638198

* Information leak in receives of Reliable Datagram Sockets protocol.

Orabug: 39772651

* Information leak when receiving message over RDS socket.

Orabug: 39772651

SUPPORT

Ksplice support is available at ksplice-support_ww@oracle.com.

ELSA-2026-54542 Important: Oracle Linux 8 .NET 10.0 security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-54542

http://linux.oracle.com/errata/ELSA-2026-54542.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
aspnetcore-runtime-10.0-10.0.11-1.0.1.el8_10.x86_64.rpm
aspnetcore-runtime-dbg-10.0-10.0.11-1.0.1.el8_10.x86_64.rpm
aspnetcore-targeting-pack-10.0-10.0.11-1.0.1.el8_10.x86_64.rpm
dotnet-10.0.111-1.0.1.el8_10.x86_64.rpm
dotnet-apphost-pack-10.0-10.0.11-1.0.1.el8_10.x86_64.rpm
dotnet-host-10.0.11-1.0.1.el8_10.x86_64.rpm
dotnet-hostfxr-10.0-10.0.11-1.0.1.el8_10.x86_64.rpm
dotnet-runtime-10.0-10.0.11-1.0.1.el8_10.x86_64.rpm
dotnet-runtime-dbg-10.0-10.0.11-1.0.1.el8_10.x86_64.rpm
dotnet-sdk-10.0-10.0.111-1.0.1.el8_10.x86_64.rpm
dotnet-sdk-10.0-source-built-artifacts-10.0.111-1.0.1.el8_10.x86_64.rpm
dotnet-sdk-aot-10.0-10.0.111-1.0.1.el8_10.x86_64.rpm
dotnet-sdk-dbg-10.0-10.0.111-1.0.1.el8_10.x86_64.rpm
dotnet-targeting-pack-10.0-10.0.11-1.0.1.el8_10.x86_64.rpm
dotnet-templates-10.0-10.0.111-1.0.1.el8_10.x86_64.rpm

aarch64:
aspnetcore-runtime-10.0-10.0.11-1.0.1.el8_10.aarch64.rpm
aspnetcore-runtime-dbg-10.0-10.0.11-1.0.1.el8_10.aarch64.rpm
aspnetcore-targeting-pack-10.0-10.0.11-1.0.1.el8_10.aarch64.rpm
dotnet-10.0.111-1.0.1.el8_10.aarch64.rpm
dotnet-apphost-pack-10.0-10.0.11-1.0.1.el8_10.aarch64.rpm
dotnet-host-10.0.11-1.0.1.el8_10.aarch64.rpm
dotnet-hostfxr-10.0-10.0.11-1.0.1.el8_10.aarch64.rpm
dotnet-runtime-10.0-10.0.11-1.0.1.el8_10.aarch64.rpm
dotnet-runtime-dbg-10.0-10.0.11-1.0.1.el8_10.aarch64.rpm
dotnet-sdk-10.0-10.0.111-1.0.1.el8_10.aarch64.rpm
dotnet-sdk-10.0-source-built-artifacts-10.0.111-1.0.1.el8_10.aarch64.rpm
dotnet-sdk-aot-10.0-10.0.111-1.0.1.el8_10.aarch64.rpm
dotnet-sdk-dbg-10.0-10.0.111-1.0.1.el8_10.aarch64.rpm
dotnet-targeting-pack-10.0-10.0.11-1.0.1.el8_10.aarch64.rpm
dotnet-templates-10.0-10.0.111-1.0.1.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/dotnet10.0-10.0.111-1.0.1.el8_10.src.rpm

Related CVEs:

CVE-2026-62899
CVE-2026-62900
CVE-2026-62901
CVE-2026-62909

Description of changes:

[10.0.111-1.0.1]
- Add support for Oracle Linux

[10.0.111-1]
- Update to .NET SDK 10.0.111 and Runtime 10.0.11
- Resolves: RHEL-235478



ELSA-2026-54538 Important: Oracle Linux 8 .NET 8.0 security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-54538

http://linux.oracle.com/errata/ELSA-2026-54538.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
aspnetcore-runtime-8.0-8.0.30-1.0.1.el8_10.x86_64.rpm
aspnetcore-runtime-dbg-8.0-8.0.30-1.0.1.el8_10.x86_64.rpm
aspnetcore-targeting-pack-8.0-8.0.30-1.0.1.el8_10.x86_64.rpm
dotnet-apphost-pack-8.0-8.0.30-1.0.1.el8_10.x86_64.rpm
dotnet-hostfxr-8.0-8.0.30-1.0.1.el8_10.x86_64.rpm
dotnet-runtime-8.0-8.0.30-1.0.1.el8_10.x86_64.rpm
dotnet-runtime-dbg-8.0-8.0.30-1.0.1.el8_10.x86_64.rpm
dotnet-sdk-8.0-8.0.130-1.0.1.el8_10.x86_64.rpm
dotnet-sdk-8.0-source-built-artifacts-8.0.130-1.0.1.el8_10.x86_64.rpm
dotnet-sdk-dbg-8.0-8.0.130-1.0.1.el8_10.x86_64.rpm
dotnet-targeting-pack-8.0-8.0.30-1.0.1.el8_10.x86_64.rpm
dotnet-templates-8.0-8.0.130-1.0.1.el8_10.x86_64.rpm

aarch64:
aspnetcore-runtime-8.0-8.0.30-1.0.1.el8_10.aarch64.rpm
aspnetcore-runtime-dbg-8.0-8.0.30-1.0.1.el8_10.aarch64.rpm
aspnetcore-targeting-pack-8.0-8.0.30-1.0.1.el8_10.aarch64.rpm
dotnet-apphost-pack-8.0-8.0.30-1.0.1.el8_10.aarch64.rpm
dotnet-hostfxr-8.0-8.0.30-1.0.1.el8_10.aarch64.rpm
dotnet-runtime-8.0-8.0.30-1.0.1.el8_10.aarch64.rpm
dotnet-runtime-dbg-8.0-8.0.30-1.0.1.el8_10.aarch64.rpm
dotnet-sdk-8.0-8.0.130-1.0.1.el8_10.aarch64.rpm
dotnet-sdk-8.0-source-built-artifacts-8.0.130-1.0.1.el8_10.aarch64.rpm
dotnet-sdk-dbg-8.0-8.0.130-1.0.1.el8_10.aarch64.rpm
dotnet-targeting-pack-8.0-8.0.30-1.0.1.el8_10.aarch64.rpm
dotnet-templates-8.0-8.0.130-1.0.1.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/dotnet8.0-8.0.130-1.0.1.el8_10.src.rpm

Related CVEs:

CVE-2026-62899
CVE-2026-62900
CVE-2026-62901
CVE-2026-62909

Description of changes:

[8.0.130-1.0.1]
- Add support for Oracle Linux

[8.0.130-1]
- Update to .NET SDK 8.0.130 and Runtime 8.0.30
- Resolves: RHEL-235468



ELSA-2026-54484 Moderate: Oracle Linux 9 python-idna security update


Oracle Linux Security Advisory ELSA-2026-54484

http://linux.oracle.com/errata/ELSA-2026-54484.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
python3-idna-2.10-8.el9_8.noarch.rpm

aarch64:
python3-idna-2.10-8.el9_8.noarch.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/python-idna-2.10-8.el9_8.src.rpm

Related CVEs:

CVE-2026-45409

Description of changes:

[2.10-8]
- Security fix for CVE-2026-45409
Resolves: RHEL-215653



ELSA-2026-54443 Important: Oracle Linux 9 kernel security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-54443

http://linux.oracle.com/errata/ELSA-2026-54443.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-abi-stablelists-5.14.0-687.39.1.el9_8.noarch.rpm
kernel-core-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-cross-headers-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-debug-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-debug-core-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-debug-devel-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-debug-devel-matched-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-debug-modules-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-debug-modules-core-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-debug-modules-extra-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-debug-uki-virt-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-devel-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-devel-matched-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-doc-5.14.0-687.39.1.el9_8.noarch.rpm
kernel-headers-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-modules-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-modules-core-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-modules-extra-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-tools-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-tools-libs-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-tools-libs-devel-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-uki-virt-5.14.0-687.39.1.el9_8.x86_64.rpm
kernel-uki-virt-addons-5.14.0-687.39.1.el9_8.x86_64.rpm
libperf-5.14.0-687.39.1.el9_8.x86_64.rpm
perf-5.14.0-687.39.1.el9_8.x86_64.rpm
python3-perf-5.14.0-687.39.1.el9_8.x86_64.rpm
rtla-5.14.0-687.39.1.el9_8.x86_64.rpm
rv-5.14.0-687.39.1.el9_8.x86_64.rpm

aarch64:
kernel-cross-headers-5.14.0-687.39.1.el9_8.aarch64.rpm
kernel-headers-5.14.0-687.39.1.el9_8.aarch64.rpm
kernel-tools-5.14.0-687.39.1.el9_8.aarch64.rpm
kernel-tools-libs-5.14.0-687.39.1.el9_8.aarch64.rpm
kernel-tools-libs-devel-5.14.0-687.39.1.el9_8.aarch64.rpm
libperf-5.14.0-687.39.1.el9_8.aarch64.rpm
perf-5.14.0-687.39.1.el9_8.aarch64.rpm
python3-perf-5.14.0-687.39.1.el9_8.aarch64.rpm
rtla-5.14.0-687.39.1.el9_8.aarch64.rpm
rv-5.14.0-687.39.1.el9_8.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/kernel-5.14.0-687.39.1.el9_8.src.rpm

Related CVEs:

CVE-2026-53202
CVE-2026-53264

Description of changes:

[5.14.0-687.39.1]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 nelems before insertion (Florian Westphal) [RHEL-185311] {CVE-2026-23272}
- netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (Florian Westphal) [RHEL-185311] {CVE-2026-43233}
- netfilter: nft_set_hash: fix get operation on big endian (Florian Westphal) [RHEL-185311]
- netfilter: nf_tables: always walk all pending catchall elements (Florian Westphal) [RHEL-185311] {CVE-2026-23278}
- netfilter: nft_set_pipapo: split gc into unlink and reclaim phase (Florian Westphal) [RHEL-185311] {CVE-2026-23351}



ELSA-2026-54210 Moderate: Oracle Linux 10 dhcpcd security update


Oracle Linux Security Advisory ELSA-2026-54210

http://linux.oracle.com/errata/ELSA-2026-54210.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
dhcpcd-10.0.6-11.el10_2.x86_64.rpm

aarch64:
dhcpcd-10.0.6-11.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/dhcpcd-10.0.6-11.el10_2.src.rpm

Related CVEs:

CVE-2026-14258

Description of changes:

[10.0.6-11]
- Fix CVE-2026-14258



ELSA-2026-53845 Important: Oracle Linux 10 iscsi-initiator-utils security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-53845

http://linux.oracle.com/errata/ELSA-2026-53845.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
iscsi-initiator-utils-6.2.1.11-1.git4b3e853.0.1.el10_2.2.x86_64.rpm
iscsi-initiator-utils-iscsiuio-6.2.1.11-1.git4b3e853.0.1.el10_2.2.x86_64.rpm
python3-iscsi-initiator-utils-6.2.1.11-1.git4b3e853.0.1.el10_2.2.x86_64.rpm

aarch64:
iscsi-initiator-utils-6.2.1.11-1.git4b3e853.0.1.el10_2.2.aarch64.rpm
iscsi-initiator-utils-iscsiuio-6.2.1.11-1.git4b3e853.0.1.el10_2.2.aarch64.rpm
python3-iscsi-initiator-utils-6.2.1.11-1.git4b3e853.0.1.el10_2.2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/iscsi-initiator-utils-6.2.1.11-1.git4b3e853.0.1.el10_2.2.src.rpm

Related CVEs:

CVE-2026-44943
CVE-2026-44944

Description of changes:

[6.2.1.11-1.git4b3e853.0.1.el10_2.2]
- Validate interface IP against target address family [Orabug: 39491397]
- iscsi delay reconnect until interface has valid IP [Orabug: 38445491]
- Change the order of restart iscsi services in spec file [Orabug: 37749406]
- Change the log_level of log_debug message in actor_delete()
- Remove 'After' keyword from install section [Orabug: 37520817]
- Add python3-rpm-macros to BuildRequires
- Allow systemd-remount-fs complete before iscsi-init.service [Orabug: 34325406]
- Allow iscsi-init.service to start after local-fs.target [Orabug: 33930979]
- Rename 0008-use-red-hat-name.patch to 0008-use-oracle-for-name.patch
and use com.oracle in prefix
- Complete the following tasks to address [Orabug: 29311709]
The following patches address [Orabug: 29128380] (Jianchao Wang)
Add 0032-Add-Requires-iscsid.service-in-iscsi.service.patch
The following patch addresses [Orabug: 29306329]
Add 0033-Update-systemd-to-always-restart-iscsid-service.patch
- Print vital iscsid messages on console using rsyslog facility. This
is particularly useful when using iscsi boot and there is a connection
or session issue. [Orabug: 29503805]
- Modify iscsi-mark-root-nodes script to only update node.startup to onboot
for iscsi sessions that are active during boot. [Orabug: 29653342]
- Modify iscsi-mark-root nodes script to not mark nodes when iscsi.service
is restarted. [Orabug: 29851447]
- Modify patches 0007 and 0032-0035 to apply cleanly
- Tune TimeoutSec of iscsid service to 10 minutes [Orabug: 29869817]

[6.2.1.11-1.git4b3e853.2]
- fix IQN name validation to prevent path traversal (CVE-2026-44943)
- fix iscsiuio control-socket credential verification (CVE-2026-44944)

[6.2.1.11-1.git4b3e853.1]
- fix IQN name validation to prevent path traversal (CVE-2026-44943)
- fix iscsiuio control-socket credential verification (CVE-2026-44944)

[6.2.1.11-1.git4b3e853]
- fix regression in fw and static node records



ELSA-2026-50778 Important: Oracle Linux 10 ruby security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-50778

http://linux.oracle.com/errata/ELSA-2026-50778.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
ruby-3.3.12-14.el10_2.x86_64.rpm
ruby-bundled-gems-3.3.12-14.el10_2.x86_64.rpm
ruby-default-gems-3.3.12-14.el10_2.noarch.rpm
ruby-devel-3.3.12-14.el10_2.x86_64.rpm
ruby-doc-3.3.12-14.el10_2.noarch.rpm
ruby-libs-3.3.12-14.el10_2.x86_64.rpm
rubygem-bigdecimal-3.1.5-14.el10_2.x86_64.rpm
rubygem-bundler-2.5.22-14.el10_2.noarch.rpm
rubygem-io-console-0.7.1-14.el10_2.x86_64.rpm
rubygem-irb-1.13.1-14.el10_2.noarch.rpm
rubygem-json-2.7.2-14.el10_2.x86_64.rpm
rubygem-minitest-5.20.0-14.el10_2.noarch.rpm
rubygem-power_assert-2.0.3-14.el10_2.noarch.rpm
rubygem-psych-5.1.2-14.el10_2.x86_64.rpm
rubygem-racc-1.7.3-14.el10_2.x86_64.rpm
rubygem-rake-13.1.0-14.el10_2.noarch.rpm
rubygem-rbs-3.4.0-14.el10_2.x86_64.rpm
rubygem-rdoc-6.6.3.1-14.el10_2.noarch.rpm
rubygem-rexml-3.4.4-14.el10_2.noarch.rpm
rubygem-rss-0.3.1-14.el10_2.noarch.rpm
rubygem-test-unit-3.6.1-14.el10_2.noarch.rpm
rubygem-typeprof-0.21.9-14.el10_2.noarch.rpm
rubygems-3.5.22-14.el10_2.noarch.rpm
rubygems-devel-3.5.22-14.el10_2.noarch.rpm

aarch64:
ruby-3.3.12-14.el10_2.aarch64.rpm
ruby-bundled-gems-3.3.12-14.el10_2.aarch64.rpm
ruby-default-gems-3.3.12-14.el10_2.noarch.rpm
ruby-devel-3.3.12-14.el10_2.aarch64.rpm
ruby-doc-3.3.12-14.el10_2.noarch.rpm
ruby-libs-3.3.12-14.el10_2.aarch64.rpm
rubygem-bigdecimal-3.1.5-14.el10_2.aarch64.rpm
rubygem-bundler-2.5.22-14.el10_2.noarch.rpm
rubygem-io-console-0.7.1-14.el10_2.aarch64.rpm
rubygem-irb-1.13.1-14.el10_2.noarch.rpm
rubygem-json-2.7.2-14.el10_2.aarch64.rpm
rubygem-minitest-5.20.0-14.el10_2.noarch.rpm
rubygem-power_assert-2.0.3-14.el10_2.noarch.rpm
rubygem-psych-5.1.2-14.el10_2.aarch64.rpm
rubygem-racc-1.7.3-14.el10_2.aarch64.rpm
rubygem-rake-13.1.0-14.el10_2.noarch.rpm
rubygem-rbs-3.4.0-14.el10_2.aarch64.rpm
rubygem-rdoc-6.6.3.1-14.el10_2.noarch.rpm
rubygem-rexml-3.4.4-14.el10_2.noarch.rpm
rubygem-rss-0.3.1-14.el10_2.noarch.rpm
rubygem-test-unit-3.6.1-14.el10_2.noarch.rpm
rubygem-typeprof-0.21.9-14.el10_2.noarch.rpm
rubygems-3.5.22-14.el10_2.noarch.rpm
rubygems-devel-3.5.22-14.el10_2.noarch.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/ruby-3.3.12-14.el10_2.src.rpm

Related CVEs:

CVE-2026-27820
CVE-2026-42256
CVE-2026-42257
CVE-2026-47240
CVE-2026-47241
CVE-2026-47242

Description of changes:

[3.3.12-14]
- Upgrade to Ruby 3.3.12.
Resolves: RHEL-211300
Resolves: RHEL-193659



ELSA-2026-50773 Important: Oracle Linux 10 ruby4.0 security, bug fix, and enhancement update


Oracle Linux Security Advisory ELSA-2026-50773

http://linux.oracle.com/errata/ELSA-2026-50773.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
ruby4.0-4.0.6-36.el10_2.x86_64.rpm
ruby4.0-devel-4.0.6-36.el10_2.x86_64.rpm
ruby4.0-doc-4.0.6-36.el10_2.noarch.rpm
ruby4.0-rubygem-mysql2-0.5.7-36.el10_2.x86_64.rpm
ruby4.0-rubygem-pg-1.6.3-36.el10_2.x86_64.rpm

aarch64:
ruby4.0-4.0.6-36.el10_2.aarch64.rpm
ruby4.0-devel-4.0.6-36.el10_2.aarch64.rpm
ruby4.0-doc-4.0.6-36.el10_2.noarch.rpm
ruby4.0-rubygem-mysql2-0.5.7-36.el10_2.aarch64.rpm
ruby4.0-rubygem-pg-1.6.3-36.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/ruby4.0-4.0.6-36.el10_2.src.rpm

Related CVEs:

CVE-2026-27820
CVE-2026-42256
CVE-2026-42257
CVE-2026-47240
CVE-2026-47241
CVE-2026-47242

Description of changes:

[4.0.6-36]
- Upgrade to Ruby 4.0.6.
Resolves: RHEL-211310
Resolves: RHEL-193660



ELSA-2026-36956 Important: Oracle Linux 10 kernel security update


Oracle Linux Security Advisory ELSA-2026-36956

http://linux.oracle.com/errata/ELSA-2026-36956.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-abi-stablelists-6.12.0-211.34.1.el10_2.noarch.rpm
kernel-core-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-cross-headers-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-core-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-devel-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-devel-matched-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-modules-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-modules-core-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-modules-extra-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-debug-uki-virt-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-devel-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-devel-matched-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-doc-6.12.0-211.34.1.el10_2.noarch.rpm
kernel-headers-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-modules-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-modules-core-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-modules-extra-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-modules-extra-matched-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-tools-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-tools-libs-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-tools-libs-devel-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-uki-virt-6.12.0-211.34.1.el10_2.x86_64.rpm
kernel-uki-virt-addons-6.12.0-211.34.1.el10_2.x86_64.rpm
libperf-6.12.0-211.34.1.el10_2.x86_64.rpm
perf-6.12.0-211.34.1.el10_2.x86_64.rpm
python3-perf-6.12.0-211.34.1.el10_2.x86_64.rpm
rtla-6.12.0-211.34.1.el10_2.x86_64.rpm
rv-6.12.0-211.34.1.el10_2.x86_64.rpm

aarch64:
kernel-cross-headers-6.12.0-211.34.1.el10_2.aarch64.rpm
kernel-headers-6.12.0-211.34.1.el10_2.aarch64.rpm
kernel-tools-6.12.0-211.34.1.el10_2.aarch64.rpm
kernel-tools-libs-6.12.0-211.34.1.el10_2.aarch64.rpm
kernel-tools-libs-devel-6.12.0-211.34.1.el10_2.aarch64.rpm
libperf-6.12.0-211.34.1.el10_2.aarch64.rpm
perf-6.12.0-211.34.1.el10_2.aarch64.rpm
python3-perf-6.12.0-211.34.1.el10_2.aarch64.rpm
rtla-6.12.0-211.34.1.el10_2.aarch64.rpm
rv-6.12.0-211.34.1.el10_2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/kernel-6.12.0-211.34.1.el10_2.src.rpm

Related CVEs:

CVE-2025-71066
CVE-2026-46113
CVE-2026-46227
CVE-2026-53359

Description of changes:

[6.12.0-211.34.1]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64