Oracle Linux 6484 Published by

Oracle has published a comprehensive set of security advisories and bug fix updates covering enterprise Linux versions seven through ten. These releases patch critical flaws in widely used packages including libpng, Ruby, rsync, giflib, BIND, GIMP, Vim, and the core kernel. System administrators will also notice important stability corrections for management utilities like systemd, rhn client tools, and satellite five client. Every updated RPM package has been uploaded to the Unbreakable Linux Network for immediate deployment on both x86_64 and aarch64 systems.

ELSA-2026-18028 Moderate: Oracle Linux 9 libpng security update
ELSA-2026-18064 Moderate: Oracle Linux 10 libpng security update
ELBA-2026-50272 Oracle Linux 10 rhn-client-tools bug fix update
ELSA-2026-18065 Important: Oracle Linux 10 ruby security update
ELBA-2026-50274 Oracle Linux 8 systemd bug fix update
OLAMSA-2026-0011 Low: Oracle Linux 8 ol-automation-manager security update
ELSA-2026-17481 Important: Oracle Linux 8 rsync security update
ELBA-2026-50269 Oracle Linux 8 satellite-5-client:1.0 bug fix update
ELSA-2026-8883 Important: Oracle Linux 7 giflib security update
ELSA-2026-11371 Important: Oracle Linux 7 bind security update
ELSA-2026-17533 Important: Oracle Linux 8 gimp:2.8 security update
ELSA-2026-6617 Important: Oracle Linux 7 vim security update
ELBA-2026-16195-1 Oracle Linux 8 kernel bug fix update
ELSA-2026-16195 Important: Oracle Linux 8 kernel security update




ELSA-2026-18028 Moderate: Oracle Linux 9 libpng security update


Oracle Linux Security Advisory ELSA-2026-18028

http://linux.oracle.com/errata/ELSA-2026-18028.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
libpng-1.6.37-12.el9_7.4.i686.rpm
libpng-1.6.37-12.el9_7.4.x86_64.rpm
libpng-devel-1.6.37-12.el9_7.4.i686.rpm
libpng-devel-1.6.37-12.el9_7.4.x86_64.rpm

aarch64:
libpng-1.6.37-12.el9_7.4.aarch64.rpm
libpng-devel-1.6.37-12.el9_7.4.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/libpng-1.6.37-12.el9_7.4.src.rpm

Related CVEs:

CVE-2026-33416

Description of changes:

[2:1.6.37-12.4]
- fix CVE-2026-33416: use-after-free via pointer aliasing in png_set_tRNS and png_set_PLTE (RHEL-161436)



ELSA-2026-18064 Moderate: Oracle Linux 10 libpng security update


Oracle Linux Security Advisory ELSA-2026-18064

http://linux.oracle.com/errata/ELSA-2026-18064.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
libpng-1.6.40-8.el10_1.4.x86_64.rpm
libpng-devel-1.6.40-8.el10_1.4.x86_64.rpm

aarch64:
libpng-1.6.40-8.el10_1.4.aarch64.rpm
libpng-devel-1.6.40-8.el10_1.4.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/libpng-1.6.40-8.el10_1.4.src.rpm

Related CVEs:

CVE-2026-33416

Description of changes:

[2:1.6.40-8.4]
- fix CVE-2026-33416: use-after-free via pointer aliasing in png_set_tRNS and png_set_PLTE (RHEL-161324)



ELBA-2026-50272 Oracle Linux 10 rhn-client-tools bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-50272

http://linux.oracle.com/errata/ELBA-2026-50272.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
python3-rhn-check-2.8.16-13.0.15.el10.x86_64.rpm
python3-rhn-client-tools-2.8.16-13.0.15.el10.x86_64.rpm
python3-rhn-setup-gnome-2.8.16-13.0.15.el10.x86_64.rpm
python3-rhn-setup-2.8.16-13.0.15.el10.x86_64.rpm
rhn-check-2.8.16-13.0.15.el10.x86_64.rpm
rhn-client-tools-2.8.16-13.0.15.el10.x86_64.rpm
rhn-setup-gnome-2.8.16-13.0.15.el10.x86_64.rpm
rhn-setup-2.8.16-13.0.15.el10.x86_64.rpm

aarch64:
python3-rhn-check-2.8.16-13.0.15.el10.aarch64.rpm
python3-rhn-client-tools-2.8.16-13.0.15.el10.aarch64.rpm
python3-rhn-setup-gnome-2.8.16-13.0.15.el10.aarch64.rpm
python3-rhn-setup-2.8.16-13.0.15.el10.aarch64.rpm
rhn-check-2.8.16-13.0.15.el10.aarch64.rpm
rhn-client-tools-2.8.16-13.0.15.el10.aarch64.rpm
rhn-setup-gnome-2.8.16-13.0.15.el10.aarch64.rpm
rhn-setup-2.8.16-13.0.15.el10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/rhn-client-tools-2.8.16-13.0.15.el10.src.rpm

Description of changes:

[2.8.16-13.0.15]
- Adding G2 Root Certificate in ULN-CA-CERT [Orabug: 39355225]



ELSA-2026-18065 Important: Oracle Linux 10 ruby security update


Oracle Linux Security Advisory ELSA-2026-18065

http://linux.oracle.com/errata/ELSA-2026-18065.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
ruby-3.3.10-12.el10_1.x86_64.rpm
ruby-bundled-gems-3.3.10-12.el10_1.x86_64.rpm
ruby-default-gems-3.3.10-12.el10_1.noarch.rpm
ruby-devel-3.3.10-12.el10_1.x86_64.rpm
ruby-doc-3.3.10-12.el10_1.noarch.rpm
ruby-libs-3.3.10-12.el10_1.x86_64.rpm
rubygem-bigdecimal-3.1.5-12.el10_1.x86_64.rpm
rubygem-bundler-2.5.22-12.el10_1.noarch.rpm
rubygem-io-console-0.7.1-12.el10_1.x86_64.rpm
rubygem-irb-1.13.1-12.el10_1.noarch.rpm
rubygem-json-2.7.2-12.el10_1.x86_64.rpm
rubygem-minitest-5.20.0-12.el10_1.noarch.rpm
rubygem-power_assert-2.0.3-12.el10_1.noarch.rpm
rubygem-psych-5.1.2-12.el10_1.x86_64.rpm
rubygem-racc-1.7.3-12.el10_1.x86_64.rpm
rubygem-rake-13.1.0-12.el10_1.noarch.rpm
rubygem-rbs-3.4.0-12.el10_1.x86_64.rpm
rubygem-rdoc-6.6.3.1-12.el10_1.noarch.rpm
rubygem-rexml-3.4.4-12.el10_1.noarch.rpm
rubygem-rss-0.3.1-12.el10_1.noarch.rpm
rubygem-test-unit-3.6.1-12.el10_1.noarch.rpm
rubygem-typeprof-0.21.9-12.el10_1.noarch.rpm
rubygems-3.5.22-12.el10_1.noarch.rpm
rubygems-devel-3.5.22-12.el10_1.noarch.rpm

aarch64:
ruby-3.3.10-12.el10_1.aarch64.rpm
ruby-bundled-gems-3.3.10-12.el10_1.aarch64.rpm
ruby-default-gems-3.3.10-12.el10_1.noarch.rpm
ruby-devel-3.3.10-12.el10_1.aarch64.rpm
ruby-doc-3.3.10-12.el10_1.noarch.rpm
ruby-libs-3.3.10-12.el10_1.aarch64.rpm
rubygem-bigdecimal-3.1.5-12.el10_1.aarch64.rpm
rubygem-bundler-2.5.22-12.el10_1.noarch.rpm
rubygem-io-console-0.7.1-12.el10_1.aarch64.rpm
rubygem-irb-1.13.1-12.el10_1.noarch.rpm
rubygem-json-2.7.2-12.el10_1.aarch64.rpm
rubygem-minitest-5.20.0-12.el10_1.noarch.rpm
rubygem-power_assert-2.0.3-12.el10_1.noarch.rpm
rubygem-psych-5.1.2-12.el10_1.aarch64.rpm
rubygem-racc-1.7.3-12.el10_1.aarch64.rpm
rubygem-rake-13.1.0-12.el10_1.noarch.rpm
rubygem-rbs-3.4.0-12.el10_1.aarch64.rpm
rubygem-rdoc-6.6.3.1-12.el10_1.noarch.rpm
rubygem-rexml-3.4.4-12.el10_1.noarch.rpm
rubygem-rss-0.3.1-12.el10_1.noarch.rpm
rubygem-test-unit-3.6.1-12.el10_1.noarch.rpm
rubygem-typeprof-0.21.9-12.el10_1.noarch.rpm
rubygems-3.5.22-12.el10_1.noarch.rpm
rubygems-devel-3.5.22-12.el10_1.noarch.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/ruby-3.3.10-12.el10_1.src.rpm

Related CVEs:

CVE-2026-41316

Description of changes:

[3.3.10-12]
- Fix arbitrary code execution via deserialization bypass in ERB. (CVE-2026-41316)
Resolves: RHEL-171244



ELBA-2026-50274 Oracle Linux 8 systemd bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-50274

http://linux.oracle.com/errata/ELBA-2026-50274.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
systemd-239-82.0.12.el8_10.16.i686.rpm
systemd-239-82.0.12.el8_10.16.x86_64.rpm
systemd-container-239-82.0.12.el8_10.16.i686.rpm
systemd-container-239-82.0.12.el8_10.16.x86_64.rpm
systemd-devel-239-82.0.12.el8_10.16.i686.rpm
systemd-devel-239-82.0.12.el8_10.16.x86_64.rpm
systemd-journal-remote-239-82.0.12.el8_10.16.x86_64.rpm
systemd-libs-239-82.0.12.el8_10.16.i686.rpm
systemd-libs-239-82.0.12.el8_10.16.x86_64.rpm
systemd-pam-239-82.0.12.el8_10.16.x86_64.rpm
systemd-tests-239-82.0.12.el8_10.16.x86_64.rpm
systemd-udev-239-82.0.12.el8_10.16.x86_64.rpm

aarch64:
systemd-239-82.0.12.el8_10.16.aarch64.rpm
systemd-container-239-82.0.12.el8_10.16.aarch64.rpm
systemd-devel-239-82.0.12.el8_10.16.aarch64.rpm
systemd-journal-remote-239-82.0.12.el8_10.16.aarch64.rpm
systemd-libs-239-82.0.12.el8_10.16.aarch64.rpm
systemd-pam-239-82.0.12.el8_10.16.aarch64.rpm
systemd-tests-239-82.0.12.el8_10.16.aarch64.rpm
systemd-udev-239-82.0.12.el8_10.16.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/systemd-239-82.0.12.el8_10.16.src.rpm

Description of changes:

[239-82.0.12.el8_10.16]
- Reapply fix for leaking devlinks [Orabug: 39126811]
- Do not infer BindsTo dependency for mount units [Orabug: 39126811]



OLAMSA-2026-0011 Low: Oracle Linux 8 ol-automation-manager security update


Oracle Linux Security Advisory OLAMSA-2026-0011

http://linux.oracle.com/errata/OLAMSA-2026-0011.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
ol-automation-manager-2.2.0-47.el8.x86_64.rpm
ol-automation-manager-cli-2.2.0-47.el8.noarch.rpm
python311-olamkit-2.2.0-47.el8.noarch.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/ol-automation-manager-2.2.0-47.el8.src.rpm

Related CVEs:

CVE-2026-34520

Description of changes:

[2.2.0-47.el8]
- OLAM-920 security: backport header value validation for CVE-2026-34520
- OLAM-921 Rework aiohttp security patches



ELSA-2026-17481 Important: Oracle Linux 8 rsync security update


Oracle Linux Security Advisory ELSA-2026-17481

http://linux.oracle.com/errata/ELSA-2026-17481.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
rsync-3.1.3-25.el8_10.x86_64.rpm
rsync-daemon-3.1.3-25.el8_10.noarch.rpm

aarch64:
rsync-3.1.3-25.el8_10.aarch64.rpm
rsync-daemon-3.1.3-25.el8_10.noarch.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/rsync-3.1.3-25.el8_10.src.rpm

Related CVEs:

CVE-2026-41035

Description of changes:

[3.1.3-25]
- Resolves: RHEL-169141 - CVE-2026-41035 - Use-after-free vulnerability in extended attribute handling



ELBA-2026-50269 Oracle Linux 8 satellite-5-client:1.0 bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-50269

http://linux.oracle.com/errata/ELBA-2026-50269.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
python3-rhn-check-2.8.16-13.0.7.module+el8.10.0+90885+e378ec41.x86_64.rpm
python3-rhn-client-tools-2.8.16-13.0.7.module+el8.10.0+90885+e378ec41.x86_64.rpm
python3-rhn-setup-2.8.16-13.0.7.module+el8.10.0+90885+e378ec41.x86_64.rpm
python3-rhn-setup-gnome-2.8.16-13.0.7.module+el8.10.0+90885+e378ec41.x86_64.rpm
rhn-check-2.8.16-13.0.7.module+el8.10.0+90885+e378ec41.x86_64.rpm
rhn-client-tools-2.8.16-13.0.7.module+el8.10.0+90885+e378ec41.x86_64.rpm
rhn-setup-2.8.16-13.0.7.module+el8.10.0+90885+e378ec41.x86_64.rpm
rhn-setup-gnome-2.8.16-13.0.7.module+el8.10.0+90885+e378ec41.x86_64.rpm
dnf-plugin-spacewalk-2.8.5-11.0.3.module+el8.3.0+20070+f5719e00.noarch.rpm
python3-dnf-plugin-spacewalk-2.8.5-11.0.3.module+el8.3.0+20070+f5719e00.noarch.rpm
python3-dnf-plugin-ulninfo-0.3-3.module+el8.10.0+90380+96a02ce9.noarch.rpm
python3-rhnlib-2.8.6-8.0.2.module+el8.7.0+21027+f0093b7a.noarch.rpm
rhnlib-2.8.6-8.0.2.module+el8.7.0+21027+f0093b7a.noarch.rpm
rhnsd-5.0.35-3.0.2.module+el8.10.0+90373+b70ceaf0.x86_64.rpm

aarch64:
python3-rhn-check-2.8.16-13.0.7.module+el8.10.0+90885+e378ec41.aarch64.rpm
python3-rhn-client-tools-2.8.16-13.0.7.module+el8.10.0+90885+e378ec41.aarch64.rpm
python3-rhn-setup-2.8.16-13.0.7.module+el8.10.0+90885+e378ec41.aarch64.rpm
python3-rhn-setup-gnome-2.8.16-13.0.7.module+el8.10.0+90885+e378ec41.aarch64.rpm
rhn-check-2.8.16-13.0.7.module+el8.10.0+90885+e378ec41.aarch64.rpm
rhn-client-tools-2.8.16-13.0.7.module+el8.10.0+90885+e378ec41.aarch64.rpm
rhn-setup-2.8.16-13.0.7.module+el8.10.0+90885+e378ec41.aarch64.rpm
rhn-setup-gnome-2.8.16-13.0.7.module+el8.10.0+90885+e378ec41.aarch64.rpm
dnf-plugin-spacewalk-2.8.5-11.0.3.module+el8.3.0+20070+f5719e00.noarch.rpm
python3-dnf-plugin-spacewalk-2.8.5-11.0.3.module+el8.3.0+20070+f5719e00.noarch.rpm
python3-dnf-plugin-ulninfo-0.3-3.module+el8.10.0+90380+96a02ce9.noarch.rpm
python3-rhnlib-2.8.6-8.0.2.module+el8.7.0+21027+f0093b7a.noarch.rpm
rhnlib-2.8.6-8.0.2.module+el8.7.0+21027+f0093b7a.noarch.rpm
rhnsd-5.0.35-3.0.2.module+el8.10.0+90373+b70ceaf0.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/rhn-client-tools-2.8.16-13.0.7.module+el8.10.0+90885+e378ec41.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/dnf-plugin-spacewalk-2.8.5-11.0.3.module+el8.3.0+20070+f5719e00.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/python3-dnf-plugin-ulninfo-0.3-3.module+el8.10.0+90380+96a02ce9.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/rhnlib-2.8.6-8.0.2.module+el8.7.0+21027+f0093b7a.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/rhnsd-5.0.35-3.0.2.module+el8.10.0+90373+b70ceaf0.src.rpm

Description of changes:

rhn-client-tools
[2.8.16-13.0.7]
- Adding G2 Root Certificate in ULN-CA-CERT [Orabug: 39323295]

[2.8.16-13.0.6]
- Adding 4k Certificate in ULN-CA-CERT [Orabug: 35287654]

[2.8.16-13.0.5]
- Making UEKR 7 channel the default channel for OL8.7 [Orabug: 34711928]

[2.8.16-13.0.4]
- disable Oracle Linux repos on ULN registration [Orabug: 32823852]

[2.8.16-13.0.3]
- Replace upstream references within description tags

[2.8.16-13.0.2]
- Send proper registration info [Orabug: 30320604]

[2.8.16-13.0.1]
- Send proper registration info [Orabug: 30320604]
- Remove RH references [Orabug: 30285107]
- Add support for ULN [Orabug: 29311325]
- Remove RH references [Orabug: 29919343]
- Add ULN registration icon [Orabug: 29933990]
- Add ULN registration to app search [Orabug: 29934046]
- Enable ksplice screen in uln_register gui [Orabug: 29947720]
- Enable channel listing in uln_register gui [Orabug: 29948628]
- Allow uln_register gui to run under wayland [Orabug: 30011133]
- Replaced upstream images with Oracle images. [Orabug: 30266967]

[2.8.16-13]
- Resolves: #1598450 - converted glade files into gtk3 format

[2.8.16-12]
- Resolves: #1666099 - python3 is picky about bytes and string

[2.8.16-11]
- Resolves: #1646929 - convert values from bytes to string in py3

dnf-plugin-spacewalk
[2.8.5-11.0.3]
- Add dependency on ulninfo plugin

[2.8.5-11.0.2]
- Fix duplicate header in needed_headers issue [Orabug: 31535056]
- Change msg to ULN or SW

[2.8.5-11.0.1]
- Remove extra debug messages [Orabug: 29928630]
- Add support for ULN [Orabug: 29311325]

[2.8.5-11]
- Resolves: #1701222 - ignore broken json cache

[2.8.5-10]
- Resolves: #1673445 - changed wording to refer to Red Hat Satellite

[2.8.5-9]
- Resolves: #1660552 - report and fail gracefully if not root
- logger.warn() has been obsoleted

[2.8.5-8]
- Resolves: #1637980 - use new api for http headers (michael.mraka@redhat.com)

[2.8.5-7]
- Resolves: rhbz#1633298 - librepo dependency is not added automatically (michael.mraka@redhat.com)

[2.8.5-6]
- spec cleanup (no more builds on Fedora 3.6.0 (michael.mraka@redhat.com)

[2.8.5-5]
- Related: #1581665 - provide useful symlinks to a manpage
(tkasparek@redhat.com)
- Resolves: #1581665 - provide yum-rhn-plugin on new RHEL systems
(tkasparek@redhat.com)

python3-dnf-plugin-ulninfo
[0.3-3]
- Fixes dnf repolist for ULN failed issue [Orabug: 36854493]

[0.3-2]
- Catch all exceptions and die quietly [Orabug: 32850127]

[0.3-1]
- Intial version

rhnlib
[2.8.6-8.0.2]
- Resolving issues while using 4k certs with ULN [OraBug: 34950241]

[2.8.6-8.0.1]
- Enable rhnreg_ks register to spacewalk server, [OraBug: 21109920]

[2.8.6-8]
- fixed build error: attempt to use unversioned python

[2.8.6-7]
- Resolves: #1666099 - python3 is picky about bytes and string

[2.8.6-6]
- Resolves: #1652859 - python3 http.client does not contain _set_hostport()

[2.8.6-5]
- Resolves: #1643415 - forbid old SSL versions during negotiation
(tkasparek@redhat.com)

[2.8.6-4]
- don't package python2 files for rhnlib (tkasparek@redhat.com)
- be compliant with new packaging guidelines when requiring python2 packages
(tkasparek@redhat.com)

[2.8.6-3]
- rhel8 utilizes python3 (tkasparek@redhat.com)

[2.8.6-2]
- rebuild for rhel8

[2.8.6-1]
- remove install/clean section initial cleanup
- removed Group from specfile
- removed BuildRoot from specfiles

rhnsd
[5.0.35-3.0.2]
- Rebuild with higher release

[5.0.35-3.0.1]
- Add patch rhnsd-oracle-network.patch
Change RHN references to Unbreakable Linux Network

[5.0.35-3]
- Resolves: #1610286 - don't start as sysv service on systemd systems
(tkasparek@redhat.com)

[5.0.35-2]
- rebuild for rhel8

[5.0.35-1]
- remove systemd-units
- remove obsoleted things from spec file

[5.0.34-1]
- removed settings for old RH build system

[5.0.33-1]
- fix rhnsd triggered upgrade of rhnsd on systemd systems
- 1494389 - Revert "[1260527] RHEL7 reboot loop"
- 1494389 - Revert "1260527 RHEL7 rhnsd reload doesn't work"

[5.0.32-1]
- 1489989 - umask(0) does not reset to default umask

[5.0.31-1]
- purged changelog entries for Spacewalk 2.0 and older

[5.0.30-1]
- 1480306 - change permissions for rhnsd.pid



ELSA-2026-8883 Important: Oracle Linux 7 giflib security update


Oracle Linux Security Advisory ELSA-2026-8883

http://linux.oracle.com/errata/ELSA-2026-8883.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
giflib-4.1.6-9.0.3.el7.i686.rpm
giflib-4.1.6-9.0.3.el7.x86_64.rpm
giflib-devel-4.1.6-9.0.3.el7.i686.rpm
giflib-devel-4.1.6-9.0.3.el7.x86_64.rpm
giflib-utils-4.1.6-9.0.3.el7.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/giflib-4.1.6-9.0.3.el7.src.rpm

Related CVEs:

CVE-2026-23868

Description of changes:

[4.1.6-9.0.3]
- Security update for CVE-2026-23868 [Orabug: 39230174]



ELSA-2026-11371 Important: Oracle Linux 7 bind security update


Oracle Linux Security Advisory ELSA-2026-11371

http://linux.oracle.com/errata/ELSA-2026-11371.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
bind-9.11.4-26.0.7.P2.el7_9.16.x86_64.rpm
bind-chroot-9.11.4-26.0.7.P2.el7_9.16.x86_64.rpm
bind-devel-9.11.4-26.0.7.P2.el7_9.16.i686.rpm
bind-devel-9.11.4-26.0.7.P2.el7_9.16.x86_64.rpm
bind-export-devel-9.11.4-26.0.7.P2.el7_9.16.i686.rpm
bind-export-devel-9.11.4-26.0.7.P2.el7_9.16.x86_64.rpm
bind-export-libs-9.11.4-26.0.7.P2.el7_9.16.i686.rpm
bind-export-libs-9.11.4-26.0.7.P2.el7_9.16.x86_64.rpm
bind-libs-9.11.4-26.0.7.P2.el7_9.16.i686.rpm
bind-libs-9.11.4-26.0.7.P2.el7_9.16.x86_64.rpm
bind-libs-lite-9.11.4-26.0.7.P2.el7_9.16.i686.rpm
bind-libs-lite-9.11.4-26.0.7.P2.el7_9.16.x86_64.rpm
bind-license-9.11.4-26.0.7.P2.el7_9.16.noarch.rpm
bind-lite-devel-9.11.4-26.0.7.P2.el7_9.16.i686.rpm
bind-lite-devel-9.11.4-26.0.7.P2.el7_9.16.x86_64.rpm
bind-pkcs11-9.11.4-26.0.7.P2.el7_9.16.x86_64.rpm
bind-pkcs11-devel-9.11.4-26.0.7.P2.el7_9.16.i686.rpm
bind-pkcs11-devel-9.11.4-26.0.7.P2.el7_9.16.x86_64.rpm
bind-pkcs11-libs-9.11.4-26.0.7.P2.el7_9.16.i686.rpm
bind-pkcs11-libs-9.11.4-26.0.7.P2.el7_9.16.x86_64.rpm
bind-pkcs11-utils-9.11.4-26.0.7.P2.el7_9.16.x86_64.rpm
bind-sdb-9.11.4-26.0.7.P2.el7_9.16.x86_64.rpm
bind-sdb-chroot-9.11.4-26.0.7.P2.el7_9.16.x86_64.rpm
bind-utils-9.11.4-26.0.7.P2.el7_9.16.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/bind-9.11.4-26.0.7.P2.el7_9.16.src.rpm

Related CVEs:

CVE-2026-1519

Description of changes:

[32:9.11.4-26.0.7.P2.16]
- Resolve CVE-2026-1519 [Orabug: 39275755]

[32:9.11.4-26.0.5.P2.16]
- Resolve CVE-2025-40778 [Orabug: 38699863]

[32:9.11.4-26.0.3.P2.16]
- Resolve CVE-2024-11187 [Orabug: 37616907]



ELSA-2026-17533 Important: Oracle Linux 8 gimp:2.8 security update


Oracle Linux Security Advisory ELSA-2026-17533

http://linux.oracle.com/errata/ELSA-2026-17533.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
gimp-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.x86_64.rpm
gimp-devel-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.x86_64.rpm
gimp-devel-tools-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.x86_64.rpm
gimp-libs-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.x86_64.rpm
pygobject2-2.28.7-5.module+el8.10.0+90497+ae78887f.x86_64.rpm
pygobject2-codegen-2.28.7-5.module+el8.10.0+90497+ae78887f.x86_64.rpm
pygobject2-devel-2.28.7-5.module+el8.10.0+90497+ae78887f.x86_64.rpm
pygobject2-doc-2.28.7-5.module+el8.10.0+90497+ae78887f.x86_64.rpm
pygtk2-2.24.0-25.module+el8.9.0+90151+46a7e4b5.x86_64.rpm
pygtk2-codegen-2.24.0-25.module+el8.9.0+90151+46a7e4b5.x86_64.rpm
pygtk2-devel-2.24.0-25.module+el8.9.0+90151+46a7e4b5.x86_64.rpm
pygtk2-doc-2.24.0-25.module+el8.9.0+90151+46a7e4b5.noarch.rpm
python2-cairo-1.16.3-7.module+el8.10.0+90497+ae78887f.x86_64.rpm
python2-cairo-devel-1.16.3-7.module+el8.10.0+90497+ae78887f.x86_64.rpm

aarch64:
gimp-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.aarch64.rpm
gimp-devel-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.aarch64.rpm
gimp-devel-tools-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.aarch64.rpm
gimp-libs-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.aarch64.rpm
pygobject2-2.28.7-5.module+el8.10.0+90497+ae78887f.aarch64.rpm
pygobject2-codegen-2.28.7-5.module+el8.10.0+90497+ae78887f.aarch64.rpm
pygobject2-devel-2.28.7-5.module+el8.10.0+90497+ae78887f.aarch64.rpm
pygobject2-doc-2.28.7-5.module+el8.10.0+90497+ae78887f.aarch64.rpm
pygtk2-2.24.0-25.module+el8.9.0+90151+46a7e4b5.aarch64.rpm
pygtk2-codegen-2.24.0-25.module+el8.9.0+90151+46a7e4b5.aarch64.rpm
pygtk2-devel-2.24.0-25.module+el8.9.0+90151+46a7e4b5.aarch64.rpm
pygtk2-doc-2.24.0-25.module+el8.9.0+90151+46a7e4b5.noarch.rpm
python2-cairo-1.16.3-7.module+el8.10.0+90497+ae78887f.aarch64.rpm
python2-cairo-devel-1.16.3-7.module+el8.10.0+90497+ae78887f.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/gimp-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/pygobject2-2.28.7-5.module+el8.10.0+90497+ae78887f.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/pygtk2-2.24.0-25.module+el8.9.0+90151+46a7e4b5.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/python2-pycairo-1.16.3-7.module+el8.10.0+90497+ae78887f.src.rpm

Related CVEs:

CVE-2026-4150
CVE-2026-4153
CVE-2026-4154
CVE-2026-4887

Description of changes:

gimp
[2:2.8.22-26.6]
- fix CVE-2026-4150
- fix CVE-2026-4153
- fix CVE-2026-4154
- fix CVE-2026-4887

[2:2.8.22-26.5]
- fix CVE-2026-0797
- fix CVE-2026-2044
- fix CVE-2026-2045
- fix CVE-2026-2048

[2:2.8.22-26.4]
- fix CVE-2025-14422

[2:2.8.22-26.3]
- fix CVE-2025-10920
- fix CVE-2025-10921
- fix CVE-2025-10922
- fix CVE-2025-10923
- fix CVE-2025-10924
- fix CVE-2025-10925
- fix CVE-2025-10934

[2:2.8.22-26.2]
- fix CVE-2025-5473 (RHEL-95696)

[2:2.8.22-26.1]
- fix CVE-2025-48797 (RHEL-93503)
- fix CVE-2025-48798 (RHEL-93506)

[2:2.28.22-26]
- bump spec

[2:2.8.22-25]
- fix CVE-2023-44442
- fix CVE-2023-44444
- disable gimp-2.8.22-python-path.patch required for flatpak
- partially cherry-pick from upstream commit 2987f012 to fix fclose leak
Resolves: RHEL-17048 RHEL-17060

[2:2.8.22-24]
- fallback to RPM gegl

[2:2.8.22-23]
- enforce gegl04

pygobject2
[2.28.7-5]
- bump spec to fix NVR

[2.28.7-4]
- update python macro to python2

[2.28.7-3]
- Add MIT license

[2.28.7-2.1]
- Fix python shebangs (#1580854)

[2.28.7-2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild

[2.28.7-1]
- Update to 2.28.7

[2.28.6-19]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild

[2.28.6-18]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild

[2.28.6-17]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild

[2.28.6-16]
- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages

pygtk2
[2.24.0-25]
- Fix shebang mangling for _prefix=app (#1907579)
- disable numpy for flatpak (#1907579)

[2.24.0-24]
- remove libglade dependency and sub-package (#1622134)

[2.24.0-23.1]
- fix python2 regex in sed command

[2.24.0-23]
- resotre doc sub package

[2.24.0-22]
- fix python2 macros

[2.24.0-21.1]
- Fix python shebangs (#1580855)

[2.24.0-21]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild

[2.24.0-20]
- Try again to fix shebangs

[2.24.0-19]
- Fix shebangs

[2.24.0-18]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild

python2-pycairo
[1.16.3-7]
- bump spec for NVR fix

[1.16.3-6]
- Rename pycairo to python2-pycairo (RCM-39388)

[1.16.3-5]
- Add python3 packages (RCM-39388)
- remove python3-test due its missing in build root

[1.16.3-4]
- Setup python2 stream branch for python2 binding of cairo library

[1.16.3-3]
- Remove the python2 subpackages
https://bugzilla.redhat.com/show_bug.cgi?id=1590820

[1.16.3-2]
- Allow Python 2 for build
See: https://hurl.corp.redhat.com/rhel8-py2

- Skip tests on Python 2 (python2-pytest is being removed)

[1.16.3-1]
- Update to 1.16.3

[1.16.1-1]
- Update to 1.16.1

[1.16.0-1]
- Update to 1.16.0

[1.15.6-1]
- Update to 1.15.6



ELSA-2026-6617 Important: Oracle Linux 7 vim security update


Oracle Linux Security Advisory ELSA-2026-6617

http://linux.oracle.com/errata/ELSA-2026-6617.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
vim-X11-7.4.629-8.0.3.el7_9.x86_64.rpm
vim-common-7.4.629-8.0.3.el7_9.x86_64.rpm
vim-enhanced-7.4.629-8.0.3.el7_9.x86_64.rpm
vim-filesystem-7.4.629-8.0.3.el7_9.x86_64.rpm
vim-minimal-7.4.629-8.0.3.el7_9.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/vim-7.4.629-8.0.3.el7_9.src.rpm

Related CVEs:

CVE-2026-25749
CVE-2026-28417
CVE-2026-28421
CVE-2026-33412

Description of changes:

[2:7.4.629-8.0.3]
- Security update CVE-2026-25749 CVE-2026-28417
- CVE-2026-28421 CVE-2026-33412 [Orabug: 39170094]



ELBA-2026-16195-1 Oracle Linux 8 kernel bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-16195-1

http://linux.oracle.com/errata/ELBA-2026-16195-1.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
bpftool-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm
kernel-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm
kernel-abi-stablelists-4.18.0-553.124.1.0.1.el8_10.noarch.rpm
kernel-core-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm
kernel-cross-headers-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm
kernel-debug-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm
kernel-debug-core-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm
kernel-debug-devel-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm
kernel-debug-modules-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm
kernel-debug-modules-extra-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm
kernel-devel-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm
kernel-doc-4.18.0-553.124.1.0.1.el8_10.noarch.rpm
kernel-headers-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm
kernel-modules-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm
kernel-modules-extra-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm
kernel-tools-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm
kernel-tools-libs-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm
kernel-tools-libs-devel-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm
perf-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm
python3-perf-4.18.0-553.124.1.0.1.el8_10.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/kernel-4.18.0-553.124.1.0.1.el8_10.src.rpm

Description of changes:

[4.18.0-553.124.1.0.1]
- scsi: core: Restrict legal sdev_state transitions via sysfs (Uday Shankar) [Orabug: 37778230]

[4.18.0-553.124.1]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64