ELSA-2026-3443 Important: Oracle Linux 10 valkey security update
ELSA-2026-3361 Important: Oracle Linux 10 firefox security update
ELSA-2026-3354 Important: Oracle Linux 10 python-pyasn1 security update
ELSA-2026-3339 Important: Oracle Linux 9 firefox security update
ELSA-2026-3343 Important: Oracle Linux 10 skopeo security update
ELSA-2026-3275 Moderate: Oracle Linux 10 kernel security update
ELSA-2026-3405 Important: Oracle Linux 9 libpng security update
ELSA-2026-3359 Important: Oracle Linux 9 python-pyasn1 security update
ELBA-2026-2778 Oracle Linux 9 WALinuxAgent bug fix and enhancement update
ELSA-2026-3337 Important: Oracle Linux 9 podman security update
ELBA-2026-3083-1 Oracle Linux 8 kernel bug fix update
ELSA-2026-3298 Important: Oracle Linux 9 buildah security update
ELSA-2026-3338 Important: Oracle Linux 8 firefox security update
ELSA-2026-3334 Important: Oracle Linux 8 freerdp security update
ELSA-2026-3443 Important: Oracle Linux 10 valkey security update
Oracle Linux Security Advisory ELSA-2026-3443
http://linux.oracle.com/errata/ELSA-2026-3443.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
valkey-8.0.7-1.el10_1.x86_64.rpm
valkey-devel-8.0.7-1.el10_1.x86_64.rpm
aarch64:
valkey-8.0.7-1.el10_1.aarch64.rpm
valkey-devel-8.0.7-1.el10_1.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/valkey-8.0.7-1.el10_1.src.rpm
Related CVEs:
CVE-2025-67733
CVE-2026-21863
Description of changes:
[8.0.7-1]
- Rebase to 8.0.7 for CVE-2026-21863 CVE-2025-67733
ELSA-2026-3361 Important: Oracle Linux 10 firefox security update
Oracle Linux Security Advisory ELSA-2026-3361
http://linux.oracle.com/errata/ELSA-2026-3361.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
firefox-140.8.0-2.0.1.el10_1.x86_64.rpm
aarch64:
firefox-140.8.0-2.0.1.el10_1.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/firefox-140.8.0-2.0.1.el10_1.src.rpm
Related CVEs:
CVE-2026-2447
CVE-2026-2757
CVE-2026-2758
CVE-2026-2759
CVE-2026-2760
CVE-2026-2761
CVE-2026-2762
CVE-2026-2763
CVE-2026-2764
CVE-2026-2765
CVE-2026-2766
CVE-2026-2767
CVE-2026-2768
CVE-2026-2769
CVE-2026-2770
CVE-2026-2771
CVE-2026-2772
CVE-2026-2773
CVE-2026-2774
CVE-2026-2775
CVE-2026-2776
CVE-2026-2777
CVE-2026-2778
CVE-2026-2779
CVE-2026-2780
CVE-2026-2781
CVE-2026-2782
CVE-2026-2783
CVE-2026-2784
CVE-2026-2785
CVE-2026-2786
CVE-2026-2787
CVE-2026-2788
CVE-2026-2789
CVE-2026-2790
CVE-2026-2791
CVE-2026-2792
CVE-2026-2793
Description of changes:
[140.8.0-2.0.1]
- Fix firefox-oracle-default-prefs.js for new nss [Orabug: 37079773]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat file
[140.8.0-2]
- Update to 140.8.0 ESR
ELSA-2026-3354 Important: Oracle Linux 10 python-pyasn1 security update
Oracle Linux Security Advisory ELSA-2026-3354
http://linux.oracle.com/errata/ELSA-2026-3354.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
python3-pyasn1-0.6.2-1.el10_1.noarch.rpm
python3-pyasn1-modules-0.6.2-1.el10_1.noarch.rpm
aarch64:
python3-pyasn1-0.6.2-1.el10_1.noarch.rpm
python3-pyasn1-modules-0.6.2-1.el10_1.noarch.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/python-pyasn1-0.6.2-1.el10_1.src.rpm
Related CVEs:
CVE-2026-23490
Description of changes:
[0.6.2-1]
- Update to 0.6.2
- Update modules to 0.4.2
Resolves: RHEL-148142
ELSA-2026-3339 Important: Oracle Linux 9 firefox security update
Oracle Linux Security Advisory ELSA-2026-3339
http://linux.oracle.com/errata/ELSA-2026-3339.html
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
x86_64:
firefox-140.8.0-2.0.1.el9_7.x86_64.rpm
firefox-x11-140.8.0-2.0.1.el9_7.x86_64.rpm
aarch64:
firefox-140.8.0-2.0.1.el9_7.aarch64.rpm
firefox-x11-140.8.0-2.0.1.el9_7.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/firefox-140.8.0-2.0.1.el9_7.src.rpm
Related CVEs:
CVE-2026-2447
CVE-2026-2757
CVE-2026-2758
CVE-2026-2759
CVE-2026-2760
CVE-2026-2761
CVE-2026-2762
CVE-2026-2763
CVE-2026-2764
CVE-2026-2765
CVE-2026-2766
CVE-2026-2767
CVE-2026-2768
CVE-2026-2769
CVE-2026-2770
CVE-2026-2771
CVE-2026-2772
CVE-2026-2773
CVE-2026-2774
CVE-2026-2775
CVE-2026-2776
CVE-2026-2777
CVE-2026-2778
CVE-2026-2779
CVE-2026-2780
CVE-2026-2781
CVE-2026-2782
CVE-2026-2783
CVE-2026-2784
CVE-2026-2785
CVE-2026-2786
CVE-2026-2787
CVE-2026-2788
CVE-2026-2789
CVE-2026-2790
CVE-2026-2791
CVE-2026-2792
CVE-2026-2793
Description of changes:
[140.8.0-2.0.1]
- Fix firefox-oracle-default-prefs.js for new nss [Orabug: 37079773]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat file
[140.8.0]
- Add debranding patches (Mustafa Gezen)
- Add OpenELA default preferences (Louis Abel)
[140.8.0-2]
- Update to 140.8.0 ESR
ELSA-2026-3343 Important: Oracle Linux 10 skopeo security update
Oracle Linux Security Advisory ELSA-2026-3343
http://linux.oracle.com/errata/ELSA-2026-3343.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
skopeo-1.20.0-3.el10_1.x86_64.rpm
skopeo-tests-1.20.0-3.el10_1.x86_64.rpm
aarch64:
skopeo-1.20.0-3.el10_1.aarch64.rpm
skopeo-tests-1.20.0-3.el10_1.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/skopeo-1.20.0-3.el10_1.src.rpm
Related CVEs:
CVE-2025-61726
CVE-2025-61729
CVE-2025-68121
Description of changes:
[1:1.20.0-3]
- Rebuild for new golang to address CVE-2025-61726
- Resolves: RHEL-146730
ELSA-2026-3275 Moderate: Oracle Linux 10 kernel security update
Oracle Linux Security Advisory ELSA-2026-3275
http://linux.oracle.com/errata/ELSA-2026-3275.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
kernel-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-abi-stablelists-6.12.0-124.39.1.el10_1.noarch.rpm
kernel-core-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-cross-headers-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-debug-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-debug-core-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-debug-devel-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-debug-devel-matched-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-debug-modules-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-debug-modules-core-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-debug-modules-extra-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-debug-uki-virt-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-devel-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-devel-matched-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-doc-6.12.0-124.39.1.el10_1.noarch.rpm
kernel-headers-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-modules-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-modules-core-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-modules-extra-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-modules-extra-matched-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-tools-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-tools-libs-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-tools-libs-devel-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-uki-virt-6.12.0-124.39.1.el10_1.x86_64.rpm
kernel-uki-virt-addons-6.12.0-124.39.1.el10_1.x86_64.rpm
libperf-6.12.0-124.39.1.el10_1.x86_64.rpm
perf-6.12.0-124.39.1.el10_1.x86_64.rpm
python3-perf-6.12.0-124.39.1.el10_1.x86_64.rpm
rtla-6.12.0-124.39.1.el10_1.x86_64.rpm
rv-6.12.0-124.39.1.el10_1.x86_64.rpm
aarch64:
kernel-cross-headers-6.12.0-124.39.1.el10_1.aarch64.rpm
kernel-headers-6.12.0-124.39.1.el10_1.aarch64.rpm
kernel-tools-6.12.0-124.39.1.el10_1.aarch64.rpm
kernel-tools-libs-6.12.0-124.39.1.el10_1.aarch64.rpm
kernel-tools-libs-devel-6.12.0-124.39.1.el10_1.aarch64.rpm
libperf-6.12.0-124.39.1.el10_1.aarch64.rpm
perf-6.12.0-124.39.1.el10_1.aarch64.rpm
python3-perf-6.12.0-124.39.1.el10_1.aarch64.rpm
rtla-6.12.0-124.39.1.el10_1.aarch64.rpm
rv-6.12.0-124.39.1.el10_1.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/kernel-6.12.0-124.39.1.el10_1.src.rpm
Related CVEs:
CVE-2025-38206
CVE-2025-40096
CVE-2025-40168
CVE-2025-68800
Description of changes:
[6.12.0-124.39.1]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64