[El-errata] ELSA-2026-59997 Moderate: Oracle Linux 10 polkit security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Thu Aug 27 11:13:52 UTC 2026


Oracle Linux Security Advisory ELSA-2026-59997

http://linux.oracle.com/errata/ELSA-2026-59997.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
polkit-125-4.0.1.el10_2.1.x86_64.rpm
polkit-devel-125-4.0.1.el10_2.1.x86_64.rpm
polkit-docs-125-4.0.1.el10_2.1.noarch.rpm
polkit-libs-125-4.0.1.el10_2.1.x86_64.rpm

aarch64:
polkit-125-4.0.1.el10_2.1.aarch64.rpm
polkit-devel-125-4.0.1.el10_2.1.aarch64.rpm
polkit-docs-125-4.0.1.el10_2.1.noarch.rpm
polkit-libs-125-4.0.1.el10_2.1.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/polkit-125-4.0.1.el10_2.1.src.rpm

Related CVEs:

CVE-2026-4897




Description of changes:

[125-4.0.1.el10_2.1]
- Increase timeout to avoid defunct processes [Orabug: 26930744]

[125-4.1]
- NOTICE (jrybar): the record 125-4 below was added in manually after Ymir's initial
- commit 125-3.1. For some reason, 125-3.1 for rhel-10.2 was based on contents
- of rhel-10.0 release instead of version 125-4 present in rhel-10.1.
- Fix CVE-2026-4897: string overflow in polkit agent helper
  Resolves: RHEL-218025




More information about the El-errata mailing list