[El-errata] ELSA-2026-2776 Moderate: Oracle Linux 9 edk2 security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Wed Feb 18 14:03:58 UTC 2026


Oracle Linux Security Advisory ELSA-2026-2776

http://linux.oracle.com/errata/ELSA-2026-2776.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
edk2-aarch64-20241117-4.0.1.el9_7.3.noarch.rpm
edk2-ovmf-20241117-4.0.1.el9_7.3.noarch.rpm
edk2-tools-20241117-4.0.1.el9_7.3.x86_64.rpm
edk2-tools-doc-20241117-4.0.1.el9_7.3.noarch.rpm

aarch64:
edk2-aarch64-20241117-4.0.1.el9_7.3.noarch.rpm
edk2-ovmf-20241117-4.0.1.el9_7.3.noarch.rpm
edk2-tools-20241117-4.0.1.el9_7.3.aarch64.rpm
edk2-tools-doc-20241117-4.0.1.el9_7.3.noarch.rpm


SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/edk2-20241117-4.0.1.el9_7.3.src.rpm

Related CVEs:

CVE-2025-9230




Description of changes:

[20241117-4.0.1.el9_7.3]
- Replace upstream references [Orabug:36569119]

[20241117-4.el9_7.3]
- edk2-OvmfPkg-MemEncryptSevLib-Evict-cache-lines-during-SN.patch [RHEL-125104]
- edk2-MdePkg-Add-the-COHERENCY_SFW_NO-CPUID-bit-field.patch [RHEL-125104]
- edk2-OvmfPkg-ResetVector-Make-ReceivedVc-a-flag-in-SEV-ES.patch [RHEL-125104]
- edk2-OvmfPkg-MemEncryptSevLib-Check-if-SEV-SNP-coherency-.patch [RHEL-125104]
- edk2-openssl-flatten-contents-of-openssl-tarball.patch [RHEL-115923]
- edk2-Bumped-openssl-submodule-to-version-3.0.7-29.1.patch [RHEL-115923]
- Resolves: RHEL-125104
  ([edk2] VM panic on booting SNP guest with large memory on Genoa [rhel-9.7.z])
- Resolves: RHEL-115923
  (CVE-2025-9230 edk2: Out-of-bounds read & write in RFC 3211 KEK Unwrap [rhel-9.7.z])

[20241117-4.el9_7.2]
- edk2-OvmfPkg-IoMmuDxe-Fix-1M-and-2M-buffer-handling.patch [RHEL-121875]
- Resolves: RHEL-121875
  (Fail to create AMD SEV SLES 15 SP4 guest via virt-install --cdrom [rhel-9.7.z])

[20241117-4.el9_7.1]
- edk2-OvmfPkg-IoMmuDxe-Fix-1M-and-2M-buffer-handling.patch [RHEL-121875]
- Resolves: RHEL-121875
  (Fail to create AMD SEV SLES 15 SP4 guest via virt-install --cdrom [rhel-9.7.z])




More information about the El-errata mailing list