[El-errata] ELSA-2026-39297 Moderate: Oracle Linux 10 edk2 security, bug fix, and enhancement update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Wed Jul 22 11:26:52 UTC 2026


Oracle Linux Security Advisory ELSA-2026-39297

http://linux.oracle.com/errata/ELSA-2026-39297.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
edk2-aarch64-20251114-5.0.1.el10_2.2.noarch.rpm
edk2-ovmf-20251114-5.0.1.el10_2.2.noarch.rpm
edk2-tools-20251114-5.0.1.el10_2.2.x86_64.rpm
edk2-tools-doc-20251114-5.0.1.el10_2.2.noarch.rpm

aarch64:
edk2-aarch64-20251114-5.0.1.el10_2.2.noarch.rpm
edk2-ovmf-20251114-5.0.1.el10_2.2.noarch.rpm
edk2-tools-20251114-5.0.1.el10_2.2.aarch64.rpm
edk2-tools-doc-20251114-5.0.1.el10_2.2.noarch.rpm


SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/edk2-20251114-5.0.1.el10_2.2.src.rpm

Related CVEs:

CVE-2026-28390
CVE-2026-31790




Description of changes:

[20251114-5.0.1.el10_2.2]
- Replace upstream references [Orabug:36569119]

[20251114-5.el10_2.2]
- edk2-Revert-OvmfPkg-X86QemuLoadImageLib-flip-default-for-.patch [RHEL-182421]
- edk2-Bumped-to-OpenSSL-3.5.5-3.patch [RHEL-165699]
- Resolves: RHEL-182421
  (edk2/x64: re-enable legacy kernel loader [rhel-10.2.z])
- Resolves: RHEL-165699
  (CVE-2026-28390 edk2: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing [rhel-10.2])

[20251114-5.el10_2.1]
- edk2-Bumped-to-OpenSSL-3.5.5-2.patch [RHEL-161573]
- Resolves: RHEL-161573
  (CVE-2026-31790 edk2: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key [rhel-10.2])




More information about the El-errata mailing list