[El-errata] ELSA-2026-39297 Moderate: Oracle Linux 10 edk2 security, bug fix, and enhancement update
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Wed Jul 22 11:26:52 UTC 2026
Oracle Linux Security Advisory ELSA-2026-39297
http://linux.oracle.com/errata/ELSA-2026-39297.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
edk2-aarch64-20251114-5.0.1.el10_2.2.noarch.rpm
edk2-ovmf-20251114-5.0.1.el10_2.2.noarch.rpm
edk2-tools-20251114-5.0.1.el10_2.2.x86_64.rpm
edk2-tools-doc-20251114-5.0.1.el10_2.2.noarch.rpm
aarch64:
edk2-aarch64-20251114-5.0.1.el10_2.2.noarch.rpm
edk2-ovmf-20251114-5.0.1.el10_2.2.noarch.rpm
edk2-tools-20251114-5.0.1.el10_2.2.aarch64.rpm
edk2-tools-doc-20251114-5.0.1.el10_2.2.noarch.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/edk2-20251114-5.0.1.el10_2.2.src.rpm
Related CVEs:
CVE-2026-28390
CVE-2026-31790
Description of changes:
[20251114-5.0.1.el10_2.2]
- Replace upstream references [Orabug:36569119]
[20251114-5.el10_2.2]
- edk2-Revert-OvmfPkg-X86QemuLoadImageLib-flip-default-for-.patch [RHEL-182421]
- edk2-Bumped-to-OpenSSL-3.5.5-3.patch [RHEL-165699]
- Resolves: RHEL-182421
(edk2/x64: re-enable legacy kernel loader [rhel-10.2.z])
- Resolves: RHEL-165699
(CVE-2026-28390 edk2: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing [rhel-10.2])
[20251114-5.el10_2.1]
- edk2-Bumped-to-OpenSSL-3.5.5-2.patch [RHEL-161573]
- Resolves: RHEL-161573
(CVE-2026-31790 edk2: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key [rhel-10.2])
More information about the El-errata
mailing list