[El-errata] ELSA-2026-67943 Important: Oracle Linux 8 python-lxml security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Mon Sep 21 13:24:37 UTC 2026


Oracle Linux Security Advisory ELSA-2026-67943

http://linux.oracle.com/errata/ELSA-2026-67943.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
python3-lxml-4.2.3-5.el8_10.x86_64.rpm

aarch64:
python3-lxml-4.2.3-5.el8_10.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/python-lxml-4.2.3-5.el8_10.src.rpm

Related CVEs:

CVE-2026-49825




Description of changes:

[4.2.3-5]
- Security fix for CVE-2026-49825: missing xlink:href in known HTML
  link attributes
Resolves: RHEL-251508

[4.2.3-4]
- Security fix for CVE-2021-43818
Resolves: rhbz#2032569

[4.2.3-3]
- Security fix for CVE-2021-28957
Resolves: rhbz#1941534

[4.2.3-2]
- Security fix for CVE-2020-27783: mXSS due to the use of improper parser
Resolves: rhbz#1901633

[4.2.3-1]
- New upstream release 4.2.3

[4.1.1-3]
- Conditionalize the python2 subpackage

[4.1.1-2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild

[4.1.1-1]
- Update to 4.1.1

[4.0.0-2]
- Conditionally allow building without Cython

[4.0.0-1]
- Update to 4.0.0




More information about the El-errata mailing list