Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 561
Alerts This Week
Warning Icon 1 561

Oracle 10 ELSA-2026-18320 edk2 Moderate DoS Info Disclosure

oracle
Calendar Grey July 28, 2026
Scroller Oracle
Oracle Linux 10 has released an advisory for edk2 addressing security issues leading to denial of service and information disclosure.
Oracle Linux 10 has received security updates with new RPM packages addressing various vulnerabilities, including CVE-2025-9230, enhancing system security and stability.

Summary

[20251114-5.0.1.el10_2.2] - Replace upstream references [Orabug:36569119] [20251114-5.el10_2.2] - edk2-Revert-OvmfPkg-X86QemuLoadImageLib-flip-default-for-.patch [RHEL-182421] - edk2-Bumped-to-OpenSSL-3.5.5-3.patch [RHEL-165699] - Resolves: RHEL-182421 (edk2/x64: re-enable legacy kernel loader [rhel-10.2.z]) - Resolves: RHEL-165699 (CVE-2026-28390 edk2: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing [rhel-10.2]) [20251114-5.el10_2.1] - edk2-Bumped-to-OpenSSL-3.5.5-2.patch [RHEL-161573] - Resolves: RHEL-161573 (CVE-2026-31790 edk2: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key [rhel-10.2])

SRPMs

http://oss.oracle.com/ol10/SRPMS-updates/edk2-20251114-5.0.1.el10_2.2.src.rpm

x86_64

edk2-aarch64-20251114-5.0.1.el10_2.2.noarch.rpm edk2-ovmf-20251114-5.0.1.el10_2.2.noarch.rpm edk2-tools-20251114-5.0.1.el10_2.2.x86_64.rpm edk2-tools-doc-20251114-5.0.1.el10_2.2.noarch.rpm

aarch64

edk2-aarch64-20251114-5.0.1.el10_2.2.noarch.rpm edk2-ovmf-20251114-5.0.1.el10_2.2.noarch.rpm edk2-tools-20251114-5.0.1.el10_2.2.aarch64.rpm edk2-tools-doc-20251114-5.0.1.el10_2.2.noarch.rpm

Severity
important
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2025-9230

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.