Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

Oracle Linux 10 ELSA-2026-39297 edk2 Moderate DoS Info Disclosure

oracle
Calendar Grey July 22, 2026
Scroller Oracle
Oracle Linux 10 advisories detail moderate severity updates for edk2 addressing critical Denial of Service and Info Disclosure.
Oracle Linux has released security updates for version 10, addressing vulnerabilities related to OpenSSL and kernel loading, along with specific RPM packages available for x86_64 a...

Summary

[20251114-5.0.1.el10_2.2] - Replace upstream references [Orabug:36569119] [20251114-5.el10_2.2] - edk2-Revert-OvmfPkg-X86QemuLoadImageLib-flip-default-for-.patch [RHEL-182421] - edk2-Bumped-to-OpenSSL-3.5.5-3.patch [RHEL-165699] - Resolves: RHEL-182421 (edk2/x64: re-enable legacy kernel loader [rhel-10.2.z]) - Resolves: RHEL-165699 (CVE-2026-28390 edk2: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing [rhel-10.2]) [20251114-5.el10_2.1] - edk2-Bumped-to-OpenSSL-3.5.5-2.patch [RHEL-161573] - Resolves: RHEL-161573 (CVE-2026-31790 edk2: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key [rhel-10.2])

SRPMs

http://oss.oracle.com/ol10/SRPMS-updates/edk2-20251114-5.0.1.el10_2.2.src.rpm

x86_64

edk2-aarch64-20251114-5.0.1.el10_2.2.noarch.rpm edk2-ovmf-20251114-5.0.1.el10_2.2.noarch.rpm edk2-tools-20251114-5.0.1.el10_2.2.x86_64.rpm edk2-tools-doc-20251114-5.0.1.el10_2.2.noarch.rpm

aarch64

edk2-aarch64-20251114-5.0.1.el10_2.2.noarch.rpm edk2-ovmf-20251114-5.0.1.el10_2.2.noarch.rpm edk2-tools-20251114-5.0.1.el10_2.2.aarch64.rpm edk2-tools-doc-20251114-5.0.1.el10_2.2.noarch.rpm

Severity
moderate
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2026-28390 CVE-2026-31790

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.