{"cves":["CVE-2026-5405","CVE-2026-5656"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[4.4.2-10.0.1]\n- Fix post script to not fail during initial installation [Orabug: 37565359]\n\n[1:4.4.2-10]\n- Resolves: RHEL-173221 - CVE-2026-5656 Improper Limitation of a Pathname to a Restricted Directory\n\n[1:4.4.2-9]\n- Resolves: RHEL-173218 - CVE-2026-5405 Heap-based Buffer Overflow\n\n[1:4.4.2-8]\n- Resolves: RHEL-152922 - CVE-2026-3203 Buffer Over-read\n\n[1:4.4.2-7]\n- Resolves: RHEL-152913 - CVE-2026-3201 Improperly Controlled Sequential Memory Allocation\n\n[1:4.4.2-6]\n- Resolves: RHEL-136919 - NULL Pointer Dereference in Wireshark (CVE-2025-9817)\n\n[1:4.4.2-5]\n- Resolves: RHEL-130427 - Access of Uninitialized Pointer in Wireshark","id":"ELSA-2026-20600","ovalId":"oval:com.oracle.elsa:def:202620600","source":"oracle_linux","title":"ELSA-2026-20600:  wireshark security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-20600.html"}