{
  "cves": [
    "CVE-2026-5405",
    "CVE-2026-5656"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[4.4.2-10.0.1]\n- Fix post script to not fail during initial installation [Orabug: 37565359]\n\n[1:4.4.2-10]\n- Resolves: RHEL-173221 - CVE-2026-5656 Improper Limitation of a Pathname to a Restricted Directory\n\n[1:4.4.2-9]\n- Resolves: RHEL-173218 - CVE-2026-5405 Heap-based Buffer Overflow\n\n[1:4.4.2-8]\n- Resolves: RHEL-152922 - CVE-2026-3203 Buffer Over-read\n\n[1:4.4.2-7]\n- Resolves: RHEL-152913 - CVE-2026-3201 Improperly Controlled Sequential Memory Allocation\n\n[1:4.4.2-6]\n- Resolves: RHEL-136919 - NULL Pointer Dereference in Wireshark (CVE-2025-9817)\n\n[1:4.4.2-5]\n- Resolves: RHEL-130427 - Access of Uninitialized Pointer in Wireshark",
  "id": "ELSA-2026-20600",
  "ovalId": "oval:com.oracle.elsa:def:202620600",
  "source": "oracle_linux",
  "title": "ELSA-2026-20600:  wireshark security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-20600.html"
}