{"cves":["CVE-2026-4802"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[310.8-1.0.1]\n- Fixed cockpit_ws_t selinux issue for tmpfs [Orabug: 36013589]\n- Move update-motd out of cockpit_ws_t context [Orabug: 36013589]\n- Update documentation links [Orabug: 34706402]\n- Drop subscription-manager-cockpit requirement for ol [Orabug: 34681110]\n- Remove duplicate reference to server in cockpit [Orabug: 33862832]\n- Update documentation links [Orabug: 32795691]\n- Make documentation links point to Oracle Linux information [Orabug: 30271413] [Orabug: 32013095]\n- Fix rendering of hwinfo page on systems with some empty memory slots [Orabug: 32826970]\n\n[310.8]\n- Remove recommends on subscription-manager-cockpit if applicable\n\n[310.8-1]\n- ws: fix uninitialized read in tls-sniffing code\n- ws: tighten up branding path construction\n- pkg/systemd: robustify argument quoting [CVE-2026-4802] (RHEL-161386)\n\n[310.7-1]\n- shell: Determine session idle time and countdown from clock time (RHEL-171011)","id":"ELSA-2026-21700","ovalId":"oval:com.oracle.elsa:def:202621700","source":"oracle_linux","title":"ELSA-2026-21700:  cockpit security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-21700.html"}