{"cves":["CVE-2026-54228","CVE-2026-54229","CVE-2026-54230","CVE-2026-54231"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[2.10.9-26.0.2]\n- Remove RHT patches\n- Drop libreport-rhel and libreport-plugin-rhtsupport requires\n\n[2.10.9-26.0.1]\n- Replaces sosreport to sos report in sosreport-event.conf [Orabug: 38590929]\n- abrt-dump-oops-Fix-vmcore-call-trace-parsing-arm [Orabug: 34184473]\n- Disable autoreporting on Oracle Linux [Orabug: 32890748]\n- Add orabug32082455-Upstream_reference_in_python3-abrt-addon.patch [Orabug: 32082455]\n- Add bug29870394-fix-redhat-reference.patch [Orabug: 29870394]\n\n[2.10.9-26]\n- Fix race condition in ChownProblemDir\n- Resolves: CVE-2026-54229\n- Fix TOCTOU in SetElement/DeleteElement\n- Resolves: CVE-2026-54228\n- Fix content injection in journal log collection\n- Resolves: CVE-2026-54231\n- Fix symlink following in event handler scripts\n- Resolves: CVE-2026-54230\n- Fix journal entry spoofing in journal dump services\n- Related: CVE-2026-54231","id":"ELSA-2026-54272","ovalId":"oval:com.oracle.elsa:def:202654272","source":"oracle_linux","title":"ELSA-2026-54272:  abrt security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-54272.html"}