elsa-2026-38504

oracle_linux
Description

aardvark-dns [2:1.10.1-2] - build off the RHEL maintenance branch - Resolves: RHEL-59129 buildah [2:1.33.14-4] - switch source URL from GitHub to the internal GitLab sustaining-engineering repo - update to the latest content of release-1.33 (commit 2cbee78) - bump golang.org/x/crypto to v0.53.0 to fix CVE-2026-39829, CVE-2026-39830, CVE-2026-39832 cockpit-podman [84.1-1] - update to https://github.com/cockpit-project/cockpit-podman/releases/tag/84.1 - Related: Jira:RHEL-25557 conmon [3:2.1.10-1] - update to https://github.com/containers/conmon/releases/tag/v2.1.10 - Related: Jira:RHEL-2110 containernetworking-plugins [1:1.4.0-8] - rebuild for CVE-2025-68121 - Resolves: RHEL-149265 containers-common [1-82.0.1] - Updated removed references [Orabug: 33473101] (Alex Burmashev) - Adjust registries.conf (Nikita Gerasimov) - remove references to RedHat registry (Nikita Gerasimov) container-selinux [2:2.229.0-3] - add user_t confined user container support (cherry-pick of upstream PR #443) - Resolves: RHEL-135342 criu [3.18-5] - rebuild to preserve upgrade path - Related: RHEL-32671 crun [1.14.3-2] - remove BR libgcrypt-devel, no longer needed - Related: Jira:RHEL-2110 fuse-overlayfs [1.13-1] - update to https://github.com/containers/fuse-overlayfs/releases/tag/v1.13 - Related: Jira:RHEL-2110 libslirp [4.4.0-2] - rebuild to preserve upgrade path 8.9 - 8.10 - Related: RHEL-32671 netavark [2:1.10.3-1] - update to https://github.com/containers/netavark/releases/tag/v1.10.3 - Related: Jira:RHEL-2110 oci-seccomp-bpf-hook [1.2.10-1] - update to https://github.com/containers/oci-seccomp-bpf-hook/releases/tag/v1.2.10 - Related: Jira:RHEL-2110 podman [4.9.4-34.0.1] - Fixes issue of container created in cgroupv2 not start in cgroupv1 [Orabug: 36136813] - Fixes container memory limit not set after host is rebooted with cgroupv2 [Orabug: 36136802] - Fixes issue of podman execvp error while using podmansh [Orabug: 36756665] [4:4.9.4-34] - upload source tarball for v4.9-rhel (commit bd39e82) - Resolves: RHEL-190070 RHEL-190856 RHEL-191102 RHEL-191553 [4:4.9.4-33] - update to the latest content of v4.9-rhel (commit bd39e82) to fix CVE-2026-39835, CVE-2026-57231, CVE-2026-25681, CVE-2026-27136 - Resolves: RHEL-190070 RHEL-190856 RHEL-191102 RHEL-191553 python-podman [4.9.0-3] - sync with release-4.9 branch - Resolves: RHEL-31069 runc [4:1.2.9-4] - rebuild for CVE-2025-68121 - Resolves: RHEL-149266 skopeo [2:1.14.6-2] - Rebuild for CVE-2026-32281 - Resolves: RHEL-177067 slirp4netns [1.2.3-1] - update to https://github.com/rootless-containers/slirp4netns/releases/tag/v1.2.3 - Related: Jira:RHEL-2110 udica [0.2.6-21] - bump release to preserve update path - Resolves: RHEL-32671

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2026-33811",
    "CVE-2026-39835",
    "CVE-2026-57231"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "aardvark-dns\n[2:1.10.1-2]\n- build off the RHEL maintenance branch\n- Resolves: RHEL-59129\n\nbuildah\n[2:1.33.14-4]\n- switch source URL from GitHub to the internal GitLab sustaining-engineering repo\n- update to the latest content of release-1.33 (commit 2cbee78)\n- bump golang.org/x/crypto to v0.53.0 to fix CVE-2026-39829, CVE-2026-39830, CVE-2026-39832\n\ncockpit-podman\n[84.1-1]\n- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/84.1\n- Related: Jira:RHEL-25557\n\nconmon\n[3:2.1.10-1]\n- update to https://github.com/containers/conmon/releases/tag/v2.1.10\n- Related: Jira:RHEL-2110\n\ncontainernetworking-plugins\n[1:1.4.0-8]\n- rebuild for CVE-2025-68121\n- Resolves: RHEL-149265\n\ncontainers-common\n[1-82.0.1]\n- Updated removed references [Orabug: 33473101] (Alex Burmashev)\n- Adjust registries.conf (Nikita Gerasimov)\n- remove references to RedHat registry (Nikita Gerasimov)\n\ncontainer-selinux\n[2:2.229.0-3]\n- add user_t confined user container support (cherry-pick of upstream PR #443)\n- Resolves: RHEL-135342\n\ncriu\n[3.18-5]\n- rebuild to preserve upgrade path\n- Related: RHEL-32671\n\ncrun\n[1.14.3-2]\n- remove BR libgcrypt-devel, no longer needed\n- Related: Jira:RHEL-2110\n\nfuse-overlayfs\n[1.13-1]\n- update to https://github.com/containers/fuse-overlayfs/releases/tag/v1.13\n- Related: Jira:RHEL-2110\n\nlibslirp\n[4.4.0-2]\n- rebuild to preserve upgrade path 8.9 - 8.10\n- Related: RHEL-32671\n\nnetavark\n[2:1.10.3-1]\n- update to https://github.com/containers/netavark/releases/tag/v1.10.3\n- Related: Jira:RHEL-2110\n\noci-seccomp-bpf-hook\n[1.2.10-1]\n- update to https://github.com/containers/oci-seccomp-bpf-hook/releases/tag/v1.2.10\n- Related: Jira:RHEL-2110\n\npodman\n[4.9.4-34.0.1]\n- Fixes issue of container created in cgroupv2 not start in cgroupv1 [Orabug: 36136813]\n- Fixes container memory limit not set after host is rebooted with cgroupv2 [Orabug: 36136802]\n- Fixes issue of podman execvp error while using podmansh [Orabug: 36756665]\n\n[4:4.9.4-34]\n- upload source tarball for v4.9-rhel (commit bd39e82)\n- Resolves: RHEL-190070 RHEL-190856 RHEL-191102 RHEL-191553\n\n[4:4.9.4-33]\n- update to the latest content of v4.9-rhel (commit bd39e82) to fix CVE-2026-39835, CVE-2026-57231, CVE-2026-25681, CVE-2026-27136\n- Resolves: RHEL-190070 RHEL-190856 RHEL-191102 RHEL-191553\n\npython-podman\n[4.9.0-3]\n- sync with release-4.9 branch\n- Resolves: RHEL-31069\n\nrunc\n[4:1.2.9-4]\n- rebuild for CVE-2025-68121\n- Resolves: RHEL-149266\n\nskopeo\n[2:1.14.6-2]\n- Rebuild for CVE-2026-32281\n- Resolves: RHEL-177067\n\nslirp4netns\n[1.2.3-1]\n- update to https://github.com/rootless-containers/slirp4netns/releases/tag/v1.2.3\n- Related: Jira:RHEL-2110\n\nudica\n[0.2.6-21]\n- bump release to preserve update path\n- Resolves: RHEL-32671",
  "id": "ELSA-2026-38504",
  "ovalId": "oval:com.oracle.elsa:def:202638504",
  "source": "oracle_linux",
  "title": "ELSA-2026-38504:  container-tools:ol8 security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-38504.html"
}
View JSON API Download JSON