elsa-2026-38504
oracle_linuxaardvark-dns [2:1.10.1-2] - build off the RHEL maintenance branch - Resolves: RHEL-59129 buildah [2:1.33.14-4] - switch source URL from GitHub to the internal GitLab sustaining-engineering repo - update to the latest content of release-1.33 (commit 2cbee78) - bump golang.org/x/crypto to v0.53.0 to fix CVE-2026-39829, CVE-2026-39830, CVE-2026-39832 cockpit-podman [84.1-1] - update to https://github.com/cockpit-project/cockpit-podman/releases/tag/84.1 - Related: Jira:RHEL-25557 conmon [3:2.1.10-1] - update to https://github.com/containers/conmon/releases/tag/v2.1.10 - Related: Jira:RHEL-2110 containernetworking-plugins [1:1.4.0-8] - rebuild for CVE-2025-68121 - Resolves: RHEL-149265 containers-common [1-82.0.1] - Updated removed references [Orabug: 33473101] (Alex Burmashev) - Adjust registries.conf (Nikita Gerasimov) - remove references to RedHat registry (Nikita Gerasimov) container-selinux [2:2.229.0-3] - add user_t confined user container support (cherry-pick of upstream PR #443) - Resolves: RHEL-135342 criu [3.18-5] - rebuild to preserve upgrade path - Related: RHEL-32671 crun [1.14.3-2] - remove BR libgcrypt-devel, no longer needed - Related: Jira:RHEL-2110 fuse-overlayfs [1.13-1] - update to https://github.com/containers/fuse-overlayfs/releases/tag/v1.13 - Related: Jira:RHEL-2110 libslirp [4.4.0-2] - rebuild to preserve upgrade path 8.9 - 8.10 - Related: RHEL-32671 netavark [2:1.10.3-1] - update to https://github.com/containers/netavark/releases/tag/v1.10.3 - Related: Jira:RHEL-2110 oci-seccomp-bpf-hook [1.2.10-1] - update to https://github.com/containers/oci-seccomp-bpf-hook/releases/tag/v1.2.10 - Related: Jira:RHEL-2110 podman [4.9.4-34.0.1] - Fixes issue of container created in cgroupv2 not start in cgroupv1 [Orabug: 36136813] - Fixes container memory limit not set after host is rebooted with cgroupv2 [Orabug: 36136802] - Fixes issue of podman execvp error while using podmansh [Orabug: 36756665] [4:4.9.4-34] - upload source tarball for v4.9-rhel (commit bd39e82) - Resolves: RHEL-190070 RHEL-190856 RHEL-191102 RHEL-191553 [4:4.9.4-33] - update to the latest content of v4.9-rhel (commit bd39e82) to fix CVE-2026-39835, CVE-2026-57231, CVE-2026-25681, CVE-2026-27136 - Resolves: RHEL-190070 RHEL-190856 RHEL-191102 RHEL-191553 python-podman [4.9.0-3] - sync with release-4.9 branch - Resolves: RHEL-31069 runc [4:1.2.9-4] - rebuild for CVE-2025-68121 - Resolves: RHEL-149266 skopeo [2:1.14.6-2] - Rebuild for CVE-2026-32281 - Resolves: RHEL-177067 slirp4netns [1.2.3-1] - update to https://github.com/rootless-containers/slirp4netns/releases/tag/v1.2.3 - Related: Jira:RHEL-2110 udica [0.2.6-21] - bump release to preserve update path - Resolves: RHEL-32671
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
No references available.
No linked vulnerabilities found.
{
"cves": [
"CVE-2026-33811",
"CVE-2026-39835",
"CVE-2026-57231"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "aardvark-dns\n[2:1.10.1-2]\n- build off the RHEL maintenance branch\n- Resolves: RHEL-59129\n\nbuildah\n[2:1.33.14-4]\n- switch source URL from GitHub to the internal GitLab sustaining-engineering repo\n- update to the latest content of release-1.33 (commit 2cbee78)\n- bump golang.org/x/crypto to v0.53.0 to fix CVE-2026-39829, CVE-2026-39830, CVE-2026-39832\n\ncockpit-podman\n[84.1-1]\n- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/84.1\n- Related: Jira:RHEL-25557\n\nconmon\n[3:2.1.10-1]\n- update to https://github.com/containers/conmon/releases/tag/v2.1.10\n- Related: Jira:RHEL-2110\n\ncontainernetworking-plugins\n[1:1.4.0-8]\n- rebuild for CVE-2025-68121\n- Resolves: RHEL-149265\n\ncontainers-common\n[1-82.0.1]\n- Updated removed references [Orabug: 33473101] (Alex Burmashev)\n- Adjust registries.conf (Nikita Gerasimov)\n- remove references to RedHat registry (Nikita Gerasimov)\n\ncontainer-selinux\n[2:2.229.0-3]\n- add user_t confined user container support (cherry-pick of upstream PR #443)\n- Resolves: RHEL-135342\n\ncriu\n[3.18-5]\n- rebuild to preserve upgrade path\n- Related: RHEL-32671\n\ncrun\n[1.14.3-2]\n- remove BR libgcrypt-devel, no longer needed\n- Related: Jira:RHEL-2110\n\nfuse-overlayfs\n[1.13-1]\n- update to https://github.com/containers/fuse-overlayfs/releases/tag/v1.13\n- Related: Jira:RHEL-2110\n\nlibslirp\n[4.4.0-2]\n- rebuild to preserve upgrade path 8.9 - 8.10\n- Related: RHEL-32671\n\nnetavark\n[2:1.10.3-1]\n- update to https://github.com/containers/netavark/releases/tag/v1.10.3\n- Related: Jira:RHEL-2110\n\noci-seccomp-bpf-hook\n[1.2.10-1]\n- update to https://github.com/containers/oci-seccomp-bpf-hook/releases/tag/v1.2.10\n- Related: Jira:RHEL-2110\n\npodman\n[4.9.4-34.0.1]\n- Fixes issue of container created in cgroupv2 not start in cgroupv1 [Orabug: 36136813]\n- Fixes container memory limit not set after host is rebooted with cgroupv2 [Orabug: 36136802]\n- Fixes issue of podman execvp error while using podmansh [Orabug: 36756665]\n\n[4:4.9.4-34]\n- upload source tarball for v4.9-rhel (commit bd39e82)\n- Resolves: RHEL-190070 RHEL-190856 RHEL-191102 RHEL-191553\n\n[4:4.9.4-33]\n- update to the latest content of v4.9-rhel (commit bd39e82) to fix CVE-2026-39835, CVE-2026-57231, CVE-2026-25681, CVE-2026-27136\n- Resolves: RHEL-190070 RHEL-190856 RHEL-191102 RHEL-191553\n\npython-podman\n[4.9.0-3]\n- sync with release-4.9 branch\n- Resolves: RHEL-31069\n\nrunc\n[4:1.2.9-4]\n- rebuild for CVE-2025-68121\n- Resolves: RHEL-149266\n\nskopeo\n[2:1.14.6-2]\n- Rebuild for CVE-2026-32281\n- Resolves: RHEL-177067\n\nslirp4netns\n[1.2.3-1]\n- update to https://github.com/rootless-containers/slirp4netns/releases/tag/v1.2.3\n- Related: Jira:RHEL-2110\n\nudica\n[0.2.6-21]\n- bump release to preserve update path\n- Resolves: RHEL-32671",
"id": "ELSA-2026-38504",
"ovalId": "oval:com.oracle.elsa:def:202638504",
"source": "oracle_linux",
"title": "ELSA-2026-38504: container-tools:ol8 security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2026-38504.html"
}