elsa-2026-54272

oracle_linux
Description

[2.10.9-26.0.2] - Remove RHT patches - Drop libreport-rhel and libreport-plugin-rhtsupport requires [2.10.9-26.0.1] - Replaces sosreport to sos report in sosreport-event.conf [Orabug: 38590929] - abrt-dump-oops-Fix-vmcore-call-trace-parsing-arm [Orabug: 34184473] - Disable autoreporting on Oracle Linux [Orabug: 32890748] - Add orabug32082455-Upstream_reference_in_python3-abrt-addon.patch [Orabug: 32082455] - Add bug29870394-fix-redhat-reference.patch [Orabug: 29870394] [2.10.9-26] - Fix race condition in ChownProblemDir - Resolves: CVE-2026-54229 - Fix TOCTOU in SetElement/DeleteElement - Resolves: CVE-2026-54228 - Fix content injection in journal log collection - Resolves: CVE-2026-54231 - Fix symlink following in event handler scripts - Resolves: CVE-2026-54230 - Fix journal entry spoofing in journal dump services - Related: CVE-2026-54231

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2026-54228",
    "CVE-2026-54229",
    "CVE-2026-54230",
    "CVE-2026-54231"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[2.10.9-26.0.2]\n- Remove RHT patches\n- Drop libreport-rhel and libreport-plugin-rhtsupport requires\n\n[2.10.9-26.0.1]\n- Replaces sosreport to sos report in sosreport-event.conf [Orabug: 38590929]\n- abrt-dump-oops-Fix-vmcore-call-trace-parsing-arm [Orabug: 34184473]\n- Disable autoreporting on Oracle Linux [Orabug: 32890748]\n- Add orabug32082455-Upstream_reference_in_python3-abrt-addon.patch [Orabug: 32082455]\n- Add bug29870394-fix-redhat-reference.patch [Orabug: 29870394]\n\n[2.10.9-26]\n- Fix race condition in ChownProblemDir\n- Resolves: CVE-2026-54229\n- Fix TOCTOU in SetElement/DeleteElement\n- Resolves: CVE-2026-54228\n- Fix content injection in journal log collection\n- Resolves: CVE-2026-54231\n- Fix symlink following in event handler scripts\n- Resolves: CVE-2026-54230\n- Fix journal entry spoofing in journal dump services\n- Related: CVE-2026-54231",
  "id": "ELSA-2026-54272",
  "ovalId": "oval:com.oracle.elsa:def:202654272",
  "source": "oracle_linux",
  "title": "ELSA-2026-54272:  abrt security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-54272.html"
}
View JSON API Download JSON