Linuxsecurity Oracle Linux 8 Kernel Security Advisory ELSA-2026 Released
Article Content
- •Oracle Linux 8 kernel vulnerabilities addressed in advisory ELSA-2026.
- •Critical CVEs include CVE-2026-46125, CVE-2026-46152, and CVE-2026-46056.
- •Immediate patching is recommended to prevent potential exploitation.
Oracle has issued an important security advisory for Oracle Linux 8, addressing multiple vulnerabilities in the kernel. The advisory includes updates for kernel versions 4.18.0-553.136.1 and 4.18.0-553.134.1. Key vulnerabilities include CVE-2026-46125, CVE-2026-46152, and CVE-2026-46056, which could lead to potential denial of service and unauthorized access. Affected systems include Oracle Linux installations that utilize the specified kernel versions. The advisory also notes conflicts with shim-ia32 and shim-x64, and introduces new driver signing certificates. Administrators are advised to apply the updates promptly to mitigate risks. The updates were published on June 23, 2026, and are critical for maintaining system security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (50)
Following this threat?
Track CVE-2026-31419 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…