Oracle Linux Security Advisories Address Critical and Moderate Vulnerabilities

Oracle Linux Security Advisories Address Critical and Moderate Vulnerabilities

3h ago Linuxsecurity 72% similarity 70.5
Share:

Article Content

Browse articles
ThreatCluster

Oracle released security advisories for Oracle Linux 8 and 9 addressing critical and moderate vulnerabilities. The advisory for Oracle Linux 8 (CVE-2026-9064) details a denial-of-service threat affecting the 389 Directory Server, published on May 20, 2026. This vulnerability could lead to service disruptions for organizations using affected versions. The advisory for Oracle Linux 9 addresses multiple memory issues in FreeRDP, including use-after-free and heap buffer overflow vulnerabilities, with CVEs published between February and March 2026. These vulnerabilities could potentially allow attackers to exploit memory management flaws, impacting system stability and security. Users are advised to apply the latest patches to mitigate these risks. Both advisories highlight the importance of timely updates to safeguard against exploitation.

Key Points: • CVE-2026-9064 poses a critical DoS threat to Oracle Linux 8's 389 Directory Server. • Oracle Linux 9's FreeRDP advisory includes multiple CVEs addressing memory vulnerabilities. • Timely patching is essential to protect systems from these identified vulnerabilities.

ThreatCluster AI

Timeline

2026-02-25
CVE-2026-25952 published
A use-after-free vulnerability in FreeRDP was disclosed, affecting multiple Linux distributions.
Linuxsecurity
2026-02-25
CVE-2026-26986 published
A double free vulnerability in FreeRDP was disclosed, impacting system memory management.
Linuxsecurity
2026-02-25
CVE-2026-27951 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-13
CVE-2026-31883 published
Heap buffer overflow vulnerabilities in FreeRDP were disclosed, affecting memory integrity.
Linuxsecurity
2026-03-13
CVE-2026-31884 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-13
CVE-2026-31885 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-13
CVE-2026-29775 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-30
CVE-2026-33983 published
DSP array bounds checks vulnerabilities were disclosed, potentially allowing memory corruption.
Linuxsecurity
2026-03-30
CVE-2026-33984 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-30
CVE-2026-33985 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

Community

Browse all →