Linuxsecurity Oracle Linux Vulnerabilities Allow Admin Control via Chained Flaws
Article Content
- •Two critical vulnerabilities in Oracle Linux allow admin control via FreeRDP and GStreamer.
- •CVE-2026-55193 and CVE-2026-85150 require immediate patching to mitigate risks.
- •Affected systems include multiple versions of Oracle Linux and associated packages.
Oracle Linux has released important fixes for two vulnerabilities, CVE-2026-55193 and CVE-2026-85150, affecting FreeRDP and GStreamer respectively. CVE-2026-55193, published on 2026-08-19, allows attackers to gain admin control through chained flaws related to RPC gateway checks. CVE-2026-85150, published on 2026-09-03, involves a crash in RTSP authentication credential parsing, also enabling potential admin access. Both vulnerabilities affect multiple versions of Oracle Linux and associated packages. Users are urged to check their versions and apply the necessary updates immediately. The vulnerabilities have been classified as important and moderate, respectively, indicating a significant risk to affected systems. The patches are available for various architectures, including x86_64 and aarch64.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-55193 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical CVE Fixes for FreeRDP in Fedora and Mageia Recent advisories detail critical security updates for FreeRDP clients in Fedora and Mageia. Fedora 43 and 44 have patched multiple CVEs, including CVE-2026-22852, CVE-2026-22854, and CVE-2026-22855, with a total of 34 vulnerabilities addressed. Mageia's update focuses on CVE-2026-22851, which is a denial-of-service…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…