Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-18868

Опубликовано: 12 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-18868: linux-sgx security update (IMPORTANT)

[2.26-7]

  • Fix pccs npm security flaws

[2.26-6]

  • Port to pycryptography and pyasn1 and make keyring optional

[2.26-5]

  • Sync specfile changes from Fedora

[2.26-4]

  • Drop sgx-mpa dep from sgx-pccs

[2.26-3]

  • Add scriptlets for PCCS

[2.26-2]

  • Enable pccsadmin everywhere

[2.26-1]

  • Update to SGX 2.26 / DCAP 1.23, adding PCCS service

[2.25-7]

  • Trigger udev to set perms on /dev/sgx_provision

[2.25-6]

  • Temporarily disable automatic tier1 gating

[2.25-5]

  • Adapt qgs.service for SELinux policy and sock perms

Обновленные пакеты

Oracle Linux 9

Oracle Linux x86_64

sgx-common

2.26-7.el9

sgx-libs

2.26-7.el9

sgx-mpa

2.26-7.el9

sgx-pccs

2.26-7.el9

sgx-pccs-admin

2.26-7.el9

sgx-pckid-tool

2.26-7.el9

tdx-qgs

2.26-7.el9

Связанные уязвимости

rocky
2 месяца назад

Important: linux-sgx security update

rocky
2 месяца назад

Important: linux-sgx security update

CVSS3: 5.3
ubuntu
6 месяцев назад

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23

CVSS3: 8.2
redhat
6 месяцев назад

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23

CVSS3: 5.3
nvd
6 месяцев назад

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23