Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-67585

Опубликовано: 16 сент. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-67585: firewalld security update (MODERATE)

[1.3.4-20.0.1]

  • Red Hat Satellite and Red Hat high availaibility reference found in cockpit UI [Orabug: 30257573]
  • discard empty RH-Satellite-6.xml [Orabug: 30328734]
  • Remove capsule file as well, since it references removed config [Orabug: 33513329]

[1.3.4-20]

  • fix(policy): use PK_ACTION_CONFIG for set{ZoneSettings2,PolicySettings} (CVE-2026-4948)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

firewall-applet

1.3.4-20.0.1.el9_8

firewall-config

1.3.4-20.0.1.el9_8

firewalld

1.3.4-20.0.1.el9_8

firewalld-filesystem

1.3.4-20.0.1.el9_8

python3-firewall

1.3.4-20.0.1.el9_8

Oracle Linux x86_64

firewall-applet

1.3.4-20.0.1.el9_8

firewall-config

1.3.4-20.0.1.el9_8

firewalld

1.3.4-20.0.1.el9_8

firewalld-filesystem

1.3.4-20.0.1.el9_8

python3-firewall

1.3.4-20.0.1.el9_8

Связанные CVE

Связанные уязвимости

CVSS3: 5.5
ubuntu
6 месяцев назад

A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations.

CVSS3: 5.5
redhat
6 месяцев назад

A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations.

CVSS3: 5.5
nvd
6 месяцев назад

A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations.

CVSS3: 5.5
msrc
5 месяцев назад

Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization

CVSS3: 5.5
debian
6 месяцев назад

A flaw was found in firewalld. A local unprivileged user can exploit t ...