Oracle Linux 6499 Published by

Oracle just released a number of security advisories for Oracle Linux 7, 8, and 9. The UEK kernel updates for OL9 and OL8 bring fixes for dozens of high-severity CVEs, ranging from memory leaks in 389-ds to remote code execution risks in the new Firefox ESR. Heads up if you're running OL7 or OL8 though, since the OpenSSH and PostgreSQL 15 releases also carry critical privilege escalation flaws that shouldn't sit on your disks any longer.

ELSA-2026-50319 Important: Unbreakable Enterprise kernel security update
ELSA-2026-50319 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
ELSA-2026-26335 Important: Oracle Linux 8 hplip security update
ELSA-2026-27717 Important: Oracle Linux 8 firefox security update
ELBA-2026-26427-1 Oracle Linux 8 kernel bug fix update
ELBA-2026-50333 Oracle Linux 8 leapp bug fix update
ELSA-2026-26459 Important: Oracle Linux 8 389-ds:1.4 security update
ELSA-2026-22468 Important: Oracle Linux 7 openssh security update
ELSA-2026-26427 Important: Oracle Linux 8 kernel security update
ELSA-2026-27353 Important: Oracle Linux 8 kernel security, bug fix, and enhancement update
ELSA-2026-26534 Important: Oracle Linux 8 dracut security update
ELSA-2026-26181 Important: Oracle Linux 8 postgresql:15 security update
ELSA-2026-26008 Important: Oracle Linux 8 redis:6 security update
ELBA-2026-50332 Oracle Linux 8 leapp-repository bug fix update




ELSA-2026-50319 Important: Unbreakable Enterprise kernel security update


Oracle Linux Security Advisory ELSA-2026-50319

http://linux.oracle.com/errata/ELSA-2026-50319.html

The following updated rpms for have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-uek-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-core-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-devel-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-doc-6.12.0-203.76.7.5.el10uek.noarch.rpm
kernel-uek-modules-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-modules-core-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-modules-deprecated-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-modules-desktop-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-modules-extra-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-modules-extra-netfilter-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-modules-usb-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-modules-wireless-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-tools-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-debug-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-debug-core-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-debug-devel-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-debug-modules-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-debug-modules-core-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-debug-modules-deprecated-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-debug-modules-desktop-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-debug-modules-extra-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-debug-modules-extra-netfilter-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-debug-modules-usb-6.12.0-203.76.7.5.el10uek.x86_64.rpm
kernel-uek-debug-modules-wireless-6.12.0-203.76.7.5.el10uek.x86_64.rpm

aarch64:
kernel-uek-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-core-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-devel-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-doc-6.12.0-203.76.7.5.el10uek.noarch.rpm
kernel-uek-modules-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-modules-core-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-modules-deprecated-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-modules-desktop-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-modules-extra-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-modules-extra-netfilter-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-modules-usb-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-modules-wireless-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-tools-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-debug-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-debug-core-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-debug-devel-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-debug-modules-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-debug-modules-core-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-debug-modules-deprecated-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-debug-modules-desktop-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-debug-modules-extra-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-debug-modules-extra-netfilter-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-debug-modules-usb-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek-debug-modules-wireless-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek64k-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek64k-core-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek64k-devel-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek64k-modules-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek64k-modules-core-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek64k-modules-deprecated-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek64k-modules-desktop-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek64k-modules-extra-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek64k-modules-extra-netfilter-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek64k-modules-usb-6.12.0-203.76.7.5.el10uek.aarch64.rpm
kernel-uek64k-modules-wireless-6.12.0-203.76.7.5.el10uek.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/kernel-uek-6.12.0-203.76.7.5.el10uek.src.rpm

Related CVEs:

CVE-2026-23272
CVE-2026-31419
CVE-2026-31504
CVE-2026-31533
CVE-2026-31657
CVE-2026-31669
CVE-2026-43037
CVE-2026-43074
CVE-2026-43499
CVE-2026-46116

Description of changes:

[6.12.0-203.76.7.5]
- uek-rpm: avoid final module link in early FIPS symvers pass (Sherry Yang) [Orabug: 39563330]
- netfilter: nf_tables: unconditionally bump set->nelems before insertion (Pablo Neira Ayuso) [Orabug: 39562729] {CVE-2026-23272}

[6.12.0-203.76.7.4]
- net: bonding: fix use-after-free in bond_xmit_broadcast() (Xiang Mei) [Orabug: 39556377] {CVE-2026-31419}
- eventpoll: defer struct eventpoll free to RCU grace period (Nicholas Carlini) [Orabug: 39556391] {CVE-2026-43074}
- batman-adv: hold claim backbone gateways by reference (Haoze Xie) [Orabug: 39556388] {CVE-2026-31657}
- net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (Muhammad Alifa Ramdhan) [Orabug: 39556386] {CVE-2026-31533}
- mptcp: fix slab-use-after-free in __inet_lookup_established (Jiayuan Chen) [Orabug: 39556381] {CVE-2026-31669}
- net: fix fanout UAF in packet_release() via NETDEV_UP race (Yochai Eisenrich) [Orabug: 39556380] {CVE-2026-31504}
- rtmutex: Use waiter::task instead of current in remove_waiter() (Keenan Dong) [Orabug: 39556379] {CVE-2026-43499}
- xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (Michal Kosiorek) [Orabug: 39556375] {CVE-2026-46116}
- ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (Eric Dumazet) [Orabug: 39556341] {CVE-2026-43037}



ELSA-2026-50319 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update


Oracle Linux Security Advisory ELSA-2026-50319

http://linux.oracle.com/errata/ELSA-2026-50319.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-uek-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-core-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-debug-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-debug-core-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-debug-devel-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-debug-modules-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-debug-modules-core-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-debug-modules-deprecated-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-debug-modules-desktop-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-debug-modules-extra-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-debug-modules-extra-netfilter-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-debug-modules-usb-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-debug-modules-wireless-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-devel-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-doc-6.12.0-203.76.7.5.el9uek.noarch.rpm
kernel-uek-modules-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-modules-core-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-modules-deprecated-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-modules-desktop-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-modules-extra-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-modules-extra-netfilter-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-modules-usb-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-modules-wireless-6.12.0-203.76.7.5.el9uek.x86_64.rpm
kernel-uek-tools-6.12.0-203.76.7.5.el9uek.x86_64.rpm

aarch64:
kernel-uek-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-core-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-debug-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-debug-core-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-debug-devel-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-debug-modules-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-debug-modules-core-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-debug-modules-deprecated-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-debug-modules-desktop-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-debug-modules-extra-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-debug-modules-extra-netfilter-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-debug-modules-usb-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-debug-modules-wireless-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-devel-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-doc-6.12.0-203.76.7.5.el9uek.noarch.rpm
kernel-uek-modules-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-modules-extra-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-modules-core-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-modules-deprecated-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-modules-desktop-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-modules-extra-netfilter-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-modules-usb-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-modules-wireless-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek-tools-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek64k-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek64k-core-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek64k-devel-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek64k-modules-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek64k-modules-core-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek64k-modules-deprecated-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek64k-modules-desktop-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek64k-modules-extra-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek64k-modules-extra-netfilter-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek64k-modules-usb-6.12.0-203.76.7.5.el9uek.aarch64.rpm
kernel-uek64k-modules-wireless-6.12.0-203.76.7.5.el9uek.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/kernel-uek-6.12.0-203.76.7.5.el9uek.src.rpm

Related CVEs:

CVE-2026-23272
CVE-2026-31419
CVE-2026-31504
CVE-2026-31533
CVE-2026-31657
CVE-2026-31669
CVE-2026-43037
CVE-2026-43074
CVE-2026-43499
CVE-2026-46116

Description of changes:

[6.12.0-203.76.7.5]
- uek-rpm: avoid final module link in early FIPS symvers pass (Sherry Yang) [Orabug: 39563330]
- netfilter: nf_tables: unconditionally bump set->nelems before insertion (Pablo Neira Ayuso) [Orabug: 39562729] {CVE-2026-23272}

[6.12.0-203.76.7.4]
- net: bonding: fix use-after-free in bond_xmit_broadcast() (Xiang Mei) [Orabug: 39556377] {CVE-2026-31419}
- eventpoll: defer struct eventpoll free to RCU grace period (Nicholas Carlini) [Orabug: 39556391] {CVE-2026-43074}
- batman-adv: hold claim backbone gateways by reference (Haoze Xie) [Orabug: 39556388] {CVE-2026-31657}
- net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (Muhammad Alifa Ramdhan) [Orabug: 39556386] {CVE-2026-31533}
- mptcp: fix slab-use-after-free in __inet_lookup_established (Jiayuan Chen) [Orabug: 39556381] {CVE-2026-31669}
- net: fix fanout UAF in packet_release() via NETDEV_UP race (Yochai Eisenrich) [Orabug: 39556380] {CVE-2026-31504}
- rtmutex: Use waiter::task instead of current in remove_waiter() (Keenan Dong) [Orabug: 39556379] {CVE-2026-43499}
- xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (Michal Kosiorek) [Orabug: 39556375] {CVE-2026-46116}
- ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (Eric Dumazet) [Orabug: 39556341] {CVE-2026-43037}



ELSA-2026-26335 Important: Oracle Linux 8 hplip security update


Oracle Linux Security Advisory ELSA-2026-26335

http://linux.oracle.com/errata/ELSA-2026-26335.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
hplip-3.18.4-13.el8_10.x86_64.rpm
hplip-common-3.18.4-13.el8_10.i686.rpm
hplip-common-3.18.4-13.el8_10.x86_64.rpm
hplip-gui-3.18.4-13.el8_10.x86_64.rpm
hplip-libs-3.18.4-13.el8_10.i686.rpm
hplip-libs-3.18.4-13.el8_10.x86_64.rpm
libsane-hpaio-3.18.4-13.el8_10.i686.rpm
libsane-hpaio-3.18.4-13.el8_10.x86_64.rpm

aarch64:
hplip-3.18.4-13.el8_10.aarch64.rpm
hplip-common-3.18.4-13.el8_10.aarch64.rpm
hplip-gui-3.18.4-13.el8_10.aarch64.rpm
hplip-libs-3.18.4-13.el8_10.aarch64.rpm
libsane-hpaio-3.18.4-13.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/hplip-3.18.4-13.el8_10.src.rpm

Related CVEs:

CVE-2026-8631
CVE-2026-8632

Description of changes:

[3.18.4-13]
- Fix more leaks in hpcups

[3.18.4-12]
- OSH fixes after CVE-2026-8631

[3.18.4-11]
- CVE-2026-8631 hplip: Arbitrary code execution and privilege escalation
via integer overflow in hpcups

[3.18.4-10]
- CVE-2026-8632 hplip: Privilege escalation and arbitrary code execution
via OS command injection in Is_Process_Running()



ELSA-2026-27717 Important: Oracle Linux 8 firefox security update


Oracle Linux Security Advisory ELSA-2026-27717

http://linux.oracle.com/errata/ELSA-2026-27717.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
firefox-140.12.0-1.0.1.el8_10.x86_64.rpm

aarch64:
firefox-140.12.0-1.0.1.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/firefox-140.12.0-1.0.1.el8_10.src.rpm

Related CVEs:

CVE-2026-12289
CVE-2026-12290
CVE-2026-12291
CVE-2026-12292
CVE-2026-12294
CVE-2026-12295
CVE-2026-12296
CVE-2026-12297
CVE-2026-12298
CVE-2026-12299
CVE-2026-12302
CVE-2026-12304
CVE-2026-12305
CVE-2026-12306
CVE-2026-12307
CVE-2026-12308
CVE-2026-12309
CVE-2026-12310
CVE-2026-12311
CVE-2026-12312
CVE-2026-12313
CVE-2026-12314
CVE-2026-12315
CVE-2026-12324
CVE-2026-12325
CVE-2026-12327
CVE-2026-12328
CVE-2026-12329
CVE-2026-12330

Description of changes:

[140.12.0-1.0.1]
- Fix firefox-oracle-default-prefs.js for new nss [Orabug: 37079789]
- diable wasi_sdk to prevent build failure with newer llvm

[140.12.0]
- Add debranding patches (Mustafa Gezen)
- Add OpenELA default preferences (Louis Abel)

[140.12.0-1]
- Update to 140.12.0 ESR



ELBA-2026-26427-1 Oracle Linux 8 kernel bug fix update


Oracle Linux Bug Fix Advisory ELBA-2026-26427-1

http://linux.oracle.com/errata/ELBA-2026-26427-1.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
bpftool-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm
kernel-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm
kernel-abi-stablelists-4.18.0-553.134.1.0.1.el8_10.noarch.rpm
kernel-core-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm
kernel-cross-headers-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm
kernel-debug-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm
kernel-debug-core-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm
kernel-debug-devel-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm
kernel-debug-modules-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm
kernel-debug-modules-extra-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm
kernel-devel-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm
kernel-doc-4.18.0-553.134.1.0.1.el8_10.noarch.rpm
kernel-headers-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm
kernel-modules-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm
kernel-modules-extra-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm
kernel-tools-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm
kernel-tools-libs-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm
kernel-tools-libs-devel-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm
perf-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm
python3-perf-4.18.0-553.134.1.0.1.el8_10.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/kernel-4.18.0-553.134.1.0.1.el8_10.src.rpm

Description of changes:

[4.18.0-553.134.1.0.1]
- scsi: core: Restrict legal sdev_state transitions via sysfs (Uday Shankar) [Orabug: 37778230]

[4.18.0-553.134.1]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64