Oracle Linux 6425 Published by

Oracle Linux has several updates available, including bug fixes and enhancements for various packages such as httpd, libvirt, openssh, podman, and python. These updates affect multiple versions of Oracle Linux, including 7, 8, 9, and 10. Some of these updates are marked as security updates, which are necessary to fix vulnerabilities and ensure the system's security.

ELBA-2025-23296 Oracle Linux 10 httpd bug fix and enhancement update
ELBA-2025-23300 Oracle Linux 10 libwacom bug fix and enhancement update
ELBA-2025-23339 Oracle Linux 9 lvm2 bug fix and enhancement update
ELSA-2025-23479 Moderate: Oracle Linux 10 openssh security update
ELBA-2025-23301 Oracle Linux 10 rust-coreos-installer bug fix and enhancement update
ELBA-2025-23341 Oracle Linux 9 dracut bug fix and enhancement update
ELBA-2025-23286 Oracle Linux 10 php bug fix and enhancement update
ELBA-2025-23299 Oracle Linux 10 libvirt bug fix and enhancement update
ELBA-2025-23289 Oracle Linux 10 ignition bug fix and enhancement update
ELBA-2025-23293 Oracle Linux 10 nodejs24 bug fix and enhancement update
ELSA-2025-23295 Moderate: Oracle Linux 10 podman security update
ELSA-2025-23342 Moderate: Oracle Linux 9 python3.9 security update
ELBA-2025-23307 Oracle Linux 10 librepo bug fix and enhancement update
ELBA-2025-23304 Oracle Linux 10 NetworkManager bug fix and enhancement update
ELBA-2025-23291 Oracle Linux 10 fuse-overlayfs bug fix and enhancement update
ELBA-2025-23287 Oracle Linux 10 maven bug fix and enhancement update
ELBA-2025-23284 Oracle Linux 10 linuxptp bug fix and enhancement update
ELBA-2025-23283 Oracle Linux 10 unbound bug fix and enhancement update
ELBA-2025-28057 Oracle Linux 10 oracle-common-release bug fix update
ELSA-2025-23700 Important: Oracle Linux 9 webkit2gtk3 security update
ELSA-2025-23480 Moderate: Oracle Linux 9 openssh security update
ELSA-2025-23343 Moderate: Oracle Linux 9 binutils security update
ELSA-2025-23309 Moderate: Oracle Linux 9 php:8.3 security update
ELSA-2025-23326 Moderate: Oracle Linux 9 skopeo security update
ELSA-2025-23325 Moderate: Oracle Linux 9 podman security update
ELSA-2025-23323 Moderate: Oracle Linux 9 python3.12 security update
ELBA-2025-23334 Oracle Linux 9 runc bug fix and enhancement update
ELSA-2025-23241 Important: Oracle Linux 9 kernel security update
ELBA-2025-23327 Oracle Linux 9 boost bug fix and enhancement update
ELBA-2025-23333 Oracle Linux 9 libwacom bug fix and enhancement update
ELBA-2025-23330 Oracle Linux 9 httpd bug fix and enhancement update
ELBA-2025-23331 Oracle Linux 9 python-awscrt bug fix and enhancement update
ELBA-2025-23329 Oracle Linux 9 ignition bug fix and enhancement update
ELBA-2025-23328 Oracle Linux 9 qemu-kvm bug fix and enhancement update
ELBA-2025-23324 Oracle Linux 9 freeradius bug fix and enhancement update
ELBA-2025-23322 Oracle Linux 9 libvirt bug fix and enhancement update
ELBA-2025-23320 Oracle Linux 9 virt-v2v bug fix and enhancement update
ELBA-2025-23319 Oracle Linux 9 java-21-openjdk bug fix update
ELBA-2025-23314 Oracle Linux 9 passt bug fix and enhancement update
ELBA-2025-23312 Oracle Linux 9 java-1.8.0-openjdk bug fix update
ELBA-2025-23311 Oracle Linux 9 nmstate bug fix and enhancement update
ELBA-2025-23310 Oracle Linux 9 php bug fix and enhancement update
ELBA-2025-23464 Oracle Linux 8 tzdata bug fix and enhancement update
ELBA-2025-23191 Oracle Linux 9 scap-security-guide bug fix and enhancement update
ELSA-2025-23481 Moderate: Oracle Linux 8 openssh security update
ELBA-2025-23368 Oracle Linux 8 gnome-control-center and gnome-settings-daemon bug fix and enhancement update
ELBA-2025-23191 Oracle Linux 8 scap-security-guide bug fix and enhancement update
ELSA-2025-22982 Important: Oracle Linux 7 python-kdcproxy security update
ELSA-2025-22866 Important: Oracle Linux 7 gimp security update
ELBA-2025-23466 Oracle Linux 7 tzdata bug fix and enhancement update




ELBA-2025-23296 Oracle Linux 10 httpd bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-23296

http://linux.oracle.com/errata/ELBA-2025-23296.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
httpd-2.4.63-4.0.1.el10_1.2.x86_64.rpm
httpd-core-2.4.63-4.0.1.el10_1.2.x86_64.rpm
httpd-devel-2.4.63-4.0.1.el10_1.2.x86_64.rpm
httpd-filesystem-2.4.63-4.0.1.el10_1.2.noarch.rpm
httpd-manual-2.4.63-4.0.1.el10_1.2.noarch.rpm
httpd-tools-2.4.63-4.0.1.el10_1.2.x86_64.rpm
mod_ldap-2.4.63-4.0.1.el10_1.2.x86_64.rpm
mod_lua-2.4.63-4.0.1.el10_1.2.x86_64.rpm
mod_proxy_html-2.4.63-4.0.1.el10_1.2.x86_64.rpm
mod_session-2.4.63-4.0.1.el10_1.2.x86_64.rpm
mod_ssl-2.4.63-4.0.1.el10_1.2.x86_64.rpm

aarch64:
httpd-2.4.63-4.0.1.el10_1.2.aarch64.rpm
httpd-core-2.4.63-4.0.1.el10_1.2.aarch64.rpm
httpd-devel-2.4.63-4.0.1.el10_1.2.aarch64.rpm
httpd-filesystem-2.4.63-4.0.1.el10_1.2.noarch.rpm
httpd-manual-2.4.63-4.0.1.el10_1.2.noarch.rpm
httpd-tools-2.4.63-4.0.1.el10_1.2.aarch64.rpm
mod_ldap-2.4.63-4.0.1.el10_1.2.aarch64.rpm
mod_lua-2.4.63-4.0.1.el10_1.2.aarch64.rpm
mod_proxy_html-2.4.63-4.0.1.el10_1.2.aarch64.rpm
mod_session-2.4.63-4.0.1.el10_1.2.aarch64.rpm
mod_ssl-2.4.63-4.0.1.el10_1.2.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/httpd-2.4.63-4.0.1.el10_1.2.src.rpm

Description of changes:

[2.4.63-4.0.1]
- Replace index.html with Oracle's index page oracle_index.html.

[2.4.63-4.2]
- Resolves: RHEL-125894 - mod_ssl: allow more fine grained SSL SNI vhost check
to avoid unnecessary 421 errors after CVE-2025-23048 fix



ELBA-2025-23300 Oracle Linux 10 libwacom bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-23300

http://linux.oracle.com/errata/ELBA-2025-23300.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
libwacom-2.14.0-4.el10_1.x86_64.rpm
libwacom-data-2.14.0-4.el10_1.noarch.rpm
libwacom-devel-2.14.0-4.el10_1.x86_64.rpm

aarch64:
libwacom-2.14.0-4.el10_1.aarch64.rpm
libwacom-data-2.14.0-4.el10_1.noarch.rpm
libwacom-devel-2.14.0-4.el10_1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/libwacom-2.14.0-4.el10_1.src.rpm

Description of changes:

[2.14.0-4]
- Rearrange the dial leaders for the Intuos Pro 3rd Gen (RHEL-122812)



ELBA-2025-23339 Oracle Linux 9 lvm2 bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-23339

http://linux.oracle.com/errata/ELBA-2025-23339.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
device-mapper-1.02.206-2.el9_7.1.x86_64.rpm
device-mapper-devel-1.02.206-2.el9_7.1.i686.rpm
device-mapper-devel-1.02.206-2.el9_7.1.x86_64.rpm
device-mapper-event-1.02.206-2.el9_7.1.x86_64.rpm
device-mapper-event-devel-1.02.206-2.el9_7.1.i686.rpm
device-mapper-event-devel-1.02.206-2.el9_7.1.x86_64.rpm
device-mapper-event-libs-1.02.206-2.el9_7.1.i686.rpm
device-mapper-event-libs-1.02.206-2.el9_7.1.x86_64.rpm
device-mapper-libs-1.02.206-2.el9_7.1.i686.rpm
device-mapper-libs-1.02.206-2.el9_7.1.x86_64.rpm
lvm2-2.03.32-2.el9_7.1.x86_64.rpm
lvm2-dbusd-2.03.32-2.el9_7.1.noarch.rpm
lvm2-devel-2.03.32-2.el9_7.1.i686.rpm
lvm2-devel-2.03.32-2.el9_7.1.x86_64.rpm
lvm2-libs-2.03.32-2.el9_7.1.i686.rpm
lvm2-libs-2.03.32-2.el9_7.1.x86_64.rpm
lvm2-lockd-2.03.32-2.el9_7.1.x86_64.rpm

aarch64:
device-mapper-1.02.206-2.el9_7.1.aarch64.rpm
device-mapper-devel-1.02.206-2.el9_7.1.aarch64.rpm
device-mapper-event-1.02.206-2.el9_7.1.aarch64.rpm
device-mapper-event-devel-1.02.206-2.el9_7.1.aarch64.rpm
device-mapper-event-libs-1.02.206-2.el9_7.1.aarch64.rpm
device-mapper-libs-1.02.206-2.el9_7.1.aarch64.rpm
lvm2-2.03.32-2.el9_7.1.aarch64.rpm
lvm2-dbusd-2.03.32-2.el9_7.1.noarch.rpm
lvm2-devel-2.03.32-2.el9_7.1.aarch64.rpm
lvm2-libs-2.03.32-2.el9_7.1.aarch64.rpm
lvm2-lockd-2.03.32-2.el9_7.1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/lvm2-2.03.32-2.el9_7.1.src.rpm

Description of changes:
[2.03.32-2.el9_7.1]
- Add message when activating RAID volumes with snapshots.



ELSA-2025-23479 Moderate: Oracle Linux 10 openssh security update


Oracle Linux Security Advisory ELSA-2025-23479

http://linux.oracle.com/errata/ELSA-2025-23479.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
openssh-9.9p1-12.0.1.el10_1.x86_64.rpm
openssh-askpass-9.9p1-12.0.1.el10_1.x86_64.rpm
openssh-clients-9.9p1-12.0.1.el10_1.x86_64.rpm
openssh-keycat-9.9p1-12.0.1.el10_1.x86_64.rpm
openssh-keysign-9.9p1-12.0.1.el10_1.x86_64.rpm
openssh-server-9.9p1-12.0.1.el10_1.x86_64.rpm

aarch64:
openssh-9.9p1-12.0.1.el10_1.aarch64.rpm
openssh-askpass-9.9p1-12.0.1.el10_1.aarch64.rpm
openssh-clients-9.9p1-12.0.1.el10_1.aarch64.rpm
openssh-keycat-9.9p1-12.0.1.el10_1.aarch64.rpm
openssh-keysign-9.9p1-12.0.1.el10_1.aarch64.rpm
openssh-server-9.9p1-12.0.1.el10_1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/openssh-9.9p1-12.0.1.el10_1.src.rpm

Related CVEs:

CVE-2025-61984
CVE-2025-61985

Description of changes:

[9.9p1-12.0.1]
- Upstream references found with /usr/bin/ssh [Orabug: 37824421]

[9.9p1-12]
- CVE-2025-61984: Reject usernames with control characters
Resolves: RHEL-128397
- CVE-2025-61985: Reject URL-strings with NULL characters
Resolves: RHEL-128387



ELBA-2025-23301 Oracle Linux 10 rust-coreos-installer bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-23301

http://linux.oracle.com/errata/ELBA-2025-23301.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
coreos-installer-0.24.0-5.0.1.el10_1.x86_64.rpm
coreos-installer-bootinfra-0.24.0-5.0.1.el10_1.x86_64.rpm
coreos-installer-dracut-0.24.0-5.0.1.el10_1.x86_64.rpm

aarch64:
coreos-installer-0.24.0-5.0.1.el10_1.aarch64.rpm
coreos-installer-bootinfra-0.24.0-5.0.1.el10_1.aarch64.rpm
coreos-installer-dracut-0.24.0-5.0.1.el10_1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/rust-coreos-installer-0.24.0-5.0.1.el10_1.src.rpm

Description of changes:

[0.24.0-5.0.1]
- Prevent error generating initrd during kernel package POSTTRANS script
[Orabug: 38073419]

[0.24.0-5]
- rootmap: Inject mpath.wwid=$WWID when on multipath
Backport https://github.com/coreos/coreos-installer/pull/1676/commits/a40af0a3ec13c4fd49b34317e80f6c0bc845b46a
Resolves RHEL-127858

[0.24.0-4]
- Check if firstboot args are defined and add them manually
Backport https://github.com/coreos/coreos-installer/pull/1699

[0.24.0-3]
- Use the full path for the 'root=' kernel arg when rootfs on mpath
Backport https://github.com/coreos/coreos-installer/pull/1677

[0.24.0-2]
- Restore single-decimal precision to stream output
Backport https://github.com/coreos/coreos-installer/pull/1654



ELBA-2025-23341 Oracle Linux 9 dracut bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-23341

http://linux.oracle.com/errata/ELBA-2025-23341.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
dracut-057-104.git20250919.0.1.el9_7.x86_64.rpm
dracut-config-generic-057-104.git20250919.0.1.el9_7.x86_64.rpm
dracut-config-rescue-057-104.git20250919.0.1.el9_7.x86_64.rpm
dracut-network-057-104.git20250919.0.1.el9_7.x86_64.rpm
dracut-squash-057-104.git20250919.0.1.el9_7.x86_64.rpm
dracut-tools-057-104.git20250919.0.1.el9_7.x86_64.rpm

aarch64:
dracut-057-104.git20250919.0.1.el9_7.aarch64.rpm
dracut-config-generic-057-104.git20250919.0.1.el9_7.aarch64.rpm
dracut-config-rescue-057-104.git20250919.0.1.el9_7.aarch64.rpm
dracut-network-057-104.git20250919.0.1.el9_7.aarch64.rpm
dracut-squash-057-104.git20250919.0.1.el9_7.aarch64.rpm
dracut-tools-057-104.git20250919.0.1.el9_7.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/dracut-057-104.git20250919.0.1.el9_7.src.rpm

Description of changes:

[057-104.git20250919.0.1]
- Ship Oracle IMA certificate [Orabug: 35992862]
- Ship 98-integrity.conf, populating initramfs with Oracle IMA certificate [Orabug: 35992862]
- Include sys-fs-fuse-connections.mount if needed [Orabug: 35267570]
- network-legacy: Revert some shellcheck that breaks parse_option_121 in dhclient [Orabug: 33778173]
- Change installation dir in network legacy module-setup so that file is never missing [Orabug: 33516170]
- Fix paths in squash module, so that correct modprobe is installed [Orabug: 33514517]
- Install missing 68-del-part-node.rules [Orabug: 32827579]
- Fix permission denied error while upgrading from OL8u2 to OL8u3 [Orabug 32160196]
- dracut-shutdown.service should run before shutdown.target is invoked [Orabug: 29629738]
- Update list of necessary files after squashfs execution [Orabug: 29864620]
- Supress iscsidm error output during non-debug PV boot [Orabug: 29846195]
- Stop block device service in case system is dropped to emergency shell [Orabug: 29851988]
- Enable booting from block device if netroot=iscsi has failed [Orabug: 29478156]
- Calculate relative path for kernel and initrd in 51-dracut-rescue.instal [Orabug: 29503293]
- 40network scripts ifup and netlib updates for iSCSI [Orabug: 28502725]
- Increase timeout when waiting for carrier detection on a network interface [Orabug: 24657828] (kevin.x.lyons@oracle.com)
- add hyperv-keyboard for Hyper-V Gen2 VM [Orabug: 19191303] (Vaughan Cao)

[057-104.git20250919]
- fix(multipath): disable user_friendly_names with mpathconf



ELBA-2025-23286 Oracle Linux 10 php bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-23286

http://linux.oracle.com/errata/ELBA-2025-23286.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
php-8.3.26-1.el10_1.x86_64.rpm
php-bcmath-8.3.26-1.el10_1.x86_64.rpm
php-cli-8.3.26-1.el10_1.x86_64.rpm
php-common-8.3.26-1.el10_1.x86_64.rpm
php-dba-8.3.26-1.el10_1.x86_64.rpm
php-dbg-8.3.26-1.el10_1.x86_64.rpm
php-devel-8.3.26-1.el10_1.x86_64.rpm
php-embedded-8.3.26-1.el10_1.x86_64.rpm
php-enchant-8.3.26-1.el10_1.x86_64.rpm
php-ffi-8.3.26-1.el10_1.x86_64.rpm
php-fpm-8.3.26-1.el10_1.x86_64.rpm
php-gd-8.3.26-1.el10_1.x86_64.rpm
php-gmp-8.3.26-1.el10_1.x86_64.rpm
php-intl-8.3.26-1.el10_1.x86_64.rpm
php-ldap-8.3.26-1.el10_1.x86_64.rpm
php-mbstring-8.3.26-1.el10_1.x86_64.rpm
php-mysqlnd-8.3.26-1.el10_1.x86_64.rpm
php-odbc-8.3.26-1.el10_1.x86_64.rpm
php-opcache-8.3.26-1.el10_1.x86_64.rpm
php-pdo-8.3.26-1.el10_1.x86_64.rpm
php-pgsql-8.3.26-1.el10_1.x86_64.rpm
php-process-8.3.26-1.el10_1.x86_64.rpm
php-snmp-8.3.26-1.el10_1.x86_64.rpm
php-soap-8.3.26-1.el10_1.x86_64.rpm
php-xml-8.3.26-1.el10_1.x86_64.rpm

aarch64:
php-8.3.26-1.el10_1.aarch64.rpm
php-bcmath-8.3.26-1.el10_1.aarch64.rpm
php-cli-8.3.26-1.el10_1.aarch64.rpm
php-common-8.3.26-1.el10_1.aarch64.rpm
php-dba-8.3.26-1.el10_1.aarch64.rpm
php-dbg-8.3.26-1.el10_1.aarch64.rpm
php-devel-8.3.26-1.el10_1.aarch64.rpm
php-embedded-8.3.26-1.el10_1.aarch64.rpm
php-enchant-8.3.26-1.el10_1.aarch64.rpm
php-ffi-8.3.26-1.el10_1.aarch64.rpm
php-fpm-8.3.26-1.el10_1.aarch64.rpm
php-gd-8.3.26-1.el10_1.aarch64.rpm
php-gmp-8.3.26-1.el10_1.aarch64.rpm
php-intl-8.3.26-1.el10_1.aarch64.rpm
php-ldap-8.3.26-1.el10_1.aarch64.rpm
php-mbstring-8.3.26-1.el10_1.aarch64.rpm
php-mysqlnd-8.3.26-1.el10_1.aarch64.rpm
php-odbc-8.3.26-1.el10_1.aarch64.rpm
php-opcache-8.3.26-1.el10_1.aarch64.rpm
php-pdo-8.3.26-1.el10_1.aarch64.rpm
php-pgsql-8.3.26-1.el10_1.aarch64.rpm
php-process-8.3.26-1.el10_1.aarch64.rpm
php-snmp-8.3.26-1.el10_1.aarch64.rpm
php-soap-8.3.26-1.el10_1.aarch64.rpm
php-xml-8.3.26-1.el10_1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/php-8.3.26-1.el10_1.src.rpm

Description of changes:

[8.3.26-1]
- rebase to 8.3.26



ELBA-2025-23299 Oracle Linux 10 libvirt bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-23299

http://linux.oracle.com/errata/ELBA-2025-23299.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
libvirt-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-client-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-client-qemu-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-common-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-config-network-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-config-nwfilter-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-driver-interface-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-driver-network-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-driver-nodedev-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-driver-nwfilter-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-driver-qemu-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-driver-secret-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-driver-storage-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-driver-storage-core-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-driver-storage-disk-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-driver-storage-iscsi-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-driver-storage-logical-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-driver-storage-mpath-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-driver-storage-rbd-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-driver-storage-scsi-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-kvm-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-lock-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-log-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-plugin-lockd-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-plugin-sanlock-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-daemon-proxy-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-devel-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-docs-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-libs-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-nss-11.5.0-4.2.0.1.el10_1.x86_64.rpm
libvirt-ssh-proxy-11.5.0-4.2.0.1.el10_1.x86_64.rpm

aarch64:
libvirt-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-client-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-client-qemu-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-common-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-config-network-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-config-nwfilter-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-driver-interface-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-driver-network-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-driver-nodedev-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-driver-nwfilter-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-driver-qemu-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-driver-secret-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-driver-storage-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-driver-storage-core-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-driver-storage-disk-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-driver-storage-iscsi-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-driver-storage-logical-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-driver-storage-mpath-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-driver-storage-rbd-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-driver-storage-scsi-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-kvm-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-lock-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-log-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-plugin-lockd-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-plugin-sanlock-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-daemon-proxy-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-devel-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-docs-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-libs-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-nss-11.5.0-4.2.0.1.el10_1.aarch64.rpm
libvirt-ssh-proxy-11.5.0-4.2.0.1.el10_1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/libvirt-11.5.0-4.2.0.1.el10_1.src.rpm

Description of changes:

[11.5.0-4.2.0.1]
- Set SOURCE_DATE_EPOCH from changelog [Orabug: 32019554]

[11.5.0-4.2.el10_1]
- cpu_conf: Make virCPUDefFilterFeatures return void (RHEL-126094)
- qemu_domain: Simplify qemuDomainFixupCPUs (RHEL-126094)
- qemu_domain: Fix qemuDomainFixupCPUs (RHEL-126094)
- qemu_process: Always fix CPUs on reconnect (RHEL-126094)
- qemu_monitor: Filter CPU features reported by QEMU (RHEL-126094)
- qemu: Ignore "ht" CPU feature (RHEL-126094)



ELBA-2025-23289 Oracle Linux 10 ignition bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-23289

http://linux.oracle.com/errata/ELBA-2025-23289.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
ignition-2.22.0-3.0.1.el10_1.x86_64.rpm
ignition-edge-2.22.0-3.0.1.el10_1.x86_64.rpm
ignition-grub-2.22.0-3.0.1.el10_1.x86_64.rpm
ignition-validate-2.22.0-3.0.1.el10_1.x86_64.rpm

aarch64:
ignition-2.22.0-3.0.1.el10_1.aarch64.rpm
ignition-edge-2.22.0-3.0.1.el10_1.aarch64.rpm
ignition-grub-2.22.0-3.0.1.el10_1.aarch64.rpm
ignition-validate-2.22.0-3.0.1.el10_1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/ignition-2.22.0-3.0.1.el10_1.src.rpm

Description of changes:

[2.22.0-3.0.1]
- Remove sgdisk requirement and create symbolic link to sgdisk [Orabug: 37470782]

[2.22.0-3]
- spec: backport fips fix and update build with
goexperiment=strictfipsruntime

[2.22.0-2]
- RHEL-125909: Backport patch to fix device mapper partitioning



ELBA-2025-23293 Oracle Linux 10 nodejs24 bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-23293

http://linux.oracle.com/errata/ELBA-2025-23293.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
nodejs24-24.11.1-1.0.1.el10_1.x86_64.rpm
nodejs24-devel-24.11.1-1.0.1.el10_1.x86_64.rpm
nodejs24-docs-24.11.1-1.0.1.el10_1.noarch.rpm
nodejs24-full-i18n-24.11.1-1.0.1.el10_1.x86_64.rpm
nodejs24-libs-24.11.1-1.0.1.el10_1.x86_64.rpm
nodejs24-npm-11.6.2-1.24.11.1.1.0.1.el10_1.noarch.rpm

aarch64:
nodejs24-24.11.1-1.0.1.el10_1.aarch64.rpm
nodejs24-devel-24.11.1-1.0.1.el10_1.aarch64.rpm
nodejs24-docs-24.11.1-1.0.1.el10_1.noarch.rpm
nodejs24-full-i18n-24.11.1-1.0.1.el10_1.aarch64.rpm
nodejs24-libs-24.11.1-1.0.1.el10_1.aarch64.rpm
nodejs24-npm-11.6.2-1.24.11.1.1.0.1.el10_1.noarch.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/nodejs24-24.11.1-1.0.1.el10_1.src.rpm

Description of changes:

[1:24.11.1-1.0.1]
- Update upstream references

[1:24.11.1-1]
- Update to version 24.11.1



ELSA-2025-23295 Moderate: Oracle Linux 10 podman security update


Oracle Linux Security Advisory ELSA-2025-23295

http://linux.oracle.com/errata/ELSA-2025-23295.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
podman-5.6.0-8.0.1.el10_1.x86_64.rpm
podman-docker-5.6.0-8.0.1.el10_1.noarch.rpm
podman-remote-5.6.0-8.0.1.el10_1.x86_64.rpm
podman-tests-5.6.0-8.0.1.el10_1.x86_64.rpm

aarch64:
podman-5.6.0-8.0.1.el10_1.aarch64.rpm
podman-docker-5.6.0-8.0.1.el10_1.noarch.rpm
podman-remote-5.6.0-8.0.1.el10_1.aarch64.rpm
podman-tests-5.6.0-8.0.1.el10_1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/podman-5.6.0-8.0.1.el10_1.src.rpm

Related CVEs:

CVE-2025-58183

Description of changes:

[5.6.0-8.0.1]
- Add devices on container startup, not on creation
- overlay: Put should ignore ENINVAL for Unmount [Orabug: 36234694]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404]

[7:5.6.0-8]
- update to the latest content of https://github.com/containers/podman/tree/v5.6-rhel
( https://github.com/containers/podman/commit/3bf5313)
- fixes "run 1.2.x upgrade throws error while using nocopy volume mount filesystem option - [RHEL 10.1]"
- Resolves: RHEL-132532

[7:5.6.0-7]
- rebuild for CVE-2025-58183
- Resolves: RHEL-125640



ELSA-2025-23342 Moderate: Oracle Linux 9 python3.9 security update


Oracle Linux Security Advisory ELSA-2025-23342

http://linux.oracle.com/errata/ELSA-2025-23342.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
python-unversioned-command-3.9.25-2.0.1.el9_7.noarch.rpm
python3-3.9.25-2.0.1.el9_7.i686.rpm
python3-3.9.25-2.0.1.el9_7.x86_64.rpm
python3-debug-3.9.25-2.0.1.el9_7.i686.rpm
python3-debug-3.9.25-2.0.1.el9_7.x86_64.rpm
python3-devel-3.9.25-2.0.1.el9_7.i686.rpm
python3-devel-3.9.25-2.0.1.el9_7.x86_64.rpm
python3-idle-3.9.25-2.0.1.el9_7.i686.rpm
python3-idle-3.9.25-2.0.1.el9_7.x86_64.rpm
python3-libs-3.9.25-2.0.1.el9_7.i686.rpm
python3-libs-3.9.25-2.0.1.el9_7.x86_64.rpm
python3-test-3.9.25-2.0.1.el9_7.i686.rpm
python3-test-3.9.25-2.0.1.el9_7.x86_64.rpm
python3-tkinter-3.9.25-2.0.1.el9_7.i686.rpm
python3-tkinter-3.9.25-2.0.1.el9_7.x86_64.rpm

aarch64:
python-unversioned-command-3.9.25-2.0.1.el9_7.noarch.rpm
python3-3.9.25-2.0.1.el9_7.aarch64.rpm
python3-debug-3.9.25-2.0.1.el9_7.aarch64.rpm
python3-devel-3.9.25-2.0.1.el9_7.aarch64.rpm
python3-idle-3.9.25-2.0.1.el9_7.aarch64.rpm
python3-libs-3.9.25-2.0.1.el9_7.aarch64.rpm
python3-test-3.9.25-2.0.1.el9_7.aarch64.rpm
python3-tkinter-3.9.25-2.0.1.el9_7.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/python3.9-3.9.25-2.0.1.el9_7.src.rpm

Related CVEs:

CVE-2024-5642
CVE-2025-6069
CVE-2025-6075
CVE-2025-8291

Description of changes:

[3.9.25-2.0.1]
- Remove upstream URL reference

[3.9.25-2]
- Move _sysconfigdata_d_linux*.py to the debug subpackage

[3.9.25-1]
- Update to Python 3.9.25

[3.9.24-1]
- Update to Python 3.9.24



ELBA-2025-23307 Oracle Linux 10 librepo bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-23307

http://linux.oracle.com/errata/ELBA-2025-23307.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
librepo-1.18.0-6.el10_1.x86_64.rpm
librepo-devel-1.18.0-6.el10_1.x86_64.rpm
python3-librepo-1.18.0-6.el10_1.x86_64.rpm

aarch64:
librepo-1.18.0-6.el10_1.aarch64.rpm
librepo-devel-1.18.0-6.el10_1.aarch64.rpm
python3-librepo-1.18.0-6.el10_1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/librepo-1.18.0-6.el10_1.src.rpm

Description of changes:

[1.18.0-6]
- Test for: Fix input termination for pgpParsePkts (RHEL-125130)



ELBA-2025-23304 Oracle Linux 10 NetworkManager bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-23304

http://linux.oracle.com/errata/ELBA-2025-23304.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
NetworkManager-1.54.0-2.0.1.el10_1.x86_64.rpm
NetworkManager-adsl-1.54.0-2.0.1.el10_1.x86_64.rpm
NetworkManager-bluetooth-1.54.0-2.0.1.el10_1.x86_64.rpm
NetworkManager-cloud-setup-1.54.0-2.0.1.el10_1.x86_64.rpm
NetworkManager-config-connectivity-oracle-1.54.0-2.0.1.el10_1.noarch.rpm
NetworkManager-config-server-1.54.0-2.0.1.el10_1.noarch.rpm
NetworkManager-libnm-1.54.0-2.0.1.el10_1.x86_64.rpm
NetworkManager-libnm-devel-1.54.0-2.0.1.el10_1.x86_64.rpm
NetworkManager-ovs-1.54.0-2.0.1.el10_1.x86_64.rpm
NetworkManager-ppp-1.54.0-2.0.1.el10_1.x86_64.rpm
NetworkManager-tui-1.54.0-2.0.1.el10_1.x86_64.rpm
NetworkManager-wifi-1.54.0-2.0.1.el10_1.x86_64.rpm
NetworkManager-wwan-1.54.0-2.0.1.el10_1.x86_64.rpm

aarch64:
NetworkManager-1.54.0-2.0.1.el10_1.aarch64.rpm
NetworkManager-adsl-1.54.0-2.0.1.el10_1.aarch64.rpm
NetworkManager-bluetooth-1.54.0-2.0.1.el10_1.aarch64.rpm
NetworkManager-cloud-setup-1.54.0-2.0.1.el10_1.aarch64.rpm
NetworkManager-config-connectivity-oracle-1.54.0-2.0.1.el10_1.noarch.rpm
NetworkManager-config-server-1.54.0-2.0.1.el10_1.noarch.rpm
NetworkManager-libnm-1.54.0-2.0.1.el10_1.aarch64.rpm
NetworkManager-libnm-devel-1.54.0-2.0.1.el10_1.aarch64.rpm
NetworkManager-ovs-1.54.0-2.0.1.el10_1.aarch64.rpm
NetworkManager-ppp-1.54.0-2.0.1.el10_1.aarch64.rpm
NetworkManager-tui-1.54.0-2.0.1.el10_1.aarch64.rpm
NetworkManager-wifi-1.54.0-2.0.1.el10_1.aarch64.rpm
NetworkManager-wwan-1.54.0-2.0.1.el10_1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/NetworkManager-1.54.0-2.0.1.el10_1.src.rpm

Description of changes:

[1.54.0-2.0.1]
- Add connectivity check via Oracle servers [Orabug: 32051972]

[1:1.54.0-2]
- Support reapplying sriov.vfs (RHEL-113956)
- Fix removing unrelated OVS ports (RHEL-121106)



ELBA-2025-23291 Oracle Linux 10 fuse-overlayfs bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-23291

http://linux.oracle.com/errata/ELBA-2025-23291.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
fuse-overlayfs-1.16-1.el10_1.x86_64.rpm

aarch64:
fuse-overlayfs-1.16-1.el10_1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/fuse-overlayfs-1.16-1.el10_1.src.rpm

Description of changes:

[1.16-1]
- update to https://github.com/containers/fuse-overlayfs/releases/tag/v1.16
- fixes "Update fuse-overlayfs to 1.16 [rhel-10.1.z]"
- Resolves: RHEL-128522



ELBA-2025-23287 Oracle Linux 10 maven bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-23287

http://linux.oracle.com/errata/ELBA-2025-23287.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
maven-3.9.9-3.el10_1.noarch.rpm
maven-javadoc-3.9.9-3.el10_1.noarch.rpm
maven-lib-3.9.9-3.el10_1.noarch.rpm
maven-openjdk21-3.9.9-3.el10_1.noarch.rpm
maven-openjdk25-3.9.9-3.el10_1.noarch.rpm
maven-unbound-3.9.9-3.el10_1.noarch.rpm

aarch64:
maven-3.9.9-3.el10_1.noarch.rpm
maven-javadoc-3.9.9-3.el10_1.noarch.rpm
maven-lib-3.9.9-3.el10_1.noarch.rpm
maven-openjdk21-3.9.9-3.el10_1.noarch.rpm
maven-openjdk25-3.9.9-3.el10_1.noarch.rpm
maven-unbound-3.9.9-3.el10_1.noarch.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/maven-3.9.9-3.el10_1.src.rpm

Description of changes:

[1:3.9.9-3]
- Add missing configuration file for maven-openjdk25

[1:3.9.9-2]
- Add maven-openjdk25 binding



ELBA-2025-23284 Oracle Linux 10 linuxptp bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-23284

http://linux.oracle.com/errata/ELBA-2025-23284.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
linuxptp-4.4-5.el10_1.x86_64.rpm
linuxptp-selinux-4.4-5.el10_1.noarch.rpm

aarch64:
linuxptp-4.4-5.el10_1.aarch64.rpm
linuxptp-selinux-4.4-5.el10_1.noarch.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/linuxptp-4.4-5.el10_1.src.rpm

Description of changes:

[4.4-5]
- handle missing pulses in ts2phc (RHEL-112344)



ELBA-2025-23283 Oracle Linux 10 unbound bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-23283

http://linux.oracle.com/errata/ELBA-2025-23283.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
python3-unbound-1.20.0-15.el10_1.x86_64.rpm
unbound-1.20.0-15.el10_1.x86_64.rpm
unbound-anchor-1.20.0-15.el10_1.x86_64.rpm
unbound-devel-1.20.0-15.el10_1.x86_64.rpm
unbound-dracut-1.20.0-15.el10_1.x86_64.rpm
unbound-libs-1.20.0-15.el10_1.x86_64.rpm

aarch64:
python3-unbound-1.20.0-15.el10_1.aarch64.rpm
unbound-1.20.0-15.el10_1.aarch64.rpm
unbound-anchor-1.20.0-15.el10_1.aarch64.rpm
unbound-devel-1.20.0-15.el10_1.aarch64.rpm
unbound-dracut-1.20.0-15.el10_1.aarch64.rpm
unbound-libs-1.20.0-15.el10_1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/unbound-1.20.0-15.el10_1.src.rpm

Description of changes:

[1.20.0-15]
- Correct existing unbound_control.key permissions

[1.20.0-14]
- Fix permissions of created control and server key



ELBA-2025-28057 Oracle Linux 10 oracle-common-release bug fix update


Oracle Linux Bug Fix Advisory ELBA-2025-28057

http://linux.oracle.com/errata/ELBA-2025-28057.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
ksplice-release-el10-1.0-5.el10.x86_64.rpm
oci-included-release-el10-1.0-5.el10.x86_64.rpm
oracle-epel-release-el10-1.0-5.el10.x86_64.rpm
oraclelinux-developer-release-el10-1.0-5.el10.x86_64.rpm
oracle-instantclient-release-26ai-el10-1.0-5.el10.x86_64.rpm

aarch64:
ksplice-release-el10-1.0-5.el10.aarch64.rpm
oci-included-release-el10-1.0-5.el10.aarch64.rpm
oracle-epel-release-el10-1.0-5.el10.aarch64.rpm
oraclelinux-developer-release-el10-1.0-5.el10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/oracle-common-release-1.0-5.el10.src.rpm

Description of changes:

[1.0-5]
- Add Oracle Instant Client 26ai repositories



ELSA-2025-23700 Important: Oracle Linux 9 webkit2gtk3 security update


Oracle Linux Security Advisory ELSA-2025-23700

http://linux.oracle.com/errata/ELSA-2025-23700.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
webkit2gtk3-2.50.4-1.el9_7.i686.rpm
webkit2gtk3-2.50.4-1.el9_7.x86_64.rpm
webkit2gtk3-devel-2.50.4-1.el9_7.i686.rpm
webkit2gtk3-devel-2.50.4-1.el9_7.x86_64.rpm
webkit2gtk3-jsc-2.50.4-1.el9_7.i686.rpm
webkit2gtk3-jsc-2.50.4-1.el9_7.x86_64.rpm
webkit2gtk3-jsc-devel-2.50.4-1.el9_7.i686.rpm
webkit2gtk3-jsc-devel-2.50.4-1.el9_7.x86_64.rpm

aarch64:
webkit2gtk3-2.50.4-1.el9_7.aarch64.rpm
webkit2gtk3-devel-2.50.4-1.el9_7.aarch64.rpm
webkit2gtk3-jsc-2.50.4-1.el9_7.aarch64.rpm
webkit2gtk3-jsc-devel-2.50.4-1.el9_7.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/webkit2gtk3-2.50.4-1.el9_7.src.rpm

Related CVEs:

CVE-2025-43501
CVE-2025-43529
CVE-2025-43531
CVE-2025-43535
CVE-2025-43536
CVE-2025-43541

Description of changes:

[2.50.4-1]
- Update to 2.50.4



ELSA-2025-23480 Moderate: Oracle Linux 9 openssh security update


Oracle Linux Security Advisory ELSA-2025-23480

http://linux.oracle.com/errata/ELSA-2025-23480.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
openssh-8.7p1-47.0.1.el9_7.x86_64.rpm
openssh-askpass-8.7p1-47.0.1.el9_7.x86_64.rpm
openssh-clients-8.7p1-47.0.1.el9_7.x86_64.rpm
openssh-keycat-8.7p1-47.0.1.el9_7.x86_64.rpm
openssh-server-8.7p1-47.0.1.el9_7.x86_64.rpm
pam_ssh_agent_auth-0.10.4-5.47.0.1.el9_7.x86_64.rpm

aarch64:
openssh-8.7p1-47.0.1.el9_7.aarch64.rpm
openssh-askpass-8.7p1-47.0.1.el9_7.aarch64.rpm
openssh-clients-8.7p1-47.0.1.el9_7.aarch64.rpm
openssh-keycat-8.7p1-47.0.1.el9_7.aarch64.rpm
openssh-server-8.7p1-47.0.1.el9_7.aarch64.rpm
pam_ssh_agent_auth-0.10.4-5.47.0.1.el9_7.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/openssh-8.7p1-47.0.1.el9_7.src.rpm

Related CVEs:

CVE-2025-61984
CVE-2025-61985

Description of changes:

[8.7p1-47.0.1]
- Upstream references found with /usr/bin/ssh [Orabug: 37814929]
- upstream: fix AuthorizedPrincipalsCommand when AuthorizedKeysCommand [Orabug: 37647064]
- Update upstream references [Orabug: 36564626]

[8.7p1-47]
- CVE-2025-61984: Reject usernames with control characters
Resolves: RHEL-128401
- CVE-2025-61985: Reject URL-strings with NULL characters
Resolves: RHEL-128392



ELSA-2025-23343 Moderate: Oracle Linux 9 binutils security update


Oracle Linux Security Advisory ELSA-2025-23343

http://linux.oracle.com/errata/ELSA-2025-23343.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
binutils-2.35.2-67.0.1.el9_7.1.i686.rpm
binutils-2.35.2-67.0.1.el9_7.1.x86_64.rpm
binutils-devel-2.35.2-67.0.1.el9_7.1.i686.rpm
binutils-devel-2.35.2-67.0.1.el9_7.1.x86_64.rpm
binutils-gold-2.35.2-67.0.1.el9_7.1.x86_64.rpm

aarch64:
binutils-2.35.2-67.0.1.el9_7.1.aarch64.rpm
binutils-devel-2.35.2-67.0.1.el9_7.1.aarch64.rpm
binutils-gold-2.35.2-67.0.1.el9_7.1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/binutils-2.35.2-67.0.1.el9_7.1.src.rpm

Related CVEs:

CVE-2025-11083

Description of changes:

[2.35.2-67.0.1.1]
- Merge Oracle patches to 2.35.2-67.1.
- CVE-2025-11083
- Reviewed-by: David Faust [david.faust@oracle.com]
Oracle history:
September-24-2025 Bruce McCulloch [bruce.mcculloch@oracle.com] - 2.35.2-67.0.1
- Merge Oracle patches to 2.35.2-66.
- Reviewed-by: Jose E. Marchesi [jose.marchesi@oracle.com]
September-5-2025 Bruce McCulloch [bruce.mcculloch@oracle.com] - 2.35.2-66.0.1
- Merge Oracle patches to 2.35.2-66.
- Reviewed-by: Jose E. Marchesi [jose.marchesi@oracle.com]
August-4-2025 Bruce McCulloch [bruce.mcculloch@oracle.com] - 2.35.2-65.0.1
- Merge Oracle patches to 2.35.2-65.
- Reviewed-by: Jose E. Marchesi [jose.marchesi@oracle.com]
April-10-2025 Bruce McCulloch [bruce.mcculloch@oracle.com] - 2.35.2-63.0.1
- Merge Oracle patches to 2.35.2-63.
- Reviewed-by: Jose E. Marchesi [jose.marchesi@oracle.com]
January-10-2025 Bruce McCulloch [bruce.mcculloch@oracle.com] - 2.35.2-55.0.1
- Forward-port Oracle patches to 2.35.2-55.
- Refresh CTF patches
March-27-2024 Jose E. Marchesi [jose.marchesi@oracle.com] - 2.35.2-43.0.1
- Forward-port Oracle patches to 2.35.2-43.
March-07-2024 Jose E. Marchesi [jose.marchesi@oracle.com] - 2.35.2-42.0.2.1
- Do not set version info on unversion symbols. (RHEL-22601)
- Reviewed by: Elena Zannoni [elena.zannoni@oracle.com]
February-06-2024 Nick Alcock [nick.alcock@oracle.com] - 2.35.2-42.0.2
- Refresh CTF patches from upstream (2.42).
- Fix more cases where operations on child dicts could leave errors on
the parent, this time associated with CTF dict creation (upstream PR
libctf/30985).
- Fix the cu-mapped link feature (not exposed by GNU ld) to use only
the last mapping provided for a given translation unit, rather than a
random mix of first and last
- Fix dependencies of libctf.so and libctf-nobfd.so to cite the libraries
the code actually depends on. (Fixes observed link problems with
libctf-nobfd.so needing extra libraries on the link line versus upstream:
libctf.so changes done purely for consistency.)
- Add upstream commit 2e93abb858ae, allowing NONE relocs against local absolute
symbols on x86-64. (Upstream PR ld/31047).
October-10-2023 Jose E. Marchesi [jose.marchesi@oracle.com] - 2.35.2-42.0.1
- Forward-port Oracle patches to 2.35.2-42.
August-04-2023 Nick Alcock [nick.alcock@oracle.com] - 2.35.2-37.0.2
- Refresh CTF patches from upstream.
- Avoid spurious corruption error with symtypetab section emitted by old OL8 GCCs
- Various obscure install-time linking problems
- Make objdump/readelf --ctf parameter optional; make objdump --ctf-parent take
a CTF member name, not a section name
- Improve dumping of types when some types elicit a libctf error
- Put functions as well as variables in the (misnamed) CTF variable section
- Improve handling of various forms of corrupted CTF input.
- Fix errors in comments in and
- Make CTF dicts reproducible even when conflicting types are seen
- Prevent corruption of output when linking multiple object files derived from
the same source
- Minor compiler warning and portability fixes
- Fix (unlikely) crash-inducing uninitialized memory access and wild
pointer overwrite when linking
- Fix the reported offsets of fields within unnamed structs/unions
[Orabug: 35191322]
- Fix a number of places where operations carried out on child dicts
that errored were producing errors on the parent, not the child,
so the caller never noticed them
March-28-2023 Guillermo E. Martinez [guillermo.e.martinez@oracle.com] - 2.35.2-37.0.1
- Forward-port Oracle patches from 2.35.2-24.0.1
- Reviewed-by: Jose E. Marchesi [jose.marchesi@oracle.com]
April-25-2022 David Faust [david.faust@oracle.com] - 2.35.2-17.0.1
- Forward-port Oracle patches from 2.35.2-9.0.1 to 2.35.2-17.0.1
- Reviewed-by: Jose E. Marchesi [jose.marchesi@oracle.com]
November-23-2021 David Faust [david.faust@oracle.com] - 2.35.2-9.0.1
- Enable libctf
- Backport all CTF improvements since 2.35.2 release, upstream commits:
6ab5b6d0f3a libctf, lookup: fix bounds of pptrtab lookup
e695879142a libctf, testsuite: fix various warnings in tests
b62d5edd0a5 libctf: fix handling of CTF symtypetab sections emitted by older GCC
ea9c2009115 libctf: try several possibilities for linker versioning flags
bef9ef8ca0f libtool.m4: fix nm BSD flag detection
bc4b1401129 libtool.m4: augment symcode for Solaris 11
7d53105d6ed libctf: link against libiberty before linking in libbfd or libctf-nobfd
ae064303efe libctf, ld: fix test results for upstream GCC
49da556c658 libctf, include: support an alternative encoding for nonrepresentable types
8592be8c7d3 ld: do not rely on the exact size of the CTF symtypetabs in test results
8f7b22ea2a9 libctf: fix ELF-in-BFD checks in the presence of ASAN
15131809c23 libctf: fix memory leak in a test
0bd65ce30a8 libctf: don't dereference out-of-bounds locations in the qualifier hashtab
5226ef61131 libctf: make ctf_bfdopen_ctfsect a debugger entry point
86f64bf43f7 libctf, serialize: functions with no args have a NULL dtd_vlen
24c877f9b19 include: always do unsigned left-shift in CTF_SET_STID
485170cdb1b libctf, dump: do not emit size or alignment if it would error
e93388417c1 Provide an inline startswith function in bfd.h
69a284867c7 libctf: support encodings for enums
e4c78f303df libctf: a couple of small error-handling fixes
d7b1416ef2c libctf: types: unify code dealing with small-vs-large struct members
08c428aff4a libctf: eliminate dtd_u, part 5: structs / unions
77d724a7ecd libctf: eliminate dtd_u, part 4: enums
986e9e3aa03 libctf: do not corrupt strings across ctf_serialize
2a05d50e90c libctf: don't lose track of all valid types upon serialization
755ba58ebef Add install dependencies for ld -> bfd and libctf -> bfd
81982d20fac libctf: eliminate dtd_u, part 3: functions
534444b1ee1 libctf: eliminate dtd_u, part 2: arrays
7879dd88efd libctf: eliminate dtd_u, part 1: int/float/slice
eefe721eadf libctf: fix GNU style for do {} while
b9a964318a7 libctf: split up ctf_serialize
01cbfcba4bc libctf: fix comment above ctf_dict_t
bf4c3185a5a libctf: split serialization and file writeout into its own file
087945261c7 libctf: fix some tabdamage and move some code around
211bcd01333 bfd, ld, libctf: skip zero-refcount strings in CTF string reporting
8e7e446446b libctf: free ctf_dynsyms properly
cf6a0b989a5 libctf: fix signed/unsigned comparison confusion
4659554b280 libctf: minor error-handling fixes
f5060e56338 libctf: add a deduplicator-specific type mapping table
478c04a55ee libctf: remove reference to "unconflicted link mode".
8915c559d40 libctf, include: remove the nondeduplicating CTF linker
fd12633780a libctf: fix ChangeLog date
ac36e134d96 libctf: reimplement many _iter iterators in terms of _next
eaa2913a7ac libctf: ctf_archive_next should set the parent name consistently
93993f67849 libctf AC_CANONICAL_TARGET
f4f60336dae libctf, include: find types of symbols by name
758f590744b libctf: add missing header in BFD ELF check
cbd8f5bbcc8 libctf: require a Tcl capable of try/catch to run tests
95148614026 bfd, opcodes, libctf: support --with-included-gettext
ee87f50b8d2 libctf: always name nameless types "", never NULL
5dacd11ddcf libctf: fix uninitialized variable in symbol serialization error handling
caa170493e8 libctf: prohibit nameless ints, floats, typedefs and forwards
78f28b89e8c libctf: rip out dead code handling typedefs with no name
35a01a04544 libctf, ld: fix symtypetab and var section population under ld -r
f04ce15e831 ld: depend on libctf
26503e2f5ea libctf, create: fix ctf_type_add of structs with unnamed members
e05a3e5a491 libctf: lookup_by_name: do not return success for nonexistent pointer types
0814dbfbfcc libctf, testsuite: adjust for real return type of ctf_member_count
70d3120f322 libctf, testsuite: don't run without a suitable compiler
b4b6ea46807 libctf, ld: fix formatting of forwards to unions and enums
abe4ca69a11 libctf: fix lookups of pointers by name in parent dicts
8769046e5a9 libctf: remove outdated comment about parent dict importing
6c3a38777b3 libctf, include: support unnamed structure members better
abed0b0718a libctf: warn about information loss because of unreleased format changes
9bc769718db libctf: new test of enum lookups with the _next iterator
c59e30ed172 libctf: new testsuite
1038406a8f6 libctf: rip out BFD_DEPENDENCIES / BFD_LIBADD
37002871ac2 libctf, ld: dump enums: generally improve dump formatting
ffeece6ac2d libctf, ld: prohibit getting the size or alignment of forwards
91e7ce2fd7b libctf, ld: more dumper improvements
57f97d0e6dd libctf, ld: CTF dumper changes for consistency
b09ad6eae98 libctf: do not print array declarators backwards
a7c23ac9317 In libctf, make AC_CONFIG_MACRO_DIR consistent with ACLOCAL_AMFLAGS
e8cda209052 libctf: Pass format argument to asprintf
96c61be508f binutils: readelf: support CTF dicts with non-native-endian symtabs
53651de80f8 libctf, include: support foreign-endianness symtabs with CTF
ef21dd3bcff libctf: do not crash when CTF symbol or variable linking fails
8f235c90a28 libctf: error-handling fixes
97a2a623d01 libctf, include: add ctf_getsymsect and ctf_getstrsect
2c78e92523a libctf, include: CTF-archive-wide symbol lookup
0e28ade476e libctf, ld: properly deduplicate function types
0ad70c536ab ld, ctf: new and adjusted CTF tests due to func info / object data sections
4665e895c37 libctf: adjust dumper for symtypetab changes
1136c379718 libctf: symbol type linking support
3d16b64e28a bfd, include, ld, binutils, libctf: CTF should use the dynstr/sym
83d59285d54 objdump, readelf: Report errors from CTF archive iteration
ae41200ba80 libctf, include, binutils, gdb: rename CTF-opening functions
139633c307e libctf, include, binutils, gdb, ld: rename ctf_file_t to ctf_dict_t
0d01fbe64f6 Remove libctf/mkerrors.sed
5e9b84f7a2e binutils, ld: dequote libctf error messages
926c9e76657 libctf, binutils, include, ld: gettextize and improve error handling
555adca2e3b libctf: compilation failure on MinGW due to missing errno values
50500ecfefd libctf: compilation failure on MinGW due to missing errno values
8c419a91d76 libctf: fixes for systems on which sizeof (void *) > sizeof (long)
734c894234e libctf: fix isspace casts
4533ed564d6 libctf, binutils: fix big-endian libctf archive opening
62cdd7b18fc ld, testsuite: do not run CTF tests at all on non-ELF for now
fa03171fb46 ld: do not produce one empty output .ctf section for every input .ctf
7cdfc3462fb ld, testsuite: only run CTF tests when ld and GCC support CTF
b1b33524ad3 ld: new CTF testsuite
0b884151088 binutils, testsuite: allow compilation before doing run_dump_test
5dba6f05b7b ld: new options --ctf-variables and --ctf-share-types
f320bba50ff ld: Reformat CTF errors into warnings.
3dd6b890b4e binutils: objdump: ctf: drop incorrect linefeeds
662df3c3f14 libctf, link: tie in the deduplicating linker
e3e8411bec4 libctf, link: add CTF_LINK_OMIT_VARIABLES_SECTION
0f0c11f7fc9 libctf, dedup: add deduplicator
a9b98702066 libctf, dedup: add new configure option --enable-libctf-hash-debugging
1f2e8b5b87d libctf: add SHA-1 support for libctf
6dd2819ffc2 libctf, link: add the ability to filter out variables from the link
19d4b1addca libctf, link: fix spurious conflicts of variables in the variable section
5f54462c6ab libctf, link: redo cu-mapping handling
e3f17159e26 libctf, link: fix ctf_link_write fd leak
8d2229ad1e7 libctf, link: add lazy linking: clean up input members: err/warn cleanup
e148b730131 libctf: drop error-prone ctf_strerror
1fa7a0c24e7 libctf: sort out potential refcount loops
3166467b00a libctf: rename the type_mapping_key to type_key
43a61d7d3e6 libctf: check for vasprintf
ac2ff760303 libctf, archive: fix bad error message
d50c08025d4 libctf, open: fix opening CTF in binaries with no symtab
70447401740 libctf, dump: fix slice dumping
8e795b46f58 libctf, dump: migrate towards dumping errors rather than truncation
b255b35feb8 libctf, decl: avoid leaks of the formatted string on error
c6e9a1e576c libctf, types: enhance ctf_type_aname to print function arg types
8b37e7b63ed libctf, ld, binutils: add textual error/warning reporting for libctf
b7190c821e5 libctf, types: ensure the emission of ECTF_NOPARENT
ec388c16cd4 libctf: error out on corrupt CTF with invalid header flags
67d4cc671b7 libctf: pass the thunk down properly when wrapping qsort_r
e28591b3dfc libctf, next, hash: add dynhash and dynset _next iteration
688d28f6214 libctf, next: introduce new class of easier-to-use iterators
2399827bfa1 libctf: add ctf_ref
9850ce4d7bb libctf: add ctf_forwardable_kind
2c9ca36be17 libctf: move existing inlines into ctf-inlines.h
77648241384 libctf, hash: introduce the ctf_dynset
a49c6c6a656 libctf, hash: save per-item space when no key/item freeing function
5ceee3dba34 libctf, hash: improve insertion of existing keys into dynhashes
809f6eb3321 libctf: add new dynhash functions
469e75b621f libctf: fix __extension__ with non-GNU C compilers
9c23dfa5aa4 libctf: add ctf_archive_count
e0325e2cede libctf: add ctf_member_count
9b15cbb7891 libctf: add ctf_type_kind_forwarded
01d9317436c libctf: add ctf_type_name_raw
5ec7465fec8 libctf: having debugging enabled is unlikely
601e455b758 libctf, archive: stop ctf_arc_bufopen triggering crazy unmaps
96e3ec29664 libctf, types: ints, floats and typedefs with no name are invalid
502e838ed96 libctf, types: support slices of anything terminating in an int
dd987f00430 libctf, create: empty dicts are dirty to start with
f47ca311356 libctf, create: fix addition of anonymous struct/union members
ab769488e75 libctf, create: member names of "" and NULL should be the same
2484ca436ac libctf, open: drop unnecessary historical wart around forwards
437061996d8 libctf, types: allow ctf_type_reference of dynamic slices
9943fa3a732 libctf, create: add explicit casts for variables' and slices' types
afd78bd6f0a libctf, create: do not corrupt function types' arglists at insertion time
2361f1c8591 libctf, create: support addition of references to the unimplemented type
7eea9d3bdb0 libctf: restructure error handling to reduce relocations
b64751cf0bc include, libctf: typo fixes
df16e041dea Fix problems in CTF handling code exposed by the Coverity static analysis tool.
- Reviewed-by: Jose E. Marchesi [jose.marchesi@oracle.com]

[2.35.2-67.1]
- Fix a potential illegal memory access when linking a corrupt input file. (RHEL-126883)



ELSA-2025-23309 Moderate: Oracle Linux 9 php:8.3 security update


Oracle Linux Security Advisory ELSA-2025-23309

http://linux.oracle.com/errata/ELSA-2025-23309.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
apcu-panel-5.1.23-1.module+el9.6.0+90525+5083e899.noarch.rpm
php-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-bcmath-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-cli-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-common-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-dba-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-dbg-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-devel-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-embedded-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-enchant-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-ffi-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-fpm-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-gd-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-gmp-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-intl-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-ldap-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-mbstring-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-mysqlnd-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-odbc-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-opcache-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-pdo-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-pecl-apcu-5.1.23-1.module+el9.6.0+90525+5083e899.x86_64.rpm
php-pecl-apcu-devel-5.1.23-1.module+el9.6.0+90525+5083e899.x86_64.rpm
php-pecl-redis6-6.1.0-2.module+el9.6.0+90525+5083e899.x86_64.rpm
php-pecl-rrd-2.0.3-4.module+el9.6.0+90525+5083e899.x86_64.rpm
php-pecl-xdebug3-3.3.1-1.module+el9.6.0+90525+5083e899.x86_64.rpm
php-pecl-zip-1.22.3-1.module+el9.6.0+90525+5083e899.x86_64.rpm
php-pgsql-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-process-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-snmp-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-soap-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm
php-xml-8.3.26-1.module+el9.4.0+90734+c13c2ce3.x86_64.rpm

aarch64:
apcu-panel-5.1.23-1.module+el9.6.0+90525+5083e899.noarch.rpm
php-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-bcmath-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-cli-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-common-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-dba-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-dbg-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-devel-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-embedded-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-enchant-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-ffi-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-fpm-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-gd-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-gmp-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-intl-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-ldap-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-mbstring-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-mysqlnd-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-odbc-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-opcache-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-pdo-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-pecl-apcu-5.1.23-1.module+el9.6.0+90525+5083e899.aarch64.rpm
php-pecl-apcu-devel-5.1.23-1.module+el9.6.0+90525+5083e899.aarch64.rpm
php-pecl-redis6-6.1.0-2.module+el9.6.0+90525+5083e899.aarch64.rpm
php-pecl-rrd-2.0.3-4.module+el9.6.0+90525+5083e899.aarch64.rpm
php-pecl-xdebug3-3.3.1-1.module+el9.6.0+90525+5083e899.aarch64.rpm
php-pecl-zip-1.22.3-1.module+el9.6.0+90525+5083e899.aarch64.rpm
php-pgsql-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-process-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-snmp-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-soap-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm
php-xml-8.3.26-1.module+el9.4.0+90734+c13c2ce3.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/php-8.3.26-1.module+el9.4.0+90734+c13c2ce3.src.rpm
http://oss.oracle.com/ol9/SRPMS-updates/php-pecl-apcu-5.1.23-1.module+el9.6.0+90525+5083e899.src.rpm
http://oss.oracle.com/ol9/SRPMS-updates/php-pecl-redis6-6.1.0-2.module+el9.6.0+90525+5083e899.src.rpm
http://oss.oracle.com/ol9/SRPMS-updates/php-pecl-rrd-2.0.3-4.module+el9.6.0+90525+5083e899.src.rpm
http://oss.oracle.com/ol9/SRPMS-updates/php-pecl-xdebug3-3.3.1-1.module+el9.6.0+90525+5083e899.src.rpm
http://oss.oracle.com/ol9/SRPMS-updates/php-pecl-zip-1.22.3-1.module+el9.6.0+90525+5083e899.src.rpm

Related CVEs:

CVE-2025-1220
CVE-2025-1735
CVE-2025-6491

Description of changes:

php-pecl-zip
[1.22.3-1]
- update to 1.22.3 for PHP 8.2 RHEL-14699

[1.20.1-1]
- update to 1.20.1 for PHP 8.1 #2070040



ELSA-2025-23326 Moderate: Oracle Linux 9 skopeo security update


Oracle Linux Security Advisory ELSA-2025-23326

http://linux.oracle.com/errata/ELSA-2025-23326.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
skopeo-1.20.0-2.el9_7.x86_64.rpm
skopeo-tests-1.20.0-2.el9_7.x86_64.rpm

aarch64:
skopeo-1.20.0-2.el9_7.aarch64.rpm
skopeo-tests-1.20.0-2.el9_7.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/skopeo-1.20.0-2.el9_7.src.rpm

Related CVEs:

CVE-2025-58183

Description of changes:

[1:1.20.0-2]
- rebuild for CVE-2025-58183
- Resolves: RHEL-125717



ELSA-2025-23325 Moderate: Oracle Linux 9 podman security update


Oracle Linux Security Advisory ELSA-2025-23325

http://linux.oracle.com/errata/ELSA-2025-23325.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
podman-5.6.0-9.0.1.el9_7.x86_64.rpm
podman-docker-5.6.0-9.0.1.el9_7.noarch.rpm
podman-plugins-5.6.0-9.0.1.el9_7.x86_64.rpm
podman-remote-5.6.0-9.0.1.el9_7.x86_64.rpm
podman-tests-5.6.0-9.0.1.el9_7.x86_64.rpm

aarch64:
podman-5.6.0-9.0.1.el9_7.aarch64.rpm
podman-docker-5.6.0-9.0.1.el9_7.noarch.rpm
podman-plugins-5.6.0-9.0.1.el9_7.aarch64.rpm
podman-remote-5.6.0-9.0.1.el9_7.aarch64.rpm
podman-tests-5.6.0-9.0.1.el9_7.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/podman-5.6.0-9.0.1.el9_7.src.rpm

Related CVEs:

CVE-2025-58183

Description of changes:

[5.6.0-9.0.1]
- Add devices on container startup, not on creation
- overlay: Put should ignore ENINVAL for Unmount [Orabug: 36234694]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404]

[6:5.6.0-9]
- update to the latest content of https://github.com/containers/podman/tree/v5.6-rhel
( https://github.com/containers/podman/commit/3bf5313)
- fixes "run 1.2.x upgrade throws error while using nocopy volume mount filesystem option - [RHEL 9.7]"
- Resolves: RHEL-132531

[6:5.6.0-8]
- rebuild for golang-1.25.3
- Resolves: RHEL-125711



ELSA-2025-23323 Moderate: Oracle Linux 9 python3.12 security update


Oracle Linux Security Advisory ELSA-2025-23323

http://linux.oracle.com/errata/ELSA-2025-23323.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
python3.12-3.12.12-1.0.1.el9_7.i686.rpm
python3.12-3.12.12-1.0.1.el9_7.x86_64.rpm
python3.12-debug-3.12.12-1.0.1.el9_7.i686.rpm
python3.12-debug-3.12.12-1.0.1.el9_7.x86_64.rpm
python3.12-devel-3.12.12-1.0.1.el9_7.i686.rpm
python3.12-devel-3.12.12-1.0.1.el9_7.x86_64.rpm
python3.12-idle-3.12.12-1.0.1.el9_7.i686.rpm
python3.12-idle-3.12.12-1.0.1.el9_7.x86_64.rpm
python3.12-libs-3.12.12-1.0.1.el9_7.i686.rpm
python3.12-libs-3.12.12-1.0.1.el9_7.x86_64.rpm
python3.12-test-3.12.12-1.0.1.el9_7.i686.rpm
python3.12-test-3.12.12-1.0.1.el9_7.x86_64.rpm
python3.12-tkinter-3.12.12-1.0.1.el9_7.i686.rpm
python3.12-tkinter-3.12.12-1.0.1.el9_7.x86_64.rpm

aarch64:
python3.12-3.12.12-1.0.1.el9_7.aarch64.rpm
python3.12-debug-3.12.12-1.0.1.el9_7.aarch64.rpm
python3.12-devel-3.12.12-1.0.1.el9_7.aarch64.rpm
python3.12-idle-3.12.12-1.0.1.el9_7.aarch64.rpm
python3.12-libs-3.12.12-1.0.1.el9_7.aarch64.rpm
python3.12-test-3.12.12-1.0.1.el9_7.aarch64.rpm
python3.12-tkinter-3.12.12-1.0.1.el9_7.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/python3.12-3.12.12-1.0.1.el9_7.src.rpm

Related CVEs:

CVE-2025-8291

Description of changes:

[3.12.12-1.0.1]
- Remove upstream URL reference

[3.12.12-1]
- Update to 3.12.12
Resolves: RHEL-125856



ELBA-2025-23334 Oracle Linux 9 runc bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-23334

http://linux.oracle.com/errata/ELBA-2025-23334.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
runc-1.4.0-1.el9_7.x86_64.rpm

aarch64:
runc-1.4.0-1.el9_7.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/runc-1.4.0-1.el9_7.src.rpm

Description of changes:

[4:1.4.0-1]
- update to https://github.com/opencontainers/runc/releases/tag/v1.4.0
- Resolves: RHEL-132800

[4:1.3.0-5]
- fix premission regression
- Related: RHEL-122400



ELSA-2025-23241 Important: Oracle Linux 9 kernel security update


Oracle Linux Security Advisory ELSA-2025-23241

http://linux.oracle.com/errata/ELSA-2025-23241.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
kernel-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-abi-stablelists-5.14.0-611.16.1.el9_7.noarch.rpm
kernel-core-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-cross-headers-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-debug-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-debug-core-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-debug-devel-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-debug-devel-matched-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-debug-modules-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-debug-modules-core-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-debug-modules-extra-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-debug-uki-virt-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-devel-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-devel-matched-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-doc-5.14.0-611.16.1.el9_7.noarch.rpm
kernel-headers-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-modules-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-modules-core-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-modules-extra-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-tools-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-tools-libs-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-tools-libs-devel-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-uki-virt-5.14.0-611.16.1.el9_7.x86_64.rpm
kernel-uki-virt-addons-5.14.0-611.16.1.el9_7.x86_64.rpm
libperf-5.14.0-611.16.1.el9_7.x86_64.rpm
perf-5.14.0-611.16.1.el9_7.x86_64.rpm
python3-perf-5.14.0-611.16.1.el9_7.x86_64.rpm
rtla-5.14.0-611.16.1.el9_7.x86_64.rpm
rv-5.14.0-611.16.1.el9_7.x86_64.rpm

aarch64:
kernel-cross-headers-5.14.0-611.16.1.el9_7.aarch64.rpm
kernel-headers-5.14.0-611.16.1.el9_7.aarch64.rpm
kernel-tools-5.14.0-611.16.1.el9_7.aarch64.rpm
kernel-tools-libs-5.14.0-611.16.1.el9_7.aarch64.rpm
kernel-tools-libs-devel-5.14.0-611.16.1.el9_7.aarch64.rpm
libperf-5.14.0-611.16.1.el9_7.aarch64.rpm
perf-5.14.0-611.16.1.el9_7.aarch64.rpm
python3-perf-5.14.0-611.16.1.el9_7.aarch64.rpm
rtla-5.14.0-611.16.1.el9_7.aarch64.rpm
rv-5.14.0-611.16.1.el9_7.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/kernel-5.14.0-611.16.1.el9_7.src.rpm

Related CVEs:

CVE-2025-38499
CVE-2025-39966
CVE-2025-40176

Description of changes:

[5.14.0-611.16.1]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64