Oracle Linux 6459 Published by

Several security updates have been uploaded to the Unbreakable Linux Network for Oracle Linux 8 and 9, addressing various vulnerabilities. The updates include fixes for CVEs such as CVE-2026-27606, CVE-2025-69419, and others, affecting packages like ol-automation-manager, compat-openssl11, vim, and .NET runtime. Some of the updates are specific to Oracle Linux and add support for Oracle Linux in addition to general security fixes.

OLAMSA-2026-0006 Important: Oracle Linux 9 ol-automation-manager security update
OLAMSA-2026-0005 Important: Oracle Linux 8 ol-automation-manager security update
ELSA-2026-4472 Moderate: Oracle Linux 9 compat-openssl11 security update
OLAMSA-2026-0004 Important: Oracle Linux 8 ol-automation-manager security update
ELBA-2026-4190 Oracle Linux 9 kmod-kvdo bug fix and enhancement update
ELSA-2026-4456 Important: Oracle Linux 9 .NET 9.0 security update
ELSA-2026-4442 Moderate: Oracle Linux 8 vim security update
ELSA-2026-4455 Important: Oracle Linux 8 .NET 8.0 security update
ELSA-2026-4463 Moderate: Oracle Linux 8 python3.12 security update
ELSA-2026-4458 Important: Oracle Linux 8 .NET 10.0 security update




OLAMSA-2026-0006 Important: Oracle Linux 9 ol-automation-manager security update


Oracle Linux Security Advisory OLAMSA-2026-0006

http://linux.oracle.com/errata/OLAMSA-2026-0006.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
ol-automation-manager-2.3.1-5.el9.x86_64.rpm
ol-automation-manager-cli-2.3.1-5.el9.noarch.rpm
python311-olamkit-2.3.1-5.el9.noarch.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/ol-automation-manager-2.3.1-5.el9.src.rpm

Related CVEs:

CVE-2026-27606

Description of changes:

[2.3.1-5.el8]
- OLAM-907 Bump rollup version to fix CVE-2026-27606



OLAMSA-2026-0005 Important: Oracle Linux 8 ol-automation-manager security update


Oracle Linux Security Advisory OLAMSA-2026-0005

http://linux.oracle.com/errata/OLAMSA-2026-0005.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
ol-automation-manager-2.3.1-6.el8.x86_64.rpm
ol-automation-manager-cli-2.3.1-6.el8.noarch.rpm
python311-olamkit-2.3.1-6.el8.noarch.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/ol-automation-manager-2.3.1-6.el8.src.rpm

Related CVEs:

CVE-2026-27606

Description of changes:

[2.3.1-6.el8]
- OLAM-907 Bump rollup version to fix CVE-2026-27606



ELSA-2026-4472 Moderate: Oracle Linux 9 compat-openssl11 security update


Oracle Linux Security Advisory ELSA-2026-4472

http://linux.oracle.com/errata/ELSA-2026-4472.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
compat-openssl11-1.1.1k-5.el9_7.1.i686.rpm
compat-openssl11-1.1.1k-5.el9_7.1.x86_64.rpm

aarch64:
compat-openssl11-1.1.1k-5.el9_7.1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/compat-openssl11-1.1.1k-5.el9_7.1.src.rpm

Related CVEs:

CVE-2025-69419

Description of changes:

[1:1.1.1k-5.2]
- Fixes CVE-2025-69419 OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing
Resolves: RHEL-142722



OLAMSA-2026-0004 Important: Oracle Linux 8 ol-automation-manager security update


Oracle Linux Security Advisory OLAMSA-2026-0004

http://linux.oracle.com/errata/OLAMSA-2026-0004.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
ol-automation-manager-2.2.0-46.el8.x86_64.rpm
ol-automation-manager-cli-2.2.0-46.el8.noarch.rpm
python311-olamkit-2.2.0-46.el8.noarch.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/ol-automation-manager-2.2.0-46.el8.src.rpm

Related CVEs:

CVE-2026-27606

Description of changes:

[2.2.0-46.el8]
- OLAM-907 Bump rollup version to fix CVE-2026-27606



ELBA-2026-4190 Oracle Linux 9 kmod-kvdo bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2026-4190

http://linux.oracle.com/errata/ELBA-2026-4190.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
kmod-kvdo-8.2.6.3-176.0.1.el9_7.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/kmod-kvdo-8.2.6.3-176.0.1.el9_7.src.rpm

Description of changes:

[8.2.6.3-176.0.1]
- Update for kernel-5.14.0-611.el9
- add OL signature



ELSA-2026-4456 Important: Oracle Linux 9 .NET 9.0 security update


Oracle Linux Security Advisory ELSA-2026-4456

http://linux.oracle.com/errata/ELSA-2026-4456.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
aspnetcore-runtime-9.0-9.0.14-1.0.1.el9_7.x86_64.rpm
aspnetcore-runtime-dbg-9.0-9.0.14-1.0.1.el9_7.x86_64.rpm
aspnetcore-targeting-pack-9.0-9.0.14-1.0.1.el9_7.x86_64.rpm
dotnet-apphost-pack-9.0-9.0.14-1.0.1.el9_7.x86_64.rpm
dotnet-hostfxr-9.0-9.0.14-1.0.1.el9_7.x86_64.rpm
dotnet-runtime-9.0-9.0.14-1.0.1.el9_7.x86_64.rpm
dotnet-runtime-dbg-9.0-9.0.14-1.0.1.el9_7.x86_64.rpm
dotnet-sdk-9.0-9.0.115-1.0.1.el9_7.x86_64.rpm
dotnet-sdk-9.0-source-built-artifacts-9.0.115-1.0.1.el9_7.x86_64.rpm
dotnet-sdk-aot-9.0-9.0.115-1.0.1.el9_7.x86_64.rpm
dotnet-sdk-dbg-9.0-9.0.115-1.0.1.el9_7.x86_64.rpm
dotnet-targeting-pack-9.0-9.0.14-1.0.1.el9_7.x86_64.rpm
dotnet-templates-9.0-9.0.115-1.0.1.el9_7.x86_64.rpm
netstandard-targeting-pack-2.1-9.0.115-1.0.1.el9_7.x86_64.rpm

aarch64:
aspnetcore-runtime-9.0-9.0.14-1.0.1.el9_7.aarch64.rpm
aspnetcore-runtime-dbg-9.0-9.0.14-1.0.1.el9_7.aarch64.rpm
aspnetcore-targeting-pack-9.0-9.0.14-1.0.1.el9_7.aarch64.rpm
dotnet-apphost-pack-9.0-9.0.14-1.0.1.el9_7.aarch64.rpm
dotnet-hostfxr-9.0-9.0.14-1.0.1.el9_7.aarch64.rpm
dotnet-runtime-9.0-9.0.14-1.0.1.el9_7.aarch64.rpm
dotnet-runtime-dbg-9.0-9.0.14-1.0.1.el9_7.aarch64.rpm
dotnet-sdk-9.0-9.0.115-1.0.1.el9_7.aarch64.rpm
dotnet-sdk-9.0-source-built-artifacts-9.0.115-1.0.1.el9_7.aarch64.rpm
dotnet-sdk-aot-9.0-9.0.115-1.0.1.el9_7.aarch64.rpm
dotnet-sdk-dbg-9.0-9.0.115-1.0.1.el9_7.aarch64.rpm
dotnet-targeting-pack-9.0-9.0.14-1.0.1.el9_7.aarch64.rpm
dotnet-templates-9.0-9.0.115-1.0.1.el9_7.aarch64.rpm
netstandard-targeting-pack-2.1-9.0.115-1.0.1.el9_7.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/dotnet9.0-9.0.115-1.0.1.el9_7.src.rpm

Related CVEs:

CVE-2026-26127
CVE-2026-26130

Description of changes:

[9.0.115-1.0.1]
- Add support for Oracle Linux

[9.0.115-1]
- Update to .NET SDK 9.0.115 and Runtime 9.0.14
- Resolves: RHEL-152944



ELSA-2026-4442 Moderate: Oracle Linux 8 vim security update


Oracle Linux Security Advisory ELSA-2026-4442

http://linux.oracle.com/errata/ELSA-2026-4442.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
vim-X11-8.0.1763-22.0.1.el8_10.x86_64.rpm
vim-common-8.0.1763-22.0.1.el8_10.x86_64.rpm
vim-enhanced-8.0.1763-22.0.1.el8_10.x86_64.rpm
vim-filesystem-8.0.1763-22.0.1.el8_10.noarch.rpm
vim-minimal-8.0.1763-22.0.1.el8_10.x86_64.rpm

aarch64:
vim-X11-8.0.1763-22.0.1.el8_10.aarch64.rpm
vim-common-8.0.1763-22.0.1.el8_10.aarch64.rpm
vim-enhanced-8.0.1763-22.0.1.el8_10.aarch64.rpm
vim-filesystem-8.0.1763-22.0.1.el8_10.noarch.rpm
vim-minimal-8.0.1763-22.0.1.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/vim-8.0.1763-22.0.1.el8_10.src.rpm

Related CVEs:

CVE-2026-25749

Description of changes:

[8.0.1763-22.0.1]
- Remove upstream references [Orabug: 31197557]
- Added glibc-gconv-extra to common requires to provide ISO-8859-2 [Orabug: 34114984]

[2:8.0.1763-22]
- RHEL-147935 CVE-2026-25749 vim: Heap Overflow in Vim



ELSA-2026-4455 Important: Oracle Linux 8 .NET 8.0 security update


Oracle Linux Security Advisory ELSA-2026-4455

http://linux.oracle.com/errata/ELSA-2026-4455.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
aspnetcore-runtime-8.0-8.0.25-1.0.1.el8_10.x86_64.rpm
aspnetcore-runtime-dbg-8.0-8.0.25-1.0.1.el8_10.x86_64.rpm
aspnetcore-targeting-pack-8.0-8.0.25-1.0.1.el8_10.x86_64.rpm
dotnet-apphost-pack-8.0-8.0.25-1.0.1.el8_10.x86_64.rpm
dotnet-hostfxr-8.0-8.0.25-1.0.1.el8_10.x86_64.rpm
dotnet-runtime-8.0-8.0.25-1.0.1.el8_10.x86_64.rpm
dotnet-runtime-dbg-8.0-8.0.25-1.0.1.el8_10.x86_64.rpm
dotnet-sdk-8.0-8.0.125-1.0.1.el8_10.x86_64.rpm
dotnet-sdk-8.0-source-built-artifacts-8.0.125-1.0.1.el8_10.x86_64.rpm
dotnet-sdk-dbg-8.0-8.0.125-1.0.1.el8_10.x86_64.rpm
dotnet-targeting-pack-8.0-8.0.25-1.0.1.el8_10.x86_64.rpm
dotnet-templates-8.0-8.0.125-1.0.1.el8_10.x86_64.rpm

aarch64:
aspnetcore-runtime-8.0-8.0.25-1.0.1.el8_10.aarch64.rpm
aspnetcore-runtime-dbg-8.0-8.0.25-1.0.1.el8_10.aarch64.rpm
aspnetcore-targeting-pack-8.0-8.0.25-1.0.1.el8_10.aarch64.rpm
dotnet-apphost-pack-8.0-8.0.25-1.0.1.el8_10.aarch64.rpm
dotnet-hostfxr-8.0-8.0.25-1.0.1.el8_10.aarch64.rpm
dotnet-runtime-8.0-8.0.25-1.0.1.el8_10.aarch64.rpm
dotnet-runtime-dbg-8.0-8.0.25-1.0.1.el8_10.aarch64.rpm
dotnet-sdk-8.0-8.0.125-1.0.1.el8_10.aarch64.rpm
dotnet-sdk-8.0-source-built-artifacts-8.0.125-1.0.1.el8_10.aarch64.rpm
dotnet-sdk-dbg-8.0-8.0.125-1.0.1.el8_10.aarch64.rpm
dotnet-targeting-pack-8.0-8.0.25-1.0.1.el8_10.aarch64.rpm
dotnet-templates-8.0-8.0.125-1.0.1.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/dotnet8.0-8.0.125-1.0.1.el8_10.src.rpm

Related CVEs:

CVE-2026-26130

Description of changes:

[8.0.125-1.0.1]
- Add support for Oracle Linux

[8.0.125-1]
- Update to .NET SDK 8.0.125 and Runtime 8.0.25
- Resolves: RHEL-152929



ELSA-2026-4463 Moderate: Oracle Linux 8 python3.12 security update


Oracle Linux Security Advisory ELSA-2026-4463

http://linux.oracle.com/errata/ELSA-2026-4463.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
python3.12-3.12.12-3.el8_10.i686.rpm
python3.12-3.12.12-3.el8_10.x86_64.rpm
python3.12-debug-3.12.12-3.el8_10.i686.rpm
python3.12-debug-3.12.12-3.el8_10.x86_64.rpm
python3.12-devel-3.12.12-3.el8_10.i686.rpm
python3.12-devel-3.12.12-3.el8_10.x86_64.rpm
python3.12-idle-3.12.12-3.el8_10.i686.rpm
python3.12-idle-3.12.12-3.el8_10.x86_64.rpm
python3.12-libs-3.12.12-3.el8_10.i686.rpm
python3.12-libs-3.12.12-3.el8_10.x86_64.rpm
python3.12-rpm-macros-3.12.12-3.el8_10.noarch.rpm
python3.12-test-3.12.12-3.el8_10.i686.rpm
python3.12-test-3.12.12-3.el8_10.x86_64.rpm
python3.12-tkinter-3.12.12-3.el8_10.i686.rpm
python3.12-tkinter-3.12.12-3.el8_10.x86_64.rpm

aarch64:
python3.12-3.12.12-3.el8_10.aarch64.rpm
python3.12-debug-3.12.12-3.el8_10.aarch64.rpm
python3.12-devel-3.12.12-3.el8_10.aarch64.rpm
python3.12-idle-3.12.12-3.el8_10.aarch64.rpm
python3.12-libs-3.12.12-3.el8_10.aarch64.rpm
python3.12-rpm-macros-3.12.12-3.el8_10.noarch.rpm
python3.12-test-3.12.12-3.el8_10.aarch64.rpm
python3.12-tkinter-3.12.12-3.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/python3.12-3.12.12-3.el8_10.src.rpm

Related CVEs:

CVE-2025-15366
CVE-2025-15367
CVE-2026-0865
CVE-2026-1299

Description of changes:

[3.12.12-3]
- Security fixes for CVE-2026-0865, CVE-2025-15366, CVE-2025-15367 and CVE-2026-1299
Resolves: RHEL-143065
Resolves: RHEL-143122
Resolves: RHEL-144862



ELSA-2026-4458 Important: Oracle Linux 8 .NET 10.0 security update


Oracle Linux Security Advisory ELSA-2026-4458

http://linux.oracle.com/errata/ELSA-2026-4458.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
aspnetcore-runtime-10.0-10.0.4-1.0.1.el8_10.x86_64.rpm
aspnetcore-runtime-dbg-10.0-10.0.4-1.0.1.el8_10.x86_64.rpm
aspnetcore-targeting-pack-10.0-10.0.4-1.0.1.el8_10.x86_64.rpm
dotnet-10.0.104-1.0.1.el8_10.x86_64.rpm
dotnet-apphost-pack-10.0-10.0.4-1.0.1.el8_10.x86_64.rpm
dotnet-host-10.0.4-1.0.1.el8_10.x86_64.rpm
dotnet-hostfxr-10.0-10.0.4-1.0.1.el8_10.x86_64.rpm
dotnet-runtime-10.0-10.0.4-1.0.1.el8_10.x86_64.rpm
dotnet-runtime-dbg-10.0-10.0.4-1.0.1.el8_10.x86_64.rpm
dotnet-sdk-10.0-10.0.104-1.0.1.el8_10.x86_64.rpm
dotnet-sdk-10.0-source-built-artifacts-10.0.104-1.0.1.el8_10.x86_64.rpm
dotnet-sdk-aot-10.0-10.0.104-1.0.1.el8_10.x86_64.rpm
dotnet-sdk-dbg-10.0-10.0.104-1.0.1.el8_10.x86_64.rpm
dotnet-targeting-pack-10.0-10.0.4-1.0.1.el8_10.x86_64.rpm
dotnet-templates-10.0-10.0.104-1.0.1.el8_10.x86_64.rpm

aarch64:
aspnetcore-runtime-10.0-10.0.4-1.0.1.el8_10.aarch64.rpm
aspnetcore-runtime-dbg-10.0-10.0.4-1.0.1.el8_10.aarch64.rpm
aspnetcore-targeting-pack-10.0-10.0.4-1.0.1.el8_10.aarch64.rpm
dotnet-10.0.104-1.0.1.el8_10.aarch64.rpm
dotnet-apphost-pack-10.0-10.0.4-1.0.1.el8_10.aarch64.rpm
dotnet-host-10.0.4-1.0.1.el8_10.aarch64.rpm
dotnet-hostfxr-10.0-10.0.4-1.0.1.el8_10.aarch64.rpm
dotnet-runtime-10.0-10.0.4-1.0.1.el8_10.aarch64.rpm
dotnet-runtime-dbg-10.0-10.0.4-1.0.1.el8_10.aarch64.rpm
dotnet-sdk-10.0-10.0.104-1.0.1.el8_10.aarch64.rpm
dotnet-sdk-10.0-source-built-artifacts-10.0.104-1.0.1.el8_10.aarch64.rpm
dotnet-sdk-aot-10.0-10.0.104-1.0.1.el8_10.aarch64.rpm
dotnet-sdk-dbg-10.0-10.0.104-1.0.1.el8_10.aarch64.rpm
dotnet-targeting-pack-10.0-10.0.4-1.0.1.el8_10.aarch64.rpm
dotnet-templates-10.0-10.0.104-1.0.1.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/dotnet10.0-10.0.104-1.0.1.el8_10.src.rpm

Related CVEs:

CVE-2026-26127
CVE-2026-26130

Description of changes:

[10.0.104-1.0.1]
- Add support for Oracle Linux

[10.0.104-1]
- Update to .NET SDK 10.0.104 and Runtime 10.0.4
- Resolves: RHEL-152949