Oracle Linux 6415 Published by

Oracle Linux has released security updates for its 10 and 8 versions. For Oracle Linux 10, an update to the perl-JSON-XS package was released to fix CVE-2025-40928, a moderate severity vulnerability. For Oracle Linux 8, a kernel bug fix update was released to address several vulnerabilities, including CVE-2025-37797, CVE-2022-50087, and others. The updates include various packages, such as OpenSSL and Kernel, and are available for download from the Unbreakable Linux Network (ULN).

ELSA-2025-17119 Moderate: Oracle Linux 10 perl-JSON-XS security update
ELBA-2025-16444 Oracle Linux 10 openssl bug fix and enhancement update
ELBA-2025-16919-1 Oracle Linux 8 kernel bug fix update




ELSA-2025-17119 Moderate: Oracle Linux 10 perl-JSON-XS security update


Oracle Linux Security Advisory ELSA-2025-17119

http://linux.oracle.com/errata/ELSA-2025-17119.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
perl-JSON-XS-4.04-1.el10_0.x86_64.rpm

aarch64:
perl-JSON-XS-4.04-1.el10_0.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/perl-JSON-XS-4.04-1.el10_0.src.rpm

Related CVEs:

CVE-2025-40928

Description of changes:

[1:4.04-1]
- Update to 4.04
- Resolves: RHEL-113624 - Fix CVE-2025-40928



ELBA-2025-16444 Oracle Linux 10 openssl bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-16444

http://linux.oracle.com/errata/ELBA-2025-16444.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
openssl-3.2.2-16.0.1.el10_0.4.x86_64.rpm
openssl-devel-3.2.2-16.0.1.el10_0.4.x86_64.rpm
openssl-libs-3.2.2-16.0.1.el10_0.4.x86_64.rpm
openssl-perl-3.2.2-16.0.1.el10_0.4.x86_64.rpm

aarch64:
openssl-3.2.2-16.0.1.el10_0.4.aarch64.rpm
openssl-devel-3.2.2-16.0.1.el10_0.4.aarch64.rpm
openssl-libs-3.2.2-16.0.1.el10_0.4.aarch64.rpm
openssl-perl-3.2.2-16.0.1.el10_0.4.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/openssl-3.2.2-16.0.1.el10_0.4.src.rpm

Description of changes:

[3.2.2-16.0.1.4]
- Replace upstream references [Orabug: 34340177]
- Update FIPS provider name [Orabug: 35824276]

[1:3.2.2-16.4]
- openssl 3.2.2 has 3_4_0 version in the symbol table (JIRA:RHEL-105518)



ELBA-2025-16919-1 Oracle Linux 8 kernel bug fix update


Oracle Linux Bug Fix Advisory ELBA-2025-16919-1

http://linux.oracle.com/errata/ELBA-2025-16919-1.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
bpftool-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm
kernel-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm
kernel-abi-stablelists-4.18.0-553.77.1.0.1.el8_10.noarch.rpm
kernel-core-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm
kernel-cross-headers-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm
kernel-debug-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm
kernel-debug-core-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm
kernel-debug-devel-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm
kernel-debug-modules-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm
kernel-debug-modules-extra-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm
kernel-devel-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm
kernel-doc-4.18.0-553.77.1.0.1.el8_10.noarch.rpm
kernel-headers-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm
kernel-modules-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm
kernel-modules-extra-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm
kernel-tools-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm
kernel-tools-libs-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm
kernel-tools-libs-devel-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm
perf-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm
python3-perf-4.18.0-553.77.1.0.1.el8_10.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/kernel-4.18.0-553.77.1.0.1.el8_10.src.rpm

Description of changes:

[4.18.0-553.77.1.0.1.el8_10.OL8]
- scsi: core: Restrict legal sdev_state transitions via sysfs (Uday Shankar) [Orabug: 37778230]

[4.18.0-553.77.1.el8_10.OL8]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64