Explore top 10 tips to secure your open-source projects now. Read More
×The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-10669 http://linux.oracle.com/errata/ELSA-2025-10669.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: bpftool-4.18.0-553.60.1.el8_10.x86_64.rpm kernel-4.18.0-553.60.1.el8_10.x86_64.rpm kernel-abi-stablelists-4.18.0-553.60.1.el8_10.noarch.rpm kernel-core-4.18.0-553.60.1.el8_10.x86_64.rpm kernel-cross-headers-4.18.0-553.60.1.el8_10.x86_64.rpm kernel-debug-4.18.0-553.60.1.el8_10.x86_64.rpm kernel-debug-core-4.18.0-553.60.1.el8_10.x86_64.rpm kernel-debug-devel-4.18.0-553.60.1.el8_10.x86_64.rpm kernel-debug-modules-4.18.0-553.60.1.el8_10.x86_64.rpm kernel-debug-modules-extra-4.18.0-553.60.1.el8_10.x86_64.rpm kernel-devel-4.18.0-553.60.1.el8_10.x86_64.rpm kernel-doc-4.18.0-553.60.1.el8_10.noarch.rpm kernel-headers-4.18.0-553.60.1.el8_10.x86_64.rpm kernel-modules-4.18.0-553.60.1.el8_10.x86_64.rpm kernel-modules-extra-4.18.0-553.60.1.el8_10.x86_64.rpm kernel-tools-4.18.0-553.60.1.el8_10.x86_64.rpm kernel-tools-libs-4.18.0-553.60.1.el8_10.x86_64.rpm kernel-tools-libs-devel-4.18.0-553.60.1.el8_10.x86_64.rpm perf-4.18.0-553.60.1.el8_10.x86_64.rpm python3-perf-4.18.0-553.60.1.el8_10.x86_64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/kernel-4.18.0-553.60.1.el8_10.src.rpm Related CVEs: CVE-2022-49111 CVE-2022-49136 CVE-2022-49846 Description of changes: - [4.18.0-553.60.1.el8_10.OL8] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-3208 http://linux.oracle.com/errata/ELSA-2025-3208.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: bpftool-7.4.0-503.34.1.el9_5.x86_64.rpm kernel-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-abi-stablelists-5.14.0-503.34.1.el9_5.noarch.rpm kernel-core-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-debug-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-debug-core-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-debug-devel-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-debug-devel-matched-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-debug-modules-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-debug-modules-core-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-debug-modules-extra-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-debug-uki-virt-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-devel-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-devel-matched-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-doc-5.14.0-503.34.1.el9_5.noarch.rpm kernel-headers-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-modules-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-modules-core-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-modules-extra-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-tools-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-tools-libs-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-uki-virt-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-uki-virt-addons-5.14.0-503.34.1.el9_5.x86_64.rpm perf-5.14.0-503.34.1.el9_5.x86_64.rpm python3-perf-5.14.0-503.34.1.el9_5.x86_64.rpm rtla-5.14.0-503.34.1.el9_5.x86_64.rpm rv-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-cross-headers-5.14.0-503.34.1.el9_5.x86_64.rpm kernel-tools-libs-devel-5.14.0-503.34.1.el9_5.x86_64.rpm libperf-5.14.0-503.34.1.el9_5.x86_64.rpm aarch64: bpftool-7.4.0-503.34.1.el9_5.aarch64.rpm kernel-headers-5.14.0-503.34.1.el9_5.aarch64.rpm kernel-tools-5.14.0-503.34.1.el9_5.aarch64.rpm kernel-tools-libs-5.14.0-503.34.1.el9_5.aarch64.rpm perf-5.14.0-503.34.1.el9_5.aarch64.rpm python3-perf-5.14.0-503.34.1.el9_5.aarch64.rpm rtla-5.14.0-503.34.1.el9_5.aarch64.rpm rv-5.14.0-503.34.1.el9_5.aarch64.rpm kernel-cross-headers-5.14.0-503.34.1.el9_5.aarch64.rpm kernel-tools-libs-devel-5.14.0-503.34.1.el9_5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//kernel-5.14.0-503.34.1.el9_5.src.rpm Related CVEs: CVE-2025-21785 Description of changes: [5.14.0-503.34.1.el9_5.OL9] - Disable UKI signing [Orabug: 36571828] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-12845 http://linux.oracle.com/errata/ELSA-2024-12845.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-5.4.17-2136.336.5.3.1.el7uek.x86_64.rpm kernel-uek-container-5.4.17-2136.336.5.3.1.el7uek.x86_64.rpm kernel-uek-container-debug-5.4.17-2136.336.5.3.1.el7uek.x86_64.rpm kernel-uek-debug-5.4.17-2136.336.5.3.1.el7uek.x86_64.rpm kernel-uek-debug-devel-5.4.17-2136.336.5.3.1.el7uek.x86_64.rpm kernel-uek-devel-5.4.17-2136.336.5.3.1.el7uek.x86_64.rpm kernel-uek-doc-5.4.17-2136.336.5.3.1.el7uek.noarch.rpm kernel-uek-tools-5.4.17-2136.336.5.3.1.el7uek.x86_64.rpm aarch64: kernel-uek-5.4.17-2136.336.5.3.1.el7uek.aarch64.rpm kernel-uek-debug-5.4.17-2136.336.5.3.1.el7uek.aarch64.rpm kernel-uek-debug-devel-5.4.17-2136.336.5.3.1.el7uek.aarch64.rpm kernel-uek-devel-5.4.17-2136.336.5.3.1.el7uek.aarch64.rpm kernel-uek-doc-5.4.17-2136.336.5.3.1.el7uek.noarch.rpm kernel-uek-tools-5.4.17-2136.336.5.3.1.el7uek.aarch64.rpm kernel-uek-tools-libs-5.4.17-2136.336.5.3.1.el7uek.aarch64.rpm perf-5.4.17-2136.336.5.3.1.el7uek.aarch64.rpm python-perf-5.4.17-2136.336.5.3.1.el7uek.aarch64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates//kernel-uek-5.4.17-2136.336.5.3.1.el7uek.src.rpm Related CVEs: CVE-2024-26734 CVE-2024-47674 Description of changes: [5.4.17-2136.336.5.3.1.el8uek] - mm: avoid leaving partial pfn mappings around in error case (Linus Torvalds) [Orabug: 37311329] {CVE-2024-47674} - mm: add remap_pfn_range_notrack (Christoph Hellwig) [Orabug: 37311329] {CVE-2024-47674} - mm/memory.c: make remap_pfn_range() reject unaligned addr (Alex Zhang) [Orabug: 37311329] {CVE-2024-47674} - mm: fix ambiguous comments for better code readability (chenqiwu) [Orabug: 37311329] {CVE-2024-47674} - mm: clarify a confusing comment for remap_pfn_range() (WANG Wenhu) [Orabug: 37311329] {CVE-2024-47674} - devlink:fix possible use-after-free and memory leaks in devlink_init() (Vasiliy Kovalev) [Orabug: 37311325] {CVE-2024-26734} _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-9541 http://linux.oracle.com/errata/ELSA-2024-9541.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: expat-2.5.0-3.el9_5.1.i686.rpm expat-2.5.0-3.el9_5.1.x86_64.rpm expat-devel-2.5.0-3.el9_5.1.i686.rpm expat-devel-2.5.0-3.el9_5.1.x86_64.rpm aarch64: expat-2.5.0-3.el9_5.1.aarch64.rpm expat-devel-2.5.0-3.el9_5.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//expat-2.5.0-3.el9_5.1.src.rpm Related CVEs: CVE-2024-50602 Description of changes: [2.5.0-3.1] - Fix CVE-2024-50602 - Resolves: RHEL-65064 [2.5.0-3] - Fix CVE-2024-45490, CVE-2024-45491, CVE-2024-45492 - Resolves: RHEL-56761 - Resolves: RHEL-57520 - Resolves: RHEL-57511 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-3826 http://linux.oracle.com/errata/ELSA-2024-3826.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: podman-4.9.4-4.0.1.el9_4.x86_64.rpm podman-docker-4.9.4-4.0.1.el9_4.noarch.rpm podman-plugins-4.9.4-4.0.1.el9_4.x86_64.rpm podman-remote-4.9.4-4.0.1.el9_4.x86_64.rpm podman-tests-4.9.4-4.0.1.el9_4.x86_64.rpm aarch64: podman-4.9.4-4.0.1.el9_4.aarch64.rpm podman-docker-4.9.4-4.0.1.el9_4.noarch.rpm podman-plugins-4.9.4-4.0.1.el9_4.aarch64.rpm podman-remote-4.9.4-4.0.1.el9_4.aarch64.rpm podman-tests-4.9.4-4.0.1.el9_4.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//podman-4.9.4-4.0.1.el9_4.src.rpm Related CVEs: CVE-2023-45290 CVE-2024-28176 CVE-2024-28180 Description of changes: [4.9.4-4.0.1] - Improved saving remote build context to tarfile in Podman daemon [Orabug: 36495655] - Add devices on container startup, not on creation - Backport fast gzip for compression [Orabug: 36420418] - overlay: Put should ignore ENINVAL for Unmount [Orabug: 36234694] - Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404] [4:4.9.4-4] - update to the latest content of https://github.com/containers/podman/tree/v4.9-rhel (https://github.com/containers/podman/commit/4afc71a) - Resolves: RHEL-28735 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network . Oracle Linux Security Advisory ELSA-2021-9459 https://linux.oracle.com/errata/ELSA-2021-9459.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-doc-4.1.12-124.54.6.1.el7uek.noarch.rpm kernel-uek-firmware-4.1.12-124.54.6.1.el7uek.noarch.rpm kernel-uek-4.1.12-124.54.6.1.el7uek.x86_64.rpm kernel-uek-devel-4.1.12-124.54.6.1.el7uek.x86_64.rpm kernel-uek-debug-4.1.12-124.54.6.1.el7uek.x86_64.rpm kernel-uek-debug-devel-4.1.12-124.54.6.1.el7uek.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates/kernel-uek-4.1.12-124.54.6.1.el7uek.src.rpm Related CVEs: CVE-2019-3900 CVE-2020-24586 CVE-2020-26139 CVE-2020-12114 CVE-2019-19448 CVE-2019-17133 CVE-2020-24587 CVE-2020-24588 CVE-2020-26139 CVE-2020-24587 CVE-2021-3655 CVE-2021-38160 CVE-2020-26140 CVE-2020-26141 CVE-2020-26142 CVE-2020-26143 CVE-2020-26144 CVE-2020-26145 CVE-2020-26146 CVE-2020-26147 CVE-2020-24586 CVE-2021-3715 CVE-2021-0512 CVE-2021-40490 Description of changes: [4.1.12-124.54.6.1.el7uek] - fs/namespace.c: fix mountpoint reference counter race (Piotr Krysiuk) [Orabug: 33369433] {CVE-2020-12114} {CVE-2020-12114} - btrfs: only search for left_info if there is no right_info in try_merge_free_space (Josef Bacik) [Orabug: 33369414] {CVE-2019-19448} {CVE-2019-19448} - cfg80211: wext: avoid copying malformed SSIDs (Will Deacon) [Orabug: 33369390] {CVE-2019-17133} - vhost_net: fix possible infinite loop (Jason Wang) [Orabug: 33369374] {CVE-2019-3900} {CVE-2019-3900} - vhost: introduce vhost_exceeds_weight() (Jason Wang) [Orabug: 33369374] {CVE-2019-3900} - vhost_net: introduce vhost_exceeds_weight() (Jason Wang) [Orabug: 33369374] {CVE-2019-3900} - vhost_net: use packet weight for rx handler, too (Paolo Abeni) [Orabug: 33369374] {CVE-2019-3900} - vhost-net: set packet weight of tx polling to 2 * vqsize (haibinzhang(张海斌)) [Orabug: 33369374] {CVE-2019-3900} - mac80211: extend protection against mixed key and fragment cache attacks (Wen Gong) [Orabug: 33369361] {CVE-2020-24586} {CVE-2020-26139} {CVE-2020-24587} {CVE-2020-24588} {CVE-2020-26139} {CVE-2020-26140} {CVE-2020-26141} {CVE-2020-26142} {CVE-2020-26143} {CVE-2020-26144} {CVE-2020-26145} {CVE-2020-26146} {CVE-2020-26147} {CVE-2020-24586} {CVE-2020-24587} - mac80211: do not accept/forward invalid EAPOL frames (Johannes Berg) [Orabug: 33369361] {CVE-2020-24586} {CVE-2020-26139} {CVE-2020-24587} {CVE-2020-24588} {CVE-2020-26139} {CVE-2020-26140} {CVE-2020-26141} {CVE-2020-26142} {CVE-2020-26143} {CVE-2020-26144} {CVE-2020-26145} {CVE-2020-26146} {CVE-2020-26147} - mac80211: prevent attacks on TKIP/WEP as well (Johannes Berg) [Orabug: 33369361] {CVE-2020-24586} {CVE-2020-26139} {CVE-2020-24587} {CVE-2020-24588} {CVE-2020-26139} {CVE-2020-26140} {CVE-2020-26141} {CVE-2020-26142} {CVE-2020-26143} {CVE-2020-26144} {CVE-2020-26145} {CVE-2020-26146} {CVE-2020-26147} - mac80211: check defrag PN against current frame (Johannes Berg) [Orabug: 33369361] {CVE-2020-24586} {CVE-2020-26139} {CVE-2020-24587} {CVE-2020-24588} {CVE-2020-26139} {CVE-2020-26140} {CVE-2020-26141} {CVE-2020-26142} {CVE-2020-26143} {CVE-2020-26144} {CVE-2020-26145} {CVE-2020-26146} {CVE-2020-26147} - mac80211: add fragment cache to sta_info (Johannes Berg) [Orabug: 33369361] {CVE-2020-24586} {CVE-2020-26139} {CVE-2020-24587} {CVE-2020-24588} {CVE-2020-26139} {CVE-2020-26140} {CVE-2020-26141} {CVE-2020-26142} {CVE-2020-26143} {CVE-2020-26144} {CVE-2020-26145} {CVE-2020-26146} {CVE-2020-26147} - mac80211: drop A-MSDUs on old ciphers (Johannes Berg) [Orabug: 33369361] {CVE-2020-24586} {CVE-2020-26139} {CVE-2020-24587} {CVE-2020-24588} {CVE-2020-26139} {CVE-2020-26140} {CVE-2020-26141} {CVE-2020-26142} {CVE-2020-26143} {CVE-2020-26144} {CVE-2020-26145} {CVE-2020-26146} {CVE-2020-26147} {CVE-2020-24588} - cfg80211: mitigate A-MSDU aggregation attacks (Mathy Vanhoef) [Orabug: 33369361] {CVE-2020-24586} {CVE-2020-26139} {CVE-2020-24587} {CVE-2020-24588} {CVE-2020-26139} {CVE-2020-26140} {CVE-2020-26141} {CVE-2020-26142} {CVE-2020-26143} {CVE-2020-26144} {CVE-2020-26145} {CVE-2020-26146} {CVE-2020-26147} {CVE-2020-24588} - mac80211: properly handle A-MSDUs that start with an RFC 1042 header (Mathy Vanhoef) [Orabug: 33369361] {CVE-2020-24586} {CVE-2020-26139} {CVE-2020-24587} {CVE-2020-24588} {CVE-2020-26139} {CVE-2020-26140} {CVE-2020-26141} {CVE-2020-26142} {CVE-2020-26143} {CVE-2020-26144} {CVE-2020-26145} {CVE-2020-26146} {CVE-2020-26147} - mac80211: prevent mixed key and fragment cache attacks (Mathy Vanhoef) [Orabug: 33369361] {CVE-2020-24586} {CVE-2020-26139} {CVE-2020-24587} {CVE-2020-24588} {CVE-2020-26139} {CVE-2020-26140} {CVE-2020-26141} {CVE-2020-26142} {CVE-2020-26143} {CVE-2020-26144} {CVE-2020-26145} {CVE-2020-26146} {CVE-2020-26147} {CVE-2020-24587} {CVE-2020-24586} - mac80211: assure all fragments are encrypted (Mathy Vanhoef) [Orabug: 33369361] {CVE-2020-24586} {CVE-2020-26139} {CVE-2020-24587} {CVE-2020-24588} {CVE-2020-26139} {CVE-2020-26140} {CVE-2020-26141} {CVE-2020-26142} {CVE-2020-26143} {CVE-2020-26144} {CVE-2020-26145} {CVE-2020-26146} {CVE-2020-26147} {CVE-2020-26147} - sctp: validate from_addr_param return (Marcelo Ricardo Leitner) [Orabug: 33369303] {CVE-2021-3655} - virtio_console: Assure used length from device is limited (Xie Yongji) [Orabug: 33369276] {CVE-2021-38160} - net_sched: cls_route: remove the right filter from hashtable (Cong Wang) [Orabug: 33369231] {CVE-2021-3715} - HID: make arrays usage and value to be the same (Will McVicker) [Orabug: 33369121] {CVE-2021-0512} - ext4: fix race writing to an inline_data file while its xattrs are changing (Theodore Ts'o) [Orabug: 33369043] {CVE-2021-40490} . Critical security patch available for Oracle Linux 7 addressing kernel flaws and associated modifications. More information within.. Oracle Linux, Kernel Update, Security Advisory, Linux RPM. . Severity: Important.LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.