Oracle Linux 6311 Published by

Oracle Linux has announced the release of multiple security updates, which include doxygen, python-jinja2, squid, firefox, webkit2gtk3, a kernel bug fix, mokutil, oracle-database-preinstall-23ai, firefox, openssh, kernel, webkit2gtk3, cockpit, and krb5:

ELSA-2025-1255 Moderate: Oracle Linux 7 doxygen security update
ELSA-2025-1250 Moderate: Oracle Linux 7 python-jinja2 security update
ELSA-2024-11049 Important: Oracle Linux 7 squid security update
ELSA-2025-2452 Important: Oracle Linux 8 firefox security update
ELSA-2025-2034 Important: Oracle Linux 8 webkit2gtk3 security update
ELBA-2025-2352 Oracle Linux 8 kernel bug fix and enhancement update
ELBA-2025-20144 Oracle Linux 8 mokutil bug fix update
ELBA-2025-20129 Oracle Linux 8 oracle-database-preinstall-23ai bug fix update
ELSA-2025-2359 Important: Oracle Linux 9 firefox security update
ELBA-2025-20145 Oracle Linux 9 openssh bug fix update
ELBA-2025-2263 Oracle Linux 9 kernel bug fix and enhancement update
ELSA-2025-2035 Important: Oracle Linux 9 webkit2gtk3 security update
ELBA-2025-20142 Oracle Linux 9 cockpit bug fix update
ELSA-2025-1352 Moderate: Oracle Linux 7 krb5 security update




ELSA-2025-1255 Moderate: Oracle Linux 7 doxygen security update


Oracle Linux Security Advisory ELSA-2025-1255

http://linux.oracle.com/errata/ELSA-2025-1255.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
doxygen-1.8.5-4.0.1.el7.x86_64.rpm
doxygen-doxywizard-1.8.5-4.0.1.el7.x86_64.rpm
doxygen-latex-1.8.5-4.0.1.el7.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates//doxygen-1.8.5-4.0.1.el7.src.rpm

Related CVEs:

CVE-2020-11023

Description of changes:

[1:1.8.5-4.0.1]
- Fix CVE-2020-11022 and CVE-2022-11023 in vendored jQuery [Orabug: 37577394]



ELSA-2025-1250 Moderate: Oracle Linux 7 python-jinja2 security update


Oracle Linux Security Advisory ELSA-2025-1250

http://linux.oracle.com/errata/ELSA-2025-1250.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
python-jinja2-2.7.2-4.0.1.el7.noarch.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates//python-jinja2-2.7.2-4.0.1.el7.src.rpm

Related CVEs:

CVE-2024-56326

Description of changes:

[2.7.2-4.0.1]
- Fix for CVE-2024-56326 [Orabug: 37576737]



ELSA-2024-11049 Important: Oracle Linux 7 squid security update


Oracle Linux Security Advisory ELSA-2024-11049

http://linux.oracle.com/errata/ELSA-2024-11049.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
squid-3.5.20-17.0.5.el7_9.13.x86_64.rpm
squid-migration-script-3.5.20-17.0.5.el7_9.13.x86_64.rpm
squid-sysvinit-3.5.20-17.0.5.el7_9.13.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates//squid-3.5.20-17.0.5.el7_9.13.src.rpm

Related CVEs:

CVE-2023-46846

Description of changes:

[7:3.5.20-17.0.5.13]
- Fixed cve 2023-46846 for http and icap request/response smuggling [Orabug: 37326730]



ELSA-2025-2452 Important: Oracle Linux 8 firefox security update


Oracle Linux Security Advisory ELSA-2025-2452

http://linux.oracle.com/errata/ELSA-2025-2452.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
firefox-128.8.0-1.0.1.el8_10.x86_64.rpm

aarch64:
firefox-128.8.0-1.0.1.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates//firefox-128.8.0-1.0.1.el8_10.src.rpm

Related CVEs:

CVE-2025-1930
CVE-2025-1931
CVE-2025-1932
CVE-2025-1933
CVE-2025-1934
CVE-2025-1935
CVE-2025-1936
CVE-2025-1937
CVE-2025-1938

Description of changes:

[128.8.0-1.0.1]
- Fix firefox-oracle-default-prefs.js for new nss [Orabug: 37079789]

[128.8.0]
- Add debranding patches (Mustafa Gezen)
- Add OpenELA default preferences (Louis Abel)

[128.8.0-1]
- Update to 128.8.0 build1



ELSA-2025-2034 Important: Oracle Linux 8 webkit2gtk3 security update


Oracle Linux Security Advisory ELSA-2025-2034

http://linux.oracle.com/errata/ELSA-2025-2034.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
webkit2gtk3-2.46.6-1.el8_10.i686.rpm
webkit2gtk3-2.46.6-1.el8_10.x86_64.rpm
webkit2gtk3-devel-2.46.6-1.el8_10.i686.rpm
webkit2gtk3-devel-2.46.6-1.el8_10.x86_64.rpm
webkit2gtk3-jsc-2.46.6-1.el8_10.i686.rpm
webkit2gtk3-jsc-2.46.6-1.el8_10.x86_64.rpm
webkit2gtk3-jsc-devel-2.46.6-1.el8_10.i686.rpm
webkit2gtk3-jsc-devel-2.46.6-1.el8_10.x86_64.rpm

aarch64:
webkit2gtk3-2.46.6-1.el8_10.aarch64.rpm
webkit2gtk3-devel-2.46.6-1.el8_10.aarch64.rpm
webkit2gtk3-jsc-2.46.6-1.el8_10.aarch64.rpm
webkit2gtk3-jsc-devel-2.46.6-1.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates//webkit2gtk3-2.46.6-1.el8_10.src.rpm

Related CVEs:

CVE-2024-54543
CVE-2025-24143
CVE-2025-24150
CVE-2025-24158
CVE-2025-24162

Description of changes:

[2.46.6-1]
- Update to 2.46.6



ELBA-2025-2352 Oracle Linux 8 kernel bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2025-2352

http://linux.oracle.com/errata/ELBA-2025-2352.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
bpftool-4.18.0-553.42.1.el8_10.x86_64.rpm
kernel-4.18.0-553.42.1.el8_10.x86_64.rpm
kernel-abi-stablelists-4.18.0-553.42.1.el8_10.noarch.rpm
kernel-core-4.18.0-553.42.1.el8_10.x86_64.rpm
kernel-cross-headers-4.18.0-553.42.1.el8_10.x86_64.rpm
kernel-debug-4.18.0-553.42.1.el8_10.x86_64.rpm
kernel-debug-core-4.18.0-553.42.1.el8_10.x86_64.rpm
kernel-debug-devel-4.18.0-553.42.1.el8_10.x86_64.rpm
kernel-debug-modules-4.18.0-553.42.1.el8_10.x86_64.rpm
kernel-debug-modules-extra-4.18.0-553.42.1.el8_10.x86_64.rpm
kernel-devel-4.18.0-553.42.1.el8_10.x86_64.rpm
kernel-doc-4.18.0-553.42.1.el8_10.noarch.rpm
kernel-headers-4.18.0-553.42.1.el8_10.x86_64.rpm
kernel-modules-4.18.0-553.42.1.el8_10.x86_64.rpm
kernel-modules-extra-4.18.0-553.42.1.el8_10.x86_64.rpm
kernel-tools-4.18.0-553.42.1.el8_10.x86_64.rpm
kernel-tools-libs-4.18.0-553.42.1.el8_10.x86_64.rpm
perf-4.18.0-553.42.1.el8_10.x86_64.rpm
python3-perf-4.18.0-553.42.1.el8_10.x86_64.rpm
kernel-tools-libs-devel-4.18.0-553.42.1.el8_10.x86_64.rpm

aarch64:
bpftool-4.18.0-553.42.1.el8_10.aarch64.rpm
kernel-cross-headers-4.18.0-553.42.1.el8_10.aarch64.rpm
kernel-headers-4.18.0-553.42.1.el8_10.aarch64.rpm
kernel-tools-4.18.0-553.42.1.el8_10.aarch64.rpm
kernel-tools-libs-4.18.0-553.42.1.el8_10.aarch64.rpm
perf-4.18.0-553.42.1.el8_10.aarch64.rpm
python3-perf-4.18.0-553.42.1.el8_10.aarch64.rpm
kernel-tools-libs-devel-4.18.0-553.42.1.el8_10.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates//kernel-4.18.0-553.42.1.el8_10.src.rpm

Description of changes:

[4.18.0-553.42.1.el8_10.OL8]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64