Skip to content
Oracle Linux 9 osbuild-composer Security Patch Released

Oracle Linux 9 osbuild-composer Security Patch Released

First seen 7 Aug 2026, 08:28 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 8, 2026 at 08:07 UTC
  • Oracle released a critical security patch for osbuild-composer on August 6, 2026.
  • The patch addresses multiple vulnerabilities including CVE-2025-61726 and CVE-2026-4427.
  • Affected systems include Oracle Linux 9 for x86_64 and aarch64 architectures.

Oracle released an important security patch for osbuild-composer in Oracle Linux 9 on August 6, 2026, addressing multiple vulnerabilities. The patch resolves critical issues linked to CVEs including CVE-2025-61726, CVE-2025-68121, and CVE-2026-4427. These vulnerabilities could allow privilege escalation and system-wide damage if exploited. The affected packages include osbuild-composer and its core and worker components for both x86_64 and aarch64 architectures. Security professionals are advised to audit Linux privileges to mitigate risks. The patch is crucial for maintaining system integrity and preventing potential exploits. Users should apply the updates promptly to safeguard their systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2026-01-28
CVE-2025-61726 published
A vulnerability was disclosed that could lead to privilege escalation in Oracle Linux.
Linuxsecurity
2026-01-28
CVE-2025-61728 published
Another vulnerability was disclosed, also allowing for privilege escalation in Oracle Linux.
Linuxsecurity
2026-02-05
CVE-2025-68121 published
A vulnerability was disclosed that could lead to privilege escalation in Oracle Linux.
Linuxsecurity
2026-03-06
CVE-2026-27137 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-06
CVE-2026-25679 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-19
CVE-2026-4427 published
A vulnerability was disclosed that could allow privilege escalation in Oracle Linux systems.
Linuxsecurity
2026-03-20
CVE-2026-33186 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-26
CVE-2026-32286 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-08
CVE-2026-32283 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-08
CVE-2026-32280 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (4)

Following this threat?

Track CVE-2025-61726 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed