ELSA-2026-3753

ELSA-2026-3753 - osbuild-composer security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-03-05

Description


[149-4.0.1]
- Add missing dependency over dracut-config-rescue for image-installer [ORABUG: 38587453]
- Switch to UEKR8 repositories for OL9.6 [Orabug: 37962207]
- Add support to create OpenScap images [JIRA: OLDIS-35301]
- Simplify repository names [JIRA: OLDIS-35893]
- Refactor patches to fix some naming and set a correct kernel for Oracle Linux [Orabug: 37253643]
- Support using OCI variables inside built images [JIRA: OLDIS-35302]
- Support using repository definitons with OCI variables [JIRA: OLDIS-38657]
- Update repositories to contain OCI variables
- Remove image types Minimal-raw and wsl [JIRA: OLDIS-38123]
- Increase default /boot size to 1GB [Orabug: 36827079]
- Add support for OCI hybrid images [JIRA: OLDIS-33593]
- enable aarch64 OCI image builds [JIRA: OLDIS-33593]
- support for building OL8/9 images on Oracle Linux 9 [Orabug: 36400619]

[149-4]
- Rebuilt to fix:
- CVE-2025-61726
- CVE-2025-61728
- CVE-2025-61729
- CVE-2025-68121
- RHEL-146868
- RHEL-147086
- RHEL-147371
- RHEL-149626


Related CVEs


CVE-2025-61726
CVE-2025-61728
CVE-2025-61729
CVE-2025-68121

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) osbuild-composer-149-4.0.1.el9_7.src.rpmcda7fc273a0011da61e0392b20138cd5d439009b16abf6ad160ee06ed85d4724-ol9_aarch64_appstream
osbuild-composer-149-4.0.1.el9_7.aarch64.rpm9d0fb202c6b97b37f0a1356e6a9e1f7cfb82b3ccf84901f8fae84b794e61a3c6-ol9_aarch64_appstream
osbuild-composer-core-149-4.0.1.el9_7.aarch64.rpm4847bb709ea5ce67f793ff852ede47fc379ded1ccd1eef1821cd3781fd7b8e77-ol9_aarch64_appstream
osbuild-composer-worker-149-4.0.1.el9_7.aarch64.rpme21d1d2215fb8cfd817ab713e915325d5c8f47328a5e84d0a2b8930abb97de72-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) osbuild-composer-149-4.0.1.el9_7.src.rpmcda7fc273a0011da61e0392b20138cd5d439009b16abf6ad160ee06ed85d4724-ol9_x86_64_appstream
osbuild-composer-149-4.0.1.el9_7.x86_64.rpm7fabcd148dc0eac17a2d8e52e840c30a1348eb626f2904529ea7cd1e91f1d112-ol9_x86_64_appstream
osbuild-composer-core-149-4.0.1.el9_7.x86_64.rpm3199d2be398a3830467bae125948d638322a123709c3fb3a1074d4fb81db517c-ol9_x86_64_appstream
osbuild-composer-worker-149-4.0.1.el9_7.x86_64.rpmc9a9dc046cc6d5fb5119fbe0e1bd359f7aa59382849e427dbd29a0cb4192e989-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete