📖 ~4 min read • Source: ELSA advisory ELSA-2025-15699
Related CVEs: CVE-2025-21574 CVE-2024-13176 CVE-2025-21575 CVE-2025-21585 CVE-2025-30683 CVE-2025-30684
Table of contents
Symptom & Impact
On Oracle Linux 10 hosts running mysql-selinux and mysql8.4, the vulnerable code is started by something else – a web or application server, or an on-demand supervisor such as inetd, xinetd or a systemd socket unit – rather than by a service of its own. Patching replaces the files on disk immediately, but a long-running parent that has already loaded them (PHP-FPM workers, an application server, a persistent worker pool) keeps serving the old code until it is recycled. Connection-per-process supervisors pick the fix up on the next connection, so the exposure window differs sharply between the two and is worth confirming rather than assuming. mysql-selinux and mysql8.4 is started by a hosting server or an on-demand supervisor rather than by a unit of its own, so restart whatever launches it – not mysql-selinux and mysql8.4.
Environment & Reproduction
Reproduction targets Oracle Linux 10 running either the Red Hat Compatible Kernel (RHCK) or the Unbreakable Enterprise Kernel (UEK). Confirm release, kernel, and installed package:
cat /etc/oracle-release
uname -r
rpm -q mysql-selinux
dnf list installed mysql-selinux
dnf history list --reverse | head -20
Exercise the workload that uses mysql-selinux and mysql8.4 while collecting:
journalctl -u mysql-selinux -b --no-pager | tail -200
journalctl -xe --no-pager | tail -200
tail -200 /var/log/dnf.log
tail -200 /var/log/audit/audit.log
Root Cause Analysis
Root cause is documented in ELSA advisory ELSA-2025-15699. Upstream Red Hat / Oracle Linux maintainers shipped a fix in the corresponding mysql-selinux errata; running an outdated build leaves the host exposed and may trigger the failure modes described in the advisory. Correlate transaction history with system logs and SELinux audit entries to isolate the originating change:
dnf history list --reverse | head -30
dnf history info $(dnf history list | awk '/mysql-selinux/ {print $1; exit}')
ausearch -m AVC,USER_AVC -ts today | tail -100
cat /proc/sys/kernel/tainted # non-zero = kernel modules / out-of-tree drivers loaded
Quick Triage
Run these checks on Oracle Linux 10 to confirm the failure mode and current state of mysql-selinux:
rpm -q mysql-selinux # installed version
rpm -V mysql-selinux # verify file integrity
dnf updateinfo info --security mysql-selinux # any security advisories outstanding
systemctl --failed --no-pager
firewall-cmd --list-all 2>/dev/null || echo 'firewalld not running'
getenforce # SELinux mode
# If mysql-selinux ships a systemd unit (unit name may differ from the pkg name,
# e.g. httpd pkg/unit match, but bind→named, postgresql-server→postgresql):
dnf repoquery -l mysql-selinux and mysql8.4 2>/dev/null | grep -E '/lib/systemd/system/.*\.(service|socket|timer)$' # same check WITHOUT installing (EL7/Amazon Linux 2: yum install yum-utils, then: repoquery -l mysql-selinux and mysql8.4)
systemctl show --no-pager -p Type,RemainAfterExit <UNIT> # Type=oneshot (often paired with a .timer) means a one-shot job, NOT a daemon -- do not 'restart' it, let the timer fire
Step-by-Step Diagnosis
-
List failed units.
systemctl --failed --no-pager -
Follow the journal for
mysql-selinuxand the system bus.journalctl -u mysql-selinux -f --no-pager journalctl -xe -f --no-pager -
Check firewall posture (skip if firewalld is masked).
firewall-cmd --list-all-zones --permanent nft list ruleset 2>/dev/null | head -50 -
Surface SELinux denials and translate them to a policy module if needed.
ausearch -m AVC,USER_AVC -ts today ausearch -m AVC -ts today | audit2allow -a -M /tmp/local-fix # Inspect /tmp/local-fix.te before applying: sudo semodule -i /tmp/local-fix.pp -
Verify
mysql-selinuxintegrity and dependency closure.dnf check rpm -V mysql-selinux rpm -q --requires mysql-selinux | xargs -r rpm -q --whatprovides | head -
Correlate findings with
/var/log/dnf.log,dnf historyand ELSA advisory ELSA-2025-15699 to pin the change that introduced the regression.
Solution – Primary Fix
Apply the corrective dnf transaction referenced by ELSA advisory ELSA-2025-15699, reload affected systemd units, and reconcile firewalld / SELinux state:
sudo dnf clean expire-cache
sudo dnf -y update mysql-selinux
sudo systemctl daemon-reload
# If mysql-selinux ships a systemd unit (unit name may differ from pkg name):
sudo systemctl restart mysql-selinux
rpm -q mysql-selinux # confirm new NVR
systemctl is-active mysql-selinux # confirm running (if a unit exists)
If the advisory says a reboot is required (kernel, glibc, systemd, openssl):
sudo needs-restarting -r # reports kernel/init/glibc need
sudo systemctl reboot # or: sudo shutdown -r now
Need help applying this fix at scale? Our IT Solutions & Services team rolls Oracle Linux patches across estates with zero-downtime change windows and Ksplice live-patching. Get in touch for a free consultation.
Solution – Alternative Approaches
If the primary fix is not viable, choose from these alternatives:
-
Roll back the offending dnf transaction:
sudo dnf history list --reverse sudo dnf history undo <id> -
Pin
mysql-selinuxwith the versionlock plugin:sudo dnf install -y python3-dnf-plugin-versionlock sudo dnf versionlock add mysql-selinux sudo dnf versionlock list | grep mysql-selinux -
Downgrade to a known-good NVR from the repo cache or vault:
sudo dnf --showduplicates list mysql-selinux sudo dnf -y downgrade mysql-selinux-<older-NVR> -
Switch firewalld backend (nftables ↔ iptables) for compatibility:
sudo sed -i 's/^FirewallBackend=.*/FirewallBackend=iptables/' /etc/firewalld/firewalld.conf sudo systemctl restart firewalld -
If SELinux is suspected, switch to permissive briefly, capture denials, and author a custom module before re-enforcing:
sudo setenforce 0 # do NOT leave permissive # reproduce the failure sudo ausearch -m AVC -ts recent | audit2allow -a -M mylocal sudo semodule -i mylocal.pp sudo setenforce 1 -
Where the advisory has Ksplice coverage, live-patch without reboot (Oracle Linux Premier Support):
sudo uptrack-show # current live patches sudo uptrack-upgrade -y # apply all available uptrack-uname -r # effective kernel after live patching
Verification & Acceptance Criteria
All of these should pass after the fix:
rpm -q mysql-selinux # shows the expected fixed NVR
dnf updateinfo list --security installed | head # no security advisories pending for us
systemctl is-active mysql-selinux 2>/dev/null # active (if a unit exists)
journalctl -u mysql-selinux --since "5 minutes ago" --no-pager # no new errors
firewall-cmd --list-services # required services present
getenforce # intended mode (Enforcing/Permissive)
The conditions described in the advisory must no longer be reported for mysql-selinux and mysql8.4 across two consecutive runs.
Rollback Plan
Capture state before any change:
rpm -qa > /root/rpm-pre.txt
dnf history list --reverse > /root/dnf-history-pre.txt
# LVM snapshot of the root LV (size to ~10% of root):
sudo lvcreate -L 4G -s -n root_pre_patch /dev/mapper/$(lvs --noheadings -o lv_path | grep -m1 root | xargs basename)
To revert if the patch is bad:
sudo dnf history undo <id>
# Or downgrade just mysql-selinux to the previous NVR:
sudo dnf -y downgrade mysql-selinux
sudo systemctl daemon-reload
# For SELinux module additions:
sudo semodule -r mylocal
# Reboot only if kernel/initramfs/glibc were rolled back:
sudo systemctl reboot
For kernel rollbacks, select the previous entry from the GRUB menu or set it as default with grubby --set-default /boot/vmlinuz-<older>.
Prevention & Hardening
Prevent recurrence on Oracle Linux 10 hosts running mysql-selinux:
-
Enable scheduled security updates via
dnf-automatic:sudo dnf install -y dnf-automatic # Edit /etc/dnf/automatic.conf: # upgrade_type = security # apply_updates = yes sudo systemctl enable --now dnf-automatic.timer -
Subscribe to the Oracle Linux Errata RSS / mailing list at linux.oracle.com/security.
-
Mirror through a local yum/dnf repository:
sudo dnf install -y dnf-utils createrepo_c sudo reposync --download-metadata --downloadcomps -p /srv/repos -m --repo=ol10_baseos_latest sudo createrepo_c /srv/repos/ol-baseos -
Pin sensitive packages so they cannot be auto-upgraded:
sudo dnf install -y python3-dnf-plugin-versionlock sudo dnf versionlock add mysql-selinux -
Snapshot the root LV before every upgrade window:
sudo lvcreate -L 4G -s -n root_pre_$(date +%Y%m%d) /dev/<vg>/<root-lv> -
Monitor file integrity with AIDE:
sudo dnf install -y aide sudo aide --init && sudo mv /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz sudo aide --check -
Lock down with SELinux audit rules in
/etc/audit/rules.d/:# /etc/audit/rules.d/90-cp.rules -w /etc/passwd -p wa -k identity -w /etc/shadow -p wa -k identity -w /etc/sudoers -p wa -k privilege -a always,exit -F arch=b64 -S execve -k exec -
Where licensed, enable Oracle Ksplice for live kernel and userspace patching:
sudo dnf install -y uptrack ksplice-tools sudo uptrack-upgrade -y sudo systemctl enable --now uptrack
Related Errors & Cross-Refs
Issues that commonly surface alongside a mysql-selinux and mysql8.4 update: dnf transaction lock contention, systemd unit ordering cycles, SELinux AVC bursts, firewalld zone drift, and kernel taint flags. Triage with:
cat /proc/sys/kernel/tainted
systemd-analyze critical-chain
ausearch -m AVC -ts today | tail
firewall-cmd --get-active-zones
dnf history list --reverse | head
View all oracle-linux-10 tutorials on the Tutorials Hub →
Browse all common problems & solutions on the Tutorials Hub.
References & Further Reading
Primary reference: ELSA advisory ELSA-2025-15699. Useful manual pages on Oracle Linux 10:
man dnf
man dnf.conf
man systemctl
man journalctl
man firewall-cmd
man semanage
man audit2allow
man grubby
Other resources: Oracle Linux 10 Administrator’s Guide at docs.oracle.com, the upstream Red Hat CVE database at access.redhat.com/security/cve, the Oracle Ksplice known-fixes feed, and /usr/share/doc/mysql-selinux/ for component-specific notes implicated in mysql-selinux and mysql8.4.