In this article, you can learn about patch delivery methods for Oracle AI Database.
- Introduction to Oracle AI Database Patch Maintenance
Discover how reactive patch maintenance differs from proactive patch maintenance. - In-Place and Out-of-Place Patch Maintenance
Oracle recommends that you perform Out-of-Place patch maintenance. Learn about the differences between In-Place and Out-of-Place patching. - Proactive Maintenance with RUs and MRPs
Proactive maintenance means that you routinely apply the quarterly Release Update, and, if you choose, apply Monthly Recommended Patches to update the Release Update patch. - Reactive Maintenance with Interim Patches
All patch methods allow interim (or "one-off") patches to be installed, but the version of an interim patch that is required can vary depending on the patching method. - Streamlining Your Update Experience with Oracle Update Advisor
Oracle Update Advisor is a software update recommendation framework that provides accurate, up-to-date information to keep software at recommended versions. - Oracle Update Advisor Advanced Concepts and Use Cases
Use Oracle Update Advisor policies to standardize maintenance across an enterprise, including the security severity that should influence software health and update recommendations. - Patch Conflict Resolution
If you choose not to use Gold Image patch maintenance, then interim patches used in conjunction with other proactive maintenance methods, including custom Gold Images, may cause patch conflicts. - Patching Oracle AI Database and Oracle GoldenGate
When you use Oracle GoldenGate with Oracle AI Database, you must ensure that Oracle GoldenGate processes are shut down before patching the database. - Frequently Asked Questions
Find answers to common questions, and learn details about how you can address common issues.
Introduction to Oracle AI Database Patch Maintenance
Discover how reactive patch maintenance differs from proactive patch maintenance.
The Critical Patch Update (CPU) is the primary mechanism for the delivery of security bug fixes for all Oracle on-premises products. Critical Patch Updates are released quarterly on the third Tuesday of January, April, July, and October, and published on the Critical Patch Updates and Security Alerts page. Oracle retains the ability to issue out of schedule patches or workaround instructions in case of particularly critical vulnerabilities and/or when active exploits are reported in the wild. This program is known as the Security Alert program.
To protect your Oracle database estate from new AI-enabled threats, Oracle strongly recommends that you upgrade the major version of your databases to either Oracle Database 19c or Oracle AI Database 26ai. Oracle also strongly recommends that customers apply very recent quarterly Release Updates (RUs) to their databases. For more information about these recommendations, see Recommendations to Help Protect Oracle Databases from Emerging AI-enabled Security Threats (PNEWS3015):
Recommendations to Help Protect Oracle Databases from Emerging AI-enabled Security Threats PNEWS3015
You can obtain up-to-date information on Oracle's Critical Patch Updates, Security Alerts and Bulletins site:
Critical Patch Updates, Security Alerts and Bulletins
The following terms are often used to refer to patches:
Reactive Patches react to specific maintenance issues. They are characterized as follows:
- Usually delivered as “Interim Patches”
- Historically known as “one-off” patches
- Are provided on demand for a given “defect, version, platform” combination
- Go through basic sanity tests
- Certain reactive fixes may be included in future Release Updates
Proactive Patches provide recommended updates for all Oracle AI Database customers. Proactive patches employ bundles of patches optimized to be delivered together. Starting with Oracle AI Database 26ai, these patch bundles will also be provided as gold images.
Proactive patches (patch bundles) are characterized as follows:
- Address high impact bugs that affect a given configuration
- Contain proven, low-risk fixes
- Include cumulative prior fixes
- Undergo additional levels of testing, determined by the features affected by the patch
- Are available on "My Oracle Support" by clicking on the Patches tab
- Are available as Release Updates (RU) and Monthly Recommended Patches (MRPs)
Starting with Oracle AI Database, for proactive patch bundles, Oracle recommends that you perform software maintenance using one of the following methods:
- Database Configuration Assistant (DBCA): Use DBCA as the recommended software maintenance method for single-instance Oracle databases.
- Oracle Fleet Patching and Provisioning (FPP): Use FPP as the recommended software maintenance method for Oracle Real Application Clusters (Oracle RAC) databases, and for Oracle databases deployed with Oracle Data Guard. In addition, Oracle recommends that you use FPP for larger database fleets, and with Exadata databases.
You can continue to use OPatch and OPatchAuto for in-place and out-of-place patching (installing the software update into a new Oracle home). Oracle recommends that all patch operations are performed as Out-of-Place patching.
Caution:
To avoid the risk of logical corruption, before you start patch maintenance, ensure that all running Oracle Data Pump jobs are stopped before applying patches or before performing any other software maintenance. You also must not start any new Oracle Data Pump jobs until the patching process is fully completed. Oracle strongly recommends that you stop all data movement operations of any kind during maintenance windows. For more information, see "Datapatch: Database 12c or later Post Patch SQL Automation KB148594 (formerly My Oracle Support 1585822.1)".For more information about preparing a maintenance plan for your release, see the following My Oracle Support notes:
Related Topics
- Critical Patch Updates, Security Alerts and Bulletins
- Primary Note for Database Quarterly Release Updates KB106822 (formerly My Oracle Support 888.1)
- Oracle Database 19c and Oracle AI Database 26ai Important Recommended One-off Patches KB188772 (formerly My Oracle Support 555.1)
- Release Schedule of Current Database Releases PNEWS1360 (formerly My Oracle Support 742060.1)
- Datapatch: Database 12c or later Post Patch SQL Automation KB148594 (formerly My Oracle Support 1585822.1)
Parent topic: Patch Delivery Methods for Oracle AI Database
In-Place and Out-of-Place Patch Maintenance
Oracle recommends that you perform Out-of-Place patch maintenance. Learn about the differences between In-Place and Out-of-Place patching.
In-Place Patching means that you have one single Oracle home, and you apply the next Release Update (RU) or one-off patch as a patch to this Oracle home. Out-of-Place patching means that you move the database stack to run from a new Oracle home that is at the desired level of software version. Oracle releases the RU as software images that you can download to set up the new Oracle home. After the home is set up, the database stack can be moved to operate from this new Oracle home.
Understanding Out-of-Place Patching
Out-of-Place patching is performed by deploying gold images into a new Oracle home. This method has many benefits, including reducing downtime, reducing the risk of patch deployment issues, reducing the time required for switching services from the existing home to the updated home, and generally simplifying the process of deployment.
As a best practice, Oracle recommends that you use Out-of-Place patch maintenance. For simplicity and ease of deployment, Oracle also recommends that you use the specific Oracle patch maintenance utilities we recommend for your configuration type. The recommended utilities are Database Configuration Assistant (DBCA) for single-instance databases and Oracle Fleet Patching and Provisioning for Oracle Real Application Clusters (Oracle RAC) and Oracle AI Database deployments using Oracle Data Guard.
Understanding In-Place Patching
In-Place patching is performed by applying patch binaries to an existing Oracle home. You can use In-Place Patching to deploy individual patches as well as RUs using either OPatch or OPatchAuto. In this case, you deploy the RU or patch to your existing Oracle home in the form of binary patches. However, In-Place patch maintenance requires more manual work, and can be more complex to perform successfully. For most customers, Oracle strongly recommends that you choose Out-of-Place patching.
Quarterly Release Updates (RUs) are created with the intention to merge the latest RU into the preceding RU, as cumulative patch update bundles. Release Update Revisions (RURs) and one-off patches are also built to deploy in an Oracle home with a specific RU. As a result, before you can deploy the latest RU with cumulative updates, you need to remove patches deployed for the earlier different RU from the existing Oracle home before you can apply the latest RU to your existing Oracle home.
When you perform an in-place Oracle home patch update, you must stop all Oracle AI Database instances using that existing Oracle home, so you require a longer downtime maintenance window to perform manual patch management. Depending on the complexity of your patch environment in the existing Oracle home, the downtime required for this work can be significant. If an issue occurs, then you will have to create a new Oracle home as part of your recovery process. And even if you clone the Oracle home, you also clone the Oracle home history, which can create unexpected complications.
Parent topic: Patch Delivery Methods for Oracle AI Database
Proactive Maintenance with RUs and MRPs
Proactive maintenance means that you routinely apply the quarterly Release Update, and, if you choose, apply Monthly Recommended Patches to update the Release Update patch.
Oracle delivers two types of proactive content: Release Updates, and Monthly Recommended Patches. These software updates are available from the My Oracle Support (MOS) Customer Portal for each Oracle AI Database software release.
About Release Updates and Monthly Recommended Patches
Release Updates (RUs) are released quarterly, typically on the third Tuesday of January, April, July and October. To help to ensure your software performance and security, the RUs are required updates for Oracle software. Oracle recommends that you update your software quarterly, when the RUs are released.
Monthly Recommended Patches (MRPs) are optional software updates that are applied to the RUs. They contain recommended updates and fixes of known issues, grouped together for ease of deployment. These software updates are released monthly for software deployed on Linux systems. Each RU will be given a maximum of six Monthly Recommended Patches. The MRP updates are additional, optional fixes applied on top of a specific RU.
For platforms other than Linux, in place of MRPs, you can continue to download recommended interim patches and known issues patches to the Oracle software home.
Software updates are announced in the following locations
- Primary Note for Database Proactive Patch Program (Doc ID 888.1)
- Monthly Recommended Patches (MRPs)
- Critical Patch Updates, Security Alerts and Bulletins
Quarterly release updates are announced on the "Critical Patch Updates, Security Alerts and Bulletins" page each January, April, July, and October. Monthly Recommended Patches are released each month in between a quarterly RU, and are cumulative bundles of recommended patches. To receive email notifications when the quarterly RU software updates are available, subscribe to Oracle Security alerts.
Recommended Apply Frequency for Proactive Maintenance Patches
Apply frequency defines how often you apply an update to the database software. The Apply Frequency does not define selecting earlier Release Update or Monthly Recommended Patches.
- Release Updates (RUs)
RUs are highly tested bundles of critical fixes which enable you to avoid known issues. They usually contain the following type of fixes: security, regression (bug), optimizer, and functional (which may include feature extensions as well). - Monthly Recommended Patches (MRP)
Oracle provides MRPs for Linux x86-64 to provide simplified recommended and interim software updates between the quarterly Release Updates. - Additional Proactive Patches
In addition to RUs and MRPs, there are quarterly full stack download patches and combo patches, as well as other proactive patches. - Proactive Apply Frequency Patching Strategy
Oracle recommends that you keep your database and Oracle Grid Infrastructure software current by applying the most recent Release Updates (RUs).
Related Topics
Parent topic: Patch Delivery Methods for Oracle AI Database
Release Updates (RUs)
RUs are highly tested bundles of critical fixes which enable you to avoid known issues. They usually contain the following type of fixes: security, regression (bug), optimizer, and functional (which may include feature extensions as well).
Oracle recommends that you stay current by using RUs. By doing this, you minimize the chance of encountering known bugs and security vulnerabilities.
The nomenclature for the RU patches is a five-field number, such as 23.26.1.0.0.
- First numeral: This numeral indicates the major release version. It also denotes the last two digits of the year in which the Oracle AI Database version was released for the first time.
-
Second numeral: This numeral indicates the release update year. In this example the release update year is 2026.
-
Third numeral: This numeral indicates a refresh of an RU version. In this example, the numeral is , indicating that this is the first quarter release update.
-
Fourth numeral: The fourth numeral indicates the Monthly Recommended Release Update patch level (MRP). Only MRPs will advance the fourth field. In this example, the numeral is 0.
-
Fifth numeral: This numeral indicates the recut level of the version. In this example, the recut level is 0.
Note:
The first three numerals mainly identify an Oracle AI Database release.
An RU is always Oracle RAC Rolling installable. The list of available RUs is documented in "Primary Note for Database Proactive Patch Program (Doc ID 888.1)"
Parent topic: Proactive Maintenance with RUs and MRPs
Monthly Recommended Patches (MRP)
Oracle provides MRPs for Linux x86-64 to provide simplified recommended and interim software updates between the quarterly Release Updates.
MRPs are a collection of recommended and interim software updates bundled
together. Unlike an RU, an MRP does not affect the release revision number. The release
number continues to be designated by the RU number. The MOS Conflict Checker will treat
the MRP fixes as it does with other bundled software updates. Regular conflict
resolution will take place. The patches in an MRP are tracked in the Oracle Inventory
directory (oraInventory), which is updated to indicate which interim
patches are installed from the MRP.
MRPs can be provided for each RU in the 6 months following each RU release. MRPs are provided for specific RUs, and will include the fixes documented in "Oracle AI Database Important Recommended Patches" (My Oracle Support Doc ID 555.1), plus the prior MRPs for the RU. All fixes in the MRP will always be Oracle RAC Rolling and Oracle Data Guard Rolling installable. While RUs will continue to be available on all supported platforms, and recommended and interim patches are available separately for all platforms, MRPs will only be offered on Linux x86-64 platforms. Customers can continue to request one-off patches on all supported platforms. The list of available MRPs is documented in "Primary Note for Database Proactive Patch Program (Doc ID 888.1)".
opatchauto or opatch (for
example, opatch napply).
Note:
Because Oracle Grid Infrastructure MRPs are system patches, you cannot useopatch napply to apply these
patches.
Related Topics
Parent topic: Proactive Maintenance with RUs and MRPs
Additional Proactive Patches
In addition to RUs and MRPs, there are quarterly full stack download patches and combo patches, as well as other proactive patches.
Quarterly Full Stack Download Patch and Combo Patch
Oracle delivers a number of different patches packaged together. For example:
- Quarterly Full Stack Download Patch for Exadata, which includes the quarterly Grid Infrastructure RU along with the OJVM update and other Exadata system patches in a single download.
- Combo Patch of Database RU
Other Proactive Patches
Oracle produces some proactive patches for very specific purposes outside of the normal update and revision cycle. Such patches are usually delivered as "Interim Patches". For example, special time zone patches are released every six months for customers who require systems to use latest time zone data.
Note:
If you are using Oracle Grid Infrastructure software in addition to Oracle AI Database software, then you should use the parallel Oracle Grid Infrastructure RU. These Oracle Grid Infrastructure RUs include everything that the parallel database RU contains.Parent topic: Proactive Maintenance with RUs and MRPs
Proactive Apply Frequency Patching Strategy
Oracle recommends that you keep your database and Oracle Grid Infrastructure software current by applying the most recent Release Updates (RUs).
Apply frequency defines how often you apply an update to the database software. It does not define selecting a Release Update that is not the latest RU. Oracle recommends that you always update to the latest available RU for your release.
Release Update Lag and Apply Frequency
Oracle recommends you install the latest Release Update (RU), whenever you perform an installation. RUs include the most recent security, regression, and critical fixes. Applying RUs minimizes the chance of encountering known bugs and security vulnerabilities. Staying current with RUs reduces the likelihood of requiring separate interim one-off patches, which lead to unique software baselines and a potential for ongoing costly patch maintenance.
Note:
As part of your proactive maintenance policy, Oracle recommends that you apply quarterly Release Updates (RU) promptly, use Oracle Database security tools and features, and adopt security best practices. You can obtain up-to-date information on Oracle's Critical Patch Updates, Security Alerts and Bulletins site:
Example 1-1 Apply the Most Recent RU each quarter
RU_Latest) quarterly, and never apply MRPs.
Note:
If you choose this strategy, then Oracle recommends that your apply frequency is quarterly (every three months).Table 1-1 Quarterly RU Software Maintenance Plan (RU_N)
| Apply Frequency | Release Updates (RU_N) |
|---|---|
|
Monthly |
Not applicable |
|
Quarterly |
Every 3 months - Apply |
|
Semiannually |
Every 6 months - Apply |
| Annually |
Every 12 months - Apply |
Example 1-2 Apply the most recent quarterly RU and most recent MRP for that RU
In this maintenance schedule example, to obtain the most current security and performance fixes, you install the latest RU (RU_Latest), and install the most recent MRP (MRP_N, where N is the most recent available MRP available for the latest RU). The latest MRP contains all recommended and interim fix patches from the previous MRPs published for that RU.Note:
If you choose this strategy, then Oracle recommends that your apply frequency is quarterly (every three months).Table 1-2 RU (RU_N) and Monthly Recommended Patches Software Maintenance Plan (MRP_N)
| Apply Frequency | RU (RU_Latest) + MRP_N |
|---|---|
|
Monthly |
Every 1 month - Apply |
|
Quarterly |
Every 1 month - Apply |
|
Semiannually |
Every 6 months - Apply |
| Annually |
Every 12 months - Apply |
Parent topic: Proactive Maintenance with RUs and MRPs
Reactive Maintenance with Interim Patches
All patch methods allow interim (or "one-off") patches to be installed, but the version of an interim patch that is required can vary depending on the patching method.
Microsoft Windows platforms do not support normal interim (also known as “one-off") patches. See Oracle Database - Overview of Database Patch Delivery Methods for 12.2.0.1 and greater (Doc ID 2337415.1) for details of current and historic proactive patches.
Interim patches are delivered on request as standalone patches for a given “defect, version, platform” combination.
- Interim patches are provided on top of any release or Release Updates (RUs) for supported software versions as long as it is technically feasible to do so.
- Interim patches go through basic functional, stress and performance sanity tests.
- Interim patches are considered for inclusion in Release Updates (RUs) based on their technical severity or number of affected features.
Generally, instead of requesting an interim patch, Oracle recommends that you apply the most recent Release Update that includes the fix. For an additional discussion of the pros and cons of asking for interim bug fixes in patches instead of following an RU maintenance schedule, see Should I ask for a one-off bug fix or wait for the next Release Update (Doc ID 2648544.1).
Oracle Database online patching (or hot patching) enables you to apply particular interim patches to a running database without shutting down instances. Using this option can minimize application disruption. Database online patching is always performed in-place using the OPatch utility. For more information, see RDBMS Online Patching Aka Hot Patching (Doc ID 761111.1).
Parent topic: Patch Delivery Methods for Oracle AI Database
Streamlining Your Update Experience with Oracle Update Advisor
Oracle Update Advisor is a software update recommendation framework that provides accurate, up-to-date information to keep software at recommended versions.
- What is Oracle Update Advisor
Oracle Update Advisor analyzes your Oracle AI Database and Grid Infrastructure homes, identifies necessary updates, and delivers preconfigured deployment packages. - How Do I Get Started with Oracle Update Advisor
To get started with Oracle Update Advisor, you just need your Oracle user information, secure HTTP, and a supported Oracle software maintenance tool. - Example of Using Oracle Update Advisor with DBCA
See how you can use Database Configuration Assistant (DBCA) with the Oracle Update Advisor features to simplify proactive checks during maintenance. - Example of Using Oracle Update Advisor with Oracle FPP
Oracle recommends that you use Oracle Fleet Patching and Provisioning (Oracle FPP) with the Oracle Update Advisor features to maintain Oracle Real Application Clusters (Oracle RAC) databases. - Example of Using Oracle Update Advisor with AutoUpgrade
Use AutoUpgrade with Oracle Update Advisor security level to specify the lowest vulnerability severity to use for software-health assessment and recommendations.
Parent topic: Patch Delivery Methods for Oracle AI Database
What is Oracle Update Advisor
Oracle Update Advisor analyzes your Oracle AI Database and Grid Infrastructure homes, identifies necessary updates, and delivers preconfigured deployment packages.
Maintaining software is not easy. To understand what you need to maintain your software enterprise security and functionality, administrators must review multiple product information sources, including My Oracle Support documents, and support recommendation technical briefs. You then must apply that information in accordance with your maintenance polices.
Streamlined Access to Updates
Oracle Update Advisor provides you with a powerful software update recommendation framework to streamline your maintenance. The advisor analyzes your Oracle AI Database and Oracle Grid Infrastructure homes, and identifies up-to-date guidance based on your defined maintenance policy, in a single, easy-to-understand report. Oracle Update Advisor also provides you with a preconfigured, fully functional gold image zip file that you can use to simplify the deployment of consistent operating system and Oracle software updates across your enterprise.
The Oracle Update Advisor commands are added to Oracle AI
Database Configuration Assistant (DBCA) and Oracle Fleet Patching and Provisioning (FPP).
With the release of Database Configuration Assistant Utility
(dbcactl) , a lightweight self extractable executable version
of the Database Configuration Assistant, DBCA now also supports Oracle Database 19c
as well as Oracle AI
Database. It is not available with Oracle Database 21c. These commands enable you to
provide to Oracle information that can help you to maintain the Oracle AI
Database and Oracle Grid Infrastructure software at recommended versions. Other Oracle
tools are planned to interact with the Oracle Update Advisor in the future.
Accurate Software Health Status, Up-to-Date Version Guidance
Oracle Update Advisor provides two fundamental functions:
- Software Status
- Software Recommendations
Software Status indicates whether the currently installed software meets Oracle's current recommendations. When the installed software does not meet current recommendations, Oracle Update Advisor provides a list of Software Recommendations and also a software image of updates and maintenance fixes that you can use to bring your software up to the current recommendations for your software. That image is then used to create a new Oracle Home that meets the software recommendations.
Where to learn more about Oracle Update Advisor
The "Oracle Update Advisor API Reference and Integration Guide" is now available directly on Oracle Help Center, without requiring a login to Oracle Support:
Oracle AI Database Oracle Update Advisor API Reference and Integration Guide
The Knowledge Base article KB886700 continues to be available.
How Do I Get Started with Oracle Update Advisor
To get started with Oracle Update Advisor, you just need your Oracle user information, secure HTTP, and a supported Oracle software maintenance tool.
What do you need?
Using Oracle Update Advisor is simple, as it enhances the use of features you already use. To enable Oracle Update Advisor functionality, you just need the following:
- A valid Oracle Support contract, Customer Support Identifier (CSI) number, and a My Oracle Support user
- Secure HTTP (HTTPS) network connectivity to Data Transport Services (DTS), https://transport.oracle.com to transport information for obtaining proactive advice on product use and configurations
- Oracle Object Store service, which is required to download the Oracle Update Advisor image.
Note:
Oracle Update Advisor uses Data Transport Services (DTS) to handle customer registration for Oracle Update Advisor, to upload configuration data (such as RU and patch inventory), and to deliver patch update status and recommendations.
How does it work?
Using Oracle Update Advisor can be as simple as 1, 2, 3:
- Register a My Oracle Support user for the Oracle Update Advisor service.
- Use either Database Configuration Assistant (DBCA), Fleet Patching
and Provisioning (FPP), or Database Configuration Assistant Utility
(
dbcactl) with Oracle Update Advisor commands to run a check on the software status of an installed Oracle home - Review the status report. If the status is not green, then download and install the recommended software image.
Example of Using Oracle Update Advisor with DBCA
See how you can use Database Configuration Assistant (DBCA) with the Oracle Update Advisor features to simplify proactive checks during maintenance.
If your preferred patching tool is DBCA then you just need to add an Oracle Update Advisor command to your patching process.
To register the user for Oracle Update Advisor, use the following command
syntax, where sso_username is the
name of the Oracle user account, and csi_number is the Customer Support Identifier (CSI)
number
dbca -managePatches -silent -registerUser -ssoUserName sso_username -csiNumber csi_number
To check software service, use the following command syntax:
dbca -managePatches -checkPatchStatus -silent
Example of Using Oracle Update Advisor with Oracle FPP
Oracle recommends that you use Oracle Fleet Patching and Provisioning (Oracle FPP) with the Oracle Update Advisor features to maintain Oracle Real Application Clusters (Oracle RAC) databases.
To manage the maintenance updates in your cluster, you use the Oracle Fleet Patching and Provisioning Control (RHPCTL) command-line utility with Oracle Update Advisor commands.
For maintenance with Oracle Update Advisor, you use Oracle Fleet Patching and Provisioning in Local Mode. This enables you to perform version updates on a local Oracle RAC Cluster without any configuration except for connectivity to the Oracle Update Advisor. See how in this example:
-
Register with Oracle Update Advisor using the command
rhpctl manage updateadvisor update. The syntax is as follows:$ rhpctl manage updateadvisor {-registeruser -ssousername <sso_username> [-csinumber <csi_number] [-proxyserver <proxy_server> -proxyport <port_number> [-proxyuser <proxy_user>] ] [-endpoint <endpoint_url>] | -unregisteruser}These options are as follows:
-registeruser: Register user to Oracle update advisor-ssousername <sso_username>: SSO user namecsinumber <csi_number>: Customer Support Identifier (CSI)-proxyserver <proxy_server>: Proxy server IP/name-proxyport <proxy_port>: Proxy server port number-proxyuser <proxy_user>: Proxy server user name-endpointOracle Update Advisor end point URL<endpoint_url>-unregisteruserUnregister the user from Oracle Update Advisor
In this example, the My Oracle Support user is
enterprise1, the CSI number is123456789, the proxy server is 192.0.2.1, the proxy port is 20001, and the proxy usermaint1:rhpctl manage updateadvisor update -registeruser --ssousername enterprise1 -csinumber 123456789 -proxyserver -192.0.2.1 -proxyport 20001 -proxyuser maint1 -
Use the command
rhpctl evaluate patchto check the status of the Oracle AI Database or Grid Infrastructure home that you are maintaining. In this example, we check the Oracle RAC home/u01/app/oracle/product/23.0.0/dbhome_1:rhpctl evaluate patch -path /u01/app/oracle/product/23.0.0/dbhome_1 -
After you validate the software installed on that test system, you can deploy the gold image software version on your production environment
This is a simple example. For examples using a centralized approach, you can refer to the Oracle Fleet Patching and Provisioning documentation. With Oracle Fleet Patching and Provisioning, you can centrally manage a complete Oracle AI Database landscape, including Oracle Exadata, Oracle Grid Infrastructure, Oracle AI Database, Oracle Restart, and Oracle Single instance deployments.
Related Topics
- Fleet Patching and Provisioning Use Cases in Oracle Fleet Patching and Provisioning Administrator's Guide
- Using Oracle Update Advisor in Oracle FPP Local Mode in Oracle Fleet Patching and Provisioning Administrator's Guide
- Using Oracle Update Advisor in Oracle FPP Server Mode in Oracle Fleet Patching and Provisioning Administrator's Guide
Example of Using Oracle Update Advisor with AutoUpgrade
Use AutoUpgrade with Oracle Update Advisor security level to specify the lowest vulnerability severity to use for software-health assessment and recommendations.
recommendationArea field.
Cojnfiguring Security Levels with Oracle Update Advisor
Oracle Update Advisor evaluates security metadata associated with applicable Release Updates and Monthly Recommended Patches and CSPUs. The assessment is performed independently for each installed Oracle home and platform. An assessment checks to determine if a security fix applies to the installed release range.
Table 1-3 Oracle Update Advisor Security Levels
| Security Level | CVSS Threshold | Meaning |
|---|---|---|
|
9.0 or higher | Evaluate missing applicable fixes for Critical vulnerabilities. |
|
7.0 or higher | Evaluate missing applicable fixes for High and Critical vulnerabilities. This is the default. |
|
4.0 or higher | Evaluate missing applicable fixes for Medium, High, and Critical vulnerabilities. |
|
0.1 or higher | Evaluate all missing applicable fixes with a positive CVSS score. |
The selected level is inclusive. For example, SecurityMedium
evaluates applicable Medium, High, and Critical exposures.
How Security Affects Health
Oracle Update Advisor identifies the highest CVSS score among missing applicable security fixes that meet the selected threshold:
- A missing Critical fix contributes
RED. - A missing High, Medium, or Low fix that meets the selected threshold contributes
YELLOW. - When no applicable fix meeting the threshold is missing, security contributes
GREEN.
Oracle Update Advisor combines the security result with the existing non-security health checks and returns the most severe overall status. A security level does not replace Release Update lag, notification level, or other active policy settings.
Default and Validation Behavior
- If the effective policy does not contain a security directive, Oracle Update
Advisor uses
SecurityHigh. - Specify no more than one distinct security directive in an effective policy.
- Repeating the same security directive is invalid and should be removed.
- Combining different security directives, such as
SecurityHigh,SecurityCritical, is invalid. - A security directive can be combined with supported functional recommendation
areas, for example
DataGuard,SecurityMedium. ALLselects supported functional recommendation areas but does not itself select a security level. IfALLis supplied without a security directive, the defaultSecurityHighstill applies.
Specify the Level through DBCA or FPP
When the installed client exposes the Oracle Update Advisor recommendation-area
policy, set the option to one security directive or to a comma-separated combination
of functional areas and one security directive. See the Database Configuration
Assistant (DBCA) and Oracle Fleet Patching and Provisioning (FPP) examples in this
publication for the released command syntax. If the installed DBCA,
dbcactl, FPP, or AutoUpgrade version does not expose this
policy, then it cannot select a non-default level through that client version. In
that event, the Oracle Update Advisor service applies SecurityHigh.
Use a supported client release or a direct REST API integration when you require an
explicit non-default level.
Specify the Level through the REST API
For direct integration, set the value in the existing
recommendationArea field:
globalElement.policy.recommendationAreaapplies a common value to request elements governed by the global policy.requestElement[n].policy.recommendationAreaoverrides the global policy for an individual request element.
The following abbreviated request applies SecurityHigh globally:
{
"requestType": "SoftwareGetStatusAndRecommendation",
"globalElement": {
"policy": {
"updateLag": "N",
"applyFrequency": "Q",
"notificationLevel": "Critical",
"recommendationArea": "SecurityHigh"
}
},
"requestElement": [
{
"id": "db-home-1",
"installedSoftwareInfo": {
"version": "19.27.0.0.0",
"type": "DB"
},
"patchList": {
"installedPatches": []
},
"goldImage": false
}
]
}
The following abbreviated request applies SecurityCritical to one
request element and overrides the global policy for that element:
{
"requestType": "SoftwareGetStatus",
"globalElement": {
"policy": {
"recommendationArea": "SecurityHigh"
}
},
"requestElement": [
{
"id": "production-db-home",
"policy": {
"recommendationArea": "SecurityCritical"
},
"installedSoftwareInfo": {
"version": "19.27.0.0.0",
"type": "DB"
},
"patchList": {
"installedPatches": []
}
}
]
}
Use SoftwareGetStatus when only software health is required. Use
SoftwareGetStatusAndRecommendation when the client also needs
recommended actions and, optionally, a software image.
Understand the Response
Review the respose to deterimine the information you need to apply the correct maintenance required for your software. In particular check:
- The effective security directive. Note if
SecurityHighwas applied by default. - The highest missing applicable CVSS score indicated in the response.
- The security contribution to the health status.
- Whether incomplete or unavailable security metadata limited the assessment.
Oracle Update Advisor Advanced Concepts and Use Cases
Use Oracle Update Advisor policies to standardize maintenance across an enterprise, including the security severity that should influence software health and update recommendations.
- Proactive Enterprise Maintenance Using Policies with Oracle Update Advisor
Oracle Update Advisor policy attributes enable an organization to define a consistent maintenance posture. - Network Configuration Considerations for Oracle Update Advisor
The Oracle Update Advisor API is hosted in Oracle Cloud Infrastructure and is publicly accessible to authorized customers. - Understanding Oracle Update Advisor Recommendations
Oracle Update Advisor returns one of three overall health indicators for each Oracle home. - Obtaining Oracle Software Images with Oracle Update Advisor
Database Configuration Assistant (DBCA) or Oracle Fleet Patching and Provisioning (FPP) can download and deploy a software image returned by an Oracle Update Advisor recommendation request.
Parent topic: Patch Delivery Methods for Oracle AI Database
Proactive Enterprise Maintenance Using Policies with Oracle Update Advisor
Oracle Update Advisor policy attributes enable an organization to define a consistent maintenance posture.
When establishing an update policy, decide:
- How frequently software should be maintained.
- Whether to use the latest Release Update or an allowed lag.
- Which notification level should trigger action.
- Which functional recommendation areas should be included.
- Which security severity should influence health and recommendations.
As part of a proactive maintenance policy, Oracle recommends applying Release Updates promptly, using Oracle Database security features, and adopting security best practices. Critical Patch Updates, Security Alerts, and Bulletins provide current Oracle security information.
| Policy Attribute | Description |
|---|---|
|
Apply Frequency |
How often updates are applied: Monthly, Quarterly (default), Semiannually, or Annually. |
|
Release Update Lag |
The permitted lag from the latest RU: NoLag (default), N-1, or N-2. |
|
Notification Level |
The patch-importance level that triggers a recommendation, such as Critical or Important. |
|
Recommendation Area |
Functional recommendation directives and one optional security directive. |
|
Security Level |
The security directive carried in
|
The security directive defines the minimum CVSS severity considered by the security assessment. It does not mean that Oracle Update Advisor recommends every patch at that severity. Oracle Update Advisor evaluates applicability to the installed home and selects the least disruptive update that satisfies the effective policy.
For example, if a Monthly Recommended Patch/CSPU on the installed RU line resolves the applicable security finding, Oracle Update Advisor can recommend that patch instead of a newer RU. A newer RU is recommended when it is required to resolve the security finding or another active policy requirement.
Parent topic: Oracle Update Advisor Advanced Concepts and Use Cases
Network Configuration Considerations for Oracle Update Advisor
The Oracle Update Advisor API is hosted in Oracle Cloud Infrastructure and is publicly accessible to authorized customers.
Client systems must be able to initiate outbound HTTPS connections to https://updateadvisor.oracle.com.
Clients can connect directly with standard HTTPS libraries or indirectly through an
enterprise HTTP or HTTPS proxy. Permit outbound TCP port 443 to
updateadvisor.oracle.com.
The selected security level does not change the network endpoint or registration process. DBCA, FPP, dbcactl, AutoUpgrade, and direct API clients transmit the selected policy with the installed-home inventory over the same secure Oracle Update Advisor connection.
Parent topic: Oracle Update Advisor Advanced Concepts and Use Cases
Understanding Oracle Update Advisor Recommendations
Oracle Update Advisor returns one of three overall health indicators for each Oracle home.
Health indicators
- Green: No action is needed. The installed software satisfies the effective policy, including its security level.
- Yellow: An update is recommended. This can indicate version lag or a missing applicable security fix that meets the selected High, Medium, or Low threshold.
- Red: Action is required. This can indicate excessive version lag, missing critical application fixes, conflicts or regressions, or a missing applicable Critical security fix.
The returned status reflects the most severe result across the active health checks. For
example, a home can satisfy its RU-lag policy but still return YELLOW
or RED because an applicable security fix is missing.
The response should identify the effective security level and, when known, the highest missing applicable CVSS score. If security metadata is incomplete, the response should state that the limitation affected the assessment.
Security requirements can override a lag-based or cadence-based recommendation, but Oracle Update Advisor selects the least disruptive compliant target. A qualifying MRPCSPU on the installed RU line can therefore be preferred over an RU upgrade when it resolves the applicable finding.
If the overall status is not GREEN, review all reported reasons and
follow the recommended actions. Use a Get Recommendation request when recommended update
details or an optional gold image are required.
Parent topic: Oracle Update Advisor Advanced Concepts and Use Cases
Obtaining Oracle Software Images with Oracle Update Advisor
Database Configuration Assistant (DBCA) or Oracle Fleet Patching and Provisioning (FPP) can download and deploy a software image returned by an Oracle Update Advisor recommendation request.
Standard RU gold images can be available immediately. Images containing additional fixes can require additional preparation time. When applicable, Oracle Update Advisor provides an availability estimate.
A selected security level can affect the contents of the recommended image. Oracle Update Advisor includes the updates required to address applicable security findings that meet the effective threshold together with other changes required by the maintenance policy. The service does not add every patch associated with that severity; applicability, installed inventory, regressions, replacements, conflicts, and the selected target release are considered.
Because proactive content and guidance can change, a later request can return a different health result or recommendation. When you compare results across environments or over time, record the effective policys and security levels.
Standardize test and production environments. Back up software before maintenance, test the recommended image in a representative nonproduction environment, and promote the validated image rather than independently creating multiple images for the same RU and policy.
Parent topic: Oracle Update Advisor Advanced Concepts and Use Cases
Patch Conflict Resolution
If you choose not to use Gold Image patch maintenance, then interim patches used in conjunction with other proactive maintenance methods, including custom Gold Images, may cause patch conflicts.
Note:
Oracle recommends that you use one of the Quarterly Gold Image deployment methods for database maintenance. With Gold Image deployment, patch conflict resolution and merges are included as part of the Gold Image creation. Custom gold images do not have this optimization.For the quarterly proactive patches (Quarterly Exadata Patch, RU, and MRPs), Oracle proactively produces new interim patches for existing patches that would conflict. The new interim patches are usually released at the same time as the proactive patches.
For information about resolving patch conflicts, see the My Oracle Support notes for patch conflicts.
Patching Oracle AI Database and Oracle GoldenGate
When you use Oracle GoldenGate with Oracle AI Database, you must ensure that Oracle GoldenGate processes are shut down before patching the database.
When you patch Oracle AI Database, and you are using Oracle GoldenGate, you must disable all Oracle GoldenGate processes before starting to patch the database. The reason for this is that patches and upgrades can modify the RDBMS internal tables and views, which cause stored procedures that call them to be invalidated. All dependent objects are invalidated as well. You cannot use SQL queries alone on the database to ensure that GoldenGate processes such as Extract, Pump, or Replicat are shut down, because they run at the operating system level, and are managed by the GoldenGate software. At a high level, the process of checking for such processes is as follows:
-
Query the status of GoldenGate processes:
GGSCI> info all -
Stop all processes
GGSCI> stop extract * GGSCI> stop replicat * . . .The
*wildcard stops all processes of that type. If you have other Oracle GoldenGate processes (for example,manager), ensure that they are stopped as well. -
Run a GGSCI
info allcommandGGSCI> info allYou should see that all processes have the status
STOPPED.
For enterprise automation, consider using shell scripts that use GGSCI commands and parse their output. To ensure Oracle GoldenGate processes are shut down, always use the GGSCI utility, and if necessary, combine this with operating system level and application-level checks.
For details about this procedure, refer to the Oracle GoldenGate documentation, and to My Oracle Support.
Related Topics
Parent topic: Patch Delivery Methods for Oracle AI Database
Frequently Asked Questions
Find answers to common questions, and learn details about how you can address common issues.
Do proactive patches include optimizer fixes?
- "Windows Database Bundle Patch" can include optimizer fixes.
- Oracle AI Database RUs can include optimizer fixes for issues that arise from inaccurate optimizer results, but only in a form that enables or disables them individually, as required. RUs include optimizer fixes in the "disabled by default" state. For more information, see: Managing "installed but disabled" bug fixes in Database Release Updates using DBMS_OPTIM_BUNDLE (Doc ID 2147007.1).
How can I tell what patching method an installation uses?
Review the opatch lsinventory output to see what patches
are applied. RUs and RURs include a description of the patch name and version in the
output.
What is the difference between "Windows Database Bundle Patch" and "QFSDP for Exadata" and so on?
These bundles are targeted at different environments. The latest versions include the same update content, but all other content is specific to the target environment. There may be some other common content but there are differences in content.
Do proactive patches affect the database version as reported in
trace files and database views like V$VERSION?
For Oracle AI
Database 26ai (23.4.0.0 and later), the patch level in the ORACLE_HOME is
reflected in the opatch lsinventory data, and for some patch types,
the patch level is reflected in DBA_REGISTRY or
DBA_REGISTRY_HISTORY. The
DBA_REGISTRY_SQLPATCH view tells you the SQL patches that are
applied to the database.
Should I ask for a one-off bug fix or wait for the next RU?
For a discussion of the pros and cons of asking for one-off bug fixes instead of waiting on RUs, see .Should I ask for a one-off bug fix or wait for the next Release Update (Doc ID 2648544.1)
How to apply patches? Use either the opatch utility
or the OPLAN utility?
Refer to the README to learn how to install patches.
OPatch - Where Can I Find the Latest Version of OPatch?
See How To Download And Install The Latest OPatch(6880880) Version (Doc ID 274526.1) or OPatch - Where Can I Find the Latest Version of OPatch(6880880)? [Video] (Doc ID 224346.1)
Parent topic: Patch Delivery Methods for Oracle AI Database
Oracle AI Database Oracle AI Database Patch Maintenance Guidelines Release 26ai
G43965-04