2026-07-31
Arch Linux disabled package adoption on the Arch User Repository on July 30 following a third sustained wave of malicious takeovers dubbed "Atomic Arch." The campaign began in late May when attackers started adopting orphaned packages and embedding compiled ELF binaries directly into build scripts, effectively bypassing the npm and JavaScript-based detection methods that caught the earlier waves. Despite Arch developers declaring the repository clean in mid-June after purging more than 1,900 compromised packages, the threat quickly escalated with obfuscated downloaders and static payloads that execute during the makepkg build phase. The ongoing crisis has exposed the fundamental tension between an open, community-maintained repository and supply-chain security, leaving adoption temporarily frozen while the ecosystem develops more robust trust and detection mechanisms.
Mabox Linux 26.07 is delivering a downstream patch to tint2 that resolves system-tray freezes triggered by Steam, Lutris, and other X11 status icon applications. The release also upgrades the default FSearch utility to version 0.3, introducing real-time inotify-based filesystem monitoring and per-folder indexing schedules. Under the hood, the ISO inherits Manjaro Stable updates that bring new Mesa drivers, VirtualBox, and System76's COSMIC 1.2 session into an Openbox-focused environment. Available in both Linux 6.18 LTS and 6.6 LTS variants, the build continues the project's monthly cadence for efficiency-driven desktop users.
Devolutions just dropped UniGetUI v2026.2.7, a maintenance patch arriving just two days after the previous update to keep pace with the project's weekly release cadence. The refresh brings configurable environment variable syntax for install paths, clickable operation cards that open live logs directly, and the return of the desktop shortcut prompt that went missing in an earlier release. Developers also squashed a text input bug blocking immersive dialogs during multi-step wizards and rolled out several localization fixes following the recent WinUI-to-Avalonia migration. You can grab the ~27 MB portable build via winget install marticliment.UniGetUI or pull it directly from the GitHub releases page.
pgAdmin 4 v9.17 dropped on July 30, 2026, addressing seven security vulnerabilities including critical command injection and credential cloning flaws, with three stemming from incomplete patches in the previous release. The update introduces four practical enhancements, led by a new row count cap for the View Data action that helps prevent accidental full-table scans on large databases. Under the hood, the application upgrades to Electron 43.1.1, pins Yarn to 4.15.0, and implements stricter supply chain hardening across the macOS build process and GitHub Actions. Operators running server mode, especially those using shared servers or external authentication, should apply the patch immediately.
Liquorix linux-liquorix 7.1-7 released on July 31, 2026, bringing a single focused packaging change: stripping out the irqbalance recommendation and disabling the service during installation. The kernel remains based on Linux 7.1.5, continuing a rapid 18-day sprint that has produced seven releases as the project aggressively converges scheduler logic with upstream mainline. Available now for Debian and Ubuntu on amd64, the update is the latest step in an enthusiast kernel built specifically for interactive responsiveness and gaming workloads over background automation.
KDE neon has released its latest build, dated 20260730-0522, continuing to deliver rolling KDE software straight from upstream on a stable Ubuntu 24.04 LTS base. The distribution maintains multiple edition tracks, including stable, testing, unstable, and developer variants, while officially supporting only Intel and AMD graphics with open-source drivers.
The ASUS Zenbook A16 uses a Snapdragon X2 Elite processor and a 16-inch 3K OLED panel to deliver lightweight performance for mobile professionals. Minisforum builds the MS-02 Ultra as a compact desktop station featuring a 285HX chip, 25-Gigabit networking ports, and plenty of internal expansion slots. Noctua NL-LC1-24 AIO coolers beat top air designs by six degrees Celsius under heavy workloads while operating significantly quieter at the same time. ASUS ROG Strix X870E-A Gaming WiFi7 Neo boards pair solid thermal management with a bright aesthetic to support next-generation AMD processors for custom desktops.
Computers: ASUS Zenbook A16 (UX3607OA) Review - Snapdragon Laptops are Getting Better and Better, Minisforum MS-02 Ultra Test: Workstation Mini-PC with 285HX
Cooling: Noctua NL-LC1-24 Review
Motherboards: ASUS ROG Strix X870E-A Gaming WiFI7 Neo Review - A New Enticing Option
Ungoogled Chromium 151.0.7922.71-1 has been released, delivering the exact same rendering engine and 370 upstream security fixes as Google's latest Stable channel release. The build gutters every Google service integration at compile time, including telemetry, Safe Browsing, and AI features, while replacing the default domain routing with a private pseudo-TLD. Linux users can grab the archive straight from the project's CI artifacts today, though Windows and macOS builds will lag slightly behind for the upcoming .72 patch. A growing Speedometer benchmark gap suggests the patch layer still carries noticeable overhead, but the privacy baseline keeps drawing a steady crowd to the repository.
PHP's July 30 security release fixes three CVEs, including a SQL injection in PostgreSQL extensions and a stack overflow in Phar archives. Remi Collet published corresponding RPM packages for Fedora ≥42 and Enterprise Linux ≥8 on July 31, covering PHP 8.5.9, 8.4.24, 8.3.33, and 8.2.33. The updates are available via remi-modular repository or as parallel Software Collections installations. PHP 8.1 has reached end-of-life, so users should upgrade to at least 8.2.33 immediately.
Ubuntu published security notices covering four separate vulnerabilities across its long-term support releases. Ruby-sinatra requires an update to block remote denial of service attacks caused by malformed header parsing. Desktop environments need patches for a libinput privilege escalation flaw, while older Python installations must address resource exhaustion and HTML parser crashes. The OpenSSL update resolves the HollowByte memory allocation bug that enables network-based denial of service attacks, though Ubuntu 22.04 and newer users must reboot their machines to apply the changes.
[USN-8624-1] Sinatra vulnerability
[USN-8602-1] libinput vulnerability
[USN-8614-1] Python vulnerabilities
[USN-8625-1] OpenSSL vulnerability
SUSE issued multiple security advisories, patching vulnerabilities across a wide range of software including Python libraries, Kubernetes components, Apache Tomcat, OpenJDK 25, and graphics tools like ImageMagick. The updates span low to important severity levels, with notable fixes targeting the Xen hypervisor, Apptainer container tool, and cryptographic libraries such as liboqs and s2n to address known exploits. Infrastructure teams managing SUSE Linux Enterprise or openSUSE distributions need to apply these patches immediately to maintain secure operations across their systems. The release also covers routine maintenance for container utilities like Helm and Kubevirt, alongside web frameworks and media encoders, ensuring broader platform hardening across all supported releases.
SUSE-SU-2026:3424-1: low: Security update for python3-pyOpenSSL
SUSE-SU-2026:3425-1: important: Security update for python-urwid
SUSE-SU-2026:3429-1: moderate: Security update for libarchive
SUSE-SU-2026:3430-1: important: Security update for tomcat11
openSUSE-SU-2026:21473-1: important: Security update for apptainer
openSUSE-SU-2026:21471-1: low: Security update for keybase-client
openSUSE-SU-2026:21474-1: moderate: Security update for s2n
openSUSE-SU-2026:21468-1: low: Security update for GraphicsMagick
openSUSE-SU-2026:21467-1: important: Security update for java-25-openjdk
openSUSE-SU-2026:21459-1: important: Security update for python313, python3
openSUSE-SU-2026:11393-1: moderate: logcli-3.7.4-1.1 on GA media
openSUSE-SU-2026:11392-1: moderate: kubevirt1.8-container-disk-1.8.4-3.1 on GA media
openSUSE-SU-2026:11384-1: moderate: ffmpeg-7-7.1.5-1.1 on GA media
openSUSE-SU-2026:11389-1: moderate: kubernetes1.34-apiserver-1.34.10-1.1 on GA media
openSUSE-SU-2026:11391-1: moderate: kubernetes1.36-apiserver-1.36.3-1.1 on GA media
openSUSE-SU-2026:11390-1: moderate: kubernetes1.35-apiserver-1.35.7-1.1 on GA media
openSUSE-SU-2026:11386-1: moderate: helm-4.2.3-4.1 on GA media
openSUSE-SU-2026:11385-1: moderate: freerdp-3.30.0-1.1 on GA media
SUSE-SU-2026:3413-1: moderate: Security update for ImageMagick
SUSE-SU-2026:3415-1: important: Security update for perl-DBI
SUSE-SU-2026:3417-1: important: Security update for apptainer
SUSE-SU-2026:3420-1: important: Security update for liboqs, oqs-provider
SUSE-SU-2026:3422-1: important: Security update for python-sh
SUSE-SU-2026:3423-1: important: Security update for xen
Rocky Linux has issued multiple security advisories affecting kernel, OpenSSH, Perl, Firefox, nodejs-nodemon, vim, fence-agents, python-pillow, and firewalld across versions 8, 9, and 10. Most updates carry an important severity rating, including patches for perl:5.32 which encompasses a wide range of sub-modules, while two items, the firewalld fix on Rocky Linux 10 and the OpenSSH update on Rocky Linux 8, hold moderate ratings. Each advisory provides Common Vulnerability Scoring System base scores linked to specific CVE identifiers so system administrators can assess the exact risk level for their environments. Users should install these errata promptly to address security flaws and incorporate the reported bug fixes and enhancements into their systems.
RLSA-2026:47040: Important: kernel security, bug fix, and enhancement update
RLSA-2026:47756: Important: openssh security update
RLSA-2026:47757: Important: openssh security update
RLBA-2026:28238: Moderate:firewalld bug fix and enhancement update
RLSA-2026:47101: Important: firefox security update
RLSA-2026:48032: Important: nodejs-nodemon security update
RLSA-2026:47982: Important: vim security update
RLSA-2026:47736: Important: fence-agents security update
RLSA-2026:47755: Moderate: openssh security update
RLSA-2026:48021: Important: python-pillow security update
RLSA-2026:48225: Important: perl:5.32 security update
Red Hat has issued a collection of security advisories rated Important for Red Hat Enterprise Linux versions 8, 9, and 10, targeting vulnerabilities across core system components and developer tools. The errata address issues within packages such as hplip, fence-agents, openssh, the kernel, golang, grafana, python3.12, nodejs24, vim, kpatch-patch, Cryostat, and OpenJDK for Windows builds. Multiple advisories also bundle bug fixes and enhancements alongside security patches, with specific releases designed for SAP Solutions services, Extended Update Support channels, and the Red Hat build of Quarkus and Apache Camel. Each advisory provides a Common Vulnerability Scoring System base score linked through CVE references so administrators can determine the precise severity rating for every identified flaw before deployment.
RHSA-2026:48603: Important: hplip security update
RHSA-2026:48615: Important: fence-agents security update
RHSA-2026:48606: Important: hplip security, bug fix, and enhancement update
RHSA-2026:47757: Important: openssh security update
RHSA-2026:47736: Important: fence-agents security update
RHSA-2026:47633: Important: kernel security, bug fix, and enhancement update
RHSA-2026:47172: Important: Red Hat build of Quarkus 3.33.2.SP3 security update
RHSA-2026:47756: Important: openssh security update
RHSA-2026:47739: Important: kernel security, bug fix, and enhancement update
RHSA-2026:48171: Important: hplip security update
RHSA-2026:47712: Important: golang security, bug fix, and enhancement update
RHSA-2026:47716: Important: grafana-pcp security, bug fix, and enhancement update
RHSA-2026:47910: Important: osbuild-composer security update
RHSA-2026:47714: Important: grafana security, bug fix, and enhancement update
RHSA-2026:47721: Important: grafana-pcp security, bug fix, and enhancement update
RHSA-2026:48222: Important: kernel-rt security update
RHSA-2026:47939: Important: python3.12 security update
RHSA-2026:48021: Important: python-pillow security update
RHSA-2026:47719: Important: golang security, bug fix, and enhancement update
RHSA-2026:47717: Important: gstreamer1-plugins-bad-free security update
RHSA-2026:48151: Important: Red Hat build of Cryostat security update
RHSA-2026:47982: Important: vim security update
RHSA-2026:48034: Important: nodejs24 security update
RHSA-2026:48095: Important: RHCS 10.8 bug fix and enhancement update
RHSA-2026:48032: Important: nodejs-nodemon security update
RHSA-2026:47981: Important: kpatch-patch security update
RHSA-2026:48118: Important: Red Hat Build of Apache Camel 4.18.3 for Quarkus 3.33 update is now available (RHBQ 3.33.2.SP3)
RHSA-2026:48605: Important: fence-agents security update
RHSA-2026:48586: Important: hplip security update
RHSA-2026:48604: Important: fence-agents security update
RHSA-2026:48845: Important: OpenJDK 25.0.4 Security Update for Windows Builds
Fedora released security patches for versions 43 and 44 targeting unbound, dokuwiki, pack, nasm, valkey, lego, and libnbd to address over thirty confirmed CVEs. The vulnerabilities span denial of service attacks through DNS-over-QUIC pressure, remote code execution via TLS connection flaws in Valkey, cache poisoning exploits in Unbound, and privilege escalation risks within containerd used by Pack. System administrators can apply the fixes immediately by running the corresponding DNF advisory commands for each affected package. Delaying these installations leaves servers exposed to memory corruption, unauthorized command execution, and data integrity breaches that attackers could exploit without authentication.
Fedora 43 Update: unbound-1.25.2-1.fc43
Fedora 43 Update: dokuwiki-20250514b-4.fc43
Fedora 43 Update: pack-0.40.8-1.fc43
Fedora 43 Update: nasm-2.16.03-5.fc43
Fedora 43 Update: valkey-8.1.9-1.fc43
Fedora 43 Update: lego-5.3.1-2.fc43
Fedora 43 Update: libnbd-1.24.3-1.fc43
Fedora 44 Update: dokuwiki-20250514b-6.fc44
Fedora 44 Update: pack-0.40.8-1.fc44
Fedora 44 Update: valkey-9.0.5-1.fc44
Debian issued security advisories addressing critical vulnerabilities in the expat, libraw, imagemagick, gsasl, and ruby-rack packages. The patches resolve integer overflows, heap buffer overflows, memory disclosure flaws, and arbitrary code execution risks that could allow attackers to crash systems or run unauthorized commands via malformed inputs. Detailed findings include multipart smuggling and denial-of-service vectors in ruby-rack, regex injection flaws in imagemagick and libraw, and missing input sanitization in the gsasl NTLM client.
[DSA 6404-1] expat security update
ELA-1790-1 libraw security update (by )
ELA-1789-1 imagemagick security update (by )
[DLA 4707-1] gsasl security update
[DLA 4706-1] ruby-rack security update
AlmaLinux issued five security errata addressing critical vulnerabilities in Node.js versions 22 and 24, OpenSSH clients, and Vim across its Linux distributions. The advisories resolve denial-of-service flaws in the brace-expansion and tar libraries that impact Node.js packages, while a distinct Vim patch targets arbitrary code execution risks arising from malicious Python docstrings and crafted tags files used during omni-completion. OpenSSH updates mitigate severe threats including remote man-in-the-middle attacks via X11 forwarding, client-side denials of service triggered by double-free errors in DH-GEX validation, heap out-of-bounds reads in GSSAPI cleanup, use-after-free conditions during host key re-exchange, and scp file misplacement issues.
ALSA-2026:48034: nodejs24 security update (Important)
ALSA-2026:48032: nodejs-nodemon security update (Important)
ALSA-2026:48033: nodejs22 security update (Important)
ALSA-2026:47757: openssh security update (Important)
ALSA-2026:48703: vim security update (Important)
ALSA-2026:47755: openssh security update (Moderate)
2026-07-30
The Xen Project has officially released version 4.22, pushing the date back from its original schedule to ensure embargo-expiring security fixes land simultaneously with the public announcement. The update brings critical hardware support including AMD Zen 5 Bus Lock Threshold handling and Intel FRED, alongside significant advancements in cloud scalability via per-domain Xenstore quotas and Arm-based guest power management. Major industry players like Honda, Ford, and Renesas are leveraging the release for software-defined vehicles and functional safety certification, solidifying the hypervisor's niche in mixed-criticality systems where competitors like KVM fall short.
Red Hat has split Fedora’s top community leadership position into two dedicated roles, with Shaun McCance inheriting the traditional Fedora Community Architect seat and Justin Wheeler moving into a newly created AI Alignment Community Architect position. The transition runs through the Fedora Linux 45 release in October 2026, giving McCance time to take over event logistics, budget stewardship, and Fedora Council representation while Wheeler focuses on aligning default AI services with the project’s four founding principles.
XanMod Linux Kernel 6.18.41-xanmod1 arrived today and built on top of upstream Linux 6.18.41 LTS. The kernel compiles with LLVM ThinLTO across three x86-64 ABI tiers and applies a curated collection of performance patches, including Google BBRv3, AMD 3D V-Cache optimization, and Cloudflare TCP Collapse. This point release prioritizes stability by backporting Thomas Gleixner's fixes for posix-cpu-timers use-after-free vulnerabilities and timer arm callback validation. The 6.18 branch provides long-term support through December 2028 and bundles NVIDIA graphics drivers for both open and proprietary stacks.
Zen Browser 1.21.10b drops five days after its predecessor, shipping the Firefox 153.0.1 engine with a sharp focus on Linux workflow stability. The release skips Windows-specific RTX and HDR patches but delivers critical fixes for Spaces crashes, accidental workspace switching, and broken CSS overrides in Boosts. Released by @mr-cheffy with a verified GPG signature, the build emphasizes a rapid five-day cadence across both the stable Release and Twilight canary channels. Linux users chasing a faster, more polished Firefox fork should install this patch to smooth out the desktop experience.
Exim 4.100-RC1 has arrived in the official testing directory. The release stays firmly within the 4.x line, but two decades of incremental development have finally been packaged under a century mark, bringing native SPF/DKIM/DMARC authentication, dynamic loadable modules, and expanded taint tracking to the long-lived codebase. Operators should audit their configurations against removed legacy drivers and patched log formats, as 4.100-RC1 also closes four confirmed CVEs including a musl-specific DNS crash and a JSON heap corruption flaw. The release candidate is available now for review, though the stable 4.99.5 build remains the production default until the RC testing period concludes.
HestiaCP released version 1.9.8, just two weeks after addressing nine critical CVEs in 1.9.7. The new update hardens access controls around the ROOT_USER account to prevent privilege escalation and patches cross-site scripting in notifications alongside command injection risks in the backup queue. Functional fixes address a regression in the SFTP jail feature that broke connectivity for jailed users, as well as broken FTP certificate reloading and corrupted JSON output from SSL queries.
Greg Kroah-Hartman released six coordinated Linux kernel stable versions this past Thursday, with every currently-supported longterm branch receiving the exact same critical patch. The fix targets a 16-year-old use-after-free vulnerability in the POSIX CPU timers subsystem caused by a race condition between sys_timer_delete() and non-leader exec() calls. Independently discovered by researchers Wongi Lee and Jungwoo Lee, the bug could silently disable timers or enable local privilege escalation on multi-threaded systems. Thomas Gleixner's four-part patch lands across all six branches, with 6.18.41 additionally picking up a preparatory callback update while stable maintainers continue merging dozens of branch-specific fixes behind the scenes.
Tech reviewers tested several new desktop and mini PC options, including the compact ASUS ROG GR70 with an RTX 5070 Laptop GPU, the Alienware Area-51 featuring a Ryzen 7 9850X3D processor, and two MSI models packing Panther Lake silicon and Core Ultra 9 chips. Each system demonstrated strong performance across gaming, productivity, and AI workloads while highlighting different design approaches to small form factor computing. On the cooling front, Noctua released a 360mm liquid CPU cooler that prioritizes quiet operation and solid build quality for both Intel and AMD platforms. Input device enthusiasts received an early look at AULA's compact 60% gaming keyboard built around magnetic switch technology.
Computers: ASUS ROG GR70 Mini PC Review, Alienware Area-51 Review: Ryzen 7 9850X3D Powered Elite Gaming, MSI Cubi NUC AI+ 3MG review: Panther Lake in an understated mini PC, MSI MEG Vision X AI review: a powerful gaming PC with a useful built-in screen
Cooling: Noctua NL-LC1-36 Liquid CPU Cooler Review
Input: AULA AG60 Pro Keyboard Review
Devolutions released UniGetUI v2026.2.6, landing a polish-heavy update that refreshes the interface with WinUI-inspired overlays and adds CSV export for installed packages and available updates. The release marks four months of active stewardship since the company acquired the project, focusing on visual parity with Windows 11, richer operation history tracking, and smarter settings management. Real-world pain points take priority in this cycle, with targeted fixes for WinGet update loops, PowerShell scope mismatches, silent install location overrides, embedded web content memory leaks, and background UAC prompts. For users juggling WinGet, Scoop, Chocolatey, Homebrew, and dozens of other package managers, v2026.2.6 delivers the kind of day-to-day friction reduction that signals a truly mature open-source tool.
Seafoam-Labs released Shelly 3.0.1 on July 30, consolidating twelve pull requests to polish Arch Linux's GTK4-based package manager. The update adds a --detail flag for AUR metadata, a persistent --install-path option for AppImages, and a dedicated Flatpak dialog that loads on demand. Critical bug fixes include rewritten package selection logic that prioritizes exact matches, added keybinding support for dialog interactions, and targeted GNOME compatibility improvements. Available now via CachyOS repositories, the AUR, or from source, Shelly 3.0.1 builds on a stable foundation with upcoming features focused on repository modification and offline updates.
Ubuntu released a batch of security notices to patch critical vulnerabilities across its Linux kernel variants for NVIDIA, IBM, Azure FIPS, Raspberry Pi, and KVM platforms. The updates fix logic flaws in networking subsystems like XFRM ESP-in-TCP alongside issues affecting storage drivers, file systems, and multiple processor architectures across Ubuntu versions ranging from 18.04 LTS to 26.04 LTS. Administrators must run a standard system upgrade followed by a manual reboot to fully apply the patches and activate the security fixes. Users relying on custom kernel modules will need to recompile those packages because the new version numbers reflect an unavoidable Application Binary Interface change.
[USN-8623-1] Linux kernel (NVIDIA) vulnerabilities
[USN-8622-1] Linux kernel (NVIDIA) vulnerabilities
[USN-8615-1] Linux kernel vulnerabilities
[USN-8616-1] Linux kernel (IBM) vulnerabilities
[USN-8620-2] Linux kernel (Azure FIPS) vulnerabilities
[USN-8547-2] Linux kernel (Azure FIPS) vulnerabilities
[USN-8615-2] Linux kernel (Raspberry Pi) vulnerabilities
[USN-8617-1] Linux kernel (KVM) vulnerabilities
SUSE issued a new batch of security patches covering rsyslog, gimp, nsd, GraphicsMagick, webkit2gtk3, python-urllib3, python-ujson, PackageKit, java-17-openjdk, openvpn, and xen. The majority of these advisories carry an important severity rating, while PackageKit and python-urllib3 receive moderate fixes and GraphicsMagick gets a low-severity patch. The openSUSE announcement specifically addresses vulnerabilities in the nsd name server application to block active exploitation attempts.
SUSE-SU-2026:3398-1: important: Security update for rsyslog
SUSE-SU-2026:3399-1: important: Security update for gimp
openSUSE-SU-2026:0265-1: important: Security update for nsd
SUSE-SU-2026:3395-1: low: Security update for GraphicsMagick
SUSE-SU-2026:3396-1: important: Security update for webkit2gtk3
SUSE-SU-2026:3397-1: moderate: Security update for python-urllib3
SUSE-SU-2026:3402-1: important: Security update for python-ujson
SUSE-SU-2026:3404-1: moderate: Security update for PackageKit
SUSE-SU-2026:3406-1: important: Security update for java-17-openjdk
SUSE-SU-2026:3407-1: important: Security update for openvpn
SUSE-SU-2026:3409-1: important: Security update for xen
Rocky Linux issued a series of security and maintenance errata covering versions 8, 9, and 10, with advisory identifiers spanning RLSA-2026:47010 through RLBA-2026:47115. Important patches resolve vulnerabilities in key packages including kernel-rt, kernel, openssh, firefox, php, nginx, postgresql, ruby, and perl 5.32 modules to harden system defenses. The update cycle also delivers moderate fixes for python-urllib3 and coreutils on Rocky Linux 8, plus security enhancements for gstreamer1-plugins-bad-free, pipewire, rest, libXfont2, and kernel targeting Rocky Linux 10 environments. Each advisory provides a Common Vulnerability Scoring System base score tied to relevant CVEs so administrators can assess severity and apply the necessary changes through the errata portal.
RLSA-2026:47010: Important: kernel-rt security update
RLSA-2026:47103: Important: libXfont2 security update
RLSA-2026:47011: Important: kernel security update
RLSA-2026:47731: Important: gstreamer1-plugins-bad-free security update
RLSA-2026:48225: Important: perl:5.32 security update
RLSA-2019:3702: Moderate: openssh security, bug fix, and enhancement update
RLSA-2026:47180: Important: gstreamer1-plugins-bad-free security update
RLSA-2026:47079: Important: libXfont2 security update
RLSA-2026:47083: Important: pipewire security update
RLSA-2026:47085: Important: rest security update
RLSA-2026:47017: Important: kernel security, bug fix, and enhancement update
RLSA-2026:27741: Important: postgresql security update
RLSA-2026:33449: Important: php security update
RLSA-2026:38796: Important: plexus-utils security update
RLSA-2026:36331: Important: nginx security, bug fix, and enhancement update
RLSA-2026:33512: Important: ruby security update
RLSA-2026:47105: Important: firefox security update
RLSA-2026:30852: Important: perl-Archive-Tar security update
RLSA-2026:30858: Important: perl-IO-Compress security update
RLSA-2026:36732: Moderate: python-urllib3 security update
RLBA-2026:47115: Moderate:coreutils bug fix and enhancement update
Red Hat Product Security released a batch of advisories rating Quarkus, kernel variants for RHEL SAP and Extended Update Support environments, kpatch-patch modules, and OpenShift Container Platform releases as having important security impacts due to identified vulnerabilities. The updates also address issues in gstreamer1-plugins-bad-free, perl:5.32, osbuild-composer, grafana, mariadb-connector-c, nodejs22, and kernel-rt for SAP Solutions across various Red Hat Enterprise Linux versions. A smaller set of advisories carries a moderate rating, covering openssh on RHEL 8 and container-selinux combined with crun within the RHEL 10.0 Extended Update Support stream.
RHSA-2026:47189: Important: Red Hat build of Quarkus 3.27.4.SP3 security update
RHSA-2026:47869: Important: kernel security update
RHSA-2026:47620: Important: kernel security update
RHSA-2026:47998: Important: kpatch-patch security update
RHSA-2026:47983: Important: kpatch-patch security update
RHSA-2026:47997: Important: kpatch-patch security update
RHSA-2026:48016: Important: kpatch-patch security update
RHSA-2026:47984: Important: kpatch-patch security update
RHSA-2026:44230: Important: OpenShift Container Platform 4.18.50 bug fix and security update
RHSA-2026:44231: Important: OpenShift Container Platform 4.19.40 bug fix and security update
RHSA-2026:47755: Moderate: openssh security update
RHSA-2026:47731: Important: gstreamer1-plugins-bad-free security update
RHSA-2026:47718: Important: gstreamer1-plugins-bad-free security update
RHSA-2026:47632: Important: kernel-rt security, bug fix, and enhancement update
RHSA-2026:48225: Important: perl:5.32 security update
RHSA-2026:48036: Important: osbuild-composer security update
RHSA-2026:47722: Important: grafana security, bug fix, and enhancement update
RHSA-2026:47772: Important: mariadb-connector-c security update
RHSA-2026:47905: Moderate: container-selinux and crun security, bug fix, and enhancement update
RHSA-2026:48033: Important: nodejs22 security update
Oracle Linux released multiple security advisories for version 10 that update core system packages including the Unbreakable Enterprise kernel, golang, openssl, podman, nginx, freerdp, libreswan, and mariadb-connector-c across x86_64 and aarch64 architectures. These patches resolve dozens of assigned CVEs covering memory corruption flaws, arbitrary code execution risks, and denial-of-service vulnerabilities alongside specific driver regressions in the arm64 ACPI subsystem and virtio_pci networking stack. Oracle Linux Premier Support subscribers can use Ksplice to patch out-of-bounds memory access flaws in the IPv6 networking stack and RDMA RXE driver on OL7 and OL8 systems without restarting their servers.
ELSA-2026-43505 Important: Oracle Linux 10 mariadb-connector-c security update
ELBA-2026-500062 Unbreakable Enterprise kernel bug fix update
ELSA-2026-46398 Important: Oracle Linux 10 libreswan security update
New Ksplice updates for UEKR6 5.4.17 on OL7 and OL8
ELSA-2026-29980 Moderate: Oracle Linux 10 golang security, bug fix, and enhancement update
ELBA-2026-39326 Oracle Linux 10 openssl bug fix and enhancement update
ELSA-2026-24386 Important: Oracle Linux 10 podman security update
ELSA-2026-18289 Important: Oracle Linux 10 podman security update
ELSA-2026-19142 Moderate: Oracle Linux 10 freerdp security update
ELSA-2026-29874 Important: Oracle Linux 10 nginx security update
ELBA-2026-500086 xfsprogs bug fix update
ELSA-2026-46394 Important: Oracle Linux 10 go-fdo-client security update
ELSA-2026-37072 Important: Oracle Linux 10 podman security, bug fix, and enhancement update
Fedora pushed a large batch of security patches to both Fedora 43 and Fedora 44. The release tackles serious flaws across WordPress 6.9.5, Node.js 24, Nginx 1.30.4, Unbound, ProFTPD, Squid, libssh, and Perl-HTTP-Date. System administrators gain fixes for remote code execution risks in the WordPress REST API, heap buffer overflows in Unbound, denial of service threats inside Node.js undici libraries, and cache poisoning flaws across several network services.
Fedora 44 Update: libssh-0.12.2-1.fc44
Fedora 44 Update: unbound-1.25.2-1.fc44
Fedora 44 Update: proftpd-1.3.9c-3.fc44
Fedora 44 Update: squid-7.6-1.fc44
Fedora 44 Update: nodejs24-24.18.0-1.fc44
Fedora 44 Update: wordpress-6.9.5-1.fc44
Fedora 43 Update: proftpd-1.3.9c-3.fc43
Fedora 43 Update: wordpress-6.9.5-1.fc43
Fedora 43 Update: nginx-mod-fancyindex-0.6.0-8.fc43
Fedora 43 Update: nginx-mod-vts-0.2.4-13.fc43
Fedora 43 Update: nginx-mod-modsecurity-1.0.4-16.fc43
Fedora 43 Update: nginx-mod-brotli-1.0.0~rc-13.fc43
Fedora 43 Update: nginx-1.30.4-1.fc43
Fedora 43 Update: nginx-mod-naxsi-1.6-21.fc43
Fedora 43 Update: nginx-mod-headers-more-0.40-3.fc43
Fedora 43 Update: perl-HTTP-Date-6.08-1.fc43
Debian issued two security advisories, addressing critical flaws in the calibre e-book manager and the nss cryptography library. The calibre update (DLA-4705-1) resolves five vulnerabilities across CVE-2026-27810, CVE-2026-27824, CVE-2026-30853, CVE-2026-33205, and CVE-2026-33206, which include path traversal risks in the RocketBook plugin, HTTP response header injection, brute-force protection bypasses via spoofed headers, and server-side request forgery that could expose data from the ebook sandbox. The nss advisory (DSA-6403-1) fixes CVE-2026-16389 in the Mozilla Network Security Service library, where processing a maliciously crafted certificate could trigger arbitrary code execution. Users running Debian 11 bullseye should upgrade calibre to version 5.12.0+dfsg-1+deb11u5 immediately, while trixie users must apply nss update 2:3.110-1+deb13u4 to close these security gaps.
[DLA 4705-1] calibre security update
[DSA 6403-1] nss security update
AlmaLinux released a batch of important security errata, targeting multiple core libraries across both the AlmaLinux 8 and 10 operating systems. The updates address memory corruption flaws in gstreamer1-plugins-bad-free, libXfont2, rest, nodejs versions 22 and 24, and libtiff that could allow remote code execution or cause system crashes. Administrators will also find patches for denial-of-service vulnerabilities in the Node.js tar and brace-expansion modules alongside a weak random number generation issue inside the librest PKCE implementation.
ALSA-2026:47180: gstreamer1-plugins-bad-free security update (Important)
ALSA-2026:47079: libXfont2 security update (Important)
ALSA-2026:47085: rest security update (Important)
ALSA-2026:47059: nodejs:22 security update (Important)
ALSA-2026:47060: nodejs:24 security update (Important)
ALSA-2026:47184: libtiff security update (Important)
ALSA-2026:47731: gstreamer1-plugins-bad-free security update (Important)
ALSA-2026:47103: libXfont2 security update (Important)
[ Archive ]