2026-08-13
Zen Browser 1.21.14b drops today, updating the Firefox fork to engine 153.0.4 and adding FFmpeg 63 for faster media decoding. The stable build finally squashes a Window Sync hang triggered by container ID mismatches and patches a dark-mode contrast bug for Live Folders.
PostgreSQL has shipped maintenance updates for every supported version, including 18.6, 17.11, 16.15, 15.19, and 14.24, to patch 30 security vulnerabilities involving heap buffer overflows and remote code execution risks. The third beta of PostgreSQL 19 is also available, bringing a unified REPACK command, SQL Property Graph query support, and temporal data handling via the FOR PORTION OF clause. Performance and optimizer enhancements in the upcoming release include automatic NOT IN to ANTI JOIN conversions, SIMD-accelerated COPY FROM operations, and a switch to LZ4 as the default TOAST compression method.
The Exim development team released 4.100-RC3 on August 13, marking the third and final release candidate before the stable major update ships. The new branch introduces native DMARC evaluation, expanded log selectors, and a musl DNS out-of-bounds read fix for containerized environments. Legacy malware scanner bridges and outdated protocol support have been removed alongside a new versioning structure that separates security patches onto a dedicated branch. Operators running mail infrastructure should test the release candidate now, with the official 4.100 tag expected within weeks.
Bottles 66.2 dropped less than 24 hours after version 66.1, patching six critical regressions and tightening network calls for the popular Linux Wine and Proton manager. The hotfix resolves a bottle-deletion crash for multi-drive setups, restores custom Steam Runtime launch flags, and finally handles case-sensitive DLL conflicts for the XACT audio dependency. Lead maintainer Mirko Brombin also merged patches that properly detect NVIDIA's open-source NVK Vulkan driver, move heavy network requests off the main UI thread, and revive the external executable launch workflow. The update is available now via Flatpak and cpak, keeping the 143,000-download-strong community on stable ground before the next major feature push lands.
Today's hardware roundups cover the InWin Covalent and Cooler Master HAF II 500 chassis, plus a $1,959 GMKtec Evo-T2 packing Intel's Panther Lake. TechPowerUp and TweakTown break down the Logitech G Pro X2 Superstrike mouse and the D-Link F518 hotspot, while Tom's Hardware labels the QIDI Plus5 a genuine rival to Bambu Lab's 3D printers. Keep in mind that review scores often shift once firmware updates drop.
Shelly ALPM v3.0.5 hit the GitHub releases today, bringing just an updated Polkit warning and a routine branch back-merge to the v3.x line. The release lands just one day after the feature-packed v3.0.4, signaling that the team behind the Zig rewrite is shifting focus from rapid-fire development to post-stabilization polish. The quiet bump sits on top of the core architecture introduced back in late July, where the project finally ditched its .NET runtime to link directly to libalpm for genuine native performance across its GTK4 UI, CLI, and TUI modes. You can grab the 6.8 MB UI bundle directly from the GitHub releases page, or sync it through the AUR if you're running a CachyOS or Arch-based install.
rsync 3.5.0 has arrived, delivering fixes for 33 CVEs across symlink race conditions, daemon protocol flaws, and authentication bypasses. The release introduces secure_relative_open(), a hardened path-resolution framework that pins directory file descriptors and blocks out-of-tree symlink hops. If you run rsync with elevated privileges or rely on it for CI/CD and cloud backups, updating immediately is non-negotiable. Backports for the 3.4.1 and 3.2.7 branches are rolling out alongside the main release this week.
AM, the open-source AppImage package manager for GNU/Linux, has released version 10.4, expanding its supported app database to 3,388 entries with a major focus on headless automation. The headline update introduces a global -y flag and enhanced non-interactive installation support, making the tool far more suitable for CI/CD pipelines, container builds, and unattended deployments without requiring manual prompts. Driven by a surge in community contributions following the maintainer's reduced involvement, the release also adds useful utilities like a relocate option for preserving portable profiles, a downgrade command, and fuzzy search suggestions for typos. Unlike Flatpak or Snap, AM keeps apps running natively outside of system package managers, though users should note that the script-based database relies on community-maintained installers rather than strict sandboxes.
Python's core team has released security-only source-only updates for Python 3.10.21, 3.11.16, and 3.12.14, confirming all three versions are now in maintenance mode with no further release cadence. The updates prioritize critical path traversal bypasses in tarfile and ZIP extraction on Windows, while also blocking remote code execution vectors in webbrowser, cookie handling, and WSGI status fields. Denial-of-service protections have been strengthened against exponential complexity attacks in csv, HTML parsing, and XML modules, complemented by a bundle update to libexpat 2.8.3 for improved billion laughs and hash flooding defenses. Users should upgrade immediately, especially those processing untrusted archives or structured data, as these patches address high-severity CVEs including a tarfile link-target escape and cookie control character injection.
Ubuntu issued a series of security notices, addressing multiple flaws across the Yelp help browser, the node-follow-redirects module, the libgit2 library, and the Linux kernel. The patches correct weaknesses that could let attackers steal credentials via improperly stripped HTTP redirect headers, expose user data through lax content security policies in help documents, or trigger crashes and arbitrary code execution through malformed Git protocol packets. Kernel updates cover dozens of cloud, IoT, and real-time variants for Ubuntu 14.04 through 26.04 LTS, and the required system reboot combined with an ABI change means users must reinstall any third-party kernel modules they previously compiled.
[USN-8627-1] Yelp vulnerability
[USN-8632-1] follow-redirects vulnerability
[USN-8628-1] libgit2 vulnerabilities
[USN-8631-1] Linux kernel vulnerabilities
[USN-8635-1] Linux kernel (Azure) vulnerabilities
[USN-8629-1] Linux kernel vulnerabilities
[USN-8633-1] Linux kernel vulnerabilities
[USN-8636-1] Linux kernel vulnerabilities
[USN-8630-1] Linux kernel vulnerabilities
[USN-8634-1] Linux kernel vulnerabilities
Rocky Linux published fifteen security advisories to patch known vulnerabilities across Linux versions 8, 9, and 10. The errata target the main kernel, storage networking utilities like isns-utils and iscsi-initiator-utils, and high-availability cluster packages including fence-agents and resource-agents. Each notice rates the update as Important or Moderate and provides official CVSS severity scores for every linked CVE. Server operators need to install these patches promptly to close security gaps and maintain system stability.
RLSA-2026:53847: Important: isns-utils security update
RLSA-2026:53365: Important: fence-agents security update
RLSA-2026:53844: Important: iscsi-initiator-utils security, bug fix, and enhancement update
RLSA-2026:53452: Moderate: gstreamer1-plugins-good security update
RLSA-2026:53329: Important: kernel security, bug fix, and enhancement update
RLSA-2026:53364: Important: resource-agents security update
RLSA-2026:53363: Important: fence-agents security update
RLSA-2026:53848: Important: isns-utils security update
RLSA-2026:53846: Important: isns-utils security update
RLSA-2026:53435: Important: udisks2 security update
RLSA-2026:53330: Important: kernel security, bug fix, and enhancement update
RLSA-2026:53845: Important: iscsi-initiator-utils security, bug fix, and enhancement update
RLSA-2026:53451: Moderate: gstreamer1-plugins-good security update
RLSA-2026:47126: Moderate: resource-agents security update
RLSA-2026:47117: Moderate: libgcrypt security update
Red Hat has issued a batch of security advisories addressing vulnerabilities across Red Hat Enterprise Linux versions 7 through 10. The patches target widely used components including Firefox, the Linux kernel, Python 3.9, MariaDB 10.11, and ldns. Administrators should review the Common Vulnerability Scoring System ratings attached to each advisory before deploying the fixes to extended support channels or standard RHEL installations.
RHSA-2026:54168: Important: rhc-worker-playbook security update
RHSA-2026:54142: Important: mariadb:10.11 security update
RHSA-2026:54254: Important: ldns security update
RHSA-2026:54246: Moderate: kernel security update
RHSA-2026:54244: Important: ldns security update
RHSA-2026:54247: Moderate: kernel-rt security update
RHSA-2026:54191: Important: rhc-worker-script security update
RHSA-2026:54182: Important: firefox security update
RHSA-2026:54181: Important: firefox security update
RHSA-2026:54178: Moderate: grafana security, bug fix, and enhancement update
RHSA-2026:54185: Important: firefox security update
RHSA-2026:54180: Important: firefox security update
RHSA-2026:54343: Important: kernel security, bug fix, and enhancement update
RHSA-2026:47117: Moderate: libgcrypt security update
RHSA-2026:47126: Moderate: resource-agents security update
RHSA-2026:47129: Moderate: resource-agents security update
RHSA-2026:54339: Important: firefox security update
RHSA-2026:54268: Important: python3.9 security update
RHSA-2026:54272: Important: abrt security update
RHSA-2026:54290: Moderate: python-idna security update
RHSA-2026:54248: Important: firefox security update
RHSA-2026:54249: Important: firefox security update
RHSA-2026:54259: Important: firefox security update
RHSA-2026:54210: Moderate: dhcpcd security update
RHSA-2026:54435: Important: Streams for Apache Kafka 3.2.1 release and security update
RHSA-2026:54417: Important: python-pillow security update
RHSA-2026:54443: Important: kernel security, bug fix, and enhancement update
RHSA-2026:54401: Important: rhc security update
RHSA-2026:54377: Important: ldns security update
Oracle issued a batch of security and bug fix advisories for Oracle Linux 7, 8, 9, and 10, ranging from Important to Moderate severity levels across multiple subsystems. The kernel includes Unbreakable Enterprise kernel updates for versions 8, 9, and 10, while version 7 receives standard kernel patches and microcode_ctl enhancements. Administrators should prioritize patches for widely used components like OpenJDK 1.8, Sudo, Dovecot, PostgreSQL, and Ruby 3.3, as these advisories address security vulnerabilities that could impact system integrity. Supporting packages also receive fixes, including GStreamer plugins, PipeWire, libarchive, libguestfs, fence-agents, and the leapp-repository, rounding out the maintenance cycle for these operating system releases.
ELSA-2026-500150 Important: Unbreakable Enterprise kernel security update
ELSA-2026-53451 Moderate: Oracle Linux 10 gstreamer1-plugins-good security update
ELSA-2026-53435 Important: Oracle Linux 10 udisks2 security update
ELSA-2026-53846 Important: Oracle Linux 10 isns-utils security update
ELSA-2026-53330 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
ELSA-2026-49526 Important: Oracle Linux 10 osbuild-composer security update
ELSA-2026-34911 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
ELBA-2026-50139-0 Oracle Linux 10 tuned bug fix and enhancement update
ELBA-2026-39299 Oracle Linux 10 microcode_ctl bug fix and enhancement update
ELSA-2026-500162 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
ELSA-2026-53847 Important: Oracle Linux 9 isns-utils security update
ELSA-2026-53452 Moderate: Oracle Linux 9 gstreamer1-plugins-good security update
ELSA-2026-53365 Important: Oracle Linux 9 fence-agents security update
ELSA-2026-53329 Important: Oracle Linux 9 kernel security, bug fix, and enhancement update
ELSA-2026-52395 Important: Oracle Linux 9 postgresql security update
ELSA-2026-52674 Moderate: Oracle Linux 9 libarchive security update
ELSA-2026-47082 Important: Oracle Linux 9 pipewire security update
ELSA-2026-42877 Important: Oracle Linux 9 java-1.8.0-openjdk security update
ELBA-2026-39314 Oracle Linux 9 microcode_ctl bug fix and enhancement update
ELSA-2026-500162 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
ELBA-2026-500146 Oracle Linux 9 libguestfs bug fix update
ELSA-2026-500162 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
ELBA-2026-500147 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
ELSA-2026-53363 Important: Oracle Linux 8 fence-agents security update
ELSA-2026-50728 Important: Oracle Linux 8 ruby:3.3 security, bug fix, and enhancement update
ELBA-2026-47114 Oracle Linux 8 microcode_ctl bug fix and enhancement update
ELSA-2026-42877 Important: Oracle Linux 8 java-1.8.0-openjdk security update
ELBA-2026-500165 Oracle Linux 8 leapp-repository bug fix update
ELSA-2026-49513 Important: Oracle Linux 7 dovecot security update
ELSA-2026-8517 Important: Oracle Linux 7 libarchive security update
ELSA-2026-47176 Important: Oracle Linux 7 gstreamer1-plugins-bad-free security update
ELSA-2026-43575 Moderate: Oracle Linux 7 gnutls security update
ELSA-2026-41904 Important: Oracle Linux 7 evince security update
ELSA-2026-37397 Important: Oracle Linux 7 ruby security update
ELSA-2026-26564 Important: Oracle Linux 7 dovecot security update
ELSA-2026-13895 Important: Oracle Linux 7 sudo security update
Gentoo Linux released security advisory GLSA 202608-02 to patch multiple vulnerabilities in media-libs/freetype for versions below 2.14.3. The flaws encompass an out-of-bounds read and information disclosure risk across nine CVE identifiers, with no known workaround available. Administrators must update the font engine to version 2.14.3 or later to resolve the issues. Install the fix by running emerge --sync and then emerge --ask --oneshot --verbose ">=media-libs/freetype-2.14.3".
[ GLSA 202608-02 ] FreeType: Multiple Vulnerabilities
Fedora 43 and 44 received a coordinated batch of security-focused package updates. The release upgrades cri-o1.34 to version 1.34.11, vaultwarden to 1.37.1, sqlite to 3.51.2, linux-firmware to 20260810, apr-util to 1.6.5, and libcupsfilters to 2.1.1. These changes close multiple critical vulnerabilities, including arbitrary code execution flaws in sqlite FTS5, denial of service risks in vaultwarden and cri-o, and XML stack attacks in apr-util. Users can apply the patches immediately by running the standard dnf upgrade command paired with the corresponding Fedora advisory ID.
Fedora 43 Update: cri-o1.34-1.34.11-1.fc43
Fedora 43 Update: vaultwarden-1.37.1-1.fc43
Fedora 44 Update: sqlite-3.51.2-2.fc44
Fedora 44 Update: linux-firmware-20260810-1.fc44
Fedora 44 Update: apr-util-1.6.5-1.fc44
Fedora 44 Update: libcupsfilters-2.1.1-9.fc44
Fedora 44 Update: cri-o1.34-1.34.11-1.fc44
Fedora 44 Update: vaultwarden-1.37.1-1.fc44
Debian and Freexian LTS distributions released security patches addressing more than forty CVEs across BIND DNS, PHP, Django, Flatpak, and several other widely used packages. The BIND9 update backports the software from Debian 10 to stretch, which fixes thirteen CVEs but breaks binary compatibility and requires third-party applications to rebuild against the new libraries. PHP 7.0 and 7.3 patches eliminate stack exhaustion crashes in phar archives and close a SQL injection route in the psql extension, while Django updates block a denial-of-service trigger and cross-site scripting flaws in the admin interface. Additional fixes target Flatpak local privilege escalation, SPIP remote code execution, Neutron network state mutation, jq arbitrary code execution, and libgd2 malformed GIF processing.
ELA-1802-1 bind9 security update (by )
ELA-1801-1 jq security update (by )
ELA-1803-1 ca-certificates CA certificates update (by )
ELA-1802-1 bind9 security update (by )
ELA-1807-1 php7.0 security update (by )
ELA-1806-1 php7.3 security update (by )
ELA-1805-1 libgd2 security update (by )
ELA-1804-1 libconfig-inifiles-perl security update (by )
[DLA 4735-1] neutron security update
[DSA 6434-1] lemonldap-ng security update
[DSA 6432-1] flatpak security update
[DLA 4736-1] python-django security update
[DSA 6435-1] spip security update
AlmaLinux issued a batch of security advisories, affecting versions 8, 9, and 10 of its operating system. The updates address vulnerabilities across essential components including the Linux kernel, PostgreSQL, Firefox, iSCSI utilities, and the automatic bug reporting tool. Remediated flaws span denial of service attacks, arbitrary code execution, privilege escalation, and memory corruption issues tied to dozens of tracked CVE identifiers. Organizations running these versions must install the updated packages immediately to prevent unauthorized access and service interruptions.
ALSA-2026:53365: fence-agents security update (Important)
ALSA-2026:49607: frr10 security, bug fix, and enhancement update (Important)
ALSA-2026:53844: iscsi-initiator-utils security, bug fix, and enhancement update (Important)
ALSA-2026:53847: isns-utils security update (Important)
ALSA-2026:47104: firefox security update (Important)
ALSA-2026:52395: postgresql security update (Important)
ALSA-2026:52772: perl-DBI:1.641 security update (Important)
ALSA-2026:53848: isns-utils security update (Important)
ALSA-2026:53452: gstreamer1-plugins-good security update (Moderate)
ALSA-2026:53363: fence-agents security update (Important)
ALSA-2026:53364: resource-agents security update (Important)
ALSA-2026:52396: postgresql:12 security update (Important)
ALSA-2026:52765: kernel security update (Moderate)
ALSA-2026:52761: kernel-rt security update (Moderate)
ALSA-2026:53845: iscsi-initiator-utils security, bug fix, and enhancement update (Important)
ALSA-2026:53846: isns-utils security update (Important)
ALSA-2026:27742: postgresql18 security update (Important)
ALSA-2026:24348: postgresql-jdbc security update (Important)
ALSA-2026:51295: kernel security, bug fix, and enhancement update (Moderate)
ALSA-2026:52841: nodejs-nodemon security update (Important)
ALSA-2026:52675: libarchive security update (Moderate)
ALSA-2026:38490: xorg-x11-server-Xwayland security update (Important)
ALSA-2026:38497: gegl04 security update (Important)
ALSA-2026:49838: osbuild-composer security, bug fix, and enhancement update (Important)
ALSA-2026:54272: abrt security update (Important)
ALSA-2026:54246: kernel security update (Moderate)
ALSA-2026:54290: python-idna security update (Moderate)
2026-08-12
Wireshark 4.6.8 is here, delivering 31 security patches that represent the largest single-release hardening effort in the tool's history. The updates focus on crashes triggered by malformed capture files, while also patching the Bluetooth stack, 5G telecom protocols, and the network-facing sharkd daemon. The Wireshark Foundation pushed the fixes alongside version 4.4.18 for long-term support users, closing memory corruption risks across dissectors for SSH, Kerberos, and various file parsers. Linux administrators should note that extcap binaries now default to /usr/libexec/wireshark/extcap, and teams relying on the tool for daily traffic analysis should update immediately to mitigate out-of-bounds read vulnerabilities.
Mesa 26.1.7 landed today, delivering a tight cluster of memory safety patches, compiler corrections, and driver-level workarounds to the stable 26.1.x maintenance branch. The update addresses long-standing buffer object refcounting bugs across the DRM shim, fixes float-to-int conversion artifacts in the NIR pipeline, and adds missing hardware stepping workarounds for Intel Arc and RDNA graphics. OpenCL developers also get a structural bump as Rusticl pivots to a community-maintained libclc fork verified against the official conformance suite. The maintenance branch will continue receiving stability-only patches through August 26, while feature development remains firmly locked to the newer 26.2.x track.
Shelly ALPM v3.0.4 shipped today, introducing the project's first dedicated terminal interface alongside a completely redesigned unified search flow for the AUR, official repositories, and Flatpak. The drop arrives just five days after v3.0.3, continuing a breakneck six-release cadence in two weeks following the July 29 Zig rewrite that completely eliminated the .NET runtime. Flatpak users get end-of-life detection, remote branch resolution, and a cleaner uninstall workflow, while polished shell completions and new CLI man pages target terminal power users who prefer direct libalpm integration. The update is live now for CachyOS via sudo pacman -S shelly and is also available through the AUR or as standalone tarballs on GitHub.
Zed Editor v1.15.0 ships with self-hosted sweep-next-edit model support for private AI inference, a new git.diff_base setting to toggle diff baselines against default branches, and Wayland drag-and-drop for Linux. The update brings linked editing for custom JSX/TSX elements, Emmet completions in arrow functions, and 11 contributions from the Zed Guild community. Copilot users must re-authenticate as Zed decouples session management for chat and edit predictions to reduce credential blast radius. The release underscores Zed's continued sprint toward production parity, combining tighter Git workflows with expanded private inference options.
Bazaar 0.9.3 is a maintenance update for the Flatpak-first app store, arriving just seven days after the feature-heavy 0.9.2 release to stabilize the newly introduced background daemon. The update brings Flathub's curated topic sections to the home page for improved discovery, alongside significant accessibility improvements led by contributor Alexander Vanhee, such as fixing screen reader button double-reading. Released on August 12, 2026, this rapid iteration addresses post-launch bugs in the auto-update system and autostart services, reflecting the project's active development cycle. Users can upgrade immediately via Flathub, GitHub Actions, or Debian and Arch repositories, keeping their alternative to GNOME Software and KDE Discover up to date.
Fail2Ban is an open-source intrusion prevention daemon that scans service logs for attack patterns and automatically blocks offending IPs through firewall rules. Debian 13 Trixie modernizes the package by defaulting to the systemd journal backend, switching to nftables for ban actions, and requiring Python 3.12. Administrators configure it through a layered override system of *.conf, *.local, and jail.d/ drop-in files, replacing legacy log paths with journalmatch directives. Production deployments combine targeted SSH, web, and mail jails with a long-term recidive jail, all validated through fail2ban-regex and managed via the daemon's client/server architecture.
Mango Wayland Compositor 0.16.0 has been released, adding native touch input and improved XWayland scaling to its dwl-inspired design. Key features include real-time overview updates, xdg_activation_v1 support to stop focus stealing, and a force_render rule for smoother animations. The update also addresses critical stability issues, fixing crashes after system suspend and increasing buffer limits for XWayland clients. Available for Arch, NixOS, and other distributions, the project now sits at roughly 3,456 stars and continues to grow its community ecosystem.
Visual Studio Code 1.133 introduces a dedicated Agent Host process that decouples AI agents from the editor, enabling shared multi-window sessions and remote execution. Microsoft pairs this architectural shift with an open Agent Host Protocol (AHP) spec, positioning the communication layer alongside LSP and DAP to support extensible third-party tooling. The update also delivers developer-friendly features like mixed Anthropic and Copilot model switching in Claude sessions, an experimental toggle to skip GitHub sign-in, and auto-reloading HTML in the integrated browser. The update is now rolling out to Windows, macOS, and Linux, with early testing available through the Insiders build.
Manjaro Linux 26.1.0 is now live on SourceForge, bringing Linux 7.1 to the default kernel lineup. The release drops all 5.x kernel options entirely, meaning hardware from the mid-2010s will no longer be supported. You can grab the new ISOs for KDE Plasma, GNOME, or Xfce today, though the official download page still lists the previous 26.0.4 build. This shift marks a major step forward for the rolling distribution, trading legacy compatibility for modern scheduler and memory management improvements.
Open-source Linux gaming tool Bottles released version 66.1, just hours after its major v66.0 launch. The initial release shipped with two critical regressions that broke game launching inside Flatpak sandboxes and crashed the custom UMU prefix picker. Lead developer Mirko Brombin addressed both issues with a two-commit emergency patch that adjusts Flatpak path resolution and corrects a mismatched method reference in the UMU integration code. The rapid sub-two-hour turnaround highlights both the responsiveness of the single-maintainer project and the ongoing friction of shipping major gaming features to a sandboxed Linux ecosystem.
LACT 0.10.0 has been released, delivering major Nvidia GPU support to the open-source Linux controller tool with new overclocking features including PowerMizer Mode and a Voltage Boost slider comparable to MSI Afterburner. The update brings first-class monitoring for NVIDIA's Blackwell architecture, resolving bogus temperature readings and enabling per-chip memory temperature sensors for GDDR6x and GDDR7 modules on RTX 50-series cards. Usability receives a boost through an interactive setup wizard, Polkit integration for standard authentication, and a new CLI command allowing GPUs to be detached and reattached for virtual machine passthrough workflows. Now available on major Linux distributions and Flathub, this release significantly expands LACT from an AMD-focused utility into a comprehensive multi-vendor GPU management application.
AIO coolers are fully embracing personality panels and daisy-chain ecosystems, with MSI’s MPG CORELIQUID P22 360 W, be quiet!’s Light Loop IO LCD 360, and Arctic’s Bionix P12 and P14 A-RGB fans all landing in this week's roundup. Razer upped the customization ante with the 23-button Naga V3 Pro, positioning it as the default peripheral for MMO and RTS players who actually want to map out their loadouts. The budget crowd keeps winning, as the Valkyrie B12 ARGB, EPOMAKER GX1 headset, and MSI’s display-equipped AIO all deliver solid performance without the usual flagship tax. While DeepCool’s woodgrain AK620 G2 and Id-Cooling’s visual "hybrid" design try to shake up the thermal market, premium acoustics and clean cable management.Â
The GNOME Shell development team has published a comprehensive roadmap outlining nine major design improvements for the desktop environment, ranging from a spatial search overlay to mobile-inspired quick settings. The most immediate update is a new search interface that spawns results as an overlay from the search field, a change currently in progress via Merge Request #4307 and expected to ship in GNOME 51 this fall. While the design team emphasizes that developer capacity remains the primary bottleneck, they plan to use community extensions like MosaicWM to prototype complex tiling and window management concepts before integrating them into the core Mutter compositor. Other proposals, including a visual login grid, dynamic battery icons, and a transparent panel system, are still in early stages and will likely span multiple release cycles as the desktop focuses on incremental refinement rather than structural overhaul.
QEMU 11.1.0 has officially landed, wrapping up roughly 3,500 commits and over 111,000 lines of code from 285 contributors. The release is squarely focused on hardening host-mode QEMU, patching at least 12 assigned CVEs across virtio, 9pfs, the dmg parser, and NVMe subsystems. Beyond the security work, you can now hotplug NVMe namespaces at runtime, enable the new sp-mem device for Intel accelerator workloads, and dynamically manage QMP monitors without restarting the daemon. While the new RISC-V IOMMU and VT100 terminal emulator round out the feature set, production deployments should prioritize this update immediately to close out-of-bounds access and memory exhaustion vulnerabilities.
Microsoft released Visual Studio Code 1.132.1 on Tuesday to address seven security vulnerabilities across the Chat, Terminal, Electron, and network subsystems. The patch arrives just six days after the feature-rich 1.132 release, which introduced a major architectural shift via the new Agent Host Protocol. Critical remote code execution flaws were patched in the integrated browser and web URL payloads, while four additional fixes target the expanding AI agent attack surface. Users should force a check for updates immediately to secure their development environment.
Bottles 66.0 drops on Linux desktops with native UMU integration that finally removes the need for external game launchers and separate Wine scripts. The update swaps in ProtoSoda as the default runtime for UMU launches and adds an adaptive launch feature that auto-tunes performance parameters based on the detected application. A new experimental cpak package format offers a lightweight, self-contained alternative to Flatpak without breaking existing sandboxed installations. Flatpak users get quiet but important fixes for NVK detection, SOCKS proxy downloads, and Proton 11 compatibility alongside cleaner onboarding flows and official runner branding.
Liquorix Kernel 7.1-11 drops a focused stability fix that hardens memory protection in the cgroup/dmem and drm/ttm subsystems to prevent race conditions during high-contention scenarios. The update builds on upstream Linux 7.1.8 and applies a single defensive patch to the scheduler and GPU buffer management paths, which helps gamers and video editors avoid sudden freezes or kernel panics while streaming or rendering. Debian and Ubuntu users can grab the package through the official PPA via a one-line install script, while Arch Linux builders pull the linux-lqx package straight from the AUR without relying on third-party wrapper tools.
The PHP project released PHP 8.4.25 RC1 and PHP 8.5.10 RC1 for testing, introducing substantial security hardening across both active branches. The patch sets focus heavily on preventing stack overflows in recursive functions like array_walk_recursive() and DOM operations, while also resolving critical use-after-free vulnerabilities in core extensions. Additional fixes address JIT deoptimizer register corruption, session heap corruption in mod_mm, and various edge cases in PDO_PGSQL, PCRE, and Reflection that previously caused silent memory issues.
The Slackware Linux Security Team released updated packages for Slackware 15.0 and -current to patch known vulnerabilities in the expat XML parser and OpenSSH. The expat refresh resolves CVE-2026-72522 by correcting an out-of-bounds read that causes an infinite loop when the parser processes low Unicode surrogates. The OpenSSH upgrade pushes the software to version 10.5p1, which ships with several security hardening patches and routine bug fixes. Users can download the new builds from the official Slackware FTP mirrors and apply them with the upgradepkg command before restarting the sshd daemon.
expat (SSA:2026-223-01)
openssh (SSA:2026-223-02)
Rocky Linux has released a collection of security errata targeting Rocky Linux versions 8, 9, and 10, addressing vulnerabilities across key system packages. Important severity patches now include vim updates for all three supported releases, plus fixes for nodejs-nodemon on Rocky Linux 10 and perl-DBI on Rocky Linux 8. Moderate updates resolve issues within the kernel and kernel-rt packages on Rocky Linux 8, while libarchive receives security corrections for both Rocky Linux 9 and Rocky Linux 10.
RLSA-2026:52674: Moderate: libarchive security update
RLBA-2022:3897: new packages: libarchive
RLSA-2026:52761: Moderate: kernel-rt security update
RLSA-2026:52772: Important: perl-DBI:1.641 security update
RLSA-2026:52765: Moderate: kernel security update
RLSA-2026:52841: Important: nodejs-nodemon security update
RLSA-2026:38509: Important: vim security update
RLSA-2026:52675: Moderate: libarchive security update
RLSA-2026:38511: Important: vim security update
RLSA-2026:38510: Important: vim security update
Red Hat Product Security published a series of errata that patch security flaws in Thunderbird, the Linux kernel, OpenShift Container Platform, and JBoss Enterprise Application Platform on Red Hat Enterprise Linux. The advisories span numerous RHEL version streams and specialized support tracks, with the company classifying most notices as important and two gstreamer1-plugins-good releases as moderate. Each notice provides Common Vulnerability Scoring System ratings tied directly to specific CVE identifiers for detailed severity analysis. IT teams managing these environments should install the listed RHSA packages promptly to maintain system integrity.
RHSA-2026:53455: Important: thunderbird security update
RHSA-2026:53446: Important: thunderbird security update
RHSA-2026:53444: Important: thunderbird security update
RHSA-2026:53475: Important: thunderbird security update
RHSA-2026:53452: Moderate: gstreamer1-plugins-good security update
RHSA-2026:53435: Important: udisks2 security update
RHSA-2026:53445: Important: thunderbird security update
RHSA-2026:53412: Important: opentelemetry-collector security update
RHSA-2026:53413: Important: opentelemetry-collector security update
RHSA-2026:53365: Important: fence-agents security update
RHSA-2026:51036: Important: OpenShift Container Platform 4.22.9 packages and security update
RHSA-2026:53330: Important: kernel security, bug fix, and enhancement update
RHSA-2026:53806: Important: Red Hat JBoss Enterprise Application Platform 7.4.25 security update
RHSA-2026:53644: Important: Red Hat JBoss Enterprise Application Platform 7.4.25 security pdate
RHSA-2026:53454: Important: thunderbird security update
RHSA-2026:53453: Important: thunderbird security update
RHSA-2026:53451: Moderate: gstreamer1-plugins-good security update
RHSA-2026:53329: Important: kernel security, bug fix, and enhancement update
RHSA-2026:53363: Important: fence-agents security update
RHSA-2026:53374: Important: rhc security update
RHSA-2026:53364: Important: resource-agents security update
RHSA-2026:53298: Important: nodejs22 security update
RHSA-2026:53416: Important: host-metering security update
RHSA-2026:53402: Important: ldns security update
RHSA-2026:53990: Important: kernel security, bug fix, and enhancement update
RHSA-2026:53989: Important: kernel security update
RHSA-2026:51422: Important: Red Hat build of MicroShift 4.19.42 security update
RHSA-2026:53844: Important: iscsi-initiator-utils security, bug fix, and enhancement update
RHSA-2026:53845: Important: iscsi-initiator-utils security, bug fix, and enhancement update
RHSA-2026:53848: Important: isns-utils security update
RHSA-2026:53847: Important: isns-utils security update
RHSA-2026:53450: Important: xorg-x11-server-Xwayland security update
RHSA-2026:53415: Important: opentelemetry-collector security update
RHSA-2026:53846: Important: isns-utils security update
Fedora published security updates for versions 43 and 44 on August 12, 2026, addressing critical vulnerabilities in the ClamAV antivirus toolkit, the libidn internationalized domain name library, and the Domoticz home automation system. The ClamAV updates to version 1.4.6 resolve multiple denial-of-service risks stemming from crafted InstallShield, 7z, PESpin, FSG, and DMG files, alongside an error handling flaw in the HTML CSS module related to UTF-8 string splitting. The libidn release fixes a CVE that allows out-of-bounds reads within the ToUnicode APIs, while the Domoticz version 2026.3 update patches significant security weaknesses in its web server and API infrastructure.
Fedora 43 Update: clamav-1.4.6-1.fc43
Fedora 43 Update: libidn-1.44-1.fc43
Fedora 44 Update: clamav-1.4.6-1.fc44
Fedora 44 Update: libidn-1.44-1.fc44
Fedora 44 Update: domoticz-2026.3-1.fc44
Debian has released six security patches released to address critical flaws across NSS, Postfix, PHP 7.4, PHP 8.2, OpenJDK 25, and libgd2. These updates resolve CVEs that enable arbitrary code execution through malformed certificates, SQL injection via backslash escaping errors, denial of service from unbounded recursion, and invalid certificate validation in Java archives. The advisory provides exact version numbers for Debian Stretch through Trixie, ensuring each affected package receives a targeted version bump. Users should deploy these patches through their standard package managers to eliminate the identified vulnerabilities across their respective operating systems.
ELA-1800-1 nss security update (by )
[DSA 6430-1] postfix security update
[DLA 4733-1] php7.4 security update
[DLA 4732-1] php8.2 security update
[DSA 6431-1] openjdk-25 security update
[DLA 4731-1] libgd2 security update
[ Archive ]