2026-08-26
Bottles 66.9 has been released as a focused hotfix that bundles xz and dconf into the experimental cpak containerized runtime while fixing regressions in custom bottle folders and game process termination. The update caps an aggressive 15-day sprint that saw the team ship ten versions, building directly on the feature-heavy 66.0 release which introduced native UMU integration and Adaptive Launch. By making the new containerized runtime self-contained and smoothing out long-standing Wine friction points, the 66.x cycle aims to finally make running Windows software on Linux a seamless desktop experience.
LibreOffice 26.8 has arrived with zero AI features, prioritizing typographic quality, complex writing system support, and document exchange fidelity. The release adds automatic bidirectional text handling, named functions for N'Ko and Adlam scripts in Math, and preserves definitions for newer OOXML chart types during round-trips. Notable improvements include a paragraph composer for balanced word spacing, native OpenType variable font support, calculated fields in Calc pivot tables, and multiple page sizes within Impress presentations.
Visual Studio Code 1.135 launches the Agent Host Protocol, an open standard that transforms the editor into a universal runtime for AI agents and allows coding sessions to move seamlessly between applications. The release introduces "Rubber Duck," an experimental feature where complementary models review each other's work, closing 74.7% of the performance gap to flagship models on SWE-Bench Pro. External Agent Sessions now let developers resume work started in other tools, though continuing these sessions typically requires a Copilot subscription. Microsoft has also rolled back the sandboxing rollout for local agents to zero percent as it shifts engineering focus to the new host infrastructure and a new single-pane default layout.
Corsair and HYTE are pushing the mid-range case market forward with the wood-paneled FRAME 5000D WOOD RS and a new $99.99 curved glass model called the HYTE Y50 RGB. Cooling options are getting smarter and more specific, as Cooler Master's MasterFan M140 ARGB tackles noise and availability head-on while Corsair's TITAN II 360 RX RGB keeps an eye on secondary VRM and M.2 temperatures. The be quiet! Light Mount TKL rounds out the peripheral lineup with a pre-lubed, 80% mechanical layout designed to keep office partitions and sleeping partners happy. Finally, Tom's Hardware puts the Asus ROG Strix B850-F Gaming Wifi Neo on the scale and finds a feature-packed motherboard that sits squarely in X870 pricing territory.
Bazzite Linux has shipped stable release 44.20260825, pushing the OGC kernel from 7.2.0-ogc4 straight through to ogc6.1 in less than a week. The update lands a critical security patch for SteamOS-Manager to resolve a jssysctl vulnerability, while also rolling out quieter improvements to the Gamescope session wrapper, InputPlumber, and OpenGamepadUI. Contributors addressed specific handheld quirks like the OneXFly F1 boot rotation, restored legacy Nvidia support, and fixed the KDE on-screen keyboard for users relying on touch input. Immutable Fedora Atomic users can pull the new image via bazzite-rollback-helper rebase stable or pin directly to the tag, with full rollback support available if any regressions surface.
Liquorix 7.1-18 is out, tracking the Linux 7.1.10 base and introducing "Project-C" scheduler micro-optimizations. The release drops two targeted patches that streamline a context switch lookup and correct a branch prediction hint on the non-migratable task path. Maintainer Steven Barrett continues his rapid August release cadence while bundling the standard low-latency defaults like hard kernel preemption and a 1000 Hz tick rate. AMD64 packages are available now for Debian, Ubuntu, and Arch via the official one-line install script.
PHP 8.5.10 and 8.4.25 officially shipped on August 27, 2026, delivering cumulative security and stability patches to both active branches. The updates prioritize stack overflow hardening against deeply nested arrays and DOM documents, alongside targeted JIT compiler adjustments in the 8.5 line. With PHP 8.4 now locked to security-only fixes, users must upgrade immediately to resolve serious vulnerabilities like the bccomp out-of-bounds write and the pgsql SQL injection flaw. Developers running untrusted nested data or Opcache-dependent workloads should patch right away to lock in the new crash protections.
Major Linux distributions including AlmaLinux, Debian, Fedora, RHEL, Rocky, SUSE, and Ubuntu all shipped critical security updates today, with the Python ecosystem, Node.js, and GStreamer taking the heaviest hits for remotely exploitable flaws. The tarfile extraction filter bypass and a cluster of heap overflows in GStreamer plugins are leading the charge, while kernel patches across the board address over 150 CVEs ranging from privilege escalation to denial of service vectors. Ubuntu cloud and Raspberry Pi users need to schedule maintenance windows carefully due to kernel ABI bumps requiring out-of-tree driver rebuilds, and Red Hat customers must juggle separate image pulls for OpenShift 4.20 through 4.22. While most updates apply cleanly through standard package managers, the sheer volume of Python and Node.js fixes makes a routine maintenance window the safest move before the weekend.
2026-08-25
COSMIC Epoch 1.7.0 delivering a broad polish update that touches nearly every component of the open-source Linux desktop. The release introduces shake-to-magnify cursor controls, faster network file browsing, and a searchable Open With dialog to smooth out daily workflows. System-level changes include a critical POSIX sh migration for the session startup script and improved PAM authentication resilience in the login greeter. If you're running Pop!_OS, expect this build to land in the 24.04 branch once System76 finalizes the next distribution update.
Fedora 45 hits four policy cut-offs today, shifting the branched stream from nightly development builds into an actively gated release candidate. The new Beta freeze, Software String freeze, and Changes completion deadline mean only blocker-busting packages can reach the stable repository while translation strings lock down. With the QA team already validating nightly composes since August, the Fedora 45 Beta should land in early September ahead of the final October 20 release.
Manjaro Linux 26.1.1 has been released with ISO images built on August 25, 2026, available across GNOME, KDE Plasma, and Xfce editions. The update introduces linux71 as the default kernel for all installations, offering the latest driver support while minimal ISOs retain options for linux6.18 and linux6.12 LTS kernels. Full images range from 5.2 GB to 5.5 GB and include preconfigured applications, whereas minimal images between 4.0 GB and 4.7 GB provide a stock desktop environment for custom setups. Users can download the new ISOs along with GnuPG signatures and hash files from the official Manjaro SourceForge repository.
WinBoat v0.9.1 has arrived as the final patch for the 0.9 series, delivering four critical security updates including a rapidly resolved PowerShell injection flaw and improved credential redaction. The release upgrades the underlying Electron framework to version 44 and backports stability improvements, tightening the attack surface for users bridging host Linux and guest Windows environments. Despite these hardened defenses, the patch underscores the inherent risks of running untrusted virtual machines via containerized QEMU and FreeRDP within a user's home directory. Developers have already shifted focus to version 1.0, where GPU acceleration and other major feature enhancements are scheduled to follow the current security baseline.
MariaDB has published Q3 2026 maintenance updates for its four active LTS branches, releasing Server 12.3.3, 11.8.9, 11.4.13, and 10.11.19 to deliver bug fixes and stability improvements. The foundation simultaneously marked the end-of-life for MariaDB 10.6, issuing 10.6.28 as the final binary on August 13 with no further community patches. Key changes in 12.3.3 include a new binary logging implementation and innodb_snapshot_isolation now defaulting to ON, a shift that could impact applications relying on REPEATABLE READ isolation. Users currently on version 10.6 are advised to migrate directly to 11.8 or 12.3 to leverage performance gains and new features without intermediate upgrade steps.
OpenSSL released version 4.0.2, addressing eleven vulnerabilities across its supported branches alongside parallel updates for OpenSSL 3.6, 3.5, 3.4, 3.0, and legacy 1.1.1 and 1.0.2 lines. The update patches a mix of Moderate and Low-severity issues, with the most critical finding being CVE-2026-18798, a Moderate-rated double-free flaw in the QUIC server that can trigger a denial of service. Other fixes target heap buffer overflows in CMS key unwrapping, memory amplification in DTLS record buffering, and format string vulnerabilities in the Certificate Management Protocol, all of which lack exploitable remote code execution paths. Administrators running OpenSSL 4.0.0 through 4.0.1 should upgrade to 4.0.2 immediately, while users on older branches must pull the corresponding point releases to resolve the disclosed resource management and integrity check issues.
PHP 8.6.0 Beta 2 has been tagged two days early by release manager Matteo Beccati, introducing an SNMP overhaul, pack() endianness modifiers, and late-arriving session hardening. The build also delivers a dense memory-safety sweep, tackling use-after-free bugs in DOM, Opcache JIT crashes, and updated handling for PDO_PGSQL and ZipArchive. Alongside these improvements, developers should prepare for new deprecations including return inside finally blocks and the removal of SplFileObject CSV methods. The release cadence continues with Beta 3 on September 10 and a hard feature freeze on September 22, targeting general availability on November 19, 2026.
Linux distributions spent the past three days pushing a massive wave of security patches, with FFmpeg, Chromium, and Erlang leading the critical fix list. Fedora 44 ships Chromium 151 to scrub twenty-three vulnerabilities, while Debian and SUSE target severe TLS hardening and kernel live patches that will break older cluster configurations. Ubuntu locks its FFmpeg updates behind a Pro subscription, and AlmaLinux issues an important advisory for an MRTG local privilege escalation that demands immediate patching. You should run your package manager now and prioritize the media parsing and privilege escalation fixes before tackling the broader network stack updates.
Today's reviews run from serious budget value to premium excess, anchored by Tom's Hardware's endorsement of the sub-$45 Cooler Master Q300L v3 MicroATX chassis. TechPowerUp and TweakTown flag the ASUS NUC 16 Pro and the 280Hz tandem QD-OLED ROG Strix ultrawide as the day's top performance picks. Meanwhile, Colorful and MSI are refreshing the AM5 and AM4 ecosystems with heavily built overclocking boards that keep aging platforms relevant. The roundup wraps up with Corsair's low-profile mechanical keyboard, Soundpeats' ear-clip earbuds, and an AutoFull gaming chair that apparently includes massage functions.
Liquorix maintainer Steven Barrett released another kernel built on the upstream Linux v7.1.10 base. The update applies four cache-line-aware optimizations directly to the Project-C scheduler's hot paths, prioritizing data locality over algorithmic trimming. These changes specifically target context switch overhead and SMT idle coordination, making them most relevant for AMD Ryzen desktops running gaming or low-latency audio workloads. The release shipped just five hours after the base kernel merge, underscoring an active development pace that closely tracks upstream stable releases.
Ardour 9.8 is live now, adding initial support for musical key and scale tracking that lets you visualize and auto-correct out-of-scale MIDI notes directly in the editor. The update caps mid-recording crash data loss at five seconds and reconstructs partially written FLAC and BWF files with their broadcast metadata intact. Clip recording now guarantees a two-bar count-in and features a new modifier that locks clip boundaries together during slip edits. You can download the free DAW for Windows, macOS, and Linux directly from the official community page.
Seafoam Labs has published Shelly ALPM v3.1.0, adding a native in-process PKGBUILD builder that fully replaces makepkg for AUR compilation without acting as a wrapper. The release arrives just 27 days after the v3.0 overhaul, which swapped the entire C#/.NET codebase for Zig and GTK4 to eliminate runtime overhead. Security improvements include Landlock sandboxing, mandatory audit logs, and integrity hashing before execution, though features like the sandbox remain opt-in and some legacy makepkg sources are unsupported. Users can install the package manager via CachyOS packages, the AUR, or by building from source with Zig 0.16.0.
[ Archive ]