2026-07-28
PHP tagged three releases in php/php-src on July 28, 2026, landing PHP 8.6.0alpha3 alongside security patches for both 8.5.9 and 8.2.33. Every active branch received the same synchronized patch set, addressing a stack-based out-of-bounds write in ext/bcmath, a pgsql SQL injection via backslash breakouts, a Phar circular symlink crash, and a libgd vulnerability. The 8.6 alpha cycle brings partial function application, a new clamp() function, and TAILCALL VM support on Windows, with the next snapshot expected around July 30. 8.5 users should watch php.net for the official bulletin, while 8.2 operators need to start planning a migration to 8.4 LTS or 8.5 before the maintenance branch hits end-of-life.
The Samba Team issued coordinated security updates for versions 4.24.5, 4.23.10, and 4.22.11 on July 28, 2026, addressing six vulnerabilities across all active maintenance branches. Two of these flaws, both rated CVSS 8.8 and discovered by OpenAI Security Research, allow low-privilege authenticated users to bypass LDAP access controls and fully compromise an Active Directory domain. Because no workarounds exist for the critical issues, administrators are strongly urged to apply the patches immediately to prevent domain takeover and cryptographic key extraction. The release also resolves additional medium-severity issues affecting DNS TSIG signing, KDC stability, and CTDB clustering protocol integrity.
PixiEditor 2.1.2.1 has officially dropped, bringing a major expansion to its open-source 2D graphics workflow just a year after a complete engine rewrite. The update pushes heavy procedural additions into the node graph, including a Color Ramp, Vector Math, and Random node, alongside long-requested tools like Find and Replace and a Gradient Brush. Built on C# and AvaloniaUI, the free app now ships native builds for Windows, macOS, and Linux, with a paid Steam tier funding ongoing development. It's fast becoming a legitimate alternative to commercial pixel art and vector editors, though the rapid release cadence means you should expect a few rough edges until 2.2 stabilizes.
Valve published Proton 11.0-1b and 10.0-4b on July 28 to add official compatibility for the newly released Steamworks SDK 1.65. Both builds include a networking patch that resolves a persistent 32-bit to 64-bit data alignment issue under WoW64 prefixes. The 10.0-4b drop also folds in a background optimization that trims unnecessary environment variable calls during Steamworks initialization. Linux gamers running either the stable 11.x stack or the older 10.x branch can grab the updates automatically through Steam's compatibility settings.
Endorfy’s Fishtank 6000 Corona offers striking aesthetics but falls short on airflow, while the Framework Laptop 13 Pro and CyberPowerPC Infinity U7 Plus deliver polished designs for builders and gamers alike. Microsoft’s Unreal Engine 5 remake of Halo: Combat Evolved pushes hardware hard, requiring extensive testing across thirty-five discrete graphics cards and dozens of handheld PCs to map out performance and VRAM demands. The Logitech G512 X 98 keyboard introduces a magnetic switch system for quick customization, the COUGAR GR 1000 power supply undercuts rivals at $129 with full ATX 3.1 compliance, and Biwin’s M560 solid-state drive tops DRAMless benchmarks with 11,000 megabytes per second of read speed. Independent lab results across these categories give shoppers precise metrics for upgrading workstations, purchasing prebuilt rigs, or tracking modern game optimization on current PC components.
Casing: Endorfy Fishtank 6000 Corona review: a handsome but expensive panoramic PC case
Computers: Framework Laptop 13 Pro review: It cleans up nice, CyberPowerPC Infinity U7 Plus Review (270K Plus + 5070 Ti)
Gaming: Halo: Campaign Evolved Handheld Performance Review, Halo: Campaign Evolved Performance Benchmark Review - 35 GPUs Tested
Input: Logitech G512 X 98 Analog Mechanical Gaming Keyboard Review - An Innovative Two-in-One
Power: COUGAR GR 1000 PSU Review
Storage: Biwin M560 2TB SSD Review - Best Overall Retail-Ready DRAMless SSD
Ubuntu released three security notices addressing vulnerabilities in Roc Toolkit, GNU C Library, and FreeIPMI across multiple LTS releases. The glibc update resolves seven flaws including heap buffer overflows in scanf functions and incorrect DNS response handling that could allow denial of service or arbitrary code execution; systems running Ubuntu 26.04, 24.04, and 22.04 LTS must reboot after applying the libc6 package update. Roc Toolkit requires a libroc0.4 update to fix a crash vector triggered by malformed WAV files, while the FreeIPMI patch corrects buffer overflow issues in IPMI OEM message processing that could enable local denial of service attacks on systems ranging from Ubuntu 14.04 LTS through 26.04 LTS.
[USN-8612-1] Roc Toolkit vulnerability
[USN-8611-1] GNU C Library vulnerabilities
[USN-8613-1] FreeIPMI vulnerabilities
Rocky Linux issued important security errata covering kernel, kernel-rt, libpq, compat-openssl11, and libreswan packages for Rocky Linux 8, 9, 10, and SIG Cloud releases. Kernel updates appear in separate advisories for the real-time variant on version 8 and the standard kernel across versions 8, 9, 10, plus specific cloud-focused builds for SIG Cloud 8 and 9. Non-kernel advisories deliver libpq maintenance for Rocky Linux 9 and 10 alongside compat-openssl11 and libreswan corrections for version 9. Each vulnerability carries a Common Vulnerability Scoring System base score, allowing users to assess severity levels via the provided CVE list before installing the updates.
RLSA-2026:45116: Important: kernel-rt security update
RLSA-2026:45115: Important: kernel security update
RLSA-2026:45114: Important: kernel security update
RLSA-2026:44391: Important: libpq security update
RLSA-2026:44308: Important: libpq security update
RLSA-2026:44438: Important: compat-openssl11 security update
RLSA-2026:46397: Important: libreswan security update
RXSA-2026:45192: Important: kernel security, bug fix, and enhancement update
RXSA-2026:45115: Important: kernel security update
RLSA-2026:45192: Important: kernel security, bug fix, and enhancement update
Red Hat published a batch of RHSA-2026 security advisories affecting Red Hat Enterprise Linux systems spanning versions 7 Extended Lifecycle Support to version 10, addressing vulnerabilities across multiple packages including kernels, tigervnc, sssd, and libreoffice. Red Hat Product Security assigned an Important impact level to the majority of these advisories, covering patches for kernel, kernel-rt, tigervnc, libreswan, freerdp, and dovecot, while rating a single kernel-rt update for RHEL 7 as Moderate based on CVSS scores available via CVE references. The advisories target diverse maintenance streams such as Advanced Mission Critical Update Support, Extended Update Support Long-Life Add-On, SAP Solutions, and Telecommunications Update Service for RHEL 8, alongside standard releases for RHEL 9 and 10 including updates for go-fdo-client and kpatch-patch.
RHSA-2026:46461: Moderate: kernel-rt security update
RHSA-2026:46460: Important: tigervnc security update
RHSA-2026:46456: Important: tigervnc security update
RHSA-2026:46482: Important: sssd security update
RHSA-2026:46473: Important: tigervnc security update
RHSA-2026:46467: Important: evince security update
RHSA-2026:46398: Important: libreswan security update
RHSA-2026:46392: Important: tigervnc security update
RHSA-2026:46388: Important: freerdp security update
RHSA-2026:46385: Important: tigervnc security update
RHSA-2026:46386: Important: libreoffice security update
RHSA-2026:46384: Important: freerdp security update
RHSA-2026:46394: Important: go-fdo-client security update
RHSA-2026:47011: Important: kernel security update
RHSA-2026:47010: Important: kernel-rt security update
RHSA-2026:46990: Important: sssd security, bug fix, and enhancement update
RHSA-2026:46986: Important: libreswan security update
RHSA-2026:46951: Important: kpatch-patch security update
RHSA-2026:46532: Important: dovecot security update
Fedora administrators should apply new security advisories for versions 43 and 44 that address critical flaws across three packages: perl-Mojolicious, rpm, and opkssh. The perl-Mojolicious update to version 9.48 resolves a BREACH attack vulnerability where CSRF tokens were previously exposed through compression oracle techniques, now masking tokens with fresh random values per request. Meanwhile, the rpm rebase to version 6.0.2 patches two distinct issues including a heap buffer overflow in NDB slot table parsing and a command injection flaw within rpmuncompress triggered by unescaped archive directory names. Finally, opkssh moves to version 0.16.0 with an upgraded openpubkey dependency that fixes GQ-commitment PK Token weaknesses affecting GitLab-CI workflows, though current opkssh usage does not reach the vulnerable code path.
Fedora 43 Update: perl-Mojolicious-9.48-1.fc43
Fedora 43 Update: rpm-6.0.2-1.fc43
Fedora 43 Update: opkssh-0.16.0-1.fc43
Fedora 44 Update: opkssh-0.16.0-1.fc44
Fedora 44 Update: perl-Mojolicious-9.48-1.fc44
Fedora 44 Update: rpm-6.0.2-1.fc44
Debian Long Term Support released advisory DLA-4701-1 to update Chromium version 150.0.7871.181-1~deb12u1 on Debian 12 Bookworm. The patch resolves eighteen vulnerabilities identified under CVE identifiers from CVE-2026-15899 through CVE-2026-16424 that could enable arbitrary code execution, denial of service attacks, or unauthorized data access.
[SECURITY] [DLA 4701-1] chromium security update
AlmaLinux released four important security errata covering Libreswan across versions 8 through 10 and Grafana for version 8. The Libreswan updates patch four separate flaws that enable denial of service attacks or daemon crashes when attackers send malformed IKE packets or improperly formatted X.509 certificates. A dedicated Grafana release fixes a validation weakness in the go-billy Git library while adjusting a build macro for the Konflux pipeline. Operators need to deploy these patches immediately to close CVE gaps spanning from 2026-12413 through 2026-50722 before threat actors exploit the VPN tunneling weaknesses.
ALSA-2026:46398: libreswan security update (Important)
ALSA-2026:46397: libreswan security update (Important)
ALSA-2026:46391: grafana security, bug fix, and enhancement update (Important)
ALSA-2026:46396: libreswan security update (Important)
2026-07-27
Hyprland 0.56.1 shipped on July 27, 2026, exactly one week after the massive 0.56.0 feature release, delivering 14 targeted fixes for regressions surfacing in real-world usage. The patch addresses critical stability issues including monitor rotation and mirroring failures, Lua environment corruption that broke third-party module paths, and renderer scale rounding artifacts on HiDPI displays. Developer Vaxry pushed the update rapidly after users reported animation slowdowns and browser crashes, with the team continuing aggressive development by adding 30 more commits to main within 24 hours. This seven-day turnaround highlights Hyprland Corp's active maintenance cadence and corporate sponsorship, leaving early adopters on stable ground as work accelerates toward 0.57.
Fwupd 2.1.7 is now live, closing a trust-boundary vulnerability that let unsigned metadata bypass authorization checks during firmware installations. The release pairs that security patch with a new systemd-pcrlock plugin for UEFI updates, expanded Hardware Security Index attributes for SPI flash and disk encryption, and fixes for several memory safety flaws in core plugins. Enterprise deployments should prioritize the OnlyTrusted metadata enforcement toggle, while desktop users will benefit from tighter D-Bus authorization and a cleaner HSI scoring report. Rolling out across all major Linux distributions starting today, the update is the latest in fwupd's accelerated mid-2026 hardening cycle driven by supply-chain pressure and AI-assisted static analysis.
Canonical has announced a new rolling virtualization Hardware Enablement stack for Ubuntu 26.04 LTS that upgrades QEMU, libvirt, EDK2, and SeaBIOS every six months for the first two years of the release cycle. The opt-in feature directly addresses the timing mismatch between fast-evolving CPU encryption standards like AMD SEV-SNP and Intel TDX and traditional two-year LTS update schedules. All virtualization components upgrade atomically through the ubuntu_virt_helper tool to prevent the inconsistent state mismatches that previously broke confidential workloads in production. The initiative aligns with AMD's newly revealed EPYC 9006 and Instinct MI455X hardware, positioning Ubuntu as a primary platform for regulated AI and sovereign cloud deployments.
OCInside.de tested the black NZXT H2 Flow chassis and found a surprisingly roomy interior packed into a compact Mini-ITX frame. Tom's Hardware evaluated the HP OmniBook X Flip 14 convertible laptop and noted that its refined build quality cannot overcome average processing speeds and an inflated asking price. The AOC U32G4 brings dependable 4K gaming with dual-refresh support to budget-conscious buyers looking for reliable display performance. Wccftech highlighted the Uperfect GR14BU as a highly portable option, offering a compact 3K OLED touchscreen panel running at 120Hz for approximately $399.
Casing: NZXT H2 Flow Review
Computers: HP OmniBook X Flip 14 Review: Premium design, middling performance
Displays: AOC U32G4 32-inch 4K Dual-Refresh gaming monitor review: Solid performance and value, Uperfect GR14BU Portable OLED Touchscreen Monitor Review: Small But Versatile
Liquorix Linux Kernel 7.1-6 has arrived, merging upstream Linux Kernel 7.1.5 and rolling out targeted fixes to Steven Barrett’s custom Project-C scheduler. The update introduces auto-detection for heterogeneous CPU topologies, improving task placement on modern hybrid processors like Intel Meteor Lake and AMD Zen 4/5. Designed for gamers and multimedia creators, the AMD64-only build trades power efficiency and raw throughput for aggressive 1000Hz scheduling and lower input latency.
Linux 7.2-rc5 hit the kernel archives on July 26, 2026, with a massive patch batch that targets the stable release just under three weeks away on August 16. Networking drivers dominate the update, consuming over 35% of the changes to clear conference-related backlogs, while USB patches actually outpace GPU updates for once. The cycle also highlights the growing role of automated tools, which are surfacing hardware-specific audio quirks and edge cases that human reviewers routinely miss during manual passes. Linus Torvalds notes the volume is larger than he prefers but confirms the patches look stable, leaving enterprise users to decide whether to stick with rc5 or start testing rc6.
The openSUSE security advisory list covers eight distinct packages with severity ratings ranging from important to moderate. The two important priority patches address vulnerabilities in java-17-openjdk and nginx that require immediate installation. Moderate severity fixes arrive for MozillaFirefox, MozillaThunderbird, java-25-openjdk, ffmpeg-7, libsrt1_5, and python313-urwid on general availability media builds. System administrators should apply these updates through the standard package manager to close the disclosed security flaws across their Linux infrastructure.
openSUSE-SU-2026:21440-1: important: Security update for java-17-openjdk
openSUSE-SU-2026:21439-1: important: Security update for nginx
openSUSE-SU-2026:11358-1: moderate: MozillaFirefox-153.0-1.1 on GA media
openSUSE-SU-2026:11359-1: moderate: MozillaThunderbird-140.13.0-1.1 on GA media
openSUSE-SU-2026:11363-1: moderate: java-25-openjdk-25.0.4.0-1.1 on GA media
openSUSE-SU-2026:11361-1: moderate: ffmpeg-7-7.1.4-5.1 on GA media
openSUSE-SU-2026:11357-1: moderate: libsrt1_5-1.5.6-1.1 on GA media
openSUSE-SU-2026:11356-1: moderate: python313-urwid-4.0.5-1.1 on GA media
Rocky Linux 8 administrators should install the java-17-openjdk security patch identified under advisory RLSA-2026:42887. The release closes known vulnerabilities that could otherwise leave Java runtime environments exposed to system compromise. Each CVE tied to this update carries a Common Vulnerability Scoring System rating so engineers can rank fixes by exact threat level.
RLSA-2026:42887: Important: java-17-openjdk security update
Fedora 43 and Fedora 44 received a batch of security advisories covering core packages like systemd, skopeo, trafficserver, libgit2, lego, and libwebsockets to address multiple vulnerabilities across the distributions. The updates resolve specific security flaws, including the Go stdlib crypto/x509 denial-of-service flaw in skopeo that golang-1.25.12 resolves, HTTP/2 stalled flow-control problems in trafficserver linked to CVE-2026-59173, and an SSH protocol handler resource consumption vulnerability in libwebsockets labeled CVE-2026-10650. Fedora 44 users must update rust-libgit2-sys and the underlying libgit2 library to version 1.9.6 to patch five distinct security issues ranging from CVE-2026-53583 through CVE-2026-53587, while the lego package upgrade to version 5.3.1 fixes an off-path DNS poisoning vulnerability described by CVE-2026-10846.
Fedora 43 Update: systemd-258.10-1.fc43
Fedora 43 Update: skopeo-1.22.2-2.fc43
Fedora 43 Update: trafficserver-10.1.3-1.fc43
Fedora 43 Update: libwebsockets-4.5.8-2.fc43
Fedora 44 Update: systemd-259.8-1.fc44
Fedora 44 Update: rust-libgit2-sys-0.18.7-1.fc44
Fedora 44 Update: libgit2-1.9.6-1.fc44
Fedora 44 Update: lego-5.3.1-2.fc44
Fedora 44 Update: trafficserver-10.1.3-1.fc44
Fedora 44 Update: libwebsockets-4.5.8-1.fc44
Debian Long Term Support and Freexian Extended advisories released security patches addressing serious flaws in the linux-6.1 kernel, hplip printing software, BIND9 DNS server, and php-phpseclib cryptography library. The update for linux-6.1 closes more than fifty vulnerabilities that could enable privilege escalation or information disclosure on Debian 11 systems while also incorporating changes to the Azure Network Adapter driver. Additional fixes resolve arbitrary code execution risks in HP's printing tools across multiple distributions and repair DNSSEC bypass, cache poisoning, and denial of service weaknesses in BIND9 for older releases.
[DLA 4700-1] linux-6.1 security update
[DLA 4699-1] hplip security update
ELA-1784-1 hplip security update
ELA-1786-1 bind9 security update
ELA-1785-1 php-phpseclib security update (by )
[ Archive ]