Product
Last Report

Click here to browse the Windows compatibility database

RTL-8851be
1 report Realtec
Anonymous
2026-07-19 18:49
P8Z77-V
1 report ASUS
Anonymous
2026-06-11 07:27
Click here to browse the Linux compatibility database

Click here to browse the macOS compatibility database

Date: 2026-07-29 19:56 | Last update:



2026-07-29

Software 44634 Published by Philipp Esselbach 0

Mesa has released version 26.1.6 for the Amber stable branch, a targeted maintenance update arriving on July 29, 2026, that focuses exclusively on bug fixes rather than new features. The release addresses several gaming regressions, including broken ambient occlusion in The Chronicles of Riddick, page faults in Doom Eternal on the new AMD RX 9070, and lighting issues in Horizon Forbidden West. Driver improvements are highlighted by Intel ANV fixes for compute-pass timing on Panther Lake hardware and AMD RADV corrections for ray-tracing workloads on NAVI32 GPUs. Additional patches cover Vulkan video codec accuracy for AV1 and H265 encoding, a Raspberry Pi 5 decoder crash, and various stability enhancements across other open-source graphics drivers.

KDE 1755 Published by Philipp Esselbach 0

Krita 5.3.3 landed today with 28 targeted bug fixes, including a long-awaited workflow tweak that stops layers from deselecting during transforms. The free and open-source painting app also drops 32-bit Windows builds, raises its macOS minimum to Catalina, and adds in-app Android donations for the first time. More significantly, this maintenance release coincides with Krita 6.0.3, which shares the exact same source code but compiles against Qt 6 to enable full HDR and fractional scaling on Linux Wayland. It's a rather aggressive rollout strategy, giving Linux users early access to next-generation display support while keeping the stable Qt 5 build polished for everyone else.

Linux 3396 Published by Philipp Esselbach 0

Greg Kroah-Hartman released Linux 6.1.179, 6.6.146, and 6.12.99 on July 29, 2026, as part of the weekly stable release cycle. These updates focus strictly on bug fixes and security hardening, with 6.1.179 touching nearly 15,000 files across the codebase. The GPU stack remains the most heavily maintained subsystem, with over a thousand DRM files altered in every release to support Intel, AMD, NVIDIA, and ARM Mali drivers. While Rust driver backports and growing LoongArch support show the kernel's evolution, users should note that the 6.1 and 6.6 trees reach end of life in December 2027.

Software 44634 Published by Philipp Esselbach 0

Amethyst Mod Manager 2.0.5 has landed for Linux, marking the sixth release in as many weeks following the project's complete v2.0 Qt rewrite. The update brings native modding support for Devil May Cry 5, Dragon’s Dogma 2, and Halo: Campaign Evolved, alongside workflow upgrades like drag-and-drop installation and an in-app wiki viewer. Solo developer ChrisDKN is pushing the Linux-native tool at a blistering pace to keep it competitive with established Windows counterparts like MO2 and Vortex. Users can grab the latest build via AppImage, Flatpak, or the Arch User Repository, with full release notes available on the project's GitHub page.

Software 44634 Published by Philipp Esselbach 0

Mesa 26.2.0 RC3 dropped today with 86 commits, marking the final release candidate before the stable 26.2.0 build lands around August 5. The patch set is anchored by Yiwei Zhang's 37 commits that rewrite the VirtIO GPU driver to use Vulkan 1.2 timeline synchronization, a major architectural upgrade for QEMU, KVM, and Wayland compositors. AMD users get VCN 5.0.2 hardware video support for RDNA 4, RADV receives raster primitive and ray tracing acceleration structure fixes, and Qualcomm's Turnip driver sees a wave of correctness patches targeting Adreno mobile silicon. Rolling-release distros like Arch and Tumbleweed will adopt the final build on day one, while production workstations will likely wait for the August 5 to 12 freeze lift before pulling the stable tarball.

Debian 11013 Published by Philipp Esselbach 0

Debian developers are casting preferential votes on how the project handles LLM-assisted contributions, with five competing resolutions currently in discussion. The proposals range from a hard ban on AI-generated code to a permissive framework that mandates disclosure and contributor accountability. The core tension pits volunteer reviewer burnout and copyright clarity against the practical reality that many maintainers already rely on AI for day-to-day work. Results will land in the coming weeks and likely define Debian's official stance on generative AI for the next several years.

Software 44634 Published by Philipp Esselbach 0

Zed Industries released version 1.13.1 of its AI-native code editor today, July 29, 2026, delivering a patch focused on agent UX improvements, Mistral model updates, and broader Dev Container interoperability. The update introduces per-response controls within multi-turn agent conversations and adds thinking support for Mistral Medium 3.5 and Small 4, while also allowing Zed-created dev containers to be reused by VS Code and the CLI. Stability work addresses platform-specific crashes on Windows and macOS alongside a significant Linux fix for Fcitx5 memory leaks on KDE Wayland, and resolves Git operation timeouts that previously interrupted slow authentication flows. With contributions from over 15 external developers through the Zed Guild, this release highlights the editor's rapid maturation toward feature parity with VS Code and strong ecosystem integration.

Software 44634 Published by Philipp Esselbach 0

Visual Studio Code 1.131 drops on MS Build 2026 day, bringing built-in dictation, deeper subagent visibility, and a hybrid Markdown editor to the Stable channel. Native voice input now runs Microsoft's offline Nemotron model across chat, editors, and the terminal on Windows, Linux, and Apple Silicon Macs, removing the need for third-party extensions. Python Environments flips to default after hitting its rollout target, while agent workflows get better observability through a new parent-conversation overlay that tracks active subagents. Several features land behind experimental flags and platform restrictions, marking an incremental but meaningful shift toward voice-driven development and agent observability.

Software 44634 Published by Philipp Esselbach 0

Node.js has published coordinated security patches for 22.23.2, 24.18.1, and 26.5.1 after a two-day delay caused by infrastructure issues. The release addresses 10 CVEs, including three high-severity vulnerabilities that exploit HTTP/2 routing, heap memory management, and the --permission sandbox model. Medium-severity fixes round out the update by patching DNS response handling, zlib compression crashes, and mTLS certificate reuse flaws. Developers should update their active release lines immediately and review the full July 2026 security advisory before restarting services.

Software 44634 Published by Philipp Esselbach 0

Ruby on Rails released coordinated security updates for versions 7.2.3.2, 8.0.5.1, and 8.1.3.1 on July 29, 2026. The patches address CVE-2026-66066 by disabling untrusted libvips image loaders at boot, shielding apps that process user-uploaded files from crafted image attacks. Applications handling BMP, ICO, PSD, or similar formats will see variant generation break and must strip those content types from the variable_content_types config. Developers should run bundle update rails immediately and confirm libvips sits at version 8.13 or higher.

Software 44634 Published by Philipp Esselbach 0

System76 released COSMIC Epoch 1.5.0, delivering a focused stability update for its Rust-based, Wayland-native desktop environment. The release prioritizes hardening over new features, addressing critical issues like GPU crash recovery, multi-monitor cursor positioning, and wallpaper orientation bugs across the compositor and settings panel. Following a rapid one-week development cycle after Epoch 1.4.0, the update continues System76's aggressive iteration cadence for Pop!_OS 24.04 and supported Linux distributions. While community engagement remains quieter for this maintenance build, the patch significantly clears Wayland plumbing debt, marking a clear shift toward production-level reliability for the desktop.

Software 44634 Published by Philipp Esselbach 0

PHP released PHP 8.3.33 on July 28 and PHP 8.4.24 on July 29, delivering critical security patches with zero new features. The updates resolve multiple CVEs, most notably a critical PostgreSQL SQL injection in the PGSQL and PDO_PGSQL extensions and an out-of-bounds memory write in PHP 8.4's BCMath extension. Additional high-severity fixes address a denial-of-service crash via recursive symbolic links in the Phar extension and upstream graphic processing vulnerabilities in libgd. With PHP 8.3 entering its final months of security support before December 2026, developers should verify GPG signatures and upgrade immediately to block potential remote code execution.

Software 44634 Published by Philipp Esselbach 0

YServer 1.4.0 dropped today, marking the Rust-native X11 display server's crossover into actual desktop usability. The release adds KDE Plasma support, fixes Electron app crashes, and corrects screenshot capture bugs by reading directly from the composited scanout. Maintained by Jos Dehaes and backed by three new external contributors, the project now passes 672 tests in its full XTS5 regression suite across AMD, Intel, NVIDIA, and Apple Silicon hardware. It does not replace Wayland, but it offers a pragmatic, memory-safe alternative for users who still need the X11 protocol without decades of C legacy code.

Reviews 52702 Published by Philipp Esselbach 0

Tech reviewers put several new hardware pieces through their paces this week, starting with a look at the GEEKOM GeekBook M16 laptop, which packs an Intel Core Ultra 9 processor into a premium aluminum chassis with a massive battery. The MSI MEG CORELIQUID E15 360 liquid cooler catches the eye with its curved AMOLED screen and straightforward installation, making it a strong match for Intel builds. Display and input peripherals also get tested, featuring Acer's touchscreen ProDesigner PE320QXT monitor that delivers 6K resolution for professional workflows, alongside Logitech's retro-styled G316 X 98 keyboard that balances vibrant lighting with overly loud tactile switches. Finally, the roundup covers internal components like the white ASRock B850 Challenger WiFi motherboard offering PCIe 5.0 and Wi-Fi 7 support, plus the BIWIN M560 Gen5 SSD that prioritizes fast write speeds and stable temperatures at 2TB capacity.

Computers: GEEKOM GeekBook M16 Review
Cooling: MSI MEG CORELIQUID E15 360 Review
Displays: Acer ProDesigner PE320QXT professional monitor review: Touchscreen functionality with a 6K resolution
Input: Logitech G316 X 98 Wired Gaming Keyboard Review - Retro-Inspired Board that Falls a Little Short
Motherboards: ASRock B850 Challenger WiFi White Motherboard Review
Storage: BIWIN M560 2TB Gen5 SSD Review

Software 44634 Published by Philipp Esselbach 0

GOverlay 1.8.10 is now available, bringing a massive wave of stability fixes, UI modernization, and automated testing to the popular Linux gaming config tool. The update resolves persistent crash issues, adds fluid resizable windows, and finally locks down config persistence for MangoHud and OptiScaler settings. Solo maintainer Benjamim Gois also integrated OpenSpec design documents and over 1,800 lines of test code, signaling a major maturity shift for the project. You can grab the release today through Flatpak, AppImage, Arch, and other supported distributions.

Software 44634 Published by Philipp Esselbach 0

Shelly 3.0.0 has launched as a complete rewrite of the Arch Linux package manager, migrating the codebase from C#/.NET to native Zig to eliminate runtime overhead and deliver faster startup times. The release introduces a modular design with Flatpak support as an optional backend, alongside a refreshed GTK4 UI, simultaneous AUR search capabilities, and shell completions for the CLI. Users upgrading from the v2.x line should review migration notes regarding config handling and the renamed keyring tool before proceeding. Installation is available through CachyOS packages or the AUR, with Seafoam Labs already working on repository modification and offline update features for the post-v3 roadmap.

Qubes OS 69 Published by Philipp Esselbach 0

Qubes Security Bulletin 116 addresses four new Xen vulnerabilities (XSA-500, XSA-505, XSA-506, and XSA-507) that could allow malicious virtual machines to compromise system memory or leak sensitive data across isolated qubes. While the default Qubes OS configuration faces moderate risk, administrators running paravirtualized workloads, untrusted HVM qubes, or templates with active memory balancing should treat these flaws as high priority. Systems operating on Qubes OS 4.3 can resolve the issues by upgrading dom0 to Xen package version 4.19.5-2 through the standard update tool and then rebooting the machine. Anyone who previously enabled Anti Evil Maid protection must also reseal their secret passphrase, since the updated binaries shift PCR values 18 and 19.

QSB-116: Multiple Xen issues (XSA-500, XSA-505, XSA-506, XSA-507)

Ubuntu 7167 Published by Philipp Esselbach 0

Ubuntu has released a series of security notices targeting significant flaws in the Linux kernel across various cloud platforms like Azure, AWS, and Oracle, while also fixing issues with Samba and correcting a regression in FreeRDP. The kernel patches include updates for specialized builds such as Azure Confidential Virtual Machines (CVM), FIPS compliance modes, and hardware enablement stacks to support diverse infrastructure requirements. These changes resolve known security gaps that could permit unauthorized access or service disruption on affected distributions, ensuring system integrity across general and provider-specific versions.

[USN-8621-1] Samba vulnerabilities
[USN-8605-1] Linux kernel (Azure CVM) vulnerabilities
[USN-8607-1] Linux kernel (Azure CVM) vulnerabilities
[USN-8606-1] Linux kernel (Azure) vulnerabilities
[USN-8610-1] Linux kernel (Azure CVM) vulnerabilities
[USN-8608-1] Linux kernel (Azure FIPS) vulnerabilities
[USN-8595-2] Linux kernel (AWS) vulnerabilities
[USN-8575-3] Linux kernel vulnerabilities
[USN-8609-1] Linux kernel (Azure CVM) vulnerabilities
[USN-8604-1] Linux kernel (Azure) vulnerabilities
[USN-8619-1] Linux kernel (HWE) vulnerabilities
[USN-8574-3] Linux kernel vulnerabilities
[USN-8595-3] Linux kernel (AWS) vulnerabilities
[USN-8618-1] Linux kernel vulnerabilities
[USN-8570-2] Linux kernel (Oracle) vulnerabilities
[USN-8620-1] Linux kernel vulnerabilities
[USN-8561-2] FreeRDP regression

SUSE 5722 Published by Philipp Esselbach 0

SUSE published a batch of security advisories in 2026 that address vulnerabilities across multiple Linux distributions and enterprise platforms. The updates include critical Live Patch releases for the Linux Kernel targeting SUSE Linux Enterprise versions 15 SP4 through SP7, alongside fixes for widely used software like samba, chromium, nginx, and java-21-openjdk. Several openSUSE community advisories also landed on general availability media, covering packages such as valkey, python313-CherryPy, libssh-config, and ignition.

openSUSE-SU-2026:11381-1: moderate: valkey-9.1.1-1.1 on GA media
openSUSE-SU-2026:11378-1: moderate: python313-CherryPy-18.10.0-4.1 on GA media
openSUSE-SU-2026:11377-1: moderate: libssh-config-0.11.5-1.1 on GA media
openSUSE-SU-2026:11376-1: moderate: ignition-2.26.0-5.1 on GA media
SUSE-SU-2026:3319-1: important: Security update for the Linux Kernel (Live Patch 35 for SUSE Linux Enterprise 15 SP5)
SUSE-SU-2026:3300-1: important: Security update for ignition
SUSE-SU-2026:3316-1: important: Security update for the Linux Kernel RT (Live Patch 2 for SUSE Linux Enterprise 15 SP7)
SUSE-SU-2026:3327-1: important: Security update for yq
SUSE-SU-2026:3329-1: important: Security update for nginx
SUSE-SU-2026:3330-1: moderate: Security update for libssh
SUSE-SU-2026:3332-1: important: Security update for java-21-openjdk
SUSE-SU-2026:3335-1: important: Security update for ImageMagick
SUSE-SU-2026:3338-1: important: Security update for webkit2gtk3
SUSE-SU-2026:3340-1: moderate: Security update for nmap
SUSE-SU-2026:3341-1: important: Security update for glib2
SUSE-SU-2026:3350-1: important: Security update for the Linux Kernel (Live Patch 42 for SUSE Linux Enterprise 15 SP5)
SUSE-SU-2026:3351-1: important: Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise 15 SP5)
SUSE-SU-2026:3344-1: important: Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise 15 SP6)
SUSE-SU-2026:3345-1: important: Security update for the Linux Kernel (Live Patch 46 for SUSE Linux Enterprise 15 SP4)
openSUSE-SU-2026:21453-1: important: Security update for chromium
openSUSE-SU-2026:21448-1: important: Security update for agama-web-ui
SUSE-SU-2026:3362-1: important: Security update for samba
SUSE-SU-2026:3364-1: important: Security update for samba
SUSE-SU-2026:3365-1: important: Security update for samba
SUSE-SU-2026:3366-1: important: Security update for samba
SUSE-SU-2026:3368-1: moderate: Security update for sssd
SUSE-SU-2026:3354-1: important: Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise 15 SP4)
SUSE-SU-2026:3372-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP7)

Slackware 1281 Published by Philipp Esselbach 0

The Slackware Linux Security Team issued advisory SSA:2026-209 to patch security vulnerabilities in libarchive, Samba, and SeaMonkey for Slackware 15.0 and -current releases. Libarchive updates to version 3.8.9 to resolve security flaws and bug reports, while Samba advances to 4.22.11 on the stable branch and 4.24.5 on -current to fix defects like DNS crashes, LDAP domain takeovers, and CTDB bounds checking errors linked to CVE-2026-6949 through CVE-2026-58224. SeaMonkey gets version 2.53.24 with security fixes that address unspecified browser exploits.

libarchive (SSA:2026-209-01)
samba (SSA:2026-209-03)
seamonkey (SSA:2026-209-02)

Rocky Linux 966 Published by Philipp Esselbach 0

Rocky Linux administrators need to apply a fresh batch of security advisories targeting core infrastructure packages across versions 8, 9, and 10. The errata address vulnerabilities in LibreSwan VPN, Grafana monitoring dashboards, Dovecot mail servers, SSSD identity management, Unbound DNS caching, and Node.js runtime modules. Each advisory links specific CVE identifiers to Common Vulnerability Scoring System ratings so teams can rank patch urgency without guessing severity levels. Installation requires visiting the official Rocky Linux errata portal for package-specific commands and release notes before deploying changes to production systems.

RLSA-2026:46396: Important: libreswan security update
RLSA-2026:46391: Important: grafana security, bug fix, and enhancement update
RLSA-2026:46532: Important: dovecot security update
RLSA-2026:46990: Important: sssd security, bug fix, and enhancement update
RLSA-2026:46394: Important: go-fdo-client security update
RLSA-2026:46395: Important: go-fdo-server security update
RLSA-2026:36320: Important: unbound security update
RLSA-2026:46398: Important: libreswan security update
RLSA-2026:36777: Important: unbound security update
RLSA-2026:37282: Important: unbound security update
RLSA-2026:47060: Important: nodejs:24 security update
RLSA-2026:47059: Important: nodejs:22 security update

Red Hat 9473 Published by Philipp Esselbach 0

Red Hat Product Security published a batch of errata for Red Hat Enterprise Linux versions 7 through 10 that patch vulnerabilities across core packages like the kernel, gstreamer plugins, OpenShift Container Platform, firefox, freerdp, nodejs, and httpd. The majority of these advisories carry an Important severity rating, while resource-agents and compat-openssl10 received Moderate ratings and OpenShift Container Platform 4.22.7 earned a Critical designation. These patches apply to standard release channels as well as Extended Update Support, SAP Solutions, Telecommunications, and Advanced Mission Critical tracks.

RHSA-2026:47069: Important: gstreamer1-plugins-bad-free security update
RHSA-2026:47090: Important: libpq security update
RHSA-2026:47085: Important: rest security update
RHSA-2026:47079: Important: libXfont2 security update
RHSA-2026:44262: Important: OpenShift Container Platform 4.21.26 bug fix and security update
RHSA-2026:44259: Important: OpenShift Container Platform 4.20.31 bug fix and security update
RHSA-2026:47076: Important: gstreamer1-plugins-bad-free security update
RHSA-2026:47091: Moderate: resource-agents security update
RHSA-2026:47049: Important: freerdp security update
RHSA-2026:47051: Important: gstreamer1-plugins-good security update
RHSA-2026:47048: Important: freerdp security update
RHSA-2026:47052: Important: gstreamer1-plugins-good security update
RHSA-2026:47046: Important: httpd security update
RHSA-2026:47017: Important: kernel security, bug fix, and enhancement update
RHSA-2026:47032: Important: gstreamer1-plugins-good security update
RHSA-2026:47174: Important: gstreamer1-plugins-good security update
RHSA-2026:47083: Important: pipewire security update
RHSA-2026:47071: Important: gstreamer1-plugins-bad-free security update
RHSA-2026:47070: Important: gstreamer1-plugins-bad-free security update
RHSA-2026:47060: Important: nodejs:24 security update
RHSA-2026:47096: Moderate: compat-openssl10 security update
RHSA-2026:47075: Important: gstreamer1-plugins-bad-free security update
RHSA-2026:47040: Important: kernel security, bug fix, and enhancement update
RHSA-2026:47092: Moderate: resource-agents security update
RHSA-2026:44232: Critical: OpenShift Container Platform 4.22.7 bug fix and security update
RHSA-2026:47050: Important: gstreamer1-plugins-good security update
RHSA-2026:47180: Important: gstreamer1-plugins-bad-free security update
RHSA-2026:47176: Important: gstreamer1-plugins-bad-free security update
RHSA-2026:47103: Important: libXfont2 security update
RHSA-2026:47105: Important: firefox security update
RHSA-2026:47248: Important: kernel security update
RHSA-2026:47201: Important: freerdp security update
RHSA-2026:47059: Important: nodejs:22 security update
RHSA-2026:47101: Important: firefox security update

Oracle Linux 6522 Published by Philipp Esselbach 0

Oracle Linux published a wide range of security advisories across operating system versions 7 through 10 to address dozens of publicly disclosed vulnerabilities in core infrastructure components. The patches deliver updated kernels for both mainline and Unbreakable Enterprise distributions alongside critical fixes for OpenSSL, glibc, Tomcat, Node.js, Python 3.14, and SSSD. Engineers will resolve heap-based buffer overflows, use-after-free errors, certificate revocation bypasses, and command injection flaws across services like Apache HTTP Server and Samba. Routine maintenance releases for Podman, Buildah, Cloud-init, and Ignition round out the advisory set by tightening container runtime security and stabilizing cloud provisioning workflows.

ELSA-2026-46395 Important: Oracle Linux 10 go-fdo-server security update
ELSA-2026-43400 Important: Oracle Linux 10 dogtag-pki security update
ELSA-2026-44391 Important: Oracle Linux 10 libpq security update
ELSA-2026-42919 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
ELSA-2026-44270 Important: Oracle Linux 10 kernel security update
ELSA-2026-42096 Important: Oracle Linux 10 c-ares security update
ELSA-2026-30855 Important: Oracle Linux 10 git-lfs security update
ELSA-2026-29195 Important: Oracle Linux 10 buildah security update
ELSA-2026-24470 Important: Oracle Linux 10 podman security update
ELSA-2026-28210 Moderate: Oracle Linux 10 vim security update
ELSA-2026-25341 Important: Oracle Linux 10 tomcat9 update
ELSA-2026-22314 Moderate: Oracle Linux 10 openssl security update
ELSA-2026-22120 Important: Oracle Linux 10 golang security update
ELSA-2026-21286 Important: Oracle Linux 10 .NET 8.0 security update
ELSA-2026-20693 Moderate: Oracle Linux 10 mysql8.4 security update
ELSA-2026-18537 Important: Oracle Linux 10 tomcat security update
ELSA-2026-19126 Important: Oracle Linux 10 yggdrasil security update
ELSA-2026-19569 Important: Oracle Linux 10 kernel security update
ELSA-2026-18320 Moderate: Oracle Linux 10 edk2 security update
ELBA-2026-500089 Oracle Linux 10 ignition bug fix update
ELBA-2026-25086 Oracle Linux 10 cloud-init bug fix and enhancement update
ELBA-2026-500050 Oracle Linux 10 fips-provider-next bug fix update
ELBA-2026-500087 Oracle Linux 9 xfsprogs bug fix update
ELBA-2026-500062 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
ELBA-2026-500088 Oracle Linux 9 xfsprogs bug fix update
ELSA-2026-44308 Important: Oracle Linux 9 libpq security update
ELSA-2026-43307 Important: Oracle Linux 9 kernel security, bug fix, and enhancement update
ELSA-2026-42122 Important: Oracle Linux 9 sssd security update
ELSA-2026-44438 Important: Oracle Linux 9 compat-openssl11 security update
ELSA-2026-42952 Moderate: Oracle Linux 9 glibc security update
ELSA-2026-41949 Important: Oracle Linux 9 python3.14 security update
ELSA-2026-40895 Important: Oracle Linux 9 jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update
ELSA-2026-19345 Important: Oracle Linux 9 LibRaw security update
ELBA-2026-500052 Oracle Linux 9 NetworkManager bug fix update
ELBA-2026-500061 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
ELBA-2026-42552-1 Oracle Linux 8 kernel bug fix update
ELSA-2026-43420 Important: Oracle Linux 8 acl security update
ELSA-2026-42828 Important: Oracle Linux 8 httpd:2.4 security, bug fix, and enhancement update
ELSA-2026-42552 Important: Oracle Linux 8 kernel security, bug fix, and enhancement update
ELSA-2026-41947 Important: Oracle Linux 8 nodejs:22 security, bug fix, and enhancement update
ELSA-2026-40841 Important: Oracle Linux 8 maven:3.8 security update
ELSA-2026-39868 Important: Oracle Linux 8 nodejs:24 security, bug fix, and enhancement update
ELBA-2026-500061 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
ELBA-2026-500061 Oracle Linux 7 Unbreakable Enterprise kernel bug fix update
ELSA-2026-30044 Important: Oracle Linux 7 poppler security update
ELSA-2026-29952 Important: Oracle Linux 7 compat-poppler022 security update
ELSA-2026-28132 Important: Oracle Linux 7 samba security update

Fedora Linux 9432 Published by Philipp Esselbach 0

Fedora released a batch of security patches for versions 43 and 44 on July 29, 2026. The update addresses critical flaws in five packages: Chromium, restic, kronosnet, btrbk, and gpsd. System administrators should apply these fixes to resolve sandbox escapes, command injection risks, memory corruption bugs, and multiple cryptographic vulnerabilities tracked under specific CVE identifiers. Users can install the patches by running dnf upgrade --advisory [update-ID] from their terminal.

Fedora 43 Update: chromium-150.0.7871.186-1.fc43
Fedora 43 Update: restic-0.19.1-1.fc43
Fedora 43 Update: kronosnet-1.35-1.fc43
Fedora 43 Update: btrbk-0.32.7-1.fc43
Fedora 43 Update: gpsd-3.26.1-7.fc43
Fedora 44 Update: chromium-150.0.7871.186-1.fc44
Fedora 44 Update: kronosnet-1.35-1.fc44
Fedora 44 Update: restic-0.19.1-1.fc44

Debian 11013 Published by Philipp Esselbach 0

Debian released security advisories covering critical updates for Samba, OpenJDK Java runtimes, HPLIP printing software, libxfont1, and libraw image library across stable and LTS distributions. The advisories remediate vulnerabilities that could allow attackers to achieve privilege escalation, arbitrary code execution, domain takeover, sandbox bypasses, or data corruption through specially crafted inputs targeting buffer handling and decoder routines in these applications.

[DSA 6401-1] samba security update
[DLA 4703-1] openjdk-17 security update
[DLA 4702-1] openjdk-11 security update
ELA-1787-1 openjdk-11 security update (by )
[DSA 6402-1] hplip security update
ELA-1788-1 libxfont1 security update (by )
[DLA 4704-1] libraw security update

AlmaLinux 2614 Published by Philipp Esselbach 0

AlmaLinux released security updates for packages including sssd, kernel, kernel-rt, dovecot, go-fdo-server, and go-fdo-client across AlmaLinux versions 8 and 10. The sssd update addresses privilege escalation via sudo LDAP provider searches (CVE-2026-14474) and Kerberos authentication bypass through GPO cache path traversal (CVE-2026-14476), while also resolving bugs in the AD UPN override tool. Kernel and kernel-rt packages fix a use-after-free vulnerability in ipv6 ICMPv6 handling (CVE-2026-53006), and dovecot resolves a denial of service issue caused by excessive IMAP bracing (CVE-2026-42006). The go-fdo-server and go-fdo-client updates for AlmaLinux 10 patch privilege escalation via Punycode processing (CVE-2026-39821) and denial of service attacks targeting DNS SAN entries (CVE-2026-27145).

ALSA-2026:46990: sssd security, bug fix, and enhancement update (Important)
ALSA-2026:47011: kernel security update (Important)
ALSA-2026:47010: kernel-rt security update (Important)
ALSA-2026:46532: dovecot security update (Important)
ALSA-2026:46395: go-fdo-server security update (Important)
ALSA-2026:46394: go-fdo-client security update (Important)
2026-07-28

Software 44634 Published by Philipp Esselbach 0

PHP tagged three releases in php/php-src on July 28, 2026, landing PHP 8.6.0alpha3 alongside security patches for both 8.5.9 and 8.2.33. Every active branch received the same synchronized patch set, addressing a stack-based out-of-bounds write in ext/bcmath, a pgsql SQL injection via backslash breakouts, a Phar circular symlink crash, and a libgd vulnerability. The 8.6 alpha cycle brings partial function application, a new clamp() function, and TAILCALL VM support on Windows, with the next snapshot expected around July 30. 8.5 users should watch php.net for the official bulletin, while 8.2 operators need to start planning a migration to 8.4 LTS or 8.5 before the maintenance branch hits end-of-life.

Software 44634 Published by Philipp Esselbach 0

The Samba Team issued coordinated security updates for versions 4.24.5, 4.23.10, and 4.22.11 on July 28, 2026, addressing six vulnerabilities across all active maintenance branches. Two of these flaws, both rated CVSS 8.8 and discovered by OpenAI Security Research, allow low-privilege authenticated users to bypass LDAP access controls and fully compromise an Active Directory domain. Because no workarounds exist for the critical issues, administrators are strongly urged to apply the patches immediately to prevent domain takeover and cryptographic key extraction. The release also resolves additional medium-severity issues affecting DNS TSIG signing, KDC stability, and CTDB clustering protocol integrity.

Software 44634 Published by Philipp Esselbach 0

PixiEditor 2.1.2.1 has officially dropped, bringing a major expansion to its open-source 2D graphics workflow just a year after a complete engine rewrite. The update pushes heavy procedural additions into the node graph, including a Color Ramp, Vector Math, and Random node, alongside long-requested tools like Find and Replace and a Gradient Brush. Built on C# and AvaloniaUI, the free app now ships native builds for Windows, macOS, and Linux, with a paid Steam tier funding ongoing development. It's fast becoming a legitimate alternative to commercial pixel art and vector editors, though the rapid release cadence means you should expect a few rough edges until 2.2 stabilizes.

Software 44634 Published by Philipp Esselbach 0

Valve published Proton 11.0-1b and 10.0-4b on July 28 to add official compatibility for the newly released Steamworks SDK 1.65. Both builds include a networking patch that resolves a persistent 32-bit to 64-bit data alignment issue under WoW64 prefixes. The 10.0-4b drop also folds in a background optimization that trims unnecessary environment variable calls during Steamworks initialization. Linux gamers running either the stable 11.x stack or the older 10.x branch can grab the updates automatically through Steam's compatibility settings.

Reviews 52702 Published by Philipp Esselbach 0

Endorfy’s Fishtank 6000 Corona offers striking aesthetics but falls short on airflow, while the Framework Laptop 13 Pro and CyberPowerPC Infinity U7 Plus deliver polished designs for builders and gamers alike. Microsoft’s Unreal Engine 5 remake of Halo: Combat Evolved pushes hardware hard, requiring extensive testing across thirty-five discrete graphics cards and dozens of handheld PCs to map out performance and VRAM demands. The Logitech G512 X 98 keyboard introduces a magnetic switch system for quick customization, the COUGAR GR 1000 power supply undercuts rivals at $129 with full ATX 3.1 compliance, and Biwin’s M560 solid-state drive tops DRAMless benchmarks with 11,000 megabytes per second of read speed. Independent lab results across these categories give shoppers precise metrics for upgrading workstations, purchasing prebuilt rigs, or tracking modern game optimization on current PC components.

Casing: Endorfy Fishtank 6000 Corona review: a handsome but expensive panoramic PC case
Computers: Framework Laptop 13 Pro review: It cleans up nice, CyberPowerPC Infinity U7 Plus Review (270K Plus + 5070 Ti)
Gaming: Halo: Campaign Evolved Handheld Performance Review, Halo: Campaign Evolved Performance Benchmark Review - 35 GPUs Tested
Input: Logitech G512 X 98 Analog Mechanical Gaming Keyboard Review - An Innovative Two-in-One
Power: COUGAR GR 1000 PSU Review
Storage: Biwin M560 2TB SSD Review - Best Overall Retail-Ready DRAMless SSD

Ubuntu 7167 Published by Philipp Esselbach 0

Ubuntu released three security notices addressing vulnerabilities in Roc Toolkit, GNU C Library, and FreeIPMI across multiple LTS releases. The glibc update resolves seven flaws including heap buffer overflows in scanf functions and incorrect DNS response handling that could allow denial of service or arbitrary code execution; systems running Ubuntu 26.04, 24.04, and 22.04 LTS must reboot after applying the libc6 package update. Roc Toolkit requires a libroc0.4 update to fix a crash vector triggered by malformed WAV files, while the FreeIPMI patch corrects buffer overflow issues in IPMI OEM message processing that could enable local denial of service attacks on systems ranging from Ubuntu 14.04 LTS through 26.04 LTS.

[USN-8612-1] Roc Toolkit vulnerability
[USN-8611-1] GNU C Library vulnerabilities
[USN-8613-1] FreeIPMI vulnerabilities

SUSE 5722 Published by Philipp Esselbach 0

SUSE released a batch of security advisories addressing critical vulnerabilities across multiple core system libraries and applications. Patches target glib2, python-Pillow, Chromium, systemd, and the Linux kernel for SUSE Enterprise versions 15 SP5 through SP7 to resolve out-of-bounds memory access issues, denial-of-service flaws, and use-after-free conditions linked to over a dozen CVE identifiers. Most advisories carry an important rating, with kernel live patches addressing high-severity memory corruption and network stack flaws that demand immediate deployment on production infrastructure. Administrators should apply these updates through YaST or zypper patch to restore system integrity across openSUSE Leap releases and SUSE Linux Enterprise deployments without disrupting running workloads for live-patched components.

SUSE-SU-2026:3235-1: important: Security update for glib2
SUSE-SU-2026:3238-1: important: Security update for python-pyasn1
SUSE-SU-2026:3240-1: important: Security update for python-soupsieve
SUSE-SU-2026:3243-1: low: Security update for gpg2
SUSE-SU-2026:3244-1: moderate: Security update for systemd
SUSE-SU-2026:3254-1: important: Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise 15 SP6)
SUSE-SU-2026:3256-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 15 SP7)
openSUSE-SU-2026:0263-1: important: Security update for trivy
openSUSE-SU-2026:0264-1: important: Security update for chromium
openSUSE-SU-2026:11366-1: moderate: mcphost-0.34.0-9.1 on GA media
openSUSE-SU-2026:11369-1: moderate: opennlp-1.9.5-2.1 on GA media
openSUSE-SU-2026:11364-1: moderate: libknet-devel-1.33-2.1 on GA media
SUSE-SU-2026:3268-1: important: Security update for python-Pillow
SUSE-SU-2026:3270-1: moderate: Security update for alsa
SUSE-SU-2026:3289-1: important: Security update for the Linux Kernel (Live Patch 29 for SUSE Linux Enterprise 15 SP5)

Rocky Linux 966 Published by Philipp Esselbach 0

Rocky Linux issued important security errata covering kernel, kernel-rt, libpq, compat-openssl11, and libreswan packages for Rocky Linux 8, 9, 10, and SIG Cloud releases. Kernel updates appear in separate advisories for the real-time variant on version 8 and the standard kernel across versions 8, 9, 10, plus specific cloud-focused builds for SIG Cloud 8 and 9. Non-kernel advisories deliver libpq maintenance for Rocky Linux 9 and 10 alongside compat-openssl11 and libreswan corrections for version 9. Each vulnerability carries a Common Vulnerability Scoring System base score, allowing users to assess severity levels via the provided CVE list before installing the updates.

RLSA-2026:45116: Important: kernel-rt security update
RLSA-2026:45115: Important: kernel security update
RLSA-2026:45114: Important: kernel security update
RLSA-2026:44391: Important: libpq security update
RLSA-2026:44308: Important: libpq security update
RLSA-2026:44438: Important: compat-openssl11 security update
RLSA-2026:46397: Important: libreswan security update
RXSA-2026:45192: Important: kernel security, bug fix, and enhancement update
RXSA-2026:45115: Important: kernel security update
RLSA-2026:45192: Important: kernel security, bug fix, and enhancement update

Red Hat 9473 Published by Philipp Esselbach 0

Red Hat published a batch of RHSA-2026 security advisories affecting Red Hat Enterprise Linux systems spanning versions 7 Extended Lifecycle Support to version 10, addressing vulnerabilities across multiple packages including kernels, tigervnc, sssd, and libreoffice. Red Hat Product Security assigned an Important impact level to the majority of these advisories, covering patches for kernel, kernel-rt, tigervnc, libreswan, freerdp, and dovecot, while rating a single kernel-rt update for RHEL 7 as Moderate based on CVSS scores available via CVE references. The advisories target diverse maintenance streams such as Advanced Mission Critical Update Support, Extended Update Support Long-Life Add-On, SAP Solutions, and Telecommunications Update Service for RHEL 8, alongside standard releases for RHEL 9 and 10 including updates for go-fdo-client and kpatch-patch.

RHSA-2026:46461: Moderate: kernel-rt security update
RHSA-2026:46460: Important: tigervnc security update
RHSA-2026:46456: Important: tigervnc security update
RHSA-2026:46482: Important: sssd security update
RHSA-2026:46473: Important: tigervnc security update
RHSA-2026:46467: Important: evince security update
RHSA-2026:46398: Important: libreswan security update
RHSA-2026:46392: Important: tigervnc security update
RHSA-2026:46388: Important: freerdp security update
RHSA-2026:46385: Important: tigervnc security update
RHSA-2026:46386: Important: libreoffice security update
RHSA-2026:46384: Important: freerdp security update
RHSA-2026:46394: Important: go-fdo-client security update
RHSA-2026:47011: Important: kernel security update
RHSA-2026:47010: Important: kernel-rt security update
RHSA-2026:46990: Important: sssd security, bug fix, and enhancement update
RHSA-2026:46986: Important: libreswan security update
RHSA-2026:46951: Important: kpatch-patch security update
RHSA-2026:46532: Important: dovecot security update

Fedora Linux 9432 Published by Philipp Esselbach 0

Fedora administrators should apply new security advisories for versions 43 and 44 that address critical flaws across three packages: perl-Mojolicious, rpm, and opkssh. The perl-Mojolicious update to version 9.48 resolves a BREACH attack vulnerability where CSRF tokens were previously exposed through compression oracle techniques, now masking tokens with fresh random values per request. Meanwhile, the rpm rebase to version 6.0.2 patches two distinct issues including a heap buffer overflow in NDB slot table parsing and a command injection flaw within rpmuncompress triggered by unescaped archive directory names. Finally, opkssh moves to version 0.16.0 with an upgraded openpubkey dependency that fixes GQ-commitment PK Token weaknesses affecting GitLab-CI workflows, though current opkssh usage does not reach the vulnerable code path.

Fedora 43 Update: perl-Mojolicious-9.48-1.fc43
Fedora 43 Update: rpm-6.0.2-1.fc43
Fedora 43 Update: opkssh-0.16.0-1.fc43
Fedora 44 Update: opkssh-0.16.0-1.fc44
Fedora 44 Update: perl-Mojolicious-9.48-1.fc44
Fedora 44 Update: rpm-6.0.2-1.fc44

Debian 11013 Published by Philipp Esselbach 0

Debian Long Term Support released advisory DLA-4701-1 to update Chromium version 150.0.7871.181-1~deb12u1 on Debian 12 Bookworm. The patch resolves eighteen vulnerabilities identified under CVE identifiers from CVE-2026-15899 through CVE-2026-16424 that could enable arbitrary code execution, denial of service attacks, or unauthorized data access.

[SECURITY] [DLA 4701-1] chromium security update

AlmaLinux 2614 Published by Philipp Esselbach 0

AlmaLinux released four important security errata covering Libreswan across versions 8 through 10 and Grafana for version 8. The Libreswan updates patch four separate flaws that enable denial of service attacks or daemon crashes when attackers send malformed IKE packets or improperly formatted X.509 certificates. A dedicated Grafana release fixes a validation weakness in the go-billy Git library while adjusting a build macro for the Konflux pipeline. Operators need to deploy these patches immediately to close CVE gaps spanning from 2026-12413 through 2026-50722 before threat actors exploit the VPN tunneling weaknesses.

ALSA-2026:46398: libreswan security update (Important)
ALSA-2026:46397: libreswan security update (Important)
ALSA-2026:46391: grafana security, bug fix, and enhancement update (Important)
ALSA-2026:46396: libreswan security update (Important)

[ Archive ]