2026-08-09
Greg Kroah-Hartman released Linux Kernel 7.1.8 today, delivering over 200 commits focused on networking use-after-free patches, Thunderbolt validation fixes, and AMD and Intel graphics driver refinements. The stable update also resolves UCSI Type-C race conditions and addresses several USB serial heap overflows, keeping production workloads running cleanly while the 7.2 release candidate cycle continues. Built on the June mainline, 7.1 introduced BPF-controlled io_uring event loops, container lifecycle flags like CLONE_AUTOREAP, and a swap table rewrite that trims roughly 30 percent of static metadata overhead. The 7.1.x branch will receive stable patches until approximately September 2026, after which distros will typically backport critical fixes into their own LTS tracks.
Greg Kroah-Hartman and Sasha Levin have pushed three new stable kernel releases into the tree, bringing you 6.18.44, 6.12.103, and 6.6.151. These point releases ship hundreds of targeted bug fixes and security patches across the block layer, networking stack, and major filesystems while deliberately avoiding new features. The 6.18 branch is the freshest of the group, having shipped in late 2025 and staying supported through December 2028, while the 6.6 line remains the longest-tested option, running until December 2027. Production teams should roll out the updates through their distro vendor after verifying driver compatibility, since stable kernels prioritize reliability over novelty.
CachyOS has shipped its August 2026 release, headlined by a full rewrite of the default GUI package manager, Shelly, from C# to the Zig programming language. The update pushes Rust into the handheld daemon's kernel backend and the systray updater, while quietly introducing experimental server edition installation profiles through the CLI. Existing users can upgrade immediately with sudo pacman -Syu, and the Noctalia desktop environment now adds mango and niri window manager variants alongside Hyprland. Desktop and Handheld ISOs are live now at iso.cachyos.org and rolling out across global mirrors.
Roundcube has released emergency updates for both its LTS and current stable branches, scrubbing eleven distinct security flaws from versions 1.6.18 and 1.7.3. The patch closes critical attack paths including unauthenticated RCE via the markasjunk plugin, pre-authentication IMAP command injection, Sieve and LDAP filter injection, plus multiple SSRF and persistent XSS bypasses. Security researchers note that the recurring HTML sanitization failures point to a deeper architectural flaw that incremental patches can no longer contain. Administrators should update immediately and disable the markasjunk plugin if it isn't actively needed.
Zen Browser has released version 1.21.13b as a targeted bug-fix update, marking the tenth drop in the 1.21.x series over just seven weeks. The build resolves a persistent sidebar loop that rendered infinite media players on complex pages and fixes a regression where restored pinned tabs incorrectly reverted to regular tabs. This quiet maintenance release continues the project's aggressive track of Mozilla's upstream Firefox 152 through 153.0.3 development, ensuring users get stability without waiting for major feature additions. Available across Windows, macOS, and Linux with GPG-signed commits, the update keeps the open-source fork running smoothly amid a heavy backlog of community-reported issues.
Linux distributions just pushed a massive wave of security advisories covering everything from the standard kernel and Thunderbird to niche tools like stunnel and goaccess. SUSE flagged a critical WebKit2GTK3 flaw, Fedora plugged a heap overflow in goaccess while trimming memory overhead, and Debian kept ELTS systems like kernel 5.10 and OpenJDK 8 patched for legacy deployments. The heavy overlap between AlmaLinux, Oracle, Rocky, and RHEL means a single maintenance window will likely clear most server fleets, though Slackware and Debian ELTS operators need to tackle their trees first. Pull the exact advisory numbers for your release, apply the updates, and verify your services before rolling out to the next cluster.
Triton, a full DirectX 11 driver stack for QEMU/KVM released by UTM developer osy, brings working GPU acceleration to Windows ARM64 virtual machines. By reverse-translating Windows DDI calls back into standard D3D11 API commands and routing them through Neptune’s VirtIO transport layer, the stack bypasses the DLL-replacement tricks that typically trigger anti-cheat systems. The project supports DXVK on Linux hosts and leverages Apple’s D3DMetal framework or DXMT for macOS, with developers already reporting playable runs of Crash Bandicoot and full 3DMark FireStrike benchmarks. Though still labeled a pre-release and awaiting shader-container polish, Triton stands as the first fully open-source, anti-cheat-compatible DirectX 11 GPU path in QEMU.
GNOME's Shotwell photo manager has officially entered its 33rd release cycle with the August 8 release of the "Elmshorn" release candidate. The update completely abandons the legacy "0." versioning scheme following a 19-month development push that fully ports the application to GTK4. Core functionality receives major upgrades, including a complete overhaul of the notoriously broken face detection system and a streamlined OAuth-based publishing workflow that removes outdated helper apps. The source tarball is already available for download, with a Flathub package expected to follow shortly.
Wine Staging 11.15 dropped today, bringing a substantial sync to the upstream Wine tree alongside a major overhaul of the vkd3d-latest patchset. The D3D12-to-Vulkan translation layer received roughly 9,100 lines of updates to keep pace with upstream API changes, which should improve compatibility for modern DirectX 12 games. Maintainer Alistair Leslie-Hughes also refined Codeweavers' DComp shared-visual-handle implementation to stabilize titles like Clip Studio Paint 4 and Corgi Warlock, while finally removing outdated workarounds for legacy d3dx9 functions. As an experimental branch, this release prioritizes bleeding-edge fixes and patch maintenance over major feature dumps, making it the go-to version for users needing the latest graphics driver improvements before they hit mainline.
openSUSE released a batch of moderate security advisories addressing vulnerabilities in the tekton-cli, libXfont2-2, Django 4, and gleam packages. The tekton-cli 0.46.0-1.1 and gleam 1.18.1-1.1 updates each fix a single CVE with lower risk profiles. Developers using libXfont2-2-2.0.7-3.1 should prioritize this release after SUSE assigned CVSS scores of 9.0 to 9.5 for CVE-2026-44950 and CVE-2026-59679. Django 4 developers must also apply the python313-Django4 4.2.30-5.1 package to resolve four flaws, including a critical CVSS 9.9 vulnerability in CVE-2026-15307.
openSUSE-SU-2026:11471-1: moderate: tekton-cli-0.46.0-1.1 on GA media
openSUSE-SU-2026:11463-1: moderate: libXfont2-2-2.0.7-3.1 on GA media
openSUSE-SU-2026:11465-1: moderate: python313-Django4-4.2.30-5.1 on GA media
openSUSE-SU-2026:11462-1: moderate: gleam-1.18.1-1.1 on GA media
Slackware Linux released updated wpa_supplicant packages to resolve multiple security vulnerabilities affecting Wi-Fi authentication. The new version 2.12 builds ship for both Slackware 15.0 and the rolling -current branch across i586, i686, and x86_64 architectures.
wpa_supplicant (SSA:2026-220-01)
Fedora released security updates for Fedora 43 and Fedora 44 that update udisks2, pgadmin4, bird, and nghttp2 to address multiple vulnerabilities. The pgadmin4 update to version 9.17 patches four flaws including a remote code execution risk in the Import/Export Data tool and an OS command injection vector in the MASTER_PASSWORD_HOOK, while the bird update to 3.3.2 fixes a stack buffer overflow in the BGP Flowspec NLRI decoder. nghttp2 version 1.68.0-5 blocks HTTP request/response smuggling and response-queue poisoning caused by ambiguous HTTP/1.1 upgrade requests, which the bug tracker lists as CVE-2026-58055, and udisks2 advances to upstream release 2.11.2 for general enhancements. Users must run the appropriate dnf upgrade commands to install these packages and secure their environments against unauthenticated access, data manipulation, and potential information disclosure.
Fedora 43 Update: udisks2-2.11.2-1.fc43
Fedora 43 Update: pgadmin4-9.17-1.fc43
Fedora 43 Update: bird-3.3.2-1.fc43
Fedora 44 Update: nghttp2-1.68.0-5.fc44
Fedora 44 Update: pgadmin4-9.17-1.fc44
Fedora 44 Update: bird-3.3.2-1.fc44
Debian published multiple security advisories to patch critical flaws across PowerDNS, Nginx, Chromium, and Bind9. The updates resolve CVE-2026-52682 in pdns-recursor, pdns, and dnsdist, which could trigger denial of service attacks through malformed DNS packets. The advisory also covers Nginx, which requires updates to patch proxy and charset module flaws, alongside Chromium, which addresses forty-one distinct vulnerabilities that could enable arbitrary code execution or memory disclosure. Bind9 receives the most extensive corrections, sealing flaws that previously enabled cache poisoning, DNSSEC validation bypass, and unbounded memory consumption.
[DSA 6421-1] pdns-recursor security update
[DSA 6420-1] pdns security update
[DSA 6419-1] dnsdist security update
ELA-1797-1 nginx security update (by )
[DSA 6422-1] chromium security update
[DLA 4725-1] bind9 security update
2026-08-08
The Heroic Games Launcher v2.22.1 source is out now on GitHub, serving as a critical hotfix that repairs the broken library loading and installation failures introduced in the v2.22 "Hajrudin" release from May. The update bundles a suite of quality-of-life improvements alongside the patches, including snappier gamepad navigation, corrected Nintendo controller mappings, and expanded GOG region and currency support for the launcher's 20 million monthly users. Under the hood, the app has upgraded to Electron v43, unified webview sessions for smoother store logins, and added Rosetta detection warnings for Apple Silicon Macs missing the translation layer.
Wine 11.15 has arrived, bringing local NTLM authentication and MinGW-mode ARM64EC build support to its development line. The new in-process NTLM implementation allows enterprise Windows apps to authenticate directly on Linux without a domain controller, while expanded BCrypt and WindowsCodecs updates round out the cryptographic and imaging improvements. This week's cut delivers 41 bug fixes and roughly 150 commits from over 40 contributors, continuing the rapid development cadence that followed Wine 11's NTSYNC kernel integration.
Valve has released SteamOS 3.8.25 Beta, bringing Steam Machine Firmware 108 with critical sleep and CPU performance fixes alongside expanded gamepad support for the MSI Claw, OneXPlayer, AYANEO Pocket S2, and Konkr FIT. The update also delivers preliminary drivers for the upcoming Steam Frame Wireless Adapter, resolves a confusing speaker dropout bug on Steam Deck OLED units, and patches HDMI and Bluetooth audio issues. While desktop mode users will appreciate fixes for app persistence and TV Game Mode flashing, the beta currently carries a known performance regression when using FSR that stable release 3.8.16 already resolved. Until that composition bug is patched, most owners should hold off unless they specifically need the Steam Machine or third-party handheld improvements.
Today's collection of hardware reviews spans desktop enclosures, portable business laptops, compact system units, input peripherals, circuit boards, and power supplies. The Cougar MX600 Max RGB and ASUS ROG Strix B850-F boards pair with the CPS PCCooler YS1200 ATX 3.1 power supply to give PC builders a solid foundation, while the Lenovo ThinkPad X13 Gen 6 and Geekom IT13 MAX serve professionals who need reliable machines that fit tight schedules and limited desk space. Gamers and office workers can weigh the magnetic switch variants in the Epomaker HE75 V2 keyboards against the ultra-lightweight Genesis Zircon 880 Pro mouse and the competitive features of the SCUF Omega controller. Each unit targets specific workflows, from all-day corporate travel and content creation to fast-paced multiplayer sessions, giving buyers clear performance trade-offs before they commit.
Casing: Cougar MX600 Max RGB Case Review
Computers: Lenovo ThinkPad X13 Gen 6 Review: An Ultralight Laptop Built For Business, HyperX Omen Max 16 review: All bark and no bite, Geekom IT13 MAX Mini PC review
Gaming: SCUF Omega Review
Input: Epomaker HE75 V2 & HE75 V2 TMR Review, Genesis Zircon 880 Pro Black review: 8K and 64 g
Motherboards: ASUS ROG Strix B850-F Gaming Wi-Fi7 Neo Review
Power: CPS PCCooler YS1200 ATX 3.1 80 PLUS Gold PSU Review
KDE's team has published a weekly development roundup highlighting their development work across Plasma 6.8, the 6.7.x maintenance branch, and Kup 0.11.0. The built-in krdp remote desktop server receives significant attention with a fix for the persistent black screen bug and reduced latency on weaker networks, while Plasma 6.8 now loads the clipboard history pop-up on demand to save system RAM. The 6.6 LTS branch sees targeted fixes for xdg-desktop-portal crash recovery and Task Manager drag-and-drop functionality, ensuring smoother performance for long-term support users. Kup 0.11.0 rounds out the release cycle with improved default backup exclusions for cache files and Btrfs snapshots, making it a more polished option for system maintenance.
Godot Engine has shipped 4.8 development snapshot 3, delivering 176 fixes from 91 contributors in the days following GodotCon Boston 2026. With feature freeze still over a month away, the build prioritizes developer experience through precise GDScript underlining, high polling rate mouse support on Windows, and expanded plugin APIs for the property clipboard. The update also introduces native admonition support for documentation, modularizes visionOS into a proper XR system, and lands a series of physics and renderer tweaks. Standard, .NET, and web editor builds are available now for Windows, macOS, Linux, and visionOS, with Android access available through the Play testing group.
Rocky Linux administrators should install the latest errata packages for versions 8, 9, and 10 to address confirmed security vulnerabilities across multiple core components. The advisories cover LibRaw, gpsd, kernel-rt, and the standard kernel, with severity ratings split between Important and Moderate designations. Each release incorporates targeted bug fixes and performance improvements alongside the patched CVEs listed in the official tracker.
RLSA-2026:51105: Important: LibRaw security update
RLSA-2026:51075: Important: gpsd security update
RLSA-2026:51153: Important: gpsd-minimal security update
RLSA-2026:50979: Important: kernel-rt security, bug fix, and enhancement update
RLSA-2026:50978: Important: kernel security, bug fix, and enhancement update
RLSA-2026:51295: Moderate: kernel security, bug fix, and enhancement update
RLSA-2026:51035: Moderate: kernel security, bug fix, and enhancement update
Red Hat released three security advisories addressing kernel and kernel-rt vulnerabilities for Red Hat Enterprise Linux 9.2 and 9.4 environments supporting SAP workloads. Product security teams assigned an Important rating to each advisory, with detailed severity scores accessible through the provided CVE references. System administrators should apply the kernel-rt packages for real-time scheduling requirements and install the standard kernel updates for regular RHEL operations. Full version details and patch information are available through the linked errata documentation.
RHSA-2026:51603: Important: kernel security, bug fix, and enhancement update
RHSA-2026:51604: Important: kernel-rt security, bug fix, and enhancement update
RHSA-2026:51746: Important: kernel security, bug fix, and enhancement update
Oracle Linux 7 through 10 received a wave of security advisories targeting the Unbreakable Enterprise Kernel, addressing memory corruption, networking stack flaws, and hypervisor vulnerabilities across x86_64 and aarch64 architectures. Administrators managing GPSD, GnuTLS, or LibRaw installations must apply immediate fixes for command injection, cryptographic bypasses, and parsing errors linked to recent CVEs.
ELSA-2026-500135 Important: Unbreakable Enterprise kernel security update
ELSA-2026-51075 Important: Oracle Linux 10 gpsd security update
ELSA-2026-500135 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
ELSA-2026-500137 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
ELSA-2026-500137 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
ELSA-2026-500137 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
ELSA-2026-500136 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
ELSA-2026-500136 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
ELSA-2026-500136 Important: Oracle Linux 7 Unbreakable Enterprise kernel security update
New Ksplice updates for UEKR6 5.4.17 on OL7 and OL8 (ELSA-2026-500136) New Ksplice updates for RHCK 9 (ELSA-2026-19225)
ELSA-2026-49871 Moderate: Oracle Linux 10 kernel security, bug fix, and enhancement update
ELSA-2026-30129 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
ELBA-2026-51069 Oracle Linux 10 tzdata bug fix and enhancement update
ELSA-2026-51105 Important: Oracle Linux 9 LibRaw security update
ELSA-2026-51035 Moderate: Oracle Linux 9 kernel security, bug fix, and enhancement update
ELBA-2026-51069 Oracle Linux 9 tzdata bug fix and enhancement update
ELBA-2026-50156-0 Oracle Linux 9 linux-firmware bug fix and enhancement update
ELSA-2026-50978 Important: Oracle Linux 8 kernel security, bug fix, and enhancement update
ELBA-2026-51069 Oracle Linux 8 tzdata bug fix and enhancement update
ELSA-2026-34372 Important: Oracle Linux 7 gnutls security update
Fedora released a coordinated security update for Fedora 43 and Fedora 44, targeting foundational packages like the Linux kernel, Python 3.12, Erlang, and Perl 5.42.3. The release closes documented flaws across the ecosystem, including a kernel vulnerability tracked as CVE-2026-68480 and an SSL authentication bypass in Erlang flagged as CVE-2026-55953. RabbitMQ received eight distinct patches that eliminate cross-site scripting risks, unauthorized message routing, and credential exposure through outdated API endpoints. Users can install the corrected packages immediately through the dnf package manager by running the advisory-specific upgrade command listed in the notification.
Fedora 44 Update: udisks2-2.11.2-1.fc44
Fedora 44 Update: kernel-7.1.7-200.fc44
Fedora 44 Update: p11-kit-0.26.5-1.fc44
Fedora 44 Update: erlang-26.2.5.21-5.fc44
Fedora 44 Update: mingw-glib2-2.88.3-1.fc44
Fedora 43 Update: kernel-7.1.7-100.fc43
Fedora 43 Update: perl-PAR-Packer-1.064-5.fc43
Fedora 43 Update: polymake-4.15-6.fc43
Fedora 43 Update: perl-5.42.3-524.fc43
Fedora 43 Update: perl-Devel-Cover-1.51-4.fc43
Fedora 43 Update: seamonkey-2.53.24-1.fc43
Fedora 43 Update: erlang-26.2.5.21-5.fc43
Fedora 43 Update: python3.12-3.12.13-6.fc43
Fedora 43 Update: rabbitmq-server-4.0.9-5.fc43
Fedora 43 Update: python-nh3-0.2.21-9.fc43
Fedora 43 Update: rust-ammonia-4.1.4-1.fc43
Debian and Freexian issued a series of security advisories to patch critical flaws across Linux kernels, Thunderbird, Nginx, Redis, and libheif on multiple Debian releases. The kernel updates for versions 6.1 and 6.12 address dozens of common vulnerabilities that could allow attackers to escalate privileges, leak memory, or crash systems. Separate advisories cover remote code execution risks in Thunderbird and Nginx, a heap overflow in the Redis RESTORE command, and memory safety issues in the libheif image decoder. System administrators should manually install the updated packages through their package managers to apply these fixes immediately.
[DLA 4724-1] linux-6.12 new package
[DLA 4723-1] linux-6.1 security update
ELA-1796-1 linux-6.1 security update (by )
ELA-1795-1 redis security update (by )
[DSA 6417-1] libheif security update
[DSA 6418-1] thunderbird security update
ELA-1797-1 nginx security update (by )
AlmaLinux released a series of security advisories, targeting versions 8, 9, and 10 of its Linux distribution. The patch cycle addresses code flaws in the standard and real-time kernels, LibRaw, libgcrypt, perl-DBI, golang, and Firefox. Attackers could exploit these moderate to important vulnerabilities to trigger buffer overflows, cause use-after-free crashes, or escalate privileges on affected systems.
ALSA-2026:49871: kernel security, bug fix, and enhancement update (Moderate)
ALSA-2026:51105: LibRaw security update (Important)
ALSA-2026:45192: kernel security, bug fix, and enhancement update (Important)
ALSA-2026:51035: kernel security, bug fix, and enhancement update (Moderate)
ALSA-2026:50147: libgcrypt security update (Moderate)
ALSA-2026:38512: perl-DBI security update (Important)
ALSA-2026:37435: golang security, bug fix, and enhancement update (Important)
ALSA-2026:45116: kernel-rt security update (Important)
ALSA-2026:45115: kernel security update (Important)
ALSA-2026:39180: kernel-rt security update (Important)
ALSA-2026:47105: firefox security update (Important)
ALSA-2026:39179: kernel security update (Important)
[ Archive ]