2026-09-30
Godot 4.8 dev 7 has put the 4.8 branch into feature freeze, so no new features will integrate from here on. The headline addition is the long-requested symbol renaming tool, though it's flagged experimental and requires an explicit opt-in because it slipped in at the last minute. Other notable improvements include runtime CanvasItem manipulation in the game view, fully animated decals, zero-allocation physics queries, native touch support for key GUI controls, and AccessKit accessibility for iOS and Android.
Bazzite Linux 44.20260929 has been released. The headline change bumps Gamescope to 3.16.31, while real code fixes tackle HDMI CEC across multiple TVs, add a TouchUp touch-screen extension for GNOME tablets like the Framework 12, and repair a Sunshine streaming-host setup path. Steam and core drivers got their usual minor bumps too, though nothing here is a reason to upgrade unless you want the latest kernel and graphics stack.
Valve has pushed SteamOS 0.4.2 (Beta) for the Steam Frame, its third OS update since the headset's September 14 launch, tightening audio reliability, connection stability (including a fix for "protocol error 17"), and proximity detection. The polish pass bundles the SteamVR 2.18.1 runtime and arrives alongside a dongle troubleshooting script aimed at making streaming work on third-party Linux distros. The Frame itself is a streaming-first, standalone VR headset powered by a Snapdragon 8 Gen 3, priced at $1,059 for 256GB and $1,299 for 1TB. Buyers are still waiting on shipped units through Valve's reservation system, and the dongle experience on non-SteamOS Linux remains a known rough edge.
Today's hardware reviews share a common theme: how much you pay for looks versus performance. The AMD Ryzen 7 7700X3D leads as the cheapest X3D chip on AM5 at $329, earning a 9/10 for gaming value. Cooling tests reveal that variant upgrades like Thermalright's Black vs ARGB and DeepCool's vapor-chamber AK700 VC deliver nearly identical results, so you're mostly paying for features. Meanwhile, retro styling carries a real premium on the SilverStone FLP03 and IQUNIX EV63, quirky peripherals like the fan-laden Pulsar mouse fill niche roles, and a recurring lesson emerges that reaching "great" costs far less than chasing best-in-class.
Today's Linux security roundup spans eight distros, from a Critical FreeIPA hole to Red Hat's 27-errata batch and hundreds of CVEs stuffed into the Debian and Ubuntu kernels. Debian's kernel update (6.12.111-1) runs from CVE-2024-52560 to CVE-2026-100079, while Ubuntu's Oracle 7.0 kernel (USN-8728-3) adds an ARM TLB race and an AMD Zen 2 flaw on top of 100+ more. The Criticals to patch first are the freeipa updates on AlmaLinux and Rocky Linux 10, the PostgreSQL 12 bump on Rocky Linux 8, and the RHEL for NVIDIA kernel (RHSA-2026:73187). Beyond kernels, watch Slackware's Firefox ESR build from roughly 43 CVEs, SUSE's near-critical 9.8-rated perl-DBI flaw, and Ubuntu's OpenSSL and Erlang fixes, though many older Ubuntu releases stay gated behind Ubuntu Pro.
2026-09-29
Archinstall, the guided installer for Arch Linux, released version 4.5 on September 29, 2026, shipping 131 commits since its previous release. The headline addition is AArch64 support for GRUB and Limine EFI bootloaders, closing the installer's biggest platform gap and letting 64-bit ARM machines use the same guided flow. It also turns on TLS verification for network fetches, moves Wayland compositors to systemd-logind, adds real-time kernel variants, and introduces three new languages: Norwegian Bokmål, Serbian, and Vietnamese. With 21 contributors, including 14 first-timers, the update leans more on security, maintainability, and standardized releases than flashy new features.
Ubuntu 26.04.1 "Resolute Raccoon" is now the supported upgrade target for the tens of millions of systems still running Ubuntu 24.04 LTS. The 26.04.1 point release, shipped on August 27, 2026, consolidates all fixes and security patches since the original April 23 launch. Notable changes include GNOME 50, a fully rewritten app suite, a new post-quantum OpenSSH, MySQL 8.4 LTS, and a Linux kernel 7.0, though several server upgrades require manual attention. The upgrade is free and can be triggered through Update Manager or do-release-upgrade, with LTS support lasting until April 2031.
OpenSSL 4.0.3 shipped today, closing 14 vulnerabilities spanning the QUIC transport, DTLS, X.509 certificate handling, the SM2 cryptographic suite and core key-management code. The project rated its worst flaw High, yet two unnumbered bugs deserve attention: an AES-SIV authentication misreporting error that could mask tampered data, and a base64 BIO regression that might silently truncate output. Reading the fixes together reveals the themes of the release, with QUIC accounting for at least five of the CVEs and a cluster of timing side channels targeting SM2 on ARM64 and RISC-V. Timing matters because OpenSSL 4.1 is nearly here while OpenSSL 3.0 already reached end of life on September 16.
The first release candidate for the Apache webserver 2.4.69 has been released for testing. The new candidate carries no fresh CVEs, since the heavy security work already landed in 2.4.68 back in June. Its biggest change makes mod_http2 drain open streams instead of dropping them on a graceful GOAWAY, bringing HTTP/2 in line with RFC 9113. Alongside that, the release disables MDServerStatus by default, drops weak RFC 2069 digest auth, adds OpenSSL 4 support, and ports the test suite from Perl to Python.
WinterSnowfall shipped D7VK v2.3, the compatibility layer that runs old Direct3D 7, 6, 5, and 3 games on Linux via Vulkan. The headline change places shadow surfaces in system memory, boosting performance in Empire Earth while adding a config fix to counter a Star Trek: Armada regression. The changelog also fixes a batch of classic titles, including Dark Vengeance, Z.A.R., and Star Wars: X-Wing Alliance. Most significantly, the developer announced the project is entering maintenance mode, meaning fewer releases and bug fixes only from here on.
Eight hardware and software reviews hit the web together painting a picture of a PC market caught between old and new sockets. Standouts include a pocket-sized Ninkear L20 mini-PC with class-ready integrated graphics, and The Witcher 3 Remaster earning a flawless 5/5 for a facelift that's free for existing owners. Power supplies and storage split the week neatly: a thoroughly tested Cooler Master 1000W PSU against a €89.90 budget Sharkoon, and a fast-read Fanxiang SSD whose writes collapse after 240 GB of cache. The bottom line is that midrange value comes down to knowing which socket, link, or cache technology you're actually buying into.
4MLinux 53.0 BETA launched as a full desktop-and-miniserver image rather than a half-built prototype. It rides on a modern core built from source with what the project calls "a huge number of updated packages." The Polish distro sidesteps traditional package managers, delivering software as self-contained addons and rebuilding its tiny core on boot to stay comfortably light on old hardware. It is one step toward a November STABLE release, with old-stable support through March 2027 and end of life in July.
Git 2.56.0 has been released and adding a safer git add --resolved conflict workflow, major merge-base speedups, and path-wallet repacking that now works with server-side bitmaps. The quarterly release contains 748 non-merge commits from 104 contributors, including 39 first-timers. Real-world gains are striking: one monorepo merge-base traversal fell from 0.68 to 0.01 seconds, and a path-wallet repack came in roughly 71% smaller than the bitmapped alternative. Also notable is that Rust support is now on by default, with the project eyeing a mandatory switch at version 3.0.
Bazzite shipped 44.20260928.1, another new stable image for its Fedora 44-based gaming Linux distro. This is a minor patch release that fixes just one issue: a stray msedit desktop icon that Bazzite normally strips from terminal-based apps. Some background maintenance accompanied it, including default editor config tweaks, GNOME extension updates, and a Sunshine on Brew script fix. Existing users can move over using the bazzite-rollback-helper, while fresh installs and Fedora Atomic users can rebase through the official site or the terminal.
SUSE led today's Linux patch wave with a 133-CVE kernel update that still needs a reboot, though the real standouts were the bugs you'd expect to be long fixed. Debian shipped rsync with 33 CVEs and dovecot with 25, while Debian's OpenStack and Slackware's 26-year-old groff command-injection holes made the week feel oddly retro. Ubuntu's Exim brought proxy-protocol code execution, but the most awkward moment went to its curl cleanup notice targeting the still-supported 14.04 LTS. If any of this software runs on boxes you manage, the advisory tables are worth a scroll and the reboot is unavoidable.
[ Archive ]