AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux distributed a series of security patches for operating system versions 8 through 10. These updates address critical flaws across several key packages including the Linux kernel, mingw-libtiff, corosync, and freeipmi that could otherwise enable remote code execution or cause service disruptions.

ALSA-2026:14929: mingw-libtiff security update (Important)
ALSA-2026:A007: kernel-rt security update (Important)
ALSA-2026:A004: kernel security update (Important)
ALSA-2026:A006: kernel security update (Important)
ALSA-2026:A005: kernel security update (Important)
ALSA-2026:13673: corosync security update (Moderate)
ALSA-2026:14819: freeipmi security update (Moderate)

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux released a moderate security update for version 8 to fix known issues in the libsoup HTTP library. The patch specifically targets CVE-2026-5119, an exploit that could leak sensitive cookie information while establishing HTTPS tunnels. You should install these refreshed packages right away to keep your systems safe from cleartext data exposure. Full technical reports and download links are available on the official errata website or by joining their community chat for support.

ALSA-2026:14087: libsoup security update (Moderate)

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux distributed a batch of security errata for versions 8 through 10 throughout. The updates address moderate and important vulnerabilities in widely used software including the Linux kernel, Tornado web framework, Dovecot mail server, and several cluster management utilities. These patches fix critical weaknesses that could otherwise allow attackers to launch denial of service attacks, inject cookies, or escalate system privileges. IT administrators should apply these updates immediately to keep their networks secure and prevent potential service disruptions.

ALSA-2026:13670: python-tornado security update (Moderate)
ALSA-2026:13657: corosync security update (Moderate)
ALSA-2026:13902: resource-agents security update (Important)
ALSA-2026:13651: systemd security update (Moderate)
ALSA-2026:3840: image-builder security update (Important)
ALSA-2026:1838: image-builder security update (Moderate)
ALSA-2026:13916: fence-agents security update (Important)
ALSA-2026:13642: image-builder security update (Important)
ALSA-2026:13515: freeipmi security update (Moderate)
ALSA-2026:13641: python-tornado security update (Moderate)
ALSA-2026:13643: osbuild-composer security update (Important)
ALSA-2026:13498: dovecot security update (Important)
ALSA-2026:13565: kernel security update (Important)
ALSA-2026:13566: kernel security update (Important)
ALSA-2026:13917: fence-agents security update (Important)
ALSA-2026:13857: dovecot security update (Important)
ALSA-2026:13978: libsoup security update (Moderate)
ALSA-2026:14200: git-lfs security update (Important)

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux released a batch of security advisories to patch critical vulnerabilities across multiple system packages. Most notifications carry an Important severity rating and cover essential tools such as the Linux kernel, Thunderbird, TigerVNC, LibRaw, Dovecot, systemd, and image builder. Engineers addressed a wide array of dangerous flaws including memory corruption issues, privilege escalation risks, and information disclosure bugs that could compromise system stability. Administrators need to install these updates quickly because the patches also fix denial of service vulnerabilities in several widely deployed services.

ALSA-2026:13578: kernel-rt security update (Important)
ALSA-2026:13537: thunderbird security update (Important)
ALSA-2026:13414: tigervnc security update (Important)
ALSA-2026:13577: kernel security update (Important)
ALSA-2026:13284: LibRaw security update (Important)
ALSA-2026:13677: systemd security update (Moderate)
ALSA-2026:13671: image-builder security update (Important)
ALSA-2026:13830: dovecot security update (Important)
ALSA-2026:3839: image-builder security update (Important)

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux 10.2 Beta Lavender Lion has arrived across all supported architectures, bringing a major refresh to the development stack with Python 3.14, PHP 8.4, Ruby 4.0, PostgreSQL 18, and MariaDB 11.8. The release restores legacy i686 userspace packages for older applications while updating core virtualization and container tools like Podman, QEMU-KVM, and libvirt. Security gets a noticeable upgrade through refreshed OpenSSL, OpenSSH, SELinux policies, and an early patch for the Copy Fail flaw tracked as CVE-2026-31431. Because this is strictly a beta build, system administrators should only validate it in isolated test environments and never push it to production until the stable version officially launches.

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux released important security updates for multiple system components. The OpenSSH patches cover versions 8 through 10 and fix five separate flaws that could enable privilege escalation or remote code execution. Another notification addresses a race condition in libcap version eight that might allow unauthorized access to file capabilities.

ALSA-2026:13381: openssh security update (Important)
ALSA-2026:13380: openssh security update (Important)
ALSA-2026:13285: libcap security update (Important)
ALSA-2026:13383: openssh security update (Important)

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux has issued an important security update for Thunderbird on version 10 of its operating system. The patch addresses a long list of vulnerabilities that could allow attackers to exploit memory safety flaws or escalate privileges within the browser and email client. These issues range from incorrect boundary conditions in networking components to dangerous use after free errors that might leak sensitive information or bypass security mitigations. System administrators should install the updated packages as soon as possible to keep their mail clients secure and prevent potential exploitation.

ALSA-2026:12285: thunderbird security update (Important)

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux released a batch of important security updates for versions 8 through 10. The notifications cover several core packages like the Linux kernel, libtiff, libcap, and sudo that handle critical system functions. Hackers could use these specific vulnerabilities to run unauthorized code or bypass permission checks entirely.

ALSA-2026:A003: kernel security update (Important)
ALSA-2026:A002: kernel security update (Important)
ALSA-2026:A001: kernel security update (Important)
ALSA-2026:12265: libtiff security update (Important)
ALSA-2026:12423: libcap security update (Important)
ALSA-2026:12271: libtiff security update (Important)
ALSA-2026:12441: libcap security update (Important)
ALSA-2026:12310: sudo security update (Important)

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux has pushed early kernel patches to its testing repository to fix the Copy Fail vulnerability, which allows unprivileged local users to easily escalate to root privileges. The flaw resides in the kernel crypto subsystem and affects all mainstream distributions built since 2017, making it a critical risk for multi tenant hosts and CI runners. Administrators can apply the fix by enabling the testing repository, updating the kernel package, rebooting the system, and verifying the installed version matches the patched release. AlmaLinux 8 through 10 receive updates through the standard process, while Kitten 10 gets the patch directly in its main repository without requiring extra steps.

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux released a series of critical security patches that address serious vulnerabilities across several major software packages. These updates fix dangerous flaws in Java runtimes, image handling libraries, container tools, and system utilities by patching memory corruption bugs, arbitrary code execution risks, and denial of service vectors. System administrators managing AlmaLinux versions eight through ten need to install these updates right away because unpatched systems remain exposed to data theft and remote compromise. You can find complete technical details for every affected package along with their specific CVE references on the official errata portal.

ALSA-2026:9683: java-1.8.0-openjdk security update (Important)
ALSA-2026:10708: gdk-pixbuf2 security update (Important)
ALSA-2026:8859: giflib security update (Important)
ALSA-2026:10135: buildah security update (Important)
ALSA-2026:9689: java-21-openjdk security update (Important)
ALSA-2026:8863: OpenEXR security update (Important)
ALSA-2026:8861: giflib security update (Important)
ALSA-2026:9689: java-21-openjdk security update (Important)
ALSA-2026:11692: xorg-x11-server security update (Important)
ALSA-2026:9683: java-1.8.0-openjdk security update (Important)
ALSA-2026:11509: vim security update (Important)
ALSA-2026:11656: xorg-x11-server-Xwayland security update (Important)
ALSA-2026:9689: java-21-openjdk security update (Important)
ALSA-2026:10711: python3.12 security update (Important)
ALSA-2026:11504: PackageKit security update (Important)
ALSA-2026:10226: grafana security update (Important)
ALSA-2026:12176: fence-agents security update (Important)

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux has issued a series of critical security patches for numerous software packages across versions 8 through 10. These updates address severe vulnerabilities that could allow attackers to execute arbitrary code, escalate privileges, or expose sensitive system information without authorization. The patches target essential components including web browsers like Firefox and Thunderbird, programming tools such as Python and Java, and various graphical interface libraries. System administrators should promptly install the updated packages to prevent potential exploitation of these newly disclosed security flaws.

ALSA-2026:11077: python3 security update (Important)
ALSA-2026:10766: firefox security update (Important)
ALSA-2026:11349: libxml2 security update (Moderate)
ALSA-2026:11521: sudo security update (Important)
ALSA-2026:11062: python3.11 security update (Important)
ALSA-2026:10950: python3.12 security update (Important)
ALSA-2026:10741: gdk-pixbuf2 security update (Important)
ALSA-2026:10702: webkit2gtk3 security update (Important)
ALSA-2026:9686: java-17-openjdk security update (Important)
ALSA-2026:11635: PackageKit security update (Important)
ALSA-2026:11413: yggdrasil security update (Important)
ALSA-2026:10767: firefox security update (Important)
ALSA-2026:11510: vim security update (Important)
ALSA-2026:10223: grafana security update (Important)
ALSA-2026:11389: vim security update (Important)
ALSA-2026:10713: pcs security update (Important)
ALSA-2026:11360: LibRaw security update (Important)
ALSA-2026:11369: xorg-x11-server-Xwayland security update (Important)
ALSA-2026:11388: xorg-x11-server security update (Important)
ALSA-2026:10710: pcs security update (Important)
ALSA-2026:10739: tigervnc security update (Important)
ALSA-2026:10774: python3.11 security update (Important)
ALSA-2026:10745: python3.12 security update (Important)
ALSA-2026:9686: java-17-openjdk security update (Important)
ALSA-2026:10758: sudo security update (Important)
ALSA-2026:11412: yggdrasil-worker-package-manager security update (Important)
ALSA-2026:10949: python3.9 security update (Important)
ALSA-2026:11352: xorg-x11-server-Xwayland security update (Important)
ALSA-2026:10757: firefox security update (Important)
ALSA-2026:10707: gdk-pixbuf2 security update (Important)

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux distributed a series of security patches for versions 8 through 10. These updates address critical vulnerabilities in essential packages like the Linux kernel, OpenJDK 25, and WebKitGTK by fixing memory corruption flaws and improper parsing routines. Applications including Thunderbird, Wireshark, and osbuild composer also received necessary corrections for buffer overflows and heap management errors that could enable remote code execution.

ALSA-2026:9264: kernel security update (Important)
ALSA-2026:9666: wireshark security update (Moderate)
ALSA-2026:9638: thunderbird security update (Important)
ALSA-2026:9693: java-25-openjdk security update (Important)
ALSA-2026:9692: webkit2gtk3 security update (Important)
ALSA-2026:9693: java-25-openjdk security update (Important)
ALSA-2026:8456: osbuild-composer security update (Important)
ALSA-2026:9345: thunderbird security update (Important)

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux just dropped the 9.8 Beta preview across x86_64, ARM64, PowerPC, and IBM Z architectures so administrators can catch upgrade headaches before they hit actual servers. The build ships Python 3.14, refreshed database streams, updated container runtimes, and tightened security policies that routinely break legacy automation scripts when tested without proper isolation. Teams should only mount these ISOs in virtual machines or dedicated lab rigs since the foundation explicitly warns against touching production hardware with beta code. Running deployment pipelines through a sandbox first lets engineers log dependency failures to the official bug tracker before trusting any release with real workloads.

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux released two critical security updates for version 9. The first patch targets osbuild-composer to fix how the tool parses IPv6 addresses inside URLs. Meanwhile, administrators must also install a kernel update that corrects traffic scheduling logic and resolves a storage driver memory leak.

ALSA-2026:9044: osbuild-composer security update (Important)
ALSA-2026:8921: kernel security update (Important)

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux released an important security patch for both the standard and real-time kernel packages on version 8. The update resolves two specific flaws identified as CVE-2025-68741 and CVE-2026-23191, which involve improper memory handling in storage drivers and race conditions within audio subsystem triggers. System administrators should apply these fixes promptly to prevent potential stability issues or unauthorized access on affected machines. Detailed documentation and download links are available through the official AlmaLinux errata portal for anyone needing further technical guidance.

ALSA-2026:9135: kernel-rt security update (Important)
ALSA-2026:9131: kernel security update (Important)

AlmaLinux 2579 Published by Philipp Esselbach 0

ELevate NG finally lets system administrators push AlmaLinux 9 into the new x86_64_v2-based AlmaLinux 10 or Kitten release, but the upgrade swaps old patching methods for a fresh rootfs image download. The migration tool requires pulling the testing repository config and installing specific leapp packages before it can even map out what needs replacing. Preupgrade scans routinely flag missing dependencies and force manual answers to configuration prompts, so skipping that step guarantees a broken boot sequence. Once the system restarts into the transitional environment, verifying package versions and deleting the temporary bootstrap files keeps the new architecture from quietly breaking custom services later.

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux just pushed out important security fixes for a handful of popular packages on versions eight through ten. You will find patches for Go build macros, the Delve debugger, FreeRDP, giflib, OpenEXR, libarchive, and several .NET framework releases. These updates close dangerous gaps that could let attackers run malicious code or crash your systems using crafted files and network traffic. Make sure to apply these updates as soon as possible to protect your servers from known exploits.

ALSA-2026:8840: go-rpm-macros security update (Important)
ALSA-2026:8842: delve security update (Important)
ALSA-2026:8458: freerdp security update (Important)
ALSA-2026:8858: giflib security update (Important)
ALSA-2026:8470: .NET 8.0 security update (Important)
ALSA-2026:8841: go-rpm-macros security update (Important)
ALSA-2026:8888: openexr security update (Important)
ALSA-2026:8468: .NET 8.0 security update (Important)
ALSA-2026:8473: .NET 10.0 security update (Important)
ALSA-2026:8534: libarchive security update (Important)
ALSA-2026:8475: .NET 9.0 security update (Important)
ALSA-2026:8945: freerdp security update (Important)

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux rolled out a series of critical security patches that affect both version nine and ten of its platform. The updates address multiple high risk vulnerabilities across .NET versions eight and nine, FreeRDP, Thunderbird, and libarchive. Attackers could potentially exploit these flaws to run malicious code remotely or crash systems through memory handling errors and parsing bugs. Administrators need to deploy these fixes right away since the issues carry an important severity rating and leave systems wide open to exploitation.

ALSA-2026:8472: .NET 9.0 security update (Important)
ALSA-2026:8492: libarchive security update (Important)
ALSA-2026:8457: freerdp security update (Important)
ALSA-2026:8469: .NET 8.0 security update (Important)
ALSA-2026:8459: thunderbird security update (Important)
ALSA-2026:8510: libarchive security update (Important)

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux issued a batch of security advisories that address important vulnerabilities across several key software packages. These updates specifically target denial of service risks found in Node.js, Squid, BIND, and PCS components running on version 8 or version 10 systems. Full details regarding the impact and CVSS scores are available in the references section of each advisory for further review.

ALSA-2026:8339: nodejs:20 security update (Important)
ALSA-2026:8317: squid:4 security update (Important)
ALSA-2026:8312: bind security update (Important)
ALSA-2026:8093: pcs security update (Moderate)
ALSA-2026:8352: bind security update (Important)

AlmaLinux 2579 Published by Philipp Esselbach 0

AlmaLinux OS Kitten 10 expands its reach by adding official i686 userspace support for those clinging to 32-bit x86 hardware or legacy software requirements. While there is no installer ISO, users can now access the necessary repositories and container images through the dedicated Kitten vault without relying on third-party mirrors. Docker commands allow developers to spin up 32-bit environments directly using a platform flag to ensure compatibility with specific glibc needs in CI pipelines.