AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux recently pushed four important security patches for version 8 that target serious flaws in both system libraries and everyday software. The standard kernel and real-time variants address a local privilege escalation flaw linked to the Dirty Frag vulnerability plus a separate bug that exposed root files to regular users. Audio handling through libsndfile gets corrected for an integer overflow problem while Firefox and Thunderbird finally close memory safety gaps and prevent sandbox escapes in their web media components.

ALSA-2026:19666: kernel security update (Important)
ALSA-2026:19664: kernel-rt security update (Important)
ALSA-2026:19559: libsndfile security update (Important)
ALSA-2026:19588: firefox security update (Important)

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux distributed a batch of security patches that address serious vulnerabilities across versions 8 through 10 of its operating system. These updates target essential packages like the Linux kernel, Ruby, nginx, and libpng by closing flaws that could let attackers escalate privileges or run arbitrary code on compromised machines. You should apply these fixes right away because leaving systems unpatched leaves them wide open to remote exploitation.

ALSA-2026:16206: kernel security update (Important)
ALSA-2026:18065: ruby security update (Important)
ALSA-2026:18063: nginx security update (Critical)
ALSA-2026:18039: ruby security update (Important)
ALSA-2026:18030: ruby:3.3 security update (Important)
ALSA-2026:18064: libpng security update (Moderate)
ALSA-2026:18041: nginx:1.24 security update (Critical)

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux released two security updates to address serious vulnerabilities in popular server software. The moderate libpng patch resolves a use-after-free flaw that could allow arbitrary code execution. A separate critical advisory fixes nginx, which contains another vulnerability capable of enabling unauthorized remote commands. Administrators should install these packages immediately and consult the official errata links for complete technical details.

ALSA-2026:18028: libpng security update (Moderate)
ALSA-2026:18029: nginx security update (Critical)

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux pushed out a batch of critical security patches for versions 8 through 10. These updates tackle dangerous loopholes inside the core Linux kernel alongside popular utilities like jq, FreeRDP, GIMP, and rsync. You will find fixes for local privilege escalation bugs, remote code execution flaws, and memory corruption issues that could easily trigger service disruptions or unauthorized access. System owners ought to install these important errata right away to keep their networks safe from the newly disclosed threats.

ALSA-2026:A008: kernel security update (Important)
ALSA-2026:A010: kernel security update (Important)
ALSA-2026:16692: jq security update (Important)
ALSA-2026:A009: kernel security update (Important)
ALSA-2026:16482: freerdp security update (Moderate)
ALSA-2026:16195: kernel security update (Important)
ALSA-2026:17533: gimp:2.8 security update (Important)
ALSA-2026:17481: rsync security update (Important)

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux released important security patches for yggdrasil, GIMP, and jq. These updates fix several critical vulnerabilities that could let attackers run malicious code or crash the software using crafted input files. Attackers could exploit these weaknesses through malformed image formats, broken JSON objects, and improper file permission checks.

ALSA-2026:17075: yggdrasil security update (Important)
ALSA-2026:16484: gimp security update (Important)
ALSA-2026:16693: jq security update (Important)

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux recently distributed a series of security patches for versions 8 through 10. These updates target essential software components like FreeRDP, Thunderbird, Kerberos, and several graphics processing libraries across multiple operating system releases. The fixes resolve critical memory corruption flaws, privilege escalation risks, and denial of service conditions that could otherwise compromise system stability or expose sensitive data. System administrators should prioritize installing these corrections right away to prevent potential exploitation of the listed vulnerabilities.

ALSA-2026:14790: libpng security update (Moderate)
ALSA-2026:15969: glib2 security update (Moderate)
ALSA-2026:16014: freerdp security update (Moderate)
ALSA-2026:13644: corosync security update (Moderate)
ALSA-2026:14791: libpng security update (Moderate)
ALSA-2026:15892: thunderbird security update (Important)
ALSA-2026:15887: openexr security update (Important)
ALSA-2026:16875: git-lfs security update (Important)
ALSA-2026:16799: krb5 security update (Important)
ALSA-2026:16252: jq security update (Important)
ALSA-2026:16196: kernel-rt security update (Important)
ALSA-2026:16055: libtiff security update (Important)

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux released a batch of security patches for versions 8 through 10. The openexr update carries an important rating because it blocks arbitrary code execution triggered by malicious image files. Moderate fixes also target memory corruption bugs in glib2, denial of service flaws in libsoup3 and freerdp, plus several heap overflow issues that could leak sensitive data. System administrators should install these errata immediately to close the documented vulnerability gaps across their infrastructure.

ALSA-2026:15888: openexr security update (Important)
ALSA-2026:15968: libsoup3 security update (Moderate)
ALSA-2026:15971: glib2 security update (Moderate)
ALSA-2026:16019: freerdp security update (Moderate)
ALSA-2026:15953: glib2 security update (Moderate)

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux distributed a series of security patches for operating system versions 8 through 10. These updates address critical flaws across several key packages including the Linux kernel, mingw-libtiff, corosync, and freeipmi that could otherwise enable remote code execution or cause service disruptions.

ALSA-2026:14929: mingw-libtiff security update (Important)
ALSA-2026:A007: kernel-rt security update (Important)
ALSA-2026:A004: kernel security update (Important)
ALSA-2026:A006: kernel security update (Important)
ALSA-2026:A005: kernel security update (Important)
ALSA-2026:13673: corosync security update (Moderate)
ALSA-2026:14819: freeipmi security update (Moderate)

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux released a moderate security update for version 8 to fix known issues in the libsoup HTTP library. The patch specifically targets CVE-2026-5119, an exploit that could leak sensitive cookie information while establishing HTTPS tunnels. You should install these refreshed packages right away to keep your systems safe from cleartext data exposure. Full technical reports and download links are available on the official errata website or by joining their community chat for support.

ALSA-2026:14087: libsoup security update (Moderate)

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux distributed a batch of security errata for versions 8 through 10 throughout. The updates address moderate and important vulnerabilities in widely used software including the Linux kernel, Tornado web framework, Dovecot mail server, and several cluster management utilities. These patches fix critical weaknesses that could otherwise allow attackers to launch denial of service attacks, inject cookies, or escalate system privileges. IT administrators should apply these updates immediately to keep their networks secure and prevent potential service disruptions.

ALSA-2026:13670: python-tornado security update (Moderate)
ALSA-2026:13657: corosync security update (Moderate)
ALSA-2026:13902: resource-agents security update (Important)
ALSA-2026:13651: systemd security update (Moderate)
ALSA-2026:3840: image-builder security update (Important)
ALSA-2026:1838: image-builder security update (Moderate)
ALSA-2026:13916: fence-agents security update (Important)
ALSA-2026:13642: image-builder security update (Important)
ALSA-2026:13515: freeipmi security update (Moderate)
ALSA-2026:13641: python-tornado security update (Moderate)
ALSA-2026:13643: osbuild-composer security update (Important)
ALSA-2026:13498: dovecot security update (Important)
ALSA-2026:13565: kernel security update (Important)
ALSA-2026:13566: kernel security update (Important)
ALSA-2026:13917: fence-agents security update (Important)
ALSA-2026:13857: dovecot security update (Important)
ALSA-2026:13978: libsoup security update (Moderate)
ALSA-2026:14200: git-lfs security update (Important)

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux released a batch of security advisories to patch critical vulnerabilities across multiple system packages. Most notifications carry an Important severity rating and cover essential tools such as the Linux kernel, Thunderbird, TigerVNC, LibRaw, Dovecot, systemd, and image builder. Engineers addressed a wide array of dangerous flaws including memory corruption issues, privilege escalation risks, and information disclosure bugs that could compromise system stability. Administrators need to install these updates quickly because the patches also fix denial of service vulnerabilities in several widely deployed services.

ALSA-2026:13578: kernel-rt security update (Important)
ALSA-2026:13537: thunderbird security update (Important)
ALSA-2026:13414: tigervnc security update (Important)
ALSA-2026:13577: kernel security update (Important)
ALSA-2026:13284: LibRaw security update (Important)
ALSA-2026:13677: systemd security update (Moderate)
ALSA-2026:13671: image-builder security update (Important)
ALSA-2026:13830: dovecot security update (Important)
ALSA-2026:3839: image-builder security update (Important)

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux 10.2 Beta Lavender Lion has arrived across all supported architectures, bringing a major refresh to the development stack with Python 3.14, PHP 8.4, Ruby 4.0, PostgreSQL 18, and MariaDB 11.8. The release restores legacy i686 userspace packages for older applications while updating core virtualization and container tools like Podman, QEMU-KVM, and libvirt. Security gets a noticeable upgrade through refreshed OpenSSL, OpenSSH, SELinux policies, and an early patch for the Copy Fail flaw tracked as CVE-2026-31431. Because this is strictly a beta build, system administrators should only validate it in isolated test environments and never push it to production until the stable version officially launches.

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux released important security updates for multiple system components. The OpenSSH patches cover versions 8 through 10 and fix five separate flaws that could enable privilege escalation or remote code execution. Another notification addresses a race condition in libcap version eight that might allow unauthorized access to file capabilities.

ALSA-2026:13381: openssh security update (Important)
ALSA-2026:13380: openssh security update (Important)
ALSA-2026:13285: libcap security update (Important)
ALSA-2026:13383: openssh security update (Important)

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux has issued an important security update for Thunderbird on version 10 of its operating system. The patch addresses a long list of vulnerabilities that could allow attackers to exploit memory safety flaws or escalate privileges within the browser and email client. These issues range from incorrect boundary conditions in networking components to dangerous use after free errors that might leak sensitive information or bypass security mitigations. System administrators should install the updated packages as soon as possible to keep their mail clients secure and prevent potential exploitation.

ALSA-2026:12285: thunderbird security update (Important)

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux released a batch of important security updates for versions 8 through 10. The notifications cover several core packages like the Linux kernel, libtiff, libcap, and sudo that handle critical system functions. Hackers could use these specific vulnerabilities to run unauthorized code or bypass permission checks entirely.

ALSA-2026:A003: kernel security update (Important)
ALSA-2026:A002: kernel security update (Important)
ALSA-2026:A001: kernel security update (Important)
ALSA-2026:12265: libtiff security update (Important)
ALSA-2026:12423: libcap security update (Important)
ALSA-2026:12271: libtiff security update (Important)
ALSA-2026:12441: libcap security update (Important)
ALSA-2026:12310: sudo security update (Important)

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux has pushed early kernel patches to its testing repository to fix the Copy Fail vulnerability, which allows unprivileged local users to easily escalate to root privileges. The flaw resides in the kernel crypto subsystem and affects all mainstream distributions built since 2017, making it a critical risk for multi tenant hosts and CI runners. Administrators can apply the fix by enabling the testing repository, updating the kernel package, rebooting the system, and verifying the installed version matches the patched release. AlmaLinux 8 through 10 receive updates through the standard process, while Kitten 10 gets the patch directly in its main repository without requiring extra steps.

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux released a series of critical security patches that address serious vulnerabilities across several major software packages. These updates fix dangerous flaws in Java runtimes, image handling libraries, container tools, and system utilities by patching memory corruption bugs, arbitrary code execution risks, and denial of service vectors. System administrators managing AlmaLinux versions eight through ten need to install these updates right away because unpatched systems remain exposed to data theft and remote compromise. You can find complete technical details for every affected package along with their specific CVE references on the official errata portal.

ALSA-2026:9683: java-1.8.0-openjdk security update (Important)
ALSA-2026:10708: gdk-pixbuf2 security update (Important)
ALSA-2026:8859: giflib security update (Important)
ALSA-2026:10135: buildah security update (Important)
ALSA-2026:9689: java-21-openjdk security update (Important)
ALSA-2026:8863: OpenEXR security update (Important)
ALSA-2026:8861: giflib security update (Important)
ALSA-2026:9689: java-21-openjdk security update (Important)
ALSA-2026:11692: xorg-x11-server security update (Important)
ALSA-2026:9683: java-1.8.0-openjdk security update (Important)
ALSA-2026:11509: vim security update (Important)
ALSA-2026:11656: xorg-x11-server-Xwayland security update (Important)
ALSA-2026:9689: java-21-openjdk security update (Important)
ALSA-2026:10711: python3.12 security update (Important)
ALSA-2026:11504: PackageKit security update (Important)
ALSA-2026:10226: grafana security update (Important)
ALSA-2026:12176: fence-agents security update (Important)

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux has issued a series of critical security patches for numerous software packages across versions 8 through 10. These updates address severe vulnerabilities that could allow attackers to execute arbitrary code, escalate privileges, or expose sensitive system information without authorization. The patches target essential components including web browsers like Firefox and Thunderbird, programming tools such as Python and Java, and various graphical interface libraries. System administrators should promptly install the updated packages to prevent potential exploitation of these newly disclosed security flaws.

ALSA-2026:11077: python3 security update (Important)
ALSA-2026:10766: firefox security update (Important)
ALSA-2026:11349: libxml2 security update (Moderate)
ALSA-2026:11521: sudo security update (Important)
ALSA-2026:11062: python3.11 security update (Important)
ALSA-2026:10950: python3.12 security update (Important)
ALSA-2026:10741: gdk-pixbuf2 security update (Important)
ALSA-2026:10702: webkit2gtk3 security update (Important)
ALSA-2026:9686: java-17-openjdk security update (Important)
ALSA-2026:11635: PackageKit security update (Important)
ALSA-2026:11413: yggdrasil security update (Important)
ALSA-2026:10767: firefox security update (Important)
ALSA-2026:11510: vim security update (Important)
ALSA-2026:10223: grafana security update (Important)
ALSA-2026:11389: vim security update (Important)
ALSA-2026:10713: pcs security update (Important)
ALSA-2026:11360: LibRaw security update (Important)
ALSA-2026:11369: xorg-x11-server-Xwayland security update (Important)
ALSA-2026:11388: xorg-x11-server security update (Important)
ALSA-2026:10710: pcs security update (Important)
ALSA-2026:10739: tigervnc security update (Important)
ALSA-2026:10774: python3.11 security update (Important)
ALSA-2026:10745: python3.12 security update (Important)
ALSA-2026:9686: java-17-openjdk security update (Important)
ALSA-2026:10758: sudo security update (Important)
ALSA-2026:11412: yggdrasil-worker-package-manager security update (Important)
ALSA-2026:10949: python3.9 security update (Important)
ALSA-2026:11352: xorg-x11-server-Xwayland security update (Important)
ALSA-2026:10757: firefox security update (Important)
ALSA-2026:10707: gdk-pixbuf2 security update (Important)

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux distributed a series of security patches for versions 8 through 10. These updates address critical vulnerabilities in essential packages like the Linux kernel, OpenJDK 25, and WebKitGTK by fixing memory corruption flaws and improper parsing routines. Applications including Thunderbird, Wireshark, and osbuild composer also received necessary corrections for buffer overflows and heap management errors that could enable remote code execution.

ALSA-2026:9264: kernel security update (Important)
ALSA-2026:9666: wireshark security update (Moderate)
ALSA-2026:9638: thunderbird security update (Important)
ALSA-2026:9693: java-25-openjdk security update (Important)
ALSA-2026:9692: webkit2gtk3 security update (Important)
ALSA-2026:9693: java-25-openjdk security update (Important)
ALSA-2026:8456: osbuild-composer security update (Important)
ALSA-2026:9345: thunderbird security update (Important)

AlmaLinux 2606 Published by Philipp Esselbach 0

AlmaLinux just dropped the 9.8 Beta preview across x86_64, ARM64, PowerPC, and IBM Z architectures so administrators can catch upgrade headaches before they hit actual servers. The build ships Python 3.14, refreshed database streams, updated container runtimes, and tightened security policies that routinely break legacy automation scripts when tested without proper isolation. Teams should only mount these ISOs in virtual machines or dedicated lab rigs since the foundation explicitly warns against touching production hardware with beta code. Running deployment pipelines through a sandbox first lets engineers log dependency failures to the official bug tracker before trusting any release with real workloads.