Rocky Linux 922 Published by Philipp Esselbach 0

Rocky Linux has rolled out a series of critical security advisories targeting PHP versions eight point two and eight point three alongside the Apache httpd server. Administrators managing either release eight or nine will need to apply these fixes immediately since core packages like Redis, Xdebug, APCu, ZIP, RRD, libzip, PEAR, mod_md, and mod_http2 contain multiple known flaws.

RLSA-2026:22142: Important: php:8.3 security update
RLSA-2026:22143: Important: php:8.2 security update
RLSA-2026:22305: Important: php:8.2 security update
RLSA-2026:22140: Important: httpd:2.4 security update

Rocky Linux 922 Published by Philipp Esselbach 0

Rocky Linux 922 Published by Philipp Esselbach 0

Rocky Linux 10.2 drops straight into production with a simple upgrade command for existing v10 systems, though older releases still demand fresh installs and stricter x86_64-v3 hardware baselines. The kernel gets sharper performance monitoring tools and better encrypted storage crash handling, while OpenSSH and libssh finally adopt hybrid post-quantum key exchange methods to future-proof authentication pipelines. Developers get a refreshed toolchain with GCC 15 and updated debuggers, but the real headache comes from running both PHP 8.3 and 8.4 side by side without careful dependency tracking. Administrators who verify CPU compatibility and lock down package versions before deploying will avoid unnecessary downtime while taking advantage of these solid infrastructure upgrades.

Rocky Linux 922 Published by Philipp Esselbach 0

Rocky Linux administrators need to install multiple security patches across versions eight and ten to address newly discovered vulnerabilities in widely used software packages. The advisory list covers essential tools like flatpak, cockpit, systemd, and golang alongside specialized libraries such as python-gevent and edk2. CVSS ratings help operators prioritize these fixes quickly. These releases also deliver necessary bug corrections and performance enhancements that keep the operating system running smoothly without unnecessary downtime.

RLSA-2026:21756: Important: flatpak security update
RLSA-2026:21700: Important: cockpit security update
RXSA-2024:3138: Moderate: kernel security, bug fix, and enhancement update
RLSA-2025:11884: Important: unbound security update
RLSA-2024:8834: Important: python-gevent security update
RLBA-2025:0736: dnssec-trigger bug fix update
RLBA-2024:3238: shim bug fix and enhancement update
RLBA-2024:6979: stunnel bug fix update
RLSA-2026:18480: Important: linux-sgx security update
RLSA-2026:18344: Moderate: mingw-glib2 security update
RLSA-2026:19151: Important: jq security update
RLSA-2026:18162: Moderate: iputils security update
RLSA-2026:19155: Important: python-markdown security update
RLSA-2026:18153: Moderate: systemd security update
RLSA-2026:19054: Important: tomcat security update
RLSA-2026:19022: Important: golang security update
RLSA-2026:19042: Low: python-jwcrypto security update
RLSA-2026:18142: Low: NetworkManager security update
RLSA-2026:19020: Moderate: crun security update
RLSA-2026:19034: Moderate: python-tornado security update
RLSA-2026:19024: Important: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update
RLSA-2026:18465: Important: edk2 security update

Rocky Linux 922 Published by Philipp Esselbach 0

Rocky Linux 9.8 drops today and pushes existing nine.x systems forward with a straightforward dnf upgrade while demanding fresh installs for anyone still running version eight. The release leans heavily into cryptographic readiness, shipping OpenSSH 9.9, post-quantum algorithm support in GnuTLS and p11-kit, and automated LUKS volume encryption through Clevis. Kernel updates bring sharper performance tracing, broader hardware driver coverage, and more reliable crash dumps for encrypted storage, while the developer stack jumps to GCC 15, Rust 1.92, Go 1.26, and modern database streams like PostgreSQL 18 and MariaDB 11.8. Administrators should verify third-party module compatibility before applying the update and retire any deprecated application streams that just lost their security patches.

Rocky Linux 922 Published by Philipp Esselbach 0

Rocky Linux just pushed out a fresh wave of security advisories that cover both version eight and version nine systems. You will find patches for widely used packages ranging from several .NET framework releases to essential networking tools like BIND and QEMU KVM. Each advisory includes detailed CVSS ratings so system administrators can quickly gauge the threat level before deploying the fixes. Applying these updates promptly keeps your server environment secure while maintaining compatibility with existing workflows.

RLSA-2026:21295: Important: .NET 10.0 security update
RLSA-2026:20586: Important: thunderbird security update
RLSA-2026:21294: Important: .NET 9.0 security update
RLSA-2026:20929: Moderate: libexif security update
RLSA-2026:21382: Important: firefox security update
RLSA-2026:20589: Important: dnsmasq security update
RLSA-2026:21291: Important: .NET 8.0 security update
RLSA-2026:20585: Important: compat-libtiff3 security update
RLSA-2026:20611: Important: gnutls security update
RLSA-2026:20587: Moderate: glibc security update
RLSA-2026:20579: Moderate: freeipmi security update
RLSA-2026:19167: Important: pcs security update
RLSA-2026:18705: Moderate: mingw-glib2 security update
RLSA-2026:19365: Important: jq security update
RLSA-2026:19366: Important: python-markdown security update
RLSA-2026:18824: Moderate: luksmeta security update
RLSA-2026:18786: Important: bind security update
RLSA-2026:18931: Moderate: unbound security update
RLSA-2026:18597: Low: NetworkManager security update
RLSA-2026:18772: Moderate: qemu-kvm security update

Rocky Linux 922 Published by Philipp Esselbach 0

Rocky Linux 8 just released three important security patches for the main kernel, real-time kernel, and Firefox browser. Teams can check the CVSS severity ratings attached to each vulnerability to figure out which systems need immediate attention. The official errata pages link straight to detailed CVE reports so engineers can review the exact technical flaws before rolling anything out.

RLSA-2026:19664: Important: kernel-rt security update
RLSA-2026:19588: Important: firefox security update
RLSA-2026:19666: Important: kernel security update

Rocky Linux 922 Published by Philipp Esselbach 0

A batch of security advisories covers numerous system packages that require immediate attention from administrators. Most of these patches carry an important or moderate rating, but one stands out as critical for the cockpit management tool. The updates also address vulnerabilities in essential utilities like the Linux kernel, OpenSSH, image builder software, and several database or development libraries. You should apply the cockpit fix right away because it blocks unauthenticated remote code execution triggered by SSH command arguments.

RXSA-2026:3488: Moderate: kernel security update
RXSA-2025:4341: Important: kernel security update
RXSA-2026:13565: Important: kernel security update
RXSA-2026:13577: Important: kernel security update
RLSA-2026:4649: Moderate: grub2 security update
RLSA-2026:13643: Important: osbuild-composer security update
RLSA-2026:9693: Important: java-25-openjdk security update
RLSA-2026:13642: Important: image-builder security update
RLSA-2026:4162: Moderate: mysql8.4 security update
RLSA-2026:3840: Important: image-builder security update
RLSA-2026:6463: Important: openssh security update
RLSA-2026:13380: Important: openssh security update
RLSA-2026:1838: Moderate: image-builder security update
RLSA-2026:13651: Moderate: systemd security update
RLSA-2026:1837: Moderate: osbuild-composer security update
RLSA-2025:20126: Moderate: openssh security update
RLSA-2025:21015: Moderate: vim security update
RLSA-2025:23479: Moderate: openssh security update
RLSA-2026:3752: Important: osbuild-composer security update
RLSA-2026:7383: Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection

Rocky Linux 922 Published by Philipp Esselbach 0

Rocky Linux 9 users should install two new security patches as soon as possible. The first one tackles several issues in PackageKit, while the second update fixes vulnerabilities inside openexr. Each package comes with a CVSS score so you can quickly see how severe each problem actually is.

RLSA-2026:19354: Important: PackageKit security update
RLSA-2026:19359: Important: openexr security update

Rocky Linux 922 Published by Philipp Esselbach 0

Rocky Linux administrators should apply several new security patches that address vulnerabilities across both versions 9 and 10 of the operating system. The most urgent fix targets nginx with a critical rating, while other important updates cover ruby, firefox, grafana, and several supporting libraries like libcap and LibRaw. Moderate severity patches are also available for essential tools such as freeipmi, crun, gdk-pixbuf2, and libpng to ensure broader system stability. Each advisory includes detailed Common Vulnerability Scoring System ratings so administrators can prioritize installations based on their specific environment needs.

RLSA-2026:18064: Moderate: libpng security update
RLSA-2026:18063: Critical: nginx security update
RLSA-2026:18065: Important: ruby security update
RLSA-2026:18039: Important: ruby security update
RLSA-2026:18028: Moderate: libpng security update
RLSA-2026:18030: Important: ruby:3.3 security update
RLSA-2026:19184: Important: grafana-pcp security update
RLSA-2026:19346: Important: libcap security update
RLSA-2026:19345: Important: LibRaw security update
RLSA-2026:19185: Important: grafana security update
RLSA-2026:19208: Moderate: freeipmi security update
RLSA-2026:19201: Important: firefox security update
RLSA-2026:19178: Moderate: crun security update
RLSA-2026:19210: Important: gdk-pixbuf2 security update

Rocky Linux 922 Published by Philipp Esselbach 0

Rocky Linux 9 received an important security update that patches multiple vulnerabilities in Ruby 3.3, specifically targeting the mysql2 gem. Administrators managing Rocky Linux 8 must apply a critical patch for Nginx version 1.24 to address similar risks. The official errata pages provide detailed CVSS ratings for every identified flaw so teams can prioritize their response effectively. System owners should install these updates immediately to maintain proper server hardening across both distributions.

RLSA-2026:18030: Important: ruby:3.3 security update
RLSA-2026:18041: Critical: nginx:1.24 security update

Rocky Linux 922 Published by Philipp Esselbach 0

Recent errata notices highlight several critical security patches for Rocky Linux systems running versions 8 through 10. Administrators managing these environments should prioritize the updated packages because they address significant vulnerabilities in tools like jq, the main kernel, and gimp. The documentation also outlines moderate updates for applications such as freerdp alongside essential infrastructure components including git-lfs and krb5.

RLSA-2026:16692: Important: jq security update
RLSA-2026:16062: Important: kernel security update
RLSA-2026:16693: Important: jq security update
RLSA-2026:16206: Important: kernel security update
RLSA-2026:16484: Important: gimp security update
RLSA-2026:16482: Moderate: freerdp security update
RLSA-2026:16196: Important: kernel-rt security update
RLSA-2026:16252: Important: jq security update
RLSA-2026:17533: Important: gimp:2.8 security update
RLSA-2026:16875: Important: git-lfs security update
RLSA-2026:16195: Important: kernel security update
RLSA-2026:16799: Important: krb5 security update

Rocky Linux 922 Published by Philipp Esselbach 0

Rocky Linux administrators should apply several new security patches that address vulnerabilities across multiple software packages. The updates target versions 8, 9, and 10 of the operating system while covering essential libraries and applications like freerdp, libtiff, glib2, libsoup3, openexr, and thunderbird. Severity levels for these fixes range from moderate to important, with detailed CVSS scores provided in the official errata documentation. System owners need to review the specific CVE listings before deploying the patches to ensure their environments remain protected against known exploits.

RLSA-2026:16019: Moderate: freerdp security update
RLSA-2026:16055: Important: libtiff security update
RLSA-2026:15953: Moderate: glib2 security update
RLSA-2026:15968: Moderate: libsoup3 security update
RLSA-2026:15969: Moderate: glib2 security update
RLSA-2026:15888: Important: openexr security update
RLSA-2026:16014: Moderate: freerdp security update
RLSA-2026:15887: Important: openexr security update
RLSA-2026:15971: Moderate: glib2 security update
RLSA-2026:15892: Important: thunderbird security update

Rocky Linux 922 Published by Philipp Esselbach 0

Rocky Linux administrators need to deploy four new security patches that address vulnerabilities across several core libraries. The most critical update targets mingw-libtiff on version eight of the operating system, while two separate moderate fixes resolve libpng flaws for releases nine and ten respectively. A fourth patch handles freeipmi issues within the Rocky Linux nine environment. Each advisory includes detailed CVSS ratings so teams can prioritize deployment based on actual risk levels.

RLSA-2026:14929: Important: mingw-libtiff security update
RLSA-2026:14790: Moderate: libpng security update
RLSA-2026:14791: Moderate: libpng security update
RLSA-2026:14819: Moderate: freeipmi security update

Rocky Linux 922 Published by Philipp Esselbach 0

Rocky Linux administrators need to apply two urgent security patches right away. The first addresses a git-lfs flaw in version nine, while the second tackles CopyFail, a severe kernel vulnerability that allows unprivileged users to escalate directly to root access. This memory-based exploit completely bypasses traditional file integrity monitoring tools and requires no special privileges to run. Simply refresh your package metadata, update all kernel packages, and restart your machines across supported releases to stay safe.

RLSA-2026:14200: Important: git-lfs security update
CopyFail (CVE-2026-31431): Patches Now Available for Rocky Linux

Rocky Linux 922 Published by Philipp Esselbach 0

Rocky Linux administrators need to install multiple security patches right away since these updates fix serious flaws across versions eight through ten. You will find fixes for thunderbird, dovecot, and fence-agents alongside important library upgrades for libsoup and resource-agents. Every single advisory includes a CVSS rating that helps your team prioritize which vulnerabilities demand immediate attention.

RLSA-2026:13902: Important: resource-agents security update
RLSA-2026:13537: Important: thunderbird security update
RLSA-2026:13414: Important: tigervnc security update
RLSA-2026:13830: Important: dovecot security update
RLSA-2026:14087: Moderate: libsoup security update
RLSA-2026:13916: Important: fence-agents security update
RLSA-2026:12285: Important: thunderbird security update
RLSA-2026:13978: Moderate: libsoup security update
RLSA-2026:13857: Important: dovecot security update
RLSA-2026:13917: Important: fence-agents security update

Rocky Linux 922 Published by Philipp Esselbach 0

Rocky Linux administrators must install several new security patches that fix vulnerabilities across versions 8 through 10. These updates cover critical software including the kernel, OpenSSH, Grafana, Go toolsets, and corosync while carrying moderate or important severity ratings. You can find detailed CVSS base scores for every listed vulnerability by visiting the official errata links provided in each advisory. Delaying these installations leaves your infrastructure open to known exploits that might disrupt daily operations or expose sensitive information.

RLSA-2026:13673: Moderate: corosync security update
RLSA-2026:13672: Important: fence-agents security update
RLSA-2026:13670: Moderate: python-tornado security update
RLSA-2026:13284: Important: LibRaw security update
RLSA-2026:13657: Moderate: corosync security update
RLSA-2026:13285: Important: libcap security update
RLSA-2026:13383: Important: openssh security update
RLSA-2026:13641: Moderate: python-tornado security update
RLSA-2026:13644: Moderate: corosync security update
RLSA-2026:13566: Important: kernel security update
RLSA-2026:13498: Important: dovecot security update
RLSA-2026:11712: Important: grafana security update
RLSA-2026:13515: Moderate: freeipmi security update
RLSA-2026:11881: Important: grafana-pcp security update
RLSA-2026:10217: Important: golang security update
RLSA-2026:11711: Important: grafana security update
RLSA-2026:13565: Important: kernel security update
RLSA-2026:10219: Important: golang security update
RLSA-2026:11704: Important: grafana-pcp security update
RLSA-2026:13578: Important: kernel-rt security update
RLSA-2026:11507: Important: grafana security update
RLSA-2026:10704: Important: go-toolset:rhel8 security update
RLSA-2026:11514: Important: grafana-pcp security update
RLSA-2026:13577: Important: kernel security update