Liquorix Linux Kernel 7.0.17 has arrived, bringing a fresh upstream sync, hardware hardening updates like KFENCE, and new default configurations for memory hotplug and USB gadgets to the popular low-latency enthusiast kernel. Maintained by Steven Barrett, the project continues to push 1,000Hz scheduling, hard kernel preemption, and its custom PDS scheduler to optimize system responsiveness for gaming and audio/video production workloads. The update includes aggressive block layer tunables and a shift to the med_power_with_dipm SATA power policy, though users should be aware of occasional video playback freezes and NVIDIA driver build issues on specific hardware.
Ubuntu released a major kernel security patch on July 1, 2026, addressing dozens of critical flaws such as Dirty Frag and Fragnesia. The update targets every active Ubuntu line, ranging from the 20.04 LTS maintenance builds to the latest 26.04 LTS release, while also covering cloud-specific kernels for AWS, Azure, GCP, and Oracle infrastructure.
[USN-8489-1] Linux kernel (OEM) vulnerabilities
[USN-8488-1] Linux kernel vulnerabilities
[USN-8490-1] Linux kernel vulnerabilities
[USN-8491-1] Linux kernel (OEM) vulnerabilities
[USN-8493-1] Linux kernel vulnerabilities
[USN-8492-1] Linux kernel vulnerabilities
[USN-8489-1] Linux kernel (OEM) vulnerabilities
[USN-8488-1] Linux kernel vulnerabilities
[USN-8490-1] Linux kernel vulnerabilities
[USN-8491-1] Linux kernel (OEM) vulnerabilities
[USN-8493-1] Linux kernel vulnerabilities
[USN-8492-1] Linux kernel vulnerabilities
Ubuntu released security patches to address critical flaws in Roundcube Webmail, libyang, HPLIP, libssh2, GD.pm, tar, Ruby, and curl. Attackers could exploit these bugs to run unauthorized commands, steal session cookies, bypass TLS encryption, or crash services through specially crafted files and network traffic. The updates cover Ubuntu releases from 14.04 LTS all the way to 26.04 LTS, with Extended Security Maintenance packages handling older versions.
[USN-8482-1] Roundcube Webmail vulnerability
[USN-8485-1] libyang vulnerability
[USN-8483-1] HPLIP vulnerabilities
[USN-8486-1] libssh2 vulnerabilities
[USN-8484-1] GD.pm vulnerability
[USN-8477-1] tar vulnerability
[USN-8478-1] Ruby vulnerabilities
[USN-8487-1] curl vulnerabilities
[USN-8482-1] Roundcube Webmail vulnerability
[USN-8485-1] libyang vulnerability
[USN-8483-1] HPLIP vulnerabilities
[USN-8486-1] libssh2 vulnerabilities
[USN-8484-1] GD.pm vulnerability
[USN-8477-1] tar vulnerability
[USN-8478-1] Ruby vulnerabilities
[USN-8487-1] curl vulnerabilities
Ubuntu issued USN-8412-3 to resolve a QEMU regression on Ubuntu 20.04 LTS that blocked boot volume creation from qcow2 images following an incomplete CVE-2024-4467 patch. USN-8481-1 corrects a Network Security Service parsing error that could crash software or expose sensitive data when processing malformed PKCS#11 URI escape sequences across four supported releases. USN-8480-1 fixes memory handling flaws in SQLite’s FTS5 extension that attackers could trigger for denial of service or arbitrary code execution on the same Ubuntu versions. USN-8479-1 patches two libheif vulnerabilities in Ubuntu 25.10 and 26.04 LTS that allow denial of service or code execution through malicious HEIF image files.
[USN-8412-3] QEMU regression
[USN-8481-1] NSS vulnerability
[USN-8480-1] SQLite vulnerabilities
[USN-8479-1] libheif vulnerabilities
[USN-8412-3] QEMU regression
[USN-8481-1] NSS vulnerability
[USN-8480-1] SQLite vulnerabilities
[USN-8479-1] libheif vulnerabilities
XanMod has released three fresh kernel builds, rounding out its maintenance cycle with 7.1.2-xanmod1, 7.0.14-xanmod1, and 6.18.37-xanmod1 LTS. The packages bundle essential upstream maintenance including virtiofs use-after-free patches, Rose networking cleanup, and bnxt_re memory safety fixes. Alongside the upstream work, XanMod continues shipping its custom performance stack featuring LLVM ThinLTO compilation, default BBRv3 congestion control, Cloudflare TCP patches, and dedicated Steam Deck and AMD 3D V-Cache modules. Debian and Ubuntu users can upgrade across four x86_64 ABI tiers, with the LTS branch offering a dedicated PREEMPT_RT variant for ultra-low latency workloads.
Ubuntu released a series of security notices to address multiple critical flaws across several widely used software packages. The updates patch dangerous memory corruption issues in ImageMagick and containerd, fix HTTP header parsing errors in cpp-httplib and Apache MINA, and resolve authentication bypasses in xrdp and NSD. Additional notices cover cryptographic key prediction risks in node-pbkdf2 and side-channel data leakage vulnerabilities affecting AMD Zen processors.
[USN-8470-1] cpp-httplib vulnerability
[USN-8468-1] ImageMagick vulnerabilities
[USN-8474-1] NSD vulnerabilities
[USN-8452-1] pbkdf2 vulnerability
[USN-8472-1] containerd vulnerabilities
[USN-8465-1] Apache MINA vulnerabilities
[USN-8473-1] containerd-stable vulnerabilities
[USN-8471-1] containerd vulnerabilities
[USN-8476-1] xrdp vulnerabilities
[USN-8475-1] AMD Microcode vulnerabilities
[USN-8470-1] cpp-httplib vulnerability
[USN-8468-1] ImageMagick vulnerabilities
[USN-8474-1] NSD vulnerabilities
[USN-8452-1] pbkdf2 vulnerability
[USN-8472-1] containerd vulnerabilities
[USN-8465-1] Apache MINA vulnerabilities
[USN-8473-1] containerd-stable vulnerabilities
[USN-8471-1] containerd vulnerabilities
[USN-8476-1] xrdp vulnerabilities
[USN-8475-1] AMD Microcode vulnerabilities
Liquorix Kernel 7.0.15 is live, built on the Linux 7.0.13 base to deliver targeted latency improvements and a critical hard freeze fix. The release abandons the mq-deadline block scheduler in favor of kyber and bfq, while cutting CPU timeslices down to 2ms for tighter interactivity. Liquorix also disables split-lock detection and adjusts virtual memory watermarks to smooth out latency spikes during demanding workloads. You can grab the updated kernel immediately using their automated curl installer, which pushes fresh binaries to Debian, Ubuntu, and Archl Linux within hours of the release.
Ubuntu released security updates for MySQL, libxml2, Perl, and FFmpeg. These fixes address serious bugs that let unauthenticated attackers crash databases or run malicious code by exploiting TLS handling, XML parsing errors, symlink manipulation, and memory management issues across multiple affected packages. libxml2 crashes remain a risk on 22.04 and 24.04 systems, where that DTD parsing bug might feel buried in the logs but can still let code slip through. Older Perl installations still need the Archive::Tar and regex patches to prevent file overwrites or heap overflows, and running a standard system update now closes these doors before remote exploitation becomes possible.
[USN-8457-2] MySQL vulnerabilities
[USN-8456-1] libxml2 vulnerability
[USN-8467-1] Perl vulnerabilities
[USN-8466-1] Perl DBI module vulnerabilities
[USN-8469-1] FFmpeg vulnerabilities
[USN-8457-2] MySQL vulnerabilities
[USN-8456-1] libxml2 vulnerability
[USN-8467-1] Perl vulnerabilities
[USN-8466-1] Perl DBI module vulnerabilities
[USN-8469-1] FFmpeg vulnerabilities
Ubuntu pushed out fresh security patches. Admins running Ubuntu 22.04 through 26.04 need to grab the libvncserver bump to 0.9.15+dfsg to plug CVE-2020-29260 and the trio of 2026 exploits that wreck Tight encoding handlers, while the libnfs fix stops a string length bug from spawning arbitrary code on remote mounts. On top of that, you'll want to run a standard system upgrade to clear the backlog, though keep in mind that patches for those older boxes from 14.04 up to 20.04 now require Ubuntu Pro to stay current.
[USN-8463-1] LibVNCServer vulnerabilities
[USN-8464-1] LIBNFS vulnerability
[USN-8193-2] libcap vulnerability
[USN-8463-1] LibVNCServer vulnerabilities
[USN-8464-1] LIBNFS vulnerability
[USN-8193-2] libcap vulnerability
Ubuntu released a comprehensive set of security notices that address numerous critical vulnerabilities across widely used infrastructure software and multiple LTS releases. The updates specifically target flaws in Netatalk, nginx, HAProxy, MySQL, and the Google Guest Agent, which could otherwise allow attackers to bypass authentication, execute arbitrary code, or trigger denial of service conditions. System administrators must also patch several heavily modified Linux kernels for Oracle, Azure, and Intel IoT platforms where logic errors and memory corruption bugs create serious risks for privilege escalation and container escapes.
[USN-8455-1] Netatalk vulnerabilities
[USN-8458-1] nginx vulnerabilities
[USN-8459-1] HAProxy vulnerabilities
[USN-8457-1] MySQL vulnerabilities
[USN-8447-3] Google Guest Agent vulnerabilities
[USN-8462-1] Linux kernel (Oracle) vulnerabilities
[USN-8388-2] Linux kernel vulnerabilities
[USN-8461-1] Linux kernel (Azure) vulnerabilities
[USN-8460-1] libxml2 vulnerabilities
[USN-8455-1] Netatalk vulnerabilities
[USN-8458-1] nginx vulnerabilities
[USN-8459-1] HAProxy vulnerabilities
[USN-8457-1] MySQL vulnerabilities
[USN-8447-3] Google Guest Agent vulnerabilities
[USN-8462-1] Linux kernel (Oracle) vulnerabilities
[USN-8388-2] Linux kernel vulnerabilities
[USN-8461-1] Linux kernel (Azure) vulnerabilities
[USN-8460-1] libxml2 vulnerabilities
The Liquorix kernel 7.0-14 update tightens the scheduler and wakelist logic to deliver more consistent frame times for gaming and audio workloads. By reintroducing PSI support for Project-C and refining CPU masking routines, the release targets the exact paths that cause context switch stutter on interactive desktops. Users can deploy the changes quickly through the official one-line installer script, which safely handles repository setup and leaves the previous kernel as a fallback. Testing the new build on live audio sessions or benchmark runs will quickly reveal whether the scheduler tweaks match specific hardware quirks.
XanMod just pushed out kernels 6.18.36 LTS, 7.0.13, and 7.1.1 for Debian and Ubuntu, packing in LLVM ThinLTO optimizations and default BBRv3 network handling. The update also adds targeted hardware patches like AMD 3D V-Cache support and Steam Deck sensor drivers to improve real-world responsiveness. Anyone running NVIDIA graphics, OpenZFS, or VMware should verify dkms compatibility first, since proprietary modules frequently break during rapid kernel shifts. Official repositories make the upgrade straightforward, and the GPLv2 license keeps the entire build process fully transparent for tinkerers.
Ubuntu released a batch of security notices to patch multiple critical flaws across several widely used software packages. The updates address serious issues in ldns, Tomcat, libheif, Vim, Net::CIDR::Lite, and LXD that could allow remote attackers to execute arbitrary code or trigger denial of service attacks. These vulnerabilities impact a wide range of Ubuntu releases from the older 14.04 LTS version all the way up to the latest 26.04 LTS release.
[USN-8449-1] ldns vulnerability
[USN-8450-1] Tomcat vulnerabilities
[USN-8454-1] libheif vulnerabilities
[USN-8451-1] Vim vulnerabilities
[USN-8453-1] Net::CIDR::Lite vulnerabilities
[USN-8447-2] LXD vulnerabilities
[USN-8449-1] ldns vulnerability
[USN-8450-1] Tomcat vulnerabilities
[USN-8454-1] libheif vulnerabilities
[USN-8451-1] Vim vulnerabilities
[USN-8453-1] Net::CIDR::Lite vulnerabilities
[USN-8447-2] LXD vulnerabilities
Ubuntu released a major batch of security notices to address critical vulnerabilities across the Linux kernel and several widely used software packages. Attackers could exploit these flaws to escalate privileges, execute arbitrary code remotely, or trigger denial of service attacks on affected systems running from Ubuntu 16.04 through 26.04 LTS. The updates specifically target weaknesses in packet socket handling, cryptographic module operations, SSH key validation, and media parsing routines within tools like GStreamer and kitty. System administrators should apply the recommended package upgrades immediately and reboot their machines to ensure all kernel changes take effect properly.
[USN-8361-3] Linux kernel vulnerability
[USN-8441-1] Linux kernel vulnerabilities
[USN-8390-2] Linux kernel vulnerability
[USN-8447-1] Go Cryptography vulnerabilities
[USN-8445-1] Config-IniFiles vulnerability
[USN-8446-1] GStreamer Bad Plugins vulnerabilities
[USN-8443-1] web.py vulnerability
[USN-8444-1] Graphite vulnerability
[USN-8425-1] njs vulnerability
[USN-8448-1] Dolibarr vulnerability
[USN-8442-1] kitty vulnerabilities
[USN-8361-3] Linux kernel vulnerability
[USN-8441-1] Linux kernel vulnerabilities
[USN-8390-2] Linux kernel vulnerability
[USN-8447-1] Go Cryptography vulnerabilities
[USN-8445-1] Config-IniFiles vulnerability
[USN-8446-1] GStreamer Bad Plugins vulnerabilities
[USN-8443-1] web.py vulnerability
[USN-8444-1] Graphite vulnerability
[USN-8425-1] njs vulnerability
[USN-8448-1] Dolibarr vulnerability
[USN-8442-1] kitty vulnerabilities
Ubuntu released a batch of security notices that address multiple critical flaws across widely used software packages including Ruby FreeRDP rsync and the Linux kernel. Remote and local attackers might leverage these flaws to bypass authentication controls or trigger system crashes that lead to denial of service conditions. The updates specifically target older LTS releases alongside recent distributions and require administrators to apply standard system upgrades followed by necessary reboots or daemon restarts. Organizations running cloud infrastructure or web proxy services should prioritize these patches immediately to prevent unauthorized access and maintain system integrity.
[USN-8431-1] Ruby vulnerabilities
[USN-8432-1] FreeRDP vulnerabilities
[USN-8349-3] rsync regression
[USN-8437-1] rabbitmq-c vulnerabilities
[USN-8435-1] Squid vulnerabilities
[USN-8436-1] ca-certificates update
[USN-8434-1] Nova vulnerability
[USN-8438-1] OpenImageIO vulnerabilities
[USN-8440-1] Linux kernel (Azure) vulnerabilities
[USN-8426-2] Linux kernel (Azure) vulnerabilities
[USN-8412-2] QEMU regression
[USN-8433-1] OpenStack Keystone vulnerabilities
[USN-8439-1] Linux kernel (Oracle) vulnerabilities
[USN-8431-1] Ruby vulnerabilities
[USN-8432-1] FreeRDP vulnerabilities
[USN-8349-3] rsync regression
[USN-8437-1] rabbitmq-c vulnerabilities
[USN-8435-1] Squid vulnerabilities
[USN-8436-1] ca-certificates update
[USN-8434-1] Nova vulnerability
[USN-8438-1] OpenImageIO vulnerabilities
[USN-8440-1] Linux kernel (Azure) vulnerabilities
[USN-8426-2] Linux kernel (Azure) vulnerabilities
[USN-8412-2] QEMU regression
[USN-8433-1] OpenStack Keystone vulnerabilities
[USN-8439-1] Linux kernel (Oracle) vulnerabilities
Ubuntu issued a series of security notices to patch critical flaws across several widely deployed software packages. The updates resolve a CUPS printing regression that triggered unexpected crashes alongside multiple vulnerabilities in nginx, tmux, Mesa, FastNetMon and ADSys. Remote attackers could exploit these weaknesses to crash services or execute arbitrary code on vulnerable machines. Administrators should run standard system upgrades right away since most patches apply automatically while a few packages require a quick service restart to take effect.
[USN-8405-2] CUPS regression
[USN-8398-3] nginx vulnerability
[USN-8428-1] tmux vulnerability
[USN-8427-1] Mesa vulnerability
[USN-8429-1] FastNetMon vulnerabilities
[USN-8430-1] ADSys vulnerabilities
[USN-8405-2] CUPS regression
[USN-8398-3] nginx vulnerability
[USN-8428-1] tmux vulnerability
[USN-8427-1] Mesa vulnerability
[USN-8429-1] FastNetMon vulnerabilities
[USN-8430-1] ADSys vulnerabilities
Ubuntu has released urgent security patches for multiple LTS distributions to address critical flaws in the Apache HTTP Server and GStreamer Base Plugins. The Apache update resolves four distinct CVEs that could allow local or remote attackers to crash services, steal sensitive data, or execute malicious code through compromised modules like mod_rewrite and mod_proxy_ajp. Meanwhile the GStreamer fix targets a parsing error in AVI media handling that previously enabled denial of service attacks or arbitrary program execution on affected systems running Ubuntu 16.04 LTS. Administrators should apply these package updates immediately and restart the web server to ensure all security changes take effect across their infrastructure.
[USN-8396-1] Apache HTTP Server vulnerabilities
[USN-8130-3] GStreamer Base Plugins vulnerability
[USN-8396-1] Apache HTTP Server vulnerabilities
[USN-8130-3] GStreamer Base Plugins vulnerability
Ubuntu released a batch of security notices to address multiple critical vulnerabilities across its supported operating system versions. These patches cover a wide range of packages such as the .NET framework, OpenStack orchestration tools, cloud kernel drivers, lightweight network protocols, and password hashing libraries. Malicious users can leverage these design oversights to run unauthorized scripts or steal credentials by manipulating file paths and network packet handlers. System administrators should apply the recommended package upgrades immediately since a standard update routine will automatically resolve most of these issues without manual intervention.
[USN-8418-1] Crypt-SaltedHash vulnerability
[USN-8421-1] Ironic vulnerabilities
[USN-8426-1] Linux kernel (Azure) vulnerabilities
[USN-8423-1] lwIP vulnerabilities
[USN-8420-1] .NET vulnerabilities
[USN-8424-1] Ubuntu Kylin Software Center vulnerability
[USN-8422-1] Mistral vulnerability
[USN-8418-1] Crypt-SaltedHash vulnerability
[USN-8421-1] Ironic vulnerabilities
[USN-8426-1] Linux kernel (Azure) vulnerabilities
[USN-8423-1] lwIP vulnerabilities
[USN-8420-1] .NET vulnerabilities
[USN-8424-1] Ubuntu Kylin Software Center vulnerability
[USN-8422-1] Mistral vulnerability
Ubuntu administrators need to install urgent security updates released this week to shield their infrastructure from multiple critical flaws across several popular software packages. The Tomcat patch alone addresses six separate vulnerabilities that could trigger memory exhaustion attacks or allow malicious actors to bypass authentication controls entirely. Smaller notices also fix an Exim logging error while patching command execution risks in HTTP Daemon and denial of service crashes within uriparser. Organizations running Ubuntu 20.04 LTS must prioritize the Samba upgrade since it closes dangerous gaps in file access controls and domain controller security that could otherwise lead to unauthorized modifications or arbitrary code execution across their networks.
[USN-8417-1] Tomcat vulnerabilities
[USN-6455-2] Exim regression
[USN-8419-1] HTTP-Daemon vulnerability
[USN-8409-1] uriparser vulnerability
[USN-8306-2] Samba vulnerabilities
[USN-8417-1] Tomcat vulnerabilities
[USN-6455-2] Exim regression
[USN-8419-1] HTTP-Daemon vulnerability
[USN-8409-1] uriparser vulnerability
[USN-8306-2] Samba vulnerabilities
Ubuntu 25.10 reaches end of life on July 9, 2026, meaning security patches and official repository access will vanish for anyone who stays on the interim release. Users should migrate to Ubuntu 26.04 well before the cutoff to avoid broken dependencies and missing package updates. Running the standard upgrade tool early keeps the system stable and prevents the usual command line headaches that come with chasing dead repositories. Waiting until the last moment only guarantees a rushed migration and a potentially broken desktop environment.