Ubuntu released security notices USN-8626-1 and USN-8592-1 to address critical flaws in systemd and ImageMagick. The systemd patches resolve three vulnerabilities that could allow local attackers to escalate privileges, terminate privileged processes, or crash system services through improperly validated requests. The ImageMagick updates fix four separate issues involving malformed image handling, out-of-bounds heap writes, and integer overflows that could lead to arbitrary code execution or denial of service.
[USN-8626-1] systemd vulnerabilities
[USN-8592-1] ImageMagick vulnerabilities
XanMod released updated kernel builds today, introducing Linux 7.1.8-xanmod1 for the rolling mainline branch and Linux 6.18.44-xanmod1 for the long-term support line. The updates also include a real-time variant at 6.18.44-rt-xanmod1, featuring XanMod's custom optimizations such as LLVM ThinLTO compilation, AMD 3D V-Cache tuning, Cloudflare TCP Collapse, and native Steam Deck EC sensor support. Both branches incorporate extensive upstream fixes spanning graphics, networking, and security, with the LTS branch maintaining stability and support through December 2028. Users can install these builds via the XanMod APT repository across major Debian and Ubuntu derivatives, selecting from x86_64 ABI packages ranging from x64v1 to x64v3 to match their specific CPU generation.
Steven Barrett has released Liquorix Linux kernel 7.1-9, shifting focus from feature additions to stabilizing "Project-C,". The release bundles roughly eleven patches, including eight direct upstream syncs that align Project-C with current mainline scheduler development alongside Liquorix-specific hardening tweaks like default latency warning suppression. AMD64 users can install the kernel via the official script or distribution PPAs, though those with AMDGPU hardware should exercise caution as several open issues report hard freezes on integrated graphics. This point release marks a deliberate move toward upstream parity and maintenance consolidation after a rapid development sprint throughout the 7.1 series.
Liquorix kernel 7.1-8 just landed, tracking upstream Linux 7.1.6 and bringing enhanced ACS override support for GPU passthrough enthusiasts. Maintainer Steven Barrett shipped the build on August 4, continuing an aggressive four-day turnaround that mirrors upstream stable point releases. The update pulls in modern hardware support including NTFSPLUS, Apple Silicon power reporting for Asahi users, and Intel FRED enabled by default for Arrow Lake processors. You're getting the usual PDS-scheduling and 2ms timeslice tweaks that make Liquorix a favorite for gaming and low-latency workloads, though you should retest your drivers before rebooting.
XanMod just published two new performance kernels today: the flagship 7.1.6-xanmod1 and the long-term support track at 6.18.42-xanmod1. The 7.1 series finally makes multigenerational LRU and sched_ext defaults production-ready, while XanMod's out-of-tree patches bake in Google's BBRv3 congestion algorithm, Cloudflare TCP collapse processing, and a dedicated AMD 3D V-Cache optimizer. You can grab precompiled packages across four CPU architecture tiers from the official APT repository, alongside DKMS modules for NVIDIA, OpenZFS, VirtualBox, and VMware.
Debian and Ubuntu users pulling from DEB.SURY.ORG received a coordinated batch of PHP updates across all active branches, led by PHP 8.4.24 and the development release 8.5.9. The July 30 patch cycle addresses high-severity vulnerabilities including a BCMath out-of-bounds write and a PostgreSQL SQL injection via pg_query(), alongside significant opcache stability fixes for the JIT. This three-week gap from the previous release indicates an emergency response to newly disclosed critical CVEs, prompting SURY to push security-only updates to both current stable and end-of-life approaching branches. Operators should upgrade immediately via apt-get update and verify GPG signatures, though 8.5 users are advised to test carefully due to the heavy changes to the tracing JIT and default OpCache behavior.
Ubuntu released security notices USN-8620-4 and USN-8620-3 to patch multiple kernel flaws in the linux-intel-iotg and linux-intel-iot-realtime packages for Ubuntu 20.04 and 22.04 LTS systems. The advisories explicitly highlight an NTFS file system parsing flaw that enables out-of-bounds memory reads, alongside two AMD processor vulnerabilities involving speculative execution data leaks and operation cache isolation failures that could allow privilege escalation. Beyond these highlighted flaws, the updated kernels address hundreds of additional CVEs spanning networking stacks, storage drivers, cryptographic libraries, GPU and USB subsystems, and various hardware interfaces across ARM, x86, MIPS, PowerPC, and S390 architectures. Administrators must apply the package updates through their standard system upgrade tools, reboot their machines to activate the changes, and rebuild any third-party kernel modules due to an unavoidable ABI version shift.
[USN-8620-4] Linux kernel (Intel IoTG) vulnerabilities
[USN-8620-3] Linux kernel (Intel IoTG) vulnerabilities
Liquorix linux-liquorix 7.1-7 released on July 31, 2026, bringing a single focused packaging change: stripping out the irqbalance recommendation and disabling the service during installation. The kernel remains based on Linux 7.1.5, continuing a rapid 18-day sprint that has produced seven releases as the project aggressively converges scheduler logic with upstream mainline. Available now for Debian and Ubuntu on amd64, the update is the latest step in an enthusiast kernel built specifically for interactive responsiveness and gaming workloads over background automation.
Ubuntu published security notices covering four separate vulnerabilities across its long-term support releases. Ruby-sinatra requires an update to block remote denial of service attacks caused by malformed header parsing. Desktop environments need patches for a libinput privilege escalation flaw, while older Python installations must address resource exhaustion and HTML parser crashes. The OpenSSL update resolves the HollowByte memory allocation bug that enables network-based denial of service attacks, though Ubuntu 22.04 and newer users must reboot their machines to apply the changes.
[USN-8624-1] Sinatra vulnerability
[USN-8602-1] libinput vulnerability
[USN-8614-1] Python vulnerabilities
[USN-8625-1] OpenSSL vulnerability
XanMod Linux Kernel 6.18.41-xanmod1 arrived today and built on top of upstream Linux 6.18.41 LTS. The kernel compiles with LLVM ThinLTO across three x86-64 ABI tiers and applies a curated collection of performance patches, including Google BBRv3, AMD 3D V-Cache optimization, and Cloudflare TCP Collapse. This point release prioritizes stability by backporting Thomas Gleixner's fixes for posix-cpu-timers use-after-free vulnerabilities and timer arm callback validation. The 6.18 branch provides long-term support through December 2028 and bundles NVIDIA graphics drivers for both open and proprietary stacks.
Ubuntu released a batch of security notices to patch critical vulnerabilities across its Linux kernel variants for NVIDIA, IBM, Azure FIPS, Raspberry Pi, and KVM platforms. The updates fix logic flaws in networking subsystems like XFRM ESP-in-TCP alongside issues affecting storage drivers, file systems, and multiple processor architectures across Ubuntu versions ranging from 18.04 LTS to 26.04 LTS. Administrators must run a standard system upgrade followed by a manual reboot to fully apply the patches and activate the security fixes. Users relying on custom kernel modules will need to recompile those packages because the new version numbers reflect an unavoidable Application Binary Interface change.
[USN-8623-1] Linux kernel (NVIDIA) vulnerabilities
[USN-8622-1] Linux kernel (NVIDIA) vulnerabilities
[USN-8615-1] Linux kernel vulnerabilities
[USN-8616-1] Linux kernel (IBM) vulnerabilities
[USN-8620-2] Linux kernel (Azure FIPS) vulnerabilities
[USN-8547-2] Linux kernel (Azure FIPS) vulnerabilities
[USN-8615-2] Linux kernel (Raspberry Pi) vulnerabilities
[USN-8617-1] Linux kernel (KVM) vulnerabilities
Ubuntu released three security notices addressing vulnerabilities in Roc Toolkit, GNU C Library, and FreeIPMI across multiple LTS releases. The glibc update resolves seven flaws including heap buffer overflows in scanf functions and incorrect DNS response handling that could allow denial of service or arbitrary code execution; systems running Ubuntu 26.04, 24.04, and 22.04 LTS must reboot after applying the libc6 package update. Roc Toolkit requires a libroc0.4 update to fix a crash vector triggered by malformed WAV files, while the FreeIPMI patch corrects buffer overflow issues in IPMI OEM message processing that could enable local denial of service attacks on systems ranging from Ubuntu 14.04 LTS through 26.04 LTS.
[USN-8612-1] Roc Toolkit vulnerability
[USN-8611-1] GNU C Library vulnerabilities
[USN-8613-1] FreeIPMI vulnerabilities
Canonical has announced a new rolling virtualization Hardware Enablement stack for Ubuntu 26.04 LTS that upgrades QEMU, libvirt, EDK2, and SeaBIOS every six months for the first two years of the release cycle. The opt-in feature directly addresses the timing mismatch between fast-evolving CPU encryption standards like AMD SEV-SNP and Intel TDX and traditional two-year LTS update schedules. All virtualization components upgrade atomically through the ubuntu_virt_helper tool to prevent the inconsistent state mismatches that previously broke confidential workloads in production. The initiative aligns with AMD's newly revealed EPYC 9006 and Instinct MI455X hardware, positioning Ubuntu as a primary platform for regulated AI and sovereign cloud deployments.
Liquorix Linux Kernel 7.1-6 has arrived, merging upstream Linux Kernel 7.1.5 and rolling out targeted fixes to Steven Barrett’s custom Project-C scheduler. The update introduces auto-detection for heterogeneous CPU topologies, improving task placement on modern hybrid processors like Intel Meteor Lake and AMD Zen 4/5. Designed for gamers and multimedia creators, the AMD64-only build trades power efficiency and raw throughput for aggressive 1000Hz scheduling and lower input latency.
XanMod has released updated builds for its Mainline and LTS kernel branches, bringing the 7.1.5 and 6.18.40 upstream releases to Debian-based systems. The builds layer in LLVM ThinLTO compilation, Google BBRv3 congestion control, Cloudflare TCP collapse processing, and the AMD 3D V-Cache optimizer. Upstream security work takes center stage, closing critical ksmbd SMB server vulnerabilities, NTFS bounds-checking gaps, and a long-standing POSIX CPU timer use-after-free. Users can install via APT using psABI-matched packages, though NVIDIA DKMS driver compatibility should be verified before switching branches.
Ubuntu released a security update for Linux kernels on Azure and Azure FDE systems running Ubuntu 26.04 LTS, patching over five hundred vulnerabilities spanning networking, file systems, drivers, and hardware interfaces. The advisory specifically flags flaws in AMD processors that let local attackers leak sensitive data through speculative execution or escalate privileges via shared cache isolation failures on Zen 2 chips. System administrators should install the corrected kernel packages immediately and reboot their virtual machines, keeping in mind that new version numbers force a recompilation of all third-party kernel modules due to an ABI change.
[USN-8603-1] Linux kernel (Azure) vulnerabilities
UBports has officially released Ubuntu Touch OTA 2.0, a major update built on Ubuntu 24.04 LTS that brings the mobile OS into the modern era. The long-awaited Chromium 134 engine upgrade lands in Morph Browser to resolve historical web compatibility headaches, while notch avoidance and Widevine DRM support round out the feature set. New hardware support now includes the Zinwa Q25 alongside existing Fairphone, Volla, and Xiaomi devices. Users can install the new software via System Settings, though a mandatory two-step migration ensures a smooth transition across supported handsets.
Ubuntu issued security notices covering vulnerabilities in Exim, tar, Kerberos, GStreamer, HTML-Parser, libgphoto2, GIFLIB, Apache HTTP Server, gawk, libarchive, and aiohttp across multiple long-term support releases. Vulnerabilities in Exim allowed local privilege escalation and unauthorized file access, while weaknesses in Apache's mod_ldap and mod_auth_digest enabled remote attackers to execute arbitrary code or bypass digest authentication using timing attacks. Multiple packages received fixes for issues where crafted inputs caused crashes, denial of service, or arbitrary code execution in GIFLIB, aiohttp, GStreamer plugins, gawk, and libarchive, alongside potential sensitive data leaks in HTML-Parser and libgphoto2. A dedicated update resolves a regression in tar that broke extraction of archives with nonzero directory entry sizes, affecting Ubuntu versions from 14.04 through 26.04 LTS following an incomplete fix in a previous advisory.
[USN-8590-1] Exim vulnerabilities
[USN-8477-3] tar regression
[USN-8585-1] Kerberos vulnerabilities
[USN-8584-1] GStreamer Good Plugins vulnerabilities
[USN-8587-1] HTML-Parser vulnerability
[USN-8586-1] libgphoto2 vulnerabilities
[USN-8583-1] GIFLIB vulnerabilities
[USN-8589-1] Apache HTTP Server vulnerabilities
[USN-8588-1] Gawk vulnerabilities
[USN-8581-1] libarchive vulnerabilities
[USN-8591-1] AIOHTTP vulnerabilities