Today's Linux security roundup spans eight distros, from a Critical FreeIPA hole to Red Hat's 27-errata batch and hundreds of CVEs stuffed into the Debian and Ubuntu kernels. Debian's kernel update (6.12.111-1) runs from CVE-2024-52560 to CVE-2026-100079, while Ubuntu's Oracle 7.0 kernel (USN-8728-3) adds an ARM TLB race and an AMD Zen 2 flaw on top of 100+ more. The Criticals to patch first are the freeipa updates on AlmaLinux and Rocky Linux 10, the PostgreSQL 12 bump on Rocky Linux 8, and the RHEL for NVIDIA kernel (RHSA-2026:73187). Beyond kernels, watch Slackware's Firefox ESR build from roughly 43 CVEs, SUSE's near-critical 9.8-rated perl-DBI flaw, and Ubuntu's OpenSSL and Erlang fixes, though many older Ubuntu releases stay gated behind Ubuntu Pro.
Hundreds of CVEs pile into Debian and Ubuntu kernels, RHEL sends 27 errata
This daily roundup spans eight distros, from a Critical FreeIPA hole to a 27-errata batch from Red Hat and hundreds of CVEs stuffed into the Debian and Ubuntu kernels.
Vendors shipped updates for AlmaLinux, Debian, Fedora, RHEL, Rocky, Slackware, SUSE, and Ubuntu today, and a few carry the kind of severity that should pull you away from your coffee. The bulk landed between September 29 and 30. Debian and Ubuntu led with kernel piles that are hundreds of CVEs deep, while RHEL reissued the same patches more than once. Not all of it is worth a reboot, but three Criticals stand out.
Where the real severity sits
Debian's kernel update is the reason this day feels big. Advisory 6.12.111-1 covers privilege escalation, denial of service, and information leaks, and its CVE range runs from CVE-2024-52560 all the way up to CVE-2026-100079. That is a few hundred identifiers for a single advisory, and it makes the rest of the day look sparse.
Ubuntu capped off the day with a two-day stack of notices, and the kernel ones carry most of the weight. USN-8728-3 is the biggest single payload: the Oracle 7.0 kernel on 24.04 patches an ARM broadcast TLB invalidation race and an AMD Zen 2 operation cache flaw that enables privilege escalation, then lists well over a hundred more CVEs. It is not fully clear whether each applies to the Oracle flavor or whether Ubuntu is just pasting the upstream changelog wholesale. Update to 7.0.0-1011 and reboot.
The other five kernel USNs cover AWS, NVIDIA, GCP, and OEM builds across 22.04, 24.04, and 26.04. Every one flags an ABI change, so third-party modules need recompiling on top of the reboot.
Red Hat's batch is essentially a numbers game. Nearly everything sits at "Important," which quietly means "not a fire drill yet." Count the names and you still land on 27 errata, most reissuing the same patches across subscriptions, so freerdp, cjose, gdb, and gstreamer1-plugins-good each reappear more than once. The exception is RHSA-2026:73187, the kernel update for RHEL for NVIDIA, at Critical.
Apply it first and set the rest aside. Four advisories rate lower, at Moderate, covering two JBoss Apache HTTP Server refreshes and a pair of gawk bumps.
Two more Criticals you should not miss. Rocky Linux shipped nine erratas this round, with its PostgreSQL 12 bump (RLSA-2026:72274) landing as Critical on Rocky Linux 8. It drags along module twins pgaudit, pg_repack, and decoderbufs.
That same freeipa advisory (RLSA-2026:72279) is Critical for Rocky Linux 10, and AlmaLinux's own IdM update hits the Critical tier for version 10 as well. That one carries eight security fixes, including an unauthenticated LDAP hole that lets a client pull administrator credentials. If you run IdM, patch it before anything else.
The rest of the day
Debian's other two advisories, PCRE2 and libwebsockets, are smaller but not trivial, each opening a path to DoS or code execution. PCRE2 has no CVE number yet, which is odd for something this blunt, and libwebsockets fails on missing input validation in its hpack path parser. You'll want 10.46-1~deb13u3 and 4.3.5-1+deb13u3 respectively.
Fedora pushed eleven updates across 43 and 44 on September 30, and while most target niche libraries, flatpak-builder at 1.4.12 is the one to care about. It closes a CVE that let host code run through a malicious git am hook during patch extraction, so building flatpaks from untrusted sources is no longer a freebie. And the upstream changelog still says "Update to 0.4.12," a typo that clearly survived the upload. The rest is plain enough: perl-Imager, sngrep through 1.8.4, parted, libxmp, rootlesskit, and a thunderbird bump to 156.0, all grabbed by a single dnf upgrade.
Slackware's Firefox update is worth pausing for. It landed an ESR build at 140.17.0esr on the 15.0 track and 153.4.0esr on -current, built from Mozilla's MFSA2026-99, one of those heavy advisories stringing together roughly 43 CVEs. Mozilla's writeup stays vague with its usual "security fixes and improvements" phrasing, but a fix this broad almost always means several memory-safety bugs got patched, which is exactly where browser exploits live. Run a single upgradepkg as root if you are on the stable track.
SUSE and openSUSE split their batch into two cleanly. The Tumbleweed pieces are the usual monthly cleanup on GA media, covering jackson-core, jackson-databind, helm, flatpak, goose, and distribution-registry. The SUSE Linux Enterprise items carry more weight, and the one to act on first is perl-DBI (CVE-2026-78030). DBD::DBM doesn't validate the dbm_type or dbm_mldbm attributes and loads arbitrary modules as a result, so SUSE rated it important even though NVD scores it a near-critical 9.8.
cosign is the busiest announcement, bundling six CVEs around signature verification and the crypto/ssh library, and one is a verification bypass in the legacy bundle that lets someone slip past checks with a plain public key. The python310 and python311 updates both drop to point releases and fix the same five flaws, with the stack overflow (CVE-2026-9669) as the headline item.
Back in Ubuntu, the non-kernel fixes worth your time are OpenSSL (USN-8847-1) and Erlang (USN-8827-1). OpenSSL covers QUIC, DTLS, and timing side-channels, which bite your normal TLS traffic. Erlang is a sprawling pile of HTTP request smuggling, heap corruption, and TLS issues across roughly 19 CVEs. Dracut (USN-8828-1) is worth a glance, since a compromised DHCP server on your LAN could run code as root at boot.
One pattern worth keeping in mind: many Ubuntu versions are marked "Available with Ubuntu Pro." If your 14.04, 16.04, or 18.04 machines aren't on that program, most of these fixes simply aren't reachable. Run unattended-upgrades or patch by hand, and reboot wherever the notice asks.
If you only patch three things today, start with the Criticals: the FreeIPA updates on AlmaLinux and Rocky Linux 10, the PostgreSQL 12 bump on Rocky Linux 8, and the RHEL for NVIDIA kernel. The Debian and Ubuntu kernel piles are hundreds of CVEs that are hard to ignore even when the individual details blur together. Then hit the full RHEL errata list for anything touching your subscriptions, and head to the Ubuntu and SUSE announcement pages for the exact version bumps.
An Overview of the Updates
AlmaLinux
Three AlmaLinux security advisories went out on September 29, and the kernel package swept up the most CVEs. Together they cover one Critical and two Important severity releases across AlmaLinux 9 and 10.
The FreeIPA (AlmaLinux IdM) update is the Critical one, and it carries eight security fixes, which is a lot to dump on a single identity system in one go. Two are unauthenticated denial-of-service holes through unbounded request-body reads in the web endpoints, /ipa/i18n_messages and /ipa/migration/migration.py. Another lets an unauthenticated LDAP client pull administrator credentials via the self-managed-token ACI, and there is a stored XSS that runs arbitrary code from a crafted URL. Layer on a privilege escalation through krbCanonicalName, a TGS-obtaining impersonation across trusts, an unauthorized LDAP write hiding in trust-fetch-domains, and an idp-add eval() bug reachable before authorization. If you run IdM, this is the one to patch first.
The Ruby fix (AlmaLinux 10, Important) is a single issue in the resolv gem: crafted DNS responses cause uncontrolled memory growth that ends in a DoS. Quick win if your box resolves anything.
The kernel update (AlmaLinux 9, Important) is the longest tail with seventeen fixes. The DRM drivers do most of the work, with a cluster of amdgpu and Xe (Intel) issues covering out-of-bounds reads, stale pointers, integer overflows, and reference-counting mistakes. Networking shows up as well: PPPoE memory corruption, an IPVS DoS from stale memory, and a nf_queue bridge issue, plus an ivpu accelerator buffer-overflow check. The only non-security change bumps a MADVISE I/O size limit in AlmaLinux 9.
| Advisory ID | Component | OS | Severity | Released | Fixes |
|---|---|---|---|---|---|
| ALSA-2026:72279 | FreeIPA / IdM | AlmaLinux 10 | Critical | 2026-09-29 | 8 security, 8 bug/enhancement |
| ALSA-2026:72785 | Ruby (resolv gem) | AlmaLinux 10 | Important | 2026-09-29 | 1 security |
| ALSA-2026:71700 | Linux kernel | AlmaLinux 9 | Important | 2026-09-29 | 17 security, 1 bug/enhancement |
Debian GNU/Linux
Debian shipped three security advisories on September 29, and if you run trixie (the stable release) you'll want to apply all three. The standout is the Linux kernel update, fixed in 6.12.111-1. The CVE list is so long you can basically stop counting and just start trusting the patch, but underneath it all sit privilege escalation, denial of service, and information-leak flaws. The count runs from CVE-2024-52560 up to CVE-2026-100079, which is a lot for a single advisory and makes the rest of the week's news look sparse.
PCRE2, the regex library that shows up wherever text matching happens, carries a single out-of-bounds write flaw that could lead to denial of service or arbitrary code execution. Debian hasn't assigned it a CVE number yet, which is a bit odd for something this blunt. It's patched in 10.46-1~deb13u3.
libwebsockets has its own single problem, CVE-2026-19773, rooted in missing input validation in the hpack path header parser. Same result: denial of service or arbitrary code execution. Fixed in 4.3.5-1+deb13u3.
The housekeeping is straightforward, so go install the new versions and move on.
| Package | CVE(s) | Issue | Fixed version |
|---|---|---|---|
| linux | CVE-2024-52560 through CVE-2026-100079 (hundreds) | Privilege escalation, denial of service, information leaks | 6.12.111-1 |
| pcre2 | Not yet assigned | Out-of-bounds write (DoS or arbitrary code execution) | 10.46-1~deb13u3 |
| libwebsockets | CVE-2026-19773 | Missing input validation in hpack parser (DoS or arbitrary code execution) | 4.3.5-1+deb13u3 |
Fedora Linux
Fedora pushed a batch of eleven security updates across Fedora 43 and 44 on September 30, and this round leans on the usual offenders: memory corruption in a few niche libraries and a handful of denial-of-service holes aimed at tooling you'd only run if you lived in that world.
The one worth actually caring about is flatpak-builder, which jumps to 1.4.12. That shuts a CVE letting host code execute through a malicious git am hook during patch extraction, so anyone building flatpaks from untrusted sources should treat this as worth the reboot. A small aside: the upstream changelog for this release reads "Update to 0.4.12," a typo that clearly survived the upload.
perl-Imager takes the next hit with two fixes. It can misread a TGA color map as negative and hand back uninitialized palette data from paletted images, so what looks like dead air in the code is really a potential information leak. If you deal with SIP traffic at all, sngrep through 1.8.4 had a stack buffer overflow that malformed SIP headers could trigger, now patched on both releases.
parted, the partition tool, went through more changes than usual. It got patched for 32-bit buffer overflows and FAT metadata handling, wrapping up two CVEs along the way. libxmp, the library that plays everything from Protracker MODs to Impulse Tracker files, picked up a medium-rated fix, which is reassuring until you remember how many retro tracker apps still lean on it.
rootlesskit closed out the batch with two SSH-related denial-of-service CVEs passed through the Go crypto library, and thunderbird quietly moved to 156.0 under a [SECURITY] tag without saying what the fix actually did. A single dnf upgrade picks all of this up if you've been letting things pile up.
| Package | Version | Fedora target | What's fixed |
|---|---|---|---|
| libxmp | 4.7.3 | 43 & 44 | Medium-rated security issue (upstream #1029) |
| thunderbird | 156.0 | 43 | Latest upstream bump, reason unspecified |
| rootlesskit | 3.2.0 | 43 & 44 | Two SSH DoS CVEs (CVE-2026-56855, CVE-2026-78662) |
| sngrep | 1.8.4 | 43 & 44 | Stack buffer overflow via SIP headers (CVE-2026-90558) |
| perl-Imager | 1.036 | 43 & 44 | Two CVEs: negative TGA color map and uninitialized palette leak |
| parted | 3.6 | 43 | 32-bit overflow fixes, FAT metadata handling, two CVEs |
| flatpak-builder | 1.4.12 | 44 | Host code execution via git am hook (CVE-2026-86320) |
Red Hat Enterprise Linux
Red Hat pushed a fresh wave of security advisories out the door, and if you count the names you land at 27 separate errata spanning kernel updates, OpenShift releases, and the utility libraries you'd rather not think about until one of them breaks.
The shape of the batch should feel familiar. Red Hat patched a few core packages, then reissued those same patches across several RHEL subscriptions, which is why freerdp, cjose, gdb, and gstreamer1-plugins-good each show up more than once. The per-package counts balloon faster than the actual number of distinct problems.
Nearly all of them sit at Red Hat's "Important" rating, the vendor's comfortable middle ground that quietly translates to "not a fire drill yet." Only the kernel update for RHEL for NVIDIA breaks that streak. RHSA-2026:73187 lands at Critical, so that's the one to set everything else aside and apply first. Four advisories rate lower, at Moderate. Those cover two JBoss Core Services Apache HTTP Server 2.4.62 Service Pack 6 refreshes and a pair of gawk bumps for RHEL 9 and 10.
Containers got plenty of attention too. Red Hat shipped new releases for OpenShift 4.20.40, 4.21.35, and 4.22.16, each mixing bug fixes with security work, plus a MicroShift 4.22.16 security refresh. The rest of the grab bag includes one-off updates for expat, thunderbird, and nodejs24.
| RHSA ID | Package | Rating | Target |
|---|---|---|---|
| RHSA-2026:73187 | kernel (security, bug fix, enhancement) | Critical | RHEL for NVIDIA |
| RHSA-2026:73076 | JBoss Core Services Apache HTTP Server 2.4.62 SP6 | Moderate | JBoss Core Services |
| RHSA-2026:73077 | JBoss Core Services Apache HTTP Server 2.4.62 SP6 | Moderate | JBoss Core Services |
| RHSA-2026:73512 | gawk | Moderate | RHEL 9 |
| RHSA-2026:73429 | gawk | Moderate | RHEL 10 |
| RHSA-2026:73428 | nodejs24 | Important | RHEL 10 |
| RHSA-2026:73130 | thunderbird | Important | RHEL 10 |
| RHSA-2026:73129 | cjose | Important | RHEL 10.0 EUS |
| RHSA-2026:73128 | cjose | Important | RHEL 9.6 EUS |
| RHSA-2026:73068 | freerdp | Important | RHEL 8.8 SAP Solutions + Telecom |
| RHSA-2026:73040 | gstreamer1-plugins-good | Important | RHEL 8.8 SAP Solutions + Telecom |
| RHSA-2026:73027 | freerdp | Important | RHEL 8.6 (AMCUSS + EUS LLA) |
| RHSA-2026:73026 | freerdp | Important | RHEL 8.4 (AMCUSS + EUS LLA) |
| RHSA-2026:73018 | cjose | Important | RHEL 9.4 SAP Solutions |
| RHSA-2026:73017 | cjose | Important | RHEL 9.2 SAP Solutions |
| RHSA-2026:72832 | kpatch-patch-5_14_0-687_10_1 | Important | RHEL 9 |
| RHSA-2026:72830 | kpatch-patch (5 packages) | Important | RHEL 9.6 EUS |
| RHSA-2026:72663 | expat | Important | RHEL 9 |
| RHSA-2026:73427 | gdb | Important | RHEL 10.2 |
| RHSA-2026:73426 | gdb | Important | RHEL 9 |
| RHSA-2026:73425 | gdb | Important | RHEL 8 |
| RHSA-2026:73424 | gstreamer1-plugins-good | Important | RHEL 8.4 (AMCUSS + EUS LLA) |
| RHSA-2026:71672 | Red Hat build of MicroShift 4.22.16 | Important | MicroShift |
| RHSA-2026:71445 | OpenShift Container Platform 4.22.16 | Important | OCP 4.22 |
| RHSA-2026:71444 | OpenShift Container Platform 4.21.35 | Important | OCP 4.21 |
| RHSA-2026:71443 | OpenShift Container Platform 4.21.35 | Important | OCP 4.21 |
| RHSA-2026:71442 | OpenShift Container Platform 4.20.40 | Important | OCP 4.20 |
Rocky Linux
Rocky Linux pushed nine security erratas this round, and a couple of them are Critical enough that you should probably patch before your coffee cools. Most of the batch is routine maintenance for Ruby, PostgreSQL, and freeipa, plus a couple of smaller libraries, but two grabbed the top severity rating and those are the ones worth your attention first.
The PostgreSQL 12 bump (RLSA-2026:72274) arrived on Rocky Linux 8 as a Critical fix and drags along its module twins pgaudit, pg_repack, and decoderbufs. The other Critical is the freeipa update (RLSA-2026:72279), aimed at the newer Rocky Linux 10. The remaining seven are all Important-level, which is the vendor's way of saying fix it soon but not tonight. Ruby is the busiest name in the queue: separate advisories cover the stock interpreter, ruby:3.3, and ruby:4.0, with a ruby4.0 package also landing on RHEL 10. If your stack leans on the MySQL or Postgres Ruby gems, both mysql2 and pg pick up version bumps for 3.3 and 4.0 on RHEL 9. Specific CVSS scores aren't spelled out in the advisory itself; the vendor links a CVE list where you can pull the per-vulnerability ratings.
| Advisory ID | Severity | Package(s) | Rocky Linux version |
|---|---|---|---|
| RLSA-2026:72286 | Important | ruby | 9 |
| RLSA-2026:72424 | Important | resteasy | 9 |
| RLSA-2026:72448 | Important | expat | 8 |
| RLSA-2026:72485 | Important | ruby:3.3 (+ mysql2, pg modules) | 9 |
| RLSA-2026:72484 | Important | ruby:4.0 (+ mysql2, pg modules) | 9 |
| RLSA-2026:72274 | Critical | postgresql:12 (+ pgaudit, pg_repack, decoderbufs) | 8 |
| RLSA-2026:72285 | Important | ruby:3.3 (+ mysql2, pg, abrt modules) | 8 |
| RLSA-2026:72279 | Critical | ipa | 10 |
| RLSA-2026:72427 | Important | ruby4.0 | 10 |
Slackware Linux
Slackware's security team has pushed a Firefox update for both 15.0 and -current. It's an ESR build, landing at 140.17.0 on the stable track and 153.4.0 on -current. Mozilla published the underlying fixes in MFSA2026-99, and this is one of those heavy ones. The advisory strings together roughly 43 CVEs, which is a lot for a single patch. The writeup itself stays vague with its usual "security fixes and improvements" phrasing, but a fix this broad almost always means they patched several memory-safety bugs, which is where browser exploits tend to live. If you run Firefox on Slackware, the fix is a single upgradepkg call run as root.
| Package | Architecture | Version | MD5 |
|---|---|---|---|
| mozilla-firefox-140.17.0esr-1_slack15.0 / mozilla-firefox-153.4.0esr-1 | i686 & x86_64 | 140.17.0esr (15.0) / 153.4.0esr (-current) | 3fc1777290f8ab65c556f64d4d38de15 / dd688c903a9423ea04b281f5614a8997 / 369c9c95bbfecf97325a15f193d02409 / 10861addfab60adb1704172fbcba038b |
SUSE Linux
SUSE and openSUSE published a batch of security patches spanning enterprise products and the rolling Tumbleweed release. You can roughly split them in two. The Tumbleweed announcements are the usual monthly cleanup on GA media, covering jackson-core, jackson-databind, helm, flatpak, and a scatter of smaller packages like goose and distribution-registry. The SUSE Linux Enterprise announcements carry more weight, and four of them carry an "important" rating that actually justifies a reboot.
The one worth your attention first is perl-DBI (CVE-2026-78030). It loads arbitrary modules because DBD::DBM doesn't validate the dbm_type or dbm_mldbm attributes, and SUSE rated it important. The NVD scores it a near-critical 9.8, which feels generous for "load a bad module," though a local attacker able to set those attributes can still do real damage.
cosign is the busiest announcement, bundling six CVEs around signature verification and the crypto/ssh library. One of them is a verification bypass in the legacy bundle that lets someone slip past checks with a plain public key. amazon-cloudwatch-agent closes out the important tier with three gRPC issues, including a heap memory exhaustion over HTTP/2 data frames. That same heap flaw (CVE-2026-84304) also shows up in kubectl-cnpg and cosign, so it's worth patching anywhere gRPC is running.
The Python updates for python310 and python311 fix the identical set of five vulnerabilities and both drop to point releases (3.10.21 and 3.11.16). The stack buffer overflow (CVE-2026-9669) is the one to treat as the headline, even though the local-only vector keeps its raw score down. The tarfile path traversal is the kind of thing you patch without reading the advisory closely.
| Announcement | Package(s) | Rating | Key CVE(s) (SUSE / NVD) | What it fixes |
|---|---|---|---|---|
| SUSE-SU-2026:4386-1 | perl-DBI | important | CVE-2026-78030 (8.6 / 9.8) | Arbitrary modules loaded via unvalidated dbm_type/dbm_mldbm in DBD::DBM |
| SUSE-SU-2026:4388-1 | amazon-cloudwatch-agent | important | CVE-2026-84303 (9.1), 84304 (8.7), 84445 (8.7) | gRPC xDS RBAC header bypass, HTTP/2 heap exhaustion, DoS from missing headers; jumps to 1.300072.0 |
| SUSE-SU-2026:4392-1 | cosign | important | 56852, 56854, 56855, 56864, 78662, 84304 | crypto/ssh auth bypass/deadlocks, norm infinite loop, sumdb hash trust, verification bypass; jumps to 3.1.3 |
| SUSE-SU-2026:4390-1 | python310 | moderate | 9669 (4.7/8.2), 15310 (3.1), 15806 (5.9), 17084 (5.3), 19672 (5.3) | Stack overflow, zipfile memory exhaustion, urllib scheme leak, StringPrep, tarfile path traversal; jumps to 3.10.21 |
| SUSE-SU-2026:4396-1 | python311 | moderate | Same five as python310 | Same fixes; jumps to 3.11.16 |
| SUSE-SU-2026:4367-1 | glib2 | moderate | CVE-2026-15588 (4.8 / 5.3) | GDBusServer pre-auth DoS from unbounded SASL line buffering; jumps to 2.78.6 |
| openSUSE-SU-2026:11879-1 | jackson-dataformat-csv (+properties, toml, yaml, text) | moderate | CVE-2026-85278 (7.5 / 8.7) | DoS via high memory usage; Tumbleweed GA media |
| openSUSE-SU-2026:11881-1 | kubectl-cnpg | moderate | CVE-2026-84304 (7.5 / 8.7) | HTTP/2 heap exhaustion (same gRPC flaw as above); Tumbleweed GA media |
| openSUSE-SU-2026:11876-1 | jackson-core | moderate | 68498, 89407, 89425 (7.5 / 8.7) | Three DoS-type issues; Tumbleweed GA media |
| openSUSE-SU-2026:11873-1 | flatpak | moderate | 87766 (8.6/9.3), 93676 (3.8/4.8) | Privilege-escalation and info leaks; Tumbleweed GA media |
| openSUSE-SU-2026:11872-1 | distribution-registry | moderate | 81871 (4.8), 81872 (5.3) | Low-severity web/info issues; Tumbleweed GA media |
| openSUSE-SU-2026:11875-1 | helm | moderate | 81871 (4.8), 81872 (5.3) | Same pair as distribution-registry; Tumbleweed GA media |
| openSUSE-SU-2026:11877-1 | jackson-databind | moderate | 19032, 68497, 83557, 91776, 91777 | Five issues, mostly denial-of-service via high memory use; Tumbleweed GA media |
| openSUSE-SU-2026:11874-1 | goose | moderate | CVE-2026-85623 | Unscoped description (no CVSS published); Tumbleweed GA media |
Ubuntu Linux
Ubuntu wrapped up the week with a two-day stack of security notices, and the kernel updates carry most of the weight. Six separate USNs touch the kernel, and if you run anything on AWS, Azure, Oracle, GCP, NVIDIA, or a generic OEM image, this affects you.
The biggest single payload is USN-8728-3, the Oracle 7.0 kernel on 24.04. It patches a pair of real hardware-level problems, an ARM broadcast TLB invalidation race and an AMD Zen 2 operation cache flaw that enables privilege escalation, before listing well over a hundred more CVEs across subsystems that run on for pages. Not clear whether each of those applies uniquely to the Oracle flavor or if Ubuntu is just pasting the upstream changelog in. Update to 7.0.0-1011 and reboot.
The other kernels are more modest. USN-8819-3 (kernel 4.15 on 18.04, 16.04, and 14.04) closes NFS server, IPv6, and Netfilter holes. USN-8818-3 (kernel 5.15 on 20.04) carries that same ARM TLB race plus a dozen more kernel bugs. USN-8729-6 (AWS 6.8, on 24.04 and 22.04), USN-8842-1 (NVIDIA 6.8, same two releases), and USN-8816-2 (GCP/OEM 7.0, on 26.04 and 24.04) cover smaller buckets. Every kernel notice flags the usual ABI change, so third-party kernel modules need recompiling on top of the reboot.
Beyond the kernel, the standalone fixes worth your attention are OpenSSL (USN-8847-1) and Erlang (USN-8827-1). OpenSSL covers QUIC, DTLS, and timing side-channels on elliptic-curve math, which means it bites the TLS in your normal traffic. Erlang is a sprawling pile: HTTP request smuggling, heap corruption, and TLS misbehavior in nearly equal measure.
The remainder are the usual file-handling and library bugs, and most target older releases you'll only reach if you are on Ubuntu Pro. Dracut (USN-8828-1) is the one to glance at, since a compromised DHCP server on your LAN could run code as root at boot. Atril, pdfminer, catdoc, and the perl DBI module all let crafted files trigger code execution, and c-ares (USN-8844-1) on 26.04 hits a use-after-free from bad DNS replies.
A pattern worth keeping in mind: many of these versions are marked "Available with Ubuntu Pro." If your 14.04, 16.04, or 18.04 machines are not on that program, most of these fixes simply aren't reachable. Run unattended-upgrades or do it by hand, and reboot wherever the notice asks.
| USN | Component(s) | Affected Ubuntu LTS | Fix highlight | Notes |
|---|---|---|---|---|
| USN-8819-3 | linux-azure-4.15, linux-aws-hwe, linux-azure | 18.04, 16.04, 14.04 | NFS server, IPv6, Netfilter | 3 CVEs; Pro only; reboot + module recompile |
| USN-8818-3 | linux-aws-5.15, linux-azure-5.15, linux-azure-fde-5.15, linux-intel-iotg-5.15 | 20.04 | ARM TLB race + ~20 more kernel bugs | Pro only; reboot + module recompile |
| USN-8728-3 | linux-oracle-7.0 | 24.04 | ARM TLB + AMD Zen 2 cache, 100+ more CVEs | Not Pro-marked; reboot + module recompile |
| USN-8729-6 | linux-aws, linux-aws-6.8 | 24.04, 22.04 | ~60 fixes across drivers, filesystems, networking | Not Pro-marked; reboot + module recompile |
| USN-8842-1 | linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency | 24.04, 22.04 | ~18 fixes | Not Pro-marked; reboot + module recompile |
| USN-8816-2 | linux-gcp, linux-gcp-7.0, linux-oem-7.0 | 26.04, 24.04 | ~60 fixes | Not Pro-marked; reboot + module recompile |
| USN-8840-1 | libevent | 26.04, 24.04, 22.04, 20.04, 18.04, 16.04, 14.04 | DNS-response and connection handling | 2 CVEs; older LTS need Pro |
| USN-8835-1 | Emacs | 26.04, 24.04 | SVG image memory corruption | Pro only |
| USN-8829-1 | Plasma Workspace | 16.04 | Session manager auth flaw, code exec as another user | Pro only |
| USN-8827-1 | Erlang | all LTS | HTTP smuggling, heap corruption, TLS issues | ~19 CVEs; newer LTS not Pro |
| USN-8839-1 | Atril (MATE document viewer) | 26.04, 24.04, 22.04, 20.04, 18.04, 16.04 | Code exec from crafted PDFs | 3 CVEs; Pro only |
| USN-8837-1 | pdfminer | 24.04, 22.04, 20.04, 18.04, 16.04 | Code exec from crafted PDFs | 2 CVEs; Pro only |
| USN-8832-1 | Booth (cluster ticket manager) | 24.04, 22.04, 20.04, 18.04 | MAC validation bypass | Pro only; restart Booth |
| USN-8828-1 | dracut | 26.04, 24.04, 22.04, 20.04, 18.04, 16.04 | DHCP-driven root code exec at boot | 4 CVEs; newer LTS not Pro |
| USN-8838-1 | catdoc (MS-Office extractor) | 24.04, 22.04, 20.04, 18.04, 16.04 | Integer overflow/underflow in Office files | 3 CVEs; Pro only |
| USN-8830-1 | phpseclib | all LTS | Non-constant-time AES/SSH checks, ASN.1 DoS | 3 CVEs; newer LTS not Pro |
| USN-8843-1 | FreeIPMI | all LTS | Stack buffer overflows from malicious IPMI devices | 6 CVEs; newer LTS not Pro |
| USN-8844-1 | c-ares | 26.04 | Use-after-free/double-free from DNS replies | Not Pro-marked |
| USN-8841-1 | libdbi-perl | all LTS | Integer arithmetic crash or code exec | 2 CVEs; newer LTS not Pro |
| USN-8846-1 | libheif | 26.04, 24.04, 22.04, 20.04, 18.04 | Image decoding denial of service | 5 CVEs; newer LTS not Pro |
| USN-8847-1 | OpenSSL | 26.04, 24.04, 22.04 | QUIC, DTLS, timing side-channels | 11 CVEs; not Pro-marked |
How to apply these Linux security updates
Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.
Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.
Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.
Debian/Ubuntu (apt)
The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.
sudo apt update sudo apt upgrade -y
Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)
On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.
sudo dnf check-update sudo dnf upgrade -y
or on older releases
sudo yum check-update sudo yum update
SUSE (zypper)
SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.
sudo zypper refresh sudo zypper update -y
Slackware (slackpkg and pkgtool)
Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.
sudo slackpkg update sudo slackpkg upgrade-all
