Security 11025 Published by

Today's Linux security roundup spans eight distros, from a Critical FreeIPA hole to Red Hat's 27-errata batch and hundreds of CVEs stuffed into the Debian and Ubuntu kernels. Debian's kernel update (6.12.111-1) runs from CVE-2024-52560 to CVE-2026-100079, while Ubuntu's Oracle 7.0 kernel (USN-8728-3) adds an ARM TLB race and an AMD Zen 2 flaw on top of 100+ more. The Criticals to patch first are the freeipa updates on AlmaLinux and Rocky Linux 10, the PostgreSQL 12 bump on Rocky Linux 8, and the RHEL for NVIDIA kernel (RHSA-2026:73187). Beyond kernels, watch Slackware's Firefox ESR build from roughly 43 CVEs, SUSE's near-critical 9.8-rated perl-DBI flaw, and Ubuntu's OpenSSL and Erlang fixes, though many older Ubuntu releases stay gated behind Ubuntu Pro.





Hundreds of CVEs pile into Debian and Ubuntu kernels, RHEL sends 27 errata

This daily roundup spans eight distros, from a Critical FreeIPA hole to a 27-errata batch from Red Hat and hundreds of CVEs stuffed into the Debian and Ubuntu kernels.

Vendors shipped updates for AlmaLinux, Debian, Fedora, RHEL, Rocky, Slackware, SUSE, and Ubuntu today, and a few carry the kind of severity that should pull you away from your coffee. The bulk landed between September 29 and 30. Debian and Ubuntu led with kernel piles that are hundreds of CVEs deep, while RHEL reissued the same patches more than once. Not all of it is worth a reboot, but three Criticals stand out.

Linux Security

Where the real severity sits

Debian's kernel update is the reason this day feels big. Advisory 6.12.111-1 covers privilege escalation, denial of service, and information leaks, and its CVE range runs from CVE-2024-52560 all the way up to CVE-2026-100079. That is a few hundred identifiers for a single advisory, and it makes the rest of the day look sparse.

Ubuntu capped off the day with a two-day stack of notices, and the kernel ones carry most of the weight. USN-8728-3 is the biggest single payload: the Oracle 7.0 kernel on 24.04 patches an ARM broadcast TLB invalidation race and an AMD Zen 2 operation cache flaw that enables privilege escalation, then lists well over a hundred more CVEs. It is not fully clear whether each applies to the Oracle flavor or whether Ubuntu is just pasting the upstream changelog wholesale. Update to 7.0.0-1011 and reboot.

The other five kernel USNs cover AWS, NVIDIA, GCP, and OEM builds across 22.04, 24.04, and 26.04. Every one flags an ABI change, so third-party modules need recompiling on top of the reboot.

Red Hat's batch is essentially a numbers game. Nearly everything sits at "Important," which quietly means "not a fire drill yet." Count the names and you still land on 27 errata, most reissuing the same patches across subscriptions, so freerdp, cjose, gdb, and gstreamer1-plugins-good each reappear more than once. The exception is RHSA-2026:73187, the kernel update for RHEL for NVIDIA, at Critical.

Apply it first and set the rest aside. Four advisories rate lower, at Moderate, covering two JBoss Apache HTTP Server refreshes and a pair of gawk bumps.

Two more Criticals you should not miss. Rocky Linux shipped nine erratas this round, with its PostgreSQL 12 bump (RLSA-2026:72274) landing as Critical on Rocky Linux 8. It drags along module twins pgaudit, pg_repack, and decoderbufs.

That same freeipa advisory (RLSA-2026:72279) is Critical for Rocky Linux 10, and AlmaLinux's own IdM update hits the Critical tier for version 10 as well. That one carries eight security fixes, including an unauthenticated LDAP hole that lets a client pull administrator credentials. If you run IdM, patch it before anything else.

The rest of the day

Debian's other two advisories, PCRE2 and libwebsockets, are smaller but not trivial, each opening a path to DoS or code execution. PCRE2 has no CVE number yet, which is odd for something this blunt, and libwebsockets fails on missing input validation in its hpack path parser. You'll want 10.46-1~deb13u3 and 4.3.5-1+deb13u3 respectively.

Fedora pushed eleven updates across 43 and 44 on September 30, and while most target niche libraries, flatpak-builder at 1.4.12 is the one to care about. It closes a CVE that let host code run through a malicious git am hook during patch extraction, so building flatpaks from untrusted sources is no longer a freebie. And the upstream changelog still says "Update to 0.4.12," a typo that clearly survived the upload. The rest is plain enough: perl-Imager, sngrep through 1.8.4, parted, libxmp, rootlesskit, and a thunderbird bump to 156.0, all grabbed by a single dnf upgrade.

Slackware's Firefox update is worth pausing for. It landed an ESR build at 140.17.0esr on the 15.0 track and 153.4.0esr on -current, built from Mozilla's MFSA2026-99, one of those heavy advisories stringing together roughly 43 CVEs. Mozilla's writeup stays vague with its usual "security fixes and improvements" phrasing, but a fix this broad almost always means several memory-safety bugs got patched, which is exactly where browser exploits live. Run a single upgradepkg as root if you are on the stable track.

SUSE and openSUSE split their batch into two cleanly. The Tumbleweed pieces are the usual monthly cleanup on GA media, covering jackson-core, jackson-databind, helm, flatpak, goose, and distribution-registry. The SUSE Linux Enterprise items carry more weight, and the one to act on first is perl-DBI (CVE-2026-78030). DBD::DBM doesn't validate the dbm_type or dbm_mldbm attributes and loads arbitrary modules as a result, so SUSE rated it important even though NVD scores it a near-critical 9.8.

cosign is the busiest announcement, bundling six CVEs around signature verification and the crypto/ssh library, and one is a verification bypass in the legacy bundle that lets someone slip past checks with a plain public key. The python310 and python311 updates both drop to point releases and fix the same five flaws, with the stack overflow (CVE-2026-9669) as the headline item.

Back in Ubuntu, the non-kernel fixes worth your time are OpenSSL (USN-8847-1) and Erlang (USN-8827-1). OpenSSL covers QUIC, DTLS, and timing side-channels, which bite your normal TLS traffic. Erlang is a sprawling pile of HTTP request smuggling, heap corruption, and TLS issues across roughly 19 CVEs. Dracut (USN-8828-1) is worth a glance, since a compromised DHCP server on your LAN could run code as root at boot.

One pattern worth keeping in mind: many Ubuntu versions are marked "Available with Ubuntu Pro." If your 14.04, 16.04, or 18.04 machines aren't on that program, most of these fixes simply aren't reachable. Run unattended-upgrades or patch by hand, and reboot wherever the notice asks.

If you only patch three things today, start with the Criticals: the FreeIPA updates on AlmaLinux and Rocky Linux 10, the PostgreSQL 12 bump on Rocky Linux 8, and the RHEL for NVIDIA kernel. The Debian and Ubuntu kernel piles are hundreds of CVEs that are hard to ignore even when the individual details blur together. Then hit the full RHEL errata list for anything touching your subscriptions, and head to the Ubuntu and SUSE announcement pages for the exact version bumps.

An Overview of the Updates

AlmaLinux

Three AlmaLinux security advisories went out on September 29, and the kernel package swept up the most CVEs. Together they cover one Critical and two Important severity releases across AlmaLinux 9 and 10.

The FreeIPA (AlmaLinux IdM) update is the Critical one, and it carries eight security fixes, which is a lot to dump on a single identity system in one go. Two are unauthenticated denial-of-service holes through unbounded request-body reads in the web endpoints, /ipa/i18n_messages and /ipa/migration/migration.py. Another lets an unauthenticated LDAP client pull administrator credentials via the self-managed-token ACI, and there is a stored XSS that runs arbitrary code from a crafted URL. Layer on a privilege escalation through krbCanonicalName, a TGS-obtaining impersonation across trusts, an unauthorized LDAP write hiding in trust-fetch-domains, and an idp-add eval() bug reachable before authorization. If you run IdM, this is the one to patch first.

The Ruby fix (AlmaLinux 10, Important) is a single issue in the resolv gem: crafted DNS responses cause uncontrolled memory growth that ends in a DoS. Quick win if your box resolves anything.

The kernel update (AlmaLinux 9, Important) is the longest tail with seventeen fixes. The DRM drivers do most of the work, with a cluster of amdgpu and Xe (Intel) issues covering out-of-bounds reads, stale pointers, integer overflows, and reference-counting mistakes. Networking shows up as well: PPPoE memory corruption, an IPVS DoS from stale memory, and a nf_queue bridge issue, plus an ivpu accelerator buffer-overflow check. The only non-security change bumps a MADVISE I/O size limit in AlmaLinux 9.

Advisory IDComponentOSSeverityReleasedFixes
ALSA-2026:72279FreeIPA / IdMAlmaLinux 10Critical2026-09-298 security, 8 bug/enhancement
ALSA-2026:72785Ruby (resolv gem)AlmaLinux 10Important2026-09-291 security
ALSA-2026:71700Linux kernelAlmaLinux 9Important2026-09-2917 security, 1 bug/enhancement

Debian GNU/Linux

Debian shipped three security advisories on September 29, and if you run trixie (the stable release) you'll want to apply all three. The standout is the Linux kernel update, fixed in 6.12.111-1. The CVE list is so long you can basically stop counting and just start trusting the patch, but underneath it all sit privilege escalation, denial of service, and information-leak flaws. The count runs from CVE-2024-52560 up to CVE-2026-100079, which is a lot for a single advisory and makes the rest of the week's news look sparse.

PCRE2, the regex library that shows up wherever text matching happens, carries a single out-of-bounds write flaw that could lead to denial of service or arbitrary code execution. Debian hasn't assigned it a CVE number yet, which is a bit odd for something this blunt. It's patched in 10.46-1~deb13u3.

libwebsockets has its own single problem, CVE-2026-19773, rooted in missing input validation in the hpack path header parser. Same result: denial of service or arbitrary code execution. Fixed in 4.3.5-1+deb13u3.

The housekeeping is straightforward, so go install the new versions and move on.

PackageCVE(s)IssueFixed version
linuxCVE-2024-52560 through CVE-2026-100079 (hundreds)Privilege escalation, denial of service, information leaks6.12.111-1
pcre2Not yet assignedOut-of-bounds write (DoS or arbitrary code execution)10.46-1~deb13u3
libwebsocketsCVE-2026-19773Missing input validation in hpack parser (DoS or arbitrary code execution)4.3.5-1+deb13u3

Fedora Linux

Fedora pushed a batch of eleven security updates across Fedora 43 and 44 on September 30, and this round leans on the usual offenders: memory corruption in a few niche libraries and a handful of denial-of-service holes aimed at tooling you'd only run if you lived in that world.

The one worth actually caring about is flatpak-builder, which jumps to 1.4.12. That shuts a CVE letting host code execute through a malicious git am hook during patch extraction, so anyone building flatpaks from untrusted sources should treat this as worth the reboot. A small aside: the upstream changelog for this release reads "Update to 0.4.12," a typo that clearly survived the upload.

perl-Imager takes the next hit with two fixes. It can misread a TGA color map as negative and hand back uninitialized palette data from paletted images, so what looks like dead air in the code is really a potential information leak. If you deal with SIP traffic at all, sngrep through 1.8.4 had a stack buffer overflow that malformed SIP headers could trigger, now patched on both releases.

parted, the partition tool, went through more changes than usual. It got patched for 32-bit buffer overflows and FAT metadata handling, wrapping up two CVEs along the way. libxmp, the library that plays everything from Protracker MODs to Impulse Tracker files, picked up a medium-rated fix, which is reassuring until you remember how many retro tracker apps still lean on it.

rootlesskit closed out the batch with two SSH-related denial-of-service CVEs passed through the Go crypto library, and thunderbird quietly moved to 156.0 under a [SECURITY] tag without saying what the fix actually did. A single dnf upgrade picks all of this up if you've been letting things pile up.

PackageVersionFedora targetWhat's fixed
libxmp4.7.343 & 44Medium-rated security issue (upstream #1029)
thunderbird156.043Latest upstream bump, reason unspecified
rootlesskit3.2.043 & 44Two SSH DoS CVEs (CVE-2026-56855, CVE-2026-78662)
sngrep1.8.443 & 44Stack buffer overflow via SIP headers (CVE-2026-90558)
perl-Imager1.03643 & 44Two CVEs: negative TGA color map and uninitialized palette leak
parted3.64332-bit overflow fixes, FAT metadata handling, two CVEs
flatpak-builder1.4.1244Host code execution via git am hook (CVE-2026-86320)

Red Hat Enterprise Linux

Red Hat pushed a fresh wave of security advisories out the door, and if you count the names you land at 27 separate errata spanning kernel updates, OpenShift releases, and the utility libraries you'd rather not think about until one of them breaks.

The shape of the batch should feel familiar. Red Hat patched a few core packages, then reissued those same patches across several RHEL subscriptions, which is why freerdp, cjose, gdb, and gstreamer1-plugins-good each show up more than once. The per-package counts balloon faster than the actual number of distinct problems.

Nearly all of them sit at Red Hat's "Important" rating, the vendor's comfortable middle ground that quietly translates to "not a fire drill yet." Only the kernel update for RHEL for NVIDIA breaks that streak. RHSA-2026:73187 lands at Critical, so that's the one to set everything else aside and apply first. Four advisories rate lower, at Moderate. Those cover two JBoss Core Services Apache HTTP Server 2.4.62 Service Pack 6 refreshes and a pair of gawk bumps for RHEL 9 and 10.

Containers got plenty of attention too. Red Hat shipped new releases for OpenShift 4.20.40, 4.21.35, and 4.22.16, each mixing bug fixes with security work, plus a MicroShift 4.22.16 security refresh. The rest of the grab bag includes one-off updates for expat, thunderbird, and nodejs24.

RHSA IDPackageRatingTarget
RHSA-2026:73187kernel (security, bug fix, enhancement)CriticalRHEL for NVIDIA
RHSA-2026:73076JBoss Core Services Apache HTTP Server 2.4.62 SP6ModerateJBoss Core Services
RHSA-2026:73077JBoss Core Services Apache HTTP Server 2.4.62 SP6ModerateJBoss Core Services
RHSA-2026:73512gawkModerateRHEL 9
RHSA-2026:73429gawkModerateRHEL 10
RHSA-2026:73428nodejs24ImportantRHEL 10
RHSA-2026:73130thunderbirdImportantRHEL 10
RHSA-2026:73129cjoseImportantRHEL 10.0 EUS
RHSA-2026:73128cjoseImportantRHEL 9.6 EUS
RHSA-2026:73068freerdpImportantRHEL 8.8 SAP Solutions + Telecom
RHSA-2026:73040gstreamer1-plugins-goodImportantRHEL 8.8 SAP Solutions + Telecom
RHSA-2026:73027freerdpImportantRHEL 8.6 (AMCUSS + EUS LLA)
RHSA-2026:73026freerdpImportantRHEL 8.4 (AMCUSS + EUS LLA)
RHSA-2026:73018cjoseImportantRHEL 9.4 SAP Solutions
RHSA-2026:73017cjoseImportantRHEL 9.2 SAP Solutions
RHSA-2026:72832kpatch-patch-5_14_0-687_10_1ImportantRHEL 9
RHSA-2026:72830kpatch-patch (5 packages)ImportantRHEL 9.6 EUS
RHSA-2026:72663expatImportantRHEL 9
RHSA-2026:73427gdbImportantRHEL 10.2
RHSA-2026:73426gdbImportantRHEL 9
RHSA-2026:73425gdbImportantRHEL 8
RHSA-2026:73424gstreamer1-plugins-goodImportantRHEL 8.4 (AMCUSS + EUS LLA)
RHSA-2026:71672Red Hat build of MicroShift 4.22.16ImportantMicroShift
RHSA-2026:71445OpenShift Container Platform 4.22.16ImportantOCP 4.22
RHSA-2026:71444OpenShift Container Platform 4.21.35ImportantOCP 4.21
RHSA-2026:71443OpenShift Container Platform 4.21.35ImportantOCP 4.21
RHSA-2026:71442OpenShift Container Platform 4.20.40ImportantOCP 4.20

Rocky Linux

Rocky Linux pushed nine security erratas this round, and a couple of them are Critical enough that you should probably patch before your coffee cools. Most of the batch is routine maintenance for Ruby, PostgreSQL, and freeipa, plus a couple of smaller libraries, but two grabbed the top severity rating and those are the ones worth your attention first.

The PostgreSQL 12 bump (RLSA-2026:72274) arrived on Rocky Linux 8 as a Critical fix and drags along its module twins pgaudit, pg_repack, and decoderbufs. The other Critical is the freeipa update (RLSA-2026:72279), aimed at the newer Rocky Linux 10. The remaining seven are all Important-level, which is the vendor's way of saying fix it soon but not tonight. Ruby is the busiest name in the queue: separate advisories cover the stock interpreter, ruby:3.3, and ruby:4.0, with a ruby4.0 package also landing on RHEL 10. If your stack leans on the MySQL or Postgres Ruby gems, both mysql2 and pg pick up version bumps for 3.3 and 4.0 on RHEL 9. Specific CVSS scores aren't spelled out in the advisory itself; the vendor links a CVE list where you can pull the per-vulnerability ratings.

Advisory IDSeverityPackage(s)Rocky Linux version
RLSA-2026:72286Importantruby9
RLSA-2026:72424Importantresteasy9
RLSA-2026:72448Importantexpat8
RLSA-2026:72485Importantruby:3.3 (+ mysql2, pg modules)9
RLSA-2026:72484Importantruby:4.0 (+ mysql2, pg modules)9
RLSA-2026:72274Criticalpostgresql:12 (+ pgaudit, pg_repack, decoderbufs)8
RLSA-2026:72285Importantruby:3.3 (+ mysql2, pg, abrt modules)8
RLSA-2026:72279Criticalipa10
RLSA-2026:72427Importantruby4.010

Slackware Linux

Slackware's security team has pushed a Firefox update for both 15.0 and -current. It's an ESR build, landing at 140.17.0 on the stable track and 153.4.0 on -current. Mozilla published the underlying fixes in MFSA2026-99, and this is one of those heavy ones. The advisory strings together roughly 43 CVEs, which is a lot for a single patch. The writeup itself stays vague with its usual "security fixes and improvements" phrasing, but a fix this broad almost always means they patched several memory-safety bugs, which is where browser exploits tend to live. If you run Firefox on Slackware, the fix is a single upgradepkg call run as root.

PackageArchitectureVersionMD5
mozilla-firefox-140.17.0esr-1_slack15.0 / mozilla-firefox-153.4.0esr-1i686 & x86_64140.17.0esr (15.0) / 153.4.0esr (-current)3fc1777290f8ab65c556f64d4d38de15 / dd688c903a9423ea04b281f5614a8997 / 369c9c95bbfecf97325a15f193d02409 / 10861addfab60adb1704172fbcba038b

SUSE Linux

SUSE and openSUSE published a batch of security patches spanning enterprise products and the rolling Tumbleweed release. You can roughly split them in two. The Tumbleweed announcements are the usual monthly cleanup on GA media, covering jackson-core, jackson-databind, helm, flatpak, and a scatter of smaller packages like goose and distribution-registry. The SUSE Linux Enterprise announcements carry more weight, and four of them carry an "important" rating that actually justifies a reboot.

The one worth your attention first is perl-DBI (CVE-2026-78030). It loads arbitrary modules because DBD::DBM doesn't validate the dbm_type or dbm_mldbm attributes, and SUSE rated it important. The NVD scores it a near-critical 9.8, which feels generous for "load a bad module," though a local attacker able to set those attributes can still do real damage.

cosign is the busiest announcement, bundling six CVEs around signature verification and the crypto/ssh library. One of them is a verification bypass in the legacy bundle that lets someone slip past checks with a plain public key. amazon-cloudwatch-agent closes out the important tier with three gRPC issues, including a heap memory exhaustion over HTTP/2 data frames. That same heap flaw (CVE-2026-84304) also shows up in kubectl-cnpg and cosign, so it's worth patching anywhere gRPC is running.

The Python updates for python310 and python311 fix the identical set of five vulnerabilities and both drop to point releases (3.10.21 and 3.11.16). The stack buffer overflow (CVE-2026-9669) is the one to treat as the headline, even though the local-only vector keeps its raw score down. The tarfile path traversal is the kind of thing you patch without reading the advisory closely.

AnnouncementPackage(s)RatingKey CVE(s) (SUSE / NVD)What it fixes
SUSE-SU-2026:4386-1perl-DBIimportantCVE-2026-78030 (8.6 / 9.8)Arbitrary modules loaded via unvalidated dbm_type/dbm_mldbm in DBD::DBM
SUSE-SU-2026:4388-1amazon-cloudwatch-agentimportantCVE-2026-84303 (9.1), 84304 (8.7), 84445 (8.7)gRPC xDS RBAC header bypass, HTTP/2 heap exhaustion, DoS from missing headers; jumps to 1.300072.0
SUSE-SU-2026:4392-1cosignimportant56852, 56854, 56855, 56864, 78662, 84304crypto/ssh auth bypass/deadlocks, norm infinite loop, sumdb hash trust, verification bypass; jumps to 3.1.3
SUSE-SU-2026:4390-1python310moderate9669 (4.7/8.2), 15310 (3.1), 15806 (5.9), 17084 (5.3), 19672 (5.3)Stack overflow, zipfile memory exhaustion, urllib scheme leak, StringPrep, tarfile path traversal; jumps to 3.10.21
SUSE-SU-2026:4396-1python311moderateSame five as python310Same fixes; jumps to 3.11.16
SUSE-SU-2026:4367-1glib2moderateCVE-2026-15588 (4.8 / 5.3)GDBusServer pre-auth DoS from unbounded SASL line buffering; jumps to 2.78.6
openSUSE-SU-2026:11879-1jackson-dataformat-csv (+properties, toml, yaml, text)moderateCVE-2026-85278 (7.5 / 8.7)DoS via high memory usage; Tumbleweed GA media
openSUSE-SU-2026:11881-1kubectl-cnpgmoderateCVE-2026-84304 (7.5 / 8.7)HTTP/2 heap exhaustion (same gRPC flaw as above); Tumbleweed GA media
openSUSE-SU-2026:11876-1jackson-coremoderate68498, 89407, 89425 (7.5 / 8.7)Three DoS-type issues; Tumbleweed GA media
openSUSE-SU-2026:11873-1flatpakmoderate87766 (8.6/9.3), 93676 (3.8/4.8)Privilege-escalation and info leaks; Tumbleweed GA media
openSUSE-SU-2026:11872-1distribution-registrymoderate81871 (4.8), 81872 (5.3)Low-severity web/info issues; Tumbleweed GA media
openSUSE-SU-2026:11875-1helmmoderate81871 (4.8), 81872 (5.3)Same pair as distribution-registry; Tumbleweed GA media
openSUSE-SU-2026:11877-1jackson-databindmoderate19032, 68497, 83557, 91776, 91777Five issues, mostly denial-of-service via high memory use; Tumbleweed GA media
openSUSE-SU-2026:11874-1goosemoderateCVE-2026-85623Unscoped description (no CVSS published); Tumbleweed GA media

Ubuntu Linux

Ubuntu wrapped up the week with a two-day stack of security notices, and the kernel updates carry most of the weight. Six separate USNs touch the kernel, and if you run anything on AWS, Azure, Oracle, GCP, NVIDIA, or a generic OEM image, this affects you.

The biggest single payload is USN-8728-3, the Oracle 7.0 kernel on 24.04. It patches a pair of real hardware-level problems, an ARM broadcast TLB invalidation race and an AMD Zen 2 operation cache flaw that enables privilege escalation, before listing well over a hundred more CVEs across subsystems that run on for pages. Not clear whether each of those applies uniquely to the Oracle flavor or if Ubuntu is just pasting the upstream changelog in. Update to 7.0.0-1011 and reboot.

The other kernels are more modest. USN-8819-3 (kernel 4.15 on 18.04, 16.04, and 14.04) closes NFS server, IPv6, and Netfilter holes. USN-8818-3 (kernel 5.15 on 20.04) carries that same ARM TLB race plus a dozen more kernel bugs. USN-8729-6 (AWS 6.8, on 24.04 and 22.04), USN-8842-1 (NVIDIA 6.8, same two releases), and USN-8816-2 (GCP/OEM 7.0, on 26.04 and 24.04) cover smaller buckets. Every kernel notice flags the usual ABI change, so third-party kernel modules need recompiling on top of the reboot.

Beyond the kernel, the standalone fixes worth your attention are OpenSSL (USN-8847-1) and Erlang (USN-8827-1). OpenSSL covers QUIC, DTLS, and timing side-channels on elliptic-curve math, which means it bites the TLS in your normal traffic. Erlang is a sprawling pile: HTTP request smuggling, heap corruption, and TLS misbehavior in nearly equal measure.

The remainder are the usual file-handling and library bugs, and most target older releases you'll only reach if you are on Ubuntu Pro. Dracut (USN-8828-1) is the one to glance at, since a compromised DHCP server on your LAN could run code as root at boot. Atril, pdfminer, catdoc, and the perl DBI module all let crafted files trigger code execution, and c-ares (USN-8844-1) on 26.04 hits a use-after-free from bad DNS replies.

A pattern worth keeping in mind: many of these versions are marked "Available with Ubuntu Pro." If your 14.04, 16.04, or 18.04 machines are not on that program, most of these fixes simply aren't reachable. Run unattended-upgrades or do it by hand, and reboot wherever the notice asks.

USNComponent(s)Affected Ubuntu LTSFix highlightNotes
USN-8819-3linux-azure-4.15, linux-aws-hwe, linux-azure18.04, 16.04, 14.04NFS server, IPv6, Netfilter3 CVEs; Pro only; reboot + module recompile
USN-8818-3linux-aws-5.15, linux-azure-5.15, linux-azure-fde-5.15, linux-intel-iotg-5.1520.04ARM TLB race + ~20 more kernel bugsPro only; reboot + module recompile
USN-8728-3linux-oracle-7.024.04ARM TLB + AMD Zen 2 cache, 100+ more CVEsNot Pro-marked; reboot + module recompile
USN-8729-6linux-aws, linux-aws-6.824.04, 22.04~60 fixes across drivers, filesystems, networkingNot Pro-marked; reboot + module recompile
USN-8842-1linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency24.04, 22.04~18 fixesNot Pro-marked; reboot + module recompile
USN-8816-2linux-gcp, linux-gcp-7.0, linux-oem-7.026.04, 24.04~60 fixesNot Pro-marked; reboot + module recompile
USN-8840-1libevent26.04, 24.04, 22.04, 20.04, 18.04, 16.04, 14.04DNS-response and connection handling2 CVEs; older LTS need Pro
USN-8835-1Emacs26.04, 24.04SVG image memory corruptionPro only
USN-8829-1Plasma Workspace16.04Session manager auth flaw, code exec as another userPro only
USN-8827-1Erlangall LTSHTTP smuggling, heap corruption, TLS issues~19 CVEs; newer LTS not Pro
USN-8839-1Atril (MATE document viewer)26.04, 24.04, 22.04, 20.04, 18.04, 16.04Code exec from crafted PDFs3 CVEs; Pro only
USN-8837-1pdfminer24.04, 22.04, 20.04, 18.04, 16.04Code exec from crafted PDFs2 CVEs; Pro only
USN-8832-1Booth (cluster ticket manager)24.04, 22.04, 20.04, 18.04MAC validation bypassPro only; restart Booth
USN-8828-1dracut26.04, 24.04, 22.04, 20.04, 18.04, 16.04DHCP-driven root code exec at boot4 CVEs; newer LTS not Pro
USN-8838-1catdoc (MS-Office extractor)24.04, 22.04, 20.04, 18.04, 16.04Integer overflow/underflow in Office files3 CVEs; Pro only
USN-8830-1phpsecliball LTSNon-constant-time AES/SSH checks, ASN.1 DoS3 CVEs; newer LTS not Pro
USN-8843-1FreeIPMIall LTSStack buffer overflows from malicious IPMI devices6 CVEs; newer LTS not Pro
USN-8844-1c-ares26.04Use-after-free/double-free from DNS repliesNot Pro-marked
USN-8841-1libdbi-perlall LTSInteger arithmetic crash or code exec2 CVEs; newer LTS not Pro
USN-8846-1libheif26.04, 24.04, 22.04, 20.04, 18.04Image decoding denial of service5 CVEs; newer LTS not Pro
USN-8847-1OpenSSL26.04, 24.04, 22.04QUIC, DTLS, timing side-channels11 CVEs; not Pro-marked

How to apply these Linux security updates

Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.

Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.

Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.

Debian/Ubuntu (apt)

The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.

sudo apt update
sudo apt upgrade -y

Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)

On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.

sudo dnf check-update
sudo dnf upgrade -y

or on older releases

sudo yum check-update
sudo yum update

SUSE (zypper)

SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.

sudo zypper refresh
sudo zypper update -y

Slackware (slackpkg and pkgtool)

Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.

sudo slackpkg update
sudo slackpkg upgrade-all