Security 11030 Published by

Four major Linux distros: Debian, Fedora, RHEL, and openSUSE, pushed fresh security updates this week, mostly routine fixes but a handful worth acting on. Firefox ESR leads the pile at 62 CVEs in version 153.4.0, while Fedora's Chromium 154.0.8037.92 ships 32 more across V8, the GPU, Bluetooth, and password handling. Debian rounds out the list with a FreeCAD zero-day style exploit, a 6.12.111 kernel update, and a PHP 8.2 fix, though the mysqlnd overread only bites against untrusted MySQL servers.





Linux Security Updates: Firefox ESR packs 62 CVEs, Chromium ships 32

Firefox ESR tops this week's wave of updates with 62 fixes, and Fedora's Chromium adds 32 more, as Debian, Fedora, RHEL, and openSUSE all shipped fresh security errata.

There was a lot of patching going around this week. Four major Linux distros pushed new security fixes, and while most are the kind you apply without cracking open the changelog, a few are worth your attention before they start mattering. The shape of it is familiar: someone opens a crafted file, you run an update, and hopefully nothing catches fire.

Linux Security

Debian moved first over the past few days, and FreeCAD is the one that makes you pause.

Load a malicious FCStd document and an attacker gains the ability to run arbitrary Python as you, write files wherever you have access, and read local files or fire off remote requests. FreeCAD loads whatever your project tells it to, so this is exactly the bug you want closed fast. It's covered by DLA-4815-1, fixed in 0.20.2+dfsg1-4+deb12u1 for bookworm.

The kernel deserves its own moment. Debian 6.12 now sits on 6.12.111-1~deb12u1, absorbing a batch of CVEs plus stable backports from 6.12.108 through 6.12.111. If you're still running 6.12, that's the update to grab.

PHP 8.2 is another heavy one, spanning TLS certificate verification, IPv6 access control, and several out-of-bounds reads. The mysqlnd overread only bites when you connect to an untrusted or compromised MySQL server. So if your database is homegrown and trustworthy, that hole never actually reaches you.

The rest of the Debian roster plays to type. PCRE2 picks up an out-of-bounds write patch, Xen's hypervisor collects a pile of fixes, node-lodash closes its prototype-pollution and template-injection gaps, and FreeXian filed an ELA for ImageMagick on stretch, since that distro is old enough that only its extended-support track still patches it. You can likely knock most of this out in a single pass: upgrade, reboot the kernel machines, and move on.

Fedora's 32-CVE Chromium

Fedora pushed fixes to both 44 and 43, and the obvious thing about the batch is that several packages got patched on both releases at the same time. If you run either version, the practical answer is basically run dnf upgrade and get on with your day.

Chromium is the standout. Version 154.0.8037.92 ships 32 CVEs, from type confusion in V8 to use-after-free bugs spread across the GPU, Bluetooth, and password handling. The list runs long enough that the advisory even truncated it in a couple of the linked bug reports. You probably don't want to be the person reading all 32 at a dinner party.

Python lands at 3.12.15 with eight fixes folded in. Not the most glamorous news in the batch, but that's what you'd want from an interpreter, and honestly you'd take it. The quietly useful bump is urllib3 to 2.8.0, which closes three issues including an HTTPS proxy that ignored your TLS settings and a chunked deflate path that would spin forever. Streamlink rides along on the same advisory, so updating it drags in the urllib3 fix automatically.

Flatpak had a rougher month. Version 1.18.4 closes off arbitrary file deletion via path traversal, world-readable auth tokens, world-writable temp repos, and a sandboxed app that could reach its unsandboxed siblings. Worth knowing that 1.18.2 already shipped a regression that broke flatpak-builder on F44. That's resolved here, so it's not bad.

The usual suspects round it out. Prometheus and LemonLDAP-NG both got patch days covering IP spoofing, XSS, and SSO authentication bypass. Cri-o and PgBouncer handle the container and database end, and PgBouncer pulls in CVEs like a magnet this round, seven of them, mostly denial-of-service variants aimed at the SCRAM authentication code.

Red Hat kept its batch quieter this cycle. It's mostly aimed at RHEL 8, with three of the four updates targeting that release and the fourth landing on RHEL 10.0 EUS, because kernel patches tend to live there. Every entry is rated "Important," which sits just under Critical in Red Hat's own severity ladder and marks the tier where you stop treating a patch as optional.

Two deserve your attention in particular. A sudo fix is roughly the IT equivalent of walking back to a door you've already left open. The kernel update quietly affects everything running on the box. librabbitmq and the pki-core:10.6 module both get security patches too, keeping the messaging and authentication plumbing from rotting quietly from the inside.

openSUSE: Firefox ESR leads a 62-CVE round

openSUSE kept most fixes at "moderate," but Firefox ESR is the one you should patch first. Version 153.4.0 piles 62 vulnerability fixes into a single release. That's a serious backlog for a long-term browser, even if ESR typically accumulates fixes between points. If you're on the extended support build instead of the rolling Firefox, grab this one.

rustup takes the only "important" rating, closing 16 CVEs across the Rust toolchain from openssl to rustls-webpki. The certificate-handling holes in rust-openssl are the ones worth worrying about, since a couple allow arbitrary code execution. This announcement also quietly ships a major rewrite of rustup itself, pushing it to 1.29.1 with a changelog long enough to need its own index. Downloads go async, "triple" quietly becomes "tuple," and they swapped the logging stack for something newer. You'll probably notice nothing at all, though a security patch rarely carries this much churn.

The Tumbleweed side is more ordinary. libwireshark19 takes 19 fixes, while rpcbind, xdg-dbus-proxy, amazon-ecs-init, openai-codex, litellm, parted, and slirp each mop up one or two. The highest-scoring bug in that group is an 8.8 in xdg-dbus-proxy, which the patch knocks down to a local-only privilege bump. 

A Detailed Overview of the Updates

Debian GNU/Linux

Debian's LTS and security teams pushed a batch of fixes over the last few days, and a handful deserve your attention before anything breaks. Most are the familiar "open a crafted file and regret it" story, but the Linux kernel update is the kind you just apply and stop thinking about.

FreeCAD is the one that makes you pause. Loading a malicious FCStd document handed an attacker the ability to run arbitrary Python as you, write files anywhere you have access, and read local files or trigger remote requests. Since FreeCAD loads whatever a project tells it to, this is worth the five-minute upgrade.

The kernel deserves a moment on its own. Debian 6.12 now sits on 6.12.111-1~deb12u1, absorbing a big batch of CVEs plus the usual stable backports from 6.12.108 through 6.12.111. If you are still on 6.12, that is the update to grab.

PHP 8.2 is another heavy one, spanning TLS certificate verification, IPv6 access control, and several out-of-bounds reads. The mysqlnd overread only bites when you connect to an untrusted or compromised MySQL server, so if your database is homegrown and trustworthy, that particular hole never reaches you.

The rest of the roster plays to type: PCRE2 gets an out-of-bounds write patch, Xen's hypervisor collects a pile of fixes, node-lodash finally closes its prototype-pollution and template-injection gaps, and Wireshark and ruby-rack-session both land fixes on trixie. FreeXian also filed an ELA for ImageMagick on stretch, since that distro is old enough that only the extended-support track still patches it.

You can likely do most of this in a single pass. Upgrade, reboot the kernel machines, and move on.

PackageAdvisoryWhat is fixedFixed versionPlatform
freecadDLA-4815-1 (Oct 3)Arbitrary code execution via module name, arbitrary file writes via path traversal, file disclosure/remote requests via XML entities0.20.2+dfsg1-4+deb12u1Debian 12 bookworm
pcre2DLA-4816-1 (Oct 3)Out-of-bounds write, leading to DoS or arbitrary code execution10.42-1+deb12u2Debian 12 bookworm
linux-6.12DLA-4817-1 (Oct 4)Privilege escalation, DoS, information leaks (plus stable backports 6.12.108-6.12.111)6.12.111-1~deb12u1Debian 12 bookworm
imagagickELA-1842-1DoS, information disclosure, arbitrary code execution from malformed images8:6.9.7.4+dfsg-11+deb9u32Debian 9 stretch (FreeXian ELA)
wiresharkDSA-6541-1 (Oct 4)DoS or arbitrary code execution while analyzing packets4.4.19-0+deb13u1Debian 13 trixie (stable)
ruby-rack-sessionDSA-6542-1 (Oct 4)Authentication bypass or privilege escalation from bad error handling2.1.1-0.1+deb13u1Debian 13 trixie (stable)
node-lodashDLA-4820-1 (Oct 5)Prototype pollution, incomplete prior fix, template code injection4.17.21+dfsg+~cs8.31.198.20210220-9+deb12u1Debian 12 bookworm
php8.2DLA-4819-1 (Oct 5)Overreads, SOAP overflow, integer overflow, TLS bypass, IPv6 access-control flaws, credential leaks8.2.34-1~deb12u1Debian 12 bookworm
xenDLA-4818-1 (Oct 4)Privilege escalation, information disclosure, DoS4.17.7-0+deb12u1Debian 12 bookworm

Fedora Linux

Fedora just pushed a batch of security fixes to Fedora 44 and 43, and the obvious thing about the whole lot is that several packages got patched on both releases at the same time. If you run either version, the practical answer is basically run dnf upgrade and move on with your day.

The one that jumps out is Chromium. Version 154.0.8037.92 ships 32 CVEs, from type confusion in V8 to use-after-free bugs spread across the GPU, Bluetooth, and password handling. It's long enough that the advisory even truncated the list in a couple of the linked bug reports. You probably don't want to be the person reading all 32 at a dinner party.

Python lands at 3.12.15 with eight fixes folded in. Not the most glamorous news in the batch, but that's what you'd want from an interpreter.

The urllib3 bump to 2.8.0 is the quietly useful one here. Three fixes, two rated high severity: an HTTPS proxy that ignored your TLS settings, memory buffers that could balloon on demand, and a chunked deflate path that would spin forever. Streamlink rides along on the same advisory, so updating it drags in the urllib3 patch automatically.

Flatpak had a rougher month. Version 1.18.4 closes off arbitrary file deletion via path traversal, world-readable auth tokens, world-writable temp repos, a denial of service, and a sandboxed app that could reach its unsandboxed siblings. Worth knowing that 1.18.2 already had a regression which broke flatpak-builder on F44, and that's resolved in 1.18.4.

The rest are the usual suspects. Prometheus and LemonLDAP-NG both got their patch days, covering IP spoofing, XSS, and SSO authentication bypass. Cri-o and PgBouncer handle the container and database end, and PgBouncer pulls in CVEs like a magnet this round, seven of them, mostly denial-of-service variants aimed at the SCRAM authentication code.

PackageVersionRelease(s)AdvisoryFixes
python3.123.12.15-1.fc44F44FEDORA-2026-b3da0d09be8 CVEs (interpreter release)
flatpak1.18.4-1.fc44F44FEDORA-2026-7a31054ed65 CVEs (incl. file deletion, token leak, sandbox escape)
nanosvg20221221-11.fc44F44FEDORA-2026-4718fc201aCVE-2026-88367 (DoS via large stroke width)
prometheus3.15.0-1.fc44F44FEDORA-2026-1e56ab167d7 CVEs
lemonldap-ng2.23.4-1.fc44F44FEDORA-2026-827241e2de3 CVEs (OAuth introspection, PKCE bypass)
assimp6.0.5-5.fc44F44FEDORA-2026-492ca436345 CVEs (buffer overflows, DoS)
chromium154.0.8037.92-1.fc44F44FEDORA-2026-35b989661c32 CVEs
cri-o1.361.36.6-1.fc44F44FEDORA-2026-f5c88f763aCVE-2026-17113 + daemon start fix
pgbouncer1.26.0-1.fc44F44FEDORA-2026-99030761e87 CVEs
nanosvg20221221-11.fc43F43FEDORA-2026-aa32e385dcCVE-2026-88367
lemonldap-ng2.23.4-1.fc43F43FEDORA-2026-33dcab55b43 CVEs
assimp6.0.5-5.fc43F43FEDORA-2026-2d7847f75c5 CVEs
cri-o1.361.36.6-1.fc43F43FEDORA-2026-0025579bc9CVE-2026-17113 + daemon start fix
pgbouncer1.26.0-1.fc43F43FEDORA-2026-6197f5c17e7 CVEs
python-streamlink8.4.0-2.fc43F43FEDORA-2026-72a7879d08urllib3 2.8.0 backport
python-urllib32.8.0-1.fc43F43FEDORA-2026-72a7879d083 fixes (TLS proxy, buffer, infinite loop)

Red Hat Enterprise Linux

Red Hat pushed a fresh batch of security errata, and this cycle is mostly aimed at Red Hat Enterprise Linux 8. Three of the four updates target that release, with the fourth landing on the RHEL 10.0 Extended Update Support line because, well, it's a kernel patch and kernel patches are where EUS lives.

Every single one is rated "Important," which sits just under Critical in Red Hat's own severity ladder. That's the tier where you stop treating a patch as optional. Two of them deserve your attention in particular: sudo and the kernel. A sudo fix is basically the IT equivalent of fixing a door you've already left open, and a kernel update quietly affects everything running on the box.

The rest are the steady, less glamorous work. librabbitmq and the pki-core:10.6 module both get security patches, which keeps the messaging and authentication plumbing from rotting from the inside out.

Each entry links to CVE references so you can pull the actual CVSS base scores if you want to prioritize more precisely than "Important" alone lets you.

Errata IDComponentTargetRating
RHSA-2026:75582librabbitmqRHEL 8Important
RHSA-2026:75573pki-core:10.6RHEL 8Important
RHSA-2026:75580sudoRHEL 8Important
RHSA-2026:75560kernel (security, bug fix, enhancement)RHEL 10.0 EUSImportant

SUSE Linux

openSUSE put out a round of security updates, and a few of these are worth your attention. Most are tagged "moderate," the rustup update on Leap 16.0 comes in at "important," and Firefox is the one that should make you patch first.

Firefox ESR is the real headline here: it piles 62 vulnerability fixes into a single release. That is a serious backlog for a long-term browser, even if ESR typically accumulates fixes between points. If you are running the extended support build instead of the rolling Firefox, grab this first.

rustup takes the only "important" rating and closes 16 CVEs across the Rust toolchain, from openssl to rustls-webpki. The certificate-handling holes in rust-openssl are the ones worth worrying about, since a couple allow arbitrary code execution. But this announcement also quietly ships a major rewrite of rustup itself, pushing it to 1.29.1 with a changelog long enough to need its own index. Downloads go async, "triple" quietly becomes "tuple," and they swapped the logging and color stack for something newer. You will probably notice nothing, though a security patch usually does not carry this much churn.

jline3 shuts a handful of SSH and terminal-related gaps on Leap 16.0, including a native stack buffer overflow and a couple of denial-of-service conditions. The Tumbleweed side is more ordinary: libwireshark19 takes 19 fixes, while rpcbind, xdg-dbus-proxy, amazon-ecs-init, openai-codex, litellm, parted, and slirp each mop up one or two. The highest-scoring bug in that group is an 8.8 in xdg-dbus-proxy, which the patch knocks down to a local-only privilege bump. Everything installs the usual way, through YaST or "zypper patch."

Package (version)Announcement IDRatingProductFixes
binaryen (133-1.1)openSUSE-SU-2026:11915-1ModerateTumbleweed3 CVEs (CVE-2025-14956, CVE-2025-14957, CVE-2026-8257)
rustup (1.29.1~0)openSUSE-SU-2026:22016-1ImportantLeap 16.016 CVEs + 14 bug fixes; openssl RCE and rustls-webpki bypasses among them
jline3 (3.30.17)openSUSE-SU-2026:22009-1ModerateLeap 16.0SSH/terminal DoS, native stack buffer overflow, plus bug and dependency bumps
gnumeric (1.12.62+8-1.1)openSUSE-SU-2026:11919-1ModerateTumbleweed1 CVE (CVE-2026-97222)
firefox-esr (153.4.0-1.1)openSUSE-SU-2026:11917-1ModerateTumbleweed62 CVEs (CVE-2026-100756 through 100832, plus CVE-2026-96869)
libwireshark19 (4.6.9-1.1)openSUSE-SU-2026:11912-1ModerateTumbleweed19 CVEs (CVE-2026-95386 through 95395, 96415 through 96423)
xdg-dbus-proxy (0.1.9-1.1)openSUSE-SU-2026:11913-1ModerateTumbleweed2 CVEs (CVE-2026-93676, CVE-2026-94422)
amazon-ecs-init (1.107.0-1.1)openSUSE-SU-2026:11914-1ModerateTumbleweed2 CVEs (CVE-2026-41178, CVE-2026-84304)
rpcbind (1.2.9-3.1)openSUSE-SU-2026:11929-1ModerateTumbleweed1 CVE (CVE-2026-94640)
openai-codex (0.158.0-1.1)openSUSE-SU-2026:11923-1ModerateTumbleweed2 CVEs (CVE-2026-91986, CVE-2026-93657)
libslirp-devel (4.9.5+1-1.1)openSUSE-SU-2026:11922-1ModerateTumbleweed1 CVE (CVE-2026-95507)
python313-litellm (1.103.0-1.1)openSUSE-SU-2026:11927-1ModerateTumbleweed2 CVEs (CVE-2026-89032, CVE-2026-93355)
libparted-fs-resize0 (3.8-1.1)openSUSE-SU-2026:11924-1ModerateTumbleweed1 CVE (CVE-2026-89085)

How to apply these Linux security updates

Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.

Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.

Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.

Debian/Ubuntu (apt)

The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.

sudo apt update
sudo apt upgrade -y

Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)

On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.

sudo dnf check-update
sudo dnf upgrade -y

or on older releases

sudo yum check-update
sudo yum update

SUSE (zypper)

SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.

sudo zypper refresh
sudo zypper update -y