Recent security advisories for major distributions like Fedora, RHEL, and Ubuntu highlight critical vulnerabilities in common applications such as Firefox, Thunderbird, and Python libraries that could enable code execution or privilege escalation. Media processing tools including GStreamer plugins and ImageMagick require urgent patches to fix decoding errors and buffer overflows that might exhaust system resources or leak sensitive data. Kernel updates across platforms like Debian and Slackware address memory safety flaws in compression modules and low-level drivers, while enterprise versions focus on securing virtualization and application server components. Administrators should treat these notifications as urgent because leaving gaps open invites attackers to leverage known weaknesses across multiple distributions immediately.
Staying Safe in the Linux World: Managing This Week’s Critical Security Updates
Administrators face a mountain of notifications this week with security patches for major distributions including Fedora, RHEL, and Ubuntu. Ignoring these alerts risks code execution and privilege escalation on systems running older software stacks like Python or Thunderbird. Readers should focus on the shared vulnerabilities that affect almost every setup before chasing version-specific advisories for their unique hardware.
Why Linux Security Updates Matter for Shared Software
Python libraries, Firefox, and Thunderbird appear in almost every advisory batch released recently because these components handle high risk logic daily. Developers patched issues that could allow attackers to run arbitrary code on the host machine or escalate privileges to root access. Fedora and Ubuntu users will notice Firefox getting bumped alongside browser plugins that handle cookies and rendering. Thunderbird mail clients also received fixes for threats involving network connections and mail headers. These are not minor patches but actual stops for known exploits targeting email reading and web browsing habits across standard corporate deployments.
Graphics and Media Components Need Attention
GStreamer, LibreOffice libraries, and ImageMagick packages carry a high burden this week because they handle raw data streams that often contain malicious payloads. Old versions of libpng12 and libpng15 have issues that allow crashes or buffer overflows when processing image files sent through web servers. SUSE Linux administrators should check for these specifically because the media stacks on openSUSE often bundle multiple plugins in single advisories for convenience. Ubuntu notices focus heavily on decoding errors that exhaust system resources during heavy rendering tasks to prevent denial of service. A server handling images without these fixes becomes an easy target for resource depletion attacks from untrusted visitors.
Kernel and System Integrity Patches
The kernel updates vary by release cycle from RHEL 8 through Debian GNU/Linux 13, but the underlying memory safety goals remain the same. Some versions get moderate risk notes while others flag critical memory safety flaws in low level drivers that manage hardware access directly. Slackware pushed an urgent fix for the xz compression module after a buffer overflow was found inside the index append routine during file decompression. Oracle Linux and AlmaLinux focus heavily on OpenJDK and virtualization tools to ensure containers do not leak memory or access host resources improperly. Ignoring kernel updates here might leave backdoors open between applications and the physical machine.
Distinct Behaviors Across Distributions
Fedora users can expect updates for BIND 9 Next alongside Python cryptography libraries which protect internal communications. RHEL releases include patches for JBoss Enterprise Application Platform which many enterprise shops run silently in the background without realizing it. Rocky Linux mirrors these fixes closely behind Oracle but uses slightly different tracking numbers and version identifiers for the same code. Ubuntu prioritizes GStreamer plugins and Dovecot security to keep server mail systems functional against modern spam vectors. Each distribution bundles its own unique version of Python or Vim depending on how long the user has stuck with that release cycle. Some older releases might require manual intervention to verify dependencies work correctly after the main system refresh finishes.

The Security Updates in Detail
Here is an in-depth overview of the updates recently released for AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux.
AlmaLinux
AlmaLinux has pushed out numerous security patches covering versions 8 through 10 of its Linux distribution. System administrators must prioritize urgent notifications because critical vulnerabilities exist within FreeRDP and Grafana alongside memory safety issues. While kernel updates often stay at moderate risk levels, other advisories highlight significant dangers in tools like Python and Thunderbird. These combined releases affect essential packages including Squid and LibPNG to ensure overall system integrity remains intact.
- ALSA-2026:6037: kernel security update (Moderate)
- ALSA-2026:6036: kernel-rt security update (Moderate)
- ALSA-2026:5932: firefox security update (Important)
- ALSA-2026:5930: firefox security update (Important)
- ALSA-2026:5931: firefox security update (Important)
- ALSA-2026:6283: python3.12 security update (Important)
- ALSA-2026:6281: python3.11 security update (Important)
- ALSA-2026:6286: python3.11 security update (Important)
- ALSA-2026:6301: squid security update (Important)
- ALSA-2026:6266: libxslt security update (Moderate)
- ALSA-2026:6285: python3.12 security update (Important)
- ALSA-2026:6004: freerdp security update (Important)
- ALSA-2026:6342: thunderbird security update (Important)
- ALSA-2026:6256: python3.12 security update (Important)
- ALSA-2026:6390: rsync security update (Moderate)
- ALSA-2026:6340: freerdp security update (Important)
- ALSA-2026:6382: grafana security update (Important)
- ALSA-2026:6153: kernel security update (Moderate)
- ALSA-2026:6188: thunderbird security update (Important)
- ALSA-2026:6445: libpng12 security update (Important)
- ALSA-2026:6470: perl-YAML-Syck security update (Important)
- ALSA-2026:6473: python3 security update (Important)
- ALSA-2026:6005: freerdp security update (Important)
- ALSA-2026:6388: grafana-pcp security update (Important)
- ALSA-2026:6259: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update (Important)
- ALSA-2026:6344: grafana security update (Important)
- ALSA-2026:6053: kernel security update (Moderate)
- ALSA-2026:6436: rsync security update (Moderate)
- ALSA-2026:6439: libpng15 security update (Important)
- ALSA-2026:6300: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update (Important)
Debian GNU/Linux
Debian security teams have released multiple advisories addressing critical flaws within essential Linux software packages like GStreamer and NodeJS. These updates are necessary because vulnerabilities could lead to severe outcomes including code execution or privilege escalation on affected systems. Users running older distributions must pay close attention since libraries such as libpng1.6 contain use-after-free errors that allow attackers to run arbitrary code. Beyond media plugins, the advisories also cover web tools like Roundcube and Tornado which fix cookie injection risks alongside denial of service threats.
- ELA-1669-1 gst-plugins-base1.0 security update
- ELA-1670-1 gst-plugins-ugly1.0 security update
- [DLA 4514-1] gst-plugins-base1.0 security update
- [DLA 4516-1] gst-plugins-ugly1.0 security update
- [DSA 6187-1] php-phpseclib3 security update
- [DSA 6186-1] php-phpseclib security update
- [DSA 6185-1] phpseclib security update
- [DSA 6184-1] incus security update
- [DSA 6183-1] nodejs security update
- ELA-1671-1 phpseclib security update
- [DLA 4515-1] asterisk security update
- [DLA 4518-1] phpseclib security update
- [DLA 4517-1] roundcube security update
- [DLA 4519-1] netty security update
- [DSA 6189-1] libpng1.6 security update
- [DSA 6188-1] lxd security update
- ELA-1672-1 python-tornado security update
- [DLA 4520-1] python-tornado security update
- [DSA 6191-1] gst-plugins-ugly1.0 security update
- [DSA 6190-1] gst-plugins-bad1.0 security update
- [DSA 6192-1] chromium security update
- [DLA 4521-1] libpng1.6 security update
- ELA-1674-1 libpng1.6 security update
- ELA-1673-1 libpng1.6 security update
- [DSA 6194-1] pyasn1 security update
- [DSA 6193-1] inetutils security update
- [DSA 6195-1] python-tornado security update
- ELA-1675-1 libxml-parser-perl security update
- [DLA 4522-1] libxml-parser-perl security update
- [DSA 6196-1] roundcube security update
Fedora Linux
Fedora Linux users on versions 42, 43 and 44 need to apply several important security updates that were recently released. Critical vulnerabilities exist within popular packages including Python, Vim, Rust libraries and the Firefox browser that require immediate attention. Exploiting these flaws could allow attackers to execute code or cause denial of service across the platform. System administrators should install the available patches for components like polkit and BIND 9 Next without delay to maintain safety.
- Fedora 43 Update: python-cryptography-46.0.6-1.fc43
- Fedora 43 Update: mingw-expat-2.7.5-1.fc43
- Fedora 43 Update: php-phpseclib3-3.0.50-1.fc43
- Fedora 43 Update: pypy3.11-7.3.21-3.3.11.fc43
- Fedora 44 Update: python-cryptography-46.0.6-1.fc44
- Fedora 44 Update: python-pycparser-2.22-8.fc44
- Fedora 44 Update: vim-9.2.240-1.fc44
- Fedora 44 Update: mingw-expat-2.7.5-1.fc44
- Fedora 44 Update: mingw-freetype-2.14.2-1.fc44
- Fedora 44 Update: pypy3.11-7.3.21-3.3.11.fc44
- Fedora 44 Update: libsoup3-3.6.6-6.fc44
- Fedora 44 Update: libtasn1-4.21.0-1.fc44
- Fedora 42 Update: ntpd-rs-1.7.1-1.fc42
- Fedora 42 Update: perl-YAML-Syck-1.39-1.fc42
- Fedora 42 Update: stgit-2.5.5-5.fc42
- Fedora 42 Update: musescore-4.3.2-21.fc42
- Fedora 42 Update: firefox-149.0-2.fc42
- Fedora 42 Update: nss-3.121.0-1.fc42
- Fedora 43 Update: ntpd-rs-1.7.1-1.fc43
- Fedora 43 Update: rust-cargo-rpmstatus-0.2.4-3.fc43
- Fedora 43 Update: stgit-2.5.5-5.fc43
- Fedora 43 Update: perl-YAML-Syck-1.39-1.fc43
- Fedora 43 Update: dotnet8.0-8.0.125-1.fc43
- Fedora 43 Update: dotnet9.0-9.0.115-1.fc43
- Fedora 43 Update: musescore-4.6.5-34.fc43
- Fedora 44 Update: webkitgtk-2.52.1-1.fc44
- Fedora 44 Update: polkit-127-2.fc44.2
- Fedora 44 Update: rust-1.94.1-1.fc44
- Fedora 44 Update: xen-4.21.1-1.fc44
- Fedora 44 Update: python3.12-3.12.13-2.fc44
- Fedora 44 Update: bind-dyndb-ldap-11.11-13.fc44
- Fedora 44 Update: bind-9.18.47-1.fc44
- Fedora 44 Update: freerdp-3.24.2-1.fc44
- Fedora 44 Update: ntpd-rs-1.7.1-1.fc44
- Fedora 44 Update: rust-cargo-vendor-filterer-0.5.18-4.fc44
- Fedora 44 Update: rust-cargo-rpmstatus-0.2.4-3.fc44
- Fedora 44 Update: stgit-2.5.5-5.fc44
- Fedora 44 Update: perl-YAML-Syck-1.39-1.fc44
- Fedora 44 Update: pyOpenSSL-26.0.0-1.fc44
- Fedora 44 Update: nss-3.121.0-1.fc44
- Fedora 42 Update: mingw-expat-2.7.5-1.fc42
- Fedora 42 Update: php-phpseclib3-3.0.50-1.fc42
- Fedora 44 Update: python3.14-3.14.3-2.fc44
- Fedora 44 Update: insight-18.0.50.20260306-2.fc44
- Fedora 44 Update: rust-scx_rusty-0.5.4-8.fc44
- Fedora 44 Update: rust-scx_rustland-0.0.3-8.fc44
- Fedora 44 Update: rust-scx_layered-0.0.6-8.fc44
- Fedora 44 Update: rust-resctl-bench-2.2.5-12.fc44
- Fedora 44 Update: cpp-httplib-0.38.0-1.fc44
- Fedora 42 Update: xen-4.19.5-1.fc42
- Fedora 42 Update: insight-18.0.50.20260306-2.fc42
- Fedora 42 Update: firefox-149.0-4.fc42
- Fedora 42 Update: rust-resctl-bench-2.2.5-12.fc42
- Fedora 42 Update: rust-cargo-vendor-filterer-0.5.18-4.fc42
- Fedora 42 Update: cpp-httplib-0.37.2-1.fc42
- Fedora 42 Update: rust-cargo-rpmstatus-0.2.4-3.fc42
- Fedora 43 Update: python-gstreamer1-1.26.11-1.fc43
- Fedora 43 Update: gstreamer1-vaapi-1.26.11-1.fc43
- Fedora 43 Update: gstreamer1-rtsp-server-1.26.11-1.fc43
- Fedora 43 Update: gstreamer1-plugins-bad-free-1.26.11-1.fc43
- Fedora 43 Update: gstreamer1-plugins-ugly-free-1.26.11-1.fc43
- Fedora 43 Update: gstreamer1-doc-1.26.11-1.fc43
- Fedora 43 Update: gstreamer1-1.26.11-1.fc43
- Fedora 43 Update: gst-editing-services-1.26.11-1.fc43
- Fedora 43 Update: gst-devtools-1.26.11-1.fc43
- Fedora 43 Update: gstreamer1-plugins-good-1.26.11-1.fc43
- Fedora 43 Update: gstreamer1-plugins-base-1.26.11-1.fc43
- Fedora 43 Update: gstreamer1-plugin-libav-1.26.11-1.fc43
- Fedora 43 Update: rust-1.94.1-1.fc43
- Fedora 43 Update: insight-18.0.50.20260306-2.fc43
- Fedora 43 Update: freerdp-3.24.2-1.fc43
- Fedora 43 Update: rust-resctl-bench-2.2.5-12.fc43
- Fedora 43 Update: chunkah-0.3.2-1.fc43
- Fedora 43 Update: cpp-httplib-0.38.0-1.fc43
- Fedora 43 Update: rust-cargo-vendor-filterer-0.5.18-4.fc43
- Fedora 43 Update: polkit-126-6.fc43.2
- Fedora 43 Update: python3.14-3.14.3-2.fc43
- Fedora 43 Update: crun-1.27-1.fc43
- Fedora 43 Update: bpfman-0.5.4-5.fc43
- Fedora 43 Update: rust-rustls-webpki-0.103.10-1.fc43
- Fedora 43 Update: rust-scx_rustland-0.0.3-8.fc43
- Fedora 43 Update: rust-scx_layered-0.0.6-8.fc43
- Fedora 43 Update: rust-scx_rusty-0.5.4-8.fc43
- Fedora 43 Update: gnome-remote-desktop-49.3-2.fc43
- Fedora 42 Update: bpfman-0.5.4-6.fc42
- Fedora 42 Update: rust-rustls-webpki-0.103.10-1.fc42
- Fedora 42 Update: rust-sccache-0.12.0-4.fc42
- Fedora 42 Update: rust-scx_rustland-0.0.3-8.fc42
- Fedora 42 Update: rust-scx_rusty-0.5.4-8.fc42
- Fedora 42 Update: rust-scx_layered-0.0.6-8.fc42
- Fedora 43 Update: openbao-2.5.2-1.fc43
- Fedora 43 Update: bind9-next-9.21.20-1.fc43
- Fedora 42 Update: tcpflow-1.6.2-0.1.8d47b53.fc42
- Fedora 42 Update: python3.14-3.14.3-2.fc42
- Fedora 42 Update: libgsasl-1.10.0-15.fc42
- Fedora 42 Update: python3.12-3.12.13-2.fc42
- Fedora 42 Update: python3.9-3.9.25-7.fc42
- Fedora 42 Update: domoticz-2026.1-1.fc42
- Fedora 43 Update: vim-9.2.280-1.fc43
- Fedora 43 Update: chromium-146.0.7680.177-1.fc43
- Fedora 43 Update: tcpflow-1.6.2-0.1.8d47b53.fc43
- Fedora 43 Update: python3.9-3.9.25-7.fc43
- Fedora 43 Update: libgsasl-1.10.0-15.fc43
- Fedora 43 Update: domoticz-2026.1-1.fc43
- Fedora 42 Update: gstreamer1-vaapi-1.26.11-1.fc42
- Fedora 42 Update: gstreamer1-plugins-base-1.26.11-1.fc42
- Fedora 42 Update: gstreamer1-plugins-bad-free-1.26.11-1.fc42
- Fedora 42 Update: gstreamer1-plugin-libav-1.26.11-1.fc42
- Fedora 42 Update: gstreamer1-1.26.11-1.fc42
- Fedora 42 Update: python-gstreamer1-1.26.11-1.fc42
- Fedora 42 Update: gst-devtools-1.26.11-1.fc42
- Fedora 42 Update: gstreamer1-plugins-ugly-free-1.26.11-1.fc42
- Fedora 42 Update: gstreamer1-rtsp-server-1.26.11-1.fc42
- Fedora 42 Update: gstreamer1-plugins-good-1.26.11-1.fc42
- Fedora 42 Update: gst-editing-services-1.26.11-1.fc42
- Fedora 42 Update: gstreamer1-doc-1.26.11-1.fc42
- Fedora 42 Update: python3.13-3.13.12-2.fc42
- Fedora 42 Update: freerdp-3.24.2-1.fc42
- Fedora 42 Update: openbao-2.5.2-1.fc42
- Fedora 42 Update: bind9-next-9.21.20-1.fc42
- Fedora 42 Update: libopenmpt-0.8.6-1.fc42
- Fedora 42 Update: cmake-3.31.11-1.fc42
- Fedora 42 Update: rust-1.94.1-1.fc42
- Fedora 42 Update: mingw-binutils-2.43.1-6.fc42
- Fedora 42 Update: mingw-gstreamer1-plugins-base-1.26.11-1.fc42
- Fedora 42 Update: mingw-gstreamer1-plugins-good-1.26.11-1.fc42
- Fedora 42 Update: mingw-gstreamer1-1.26.11-1.fc42
- Fedora 42 Update: mingw-gstreamer1-plugins-bad-free-1.26.11-1.fc42
- Fedora 42 Update: mapserver-8.4.1-3.fc42
- Fedora 42 Update: mingw-python3-3.11.15-2.fc42
- Fedora 42 Update: mingw-libpng-1.6.56-1.fc42
- Fedora 43 Update: libinput-1.30.3-1.fc43
- Fedora 43 Update: mingw-binutils-2.45.1-2.fc43
- Fedora 43 Update: mingw-gstreamer1-plugins-bad-free-1.26.11-1.fc43
- Fedora 43 Update: mingw-gstreamer1-1.26.11-1.fc43
- Fedora 43 Update: mingw-gstreamer1-plugins-base-1.26.11-1.fc43
- Fedora 43 Update: mingw-gstreamer1-plugins-good-1.26.11-1.fc43
- Fedora 43 Update: mapserver-8.4.1-3.fc43
- Fedora 43 Update: mingw-python3-3.11.15-2.fc43
- Fedora 43 Update: mingw-libpng-1.6.56-1.fc43
- Fedora 43 Update: rust-sccache-0.14.0-2.fc43
Oracle Linux
Oracle Linux administrators must apply a significant batch of security patches covering versions seven through ten soon. Critical updates target popular software including Firefox and Thunderbird alongside essential system components like the kernel and OpenJDK libraries. Python and FreeRDP also receive important updates that address significant vulnerabilities across all supported releases. Administrators must prioritize these actions to mitigate the identified security risks effectively.
- ELSA-2026-50170 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
- ELBA-2026-6009 Oracle Linux 9 java-25-openjdk bug fix and enhancement update
- ELSA-2026-5578 Moderate: Oracle Linux 8 virt:ol and virt-devel:ol security update
- ELSA-2026-5932 Important: Oracle Linux 8 firefox security update
- ELSA-2026-6004 Important: Oracle Linux 9 freerdp security update
- ELSA-2026-6005 Important: Oracle Linux 8 freerdp security update
- ELSA-2026-4756 Important: Oracle Linux 7 libpng security update
- ELSA-2026-4471 Important: Oracle Linux 7 freerdp security update
- ELSA-2026-50171 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
- ELBA-2026-6010 Oracle Linux 8 gnome-shell-extensions bug fix and enhancement update
- ELSA-2026-50171 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-5931 Important: Oracle Linux 10 firefox security update
- ELSA-2026-6188 Important: Oracle Linux 9 thunderbird security update
- ELSA-2026-6053 Moderate: Oracle Linux 10 kernel security update
- ELSA-2026-5930 Important: Oracle Linux 9 firefox security update
- ELSA-2026-50171 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
- ELBA-2026-50169 Oracle Linux 10 oracle-common-release bug fix update
- ELBA-2026-50168 Oracle Linux 10 oraclelinux-release-el10 bug fix update
- ELSA-2026-50170 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-6342 Important: Oracle Linux 10 thunderbird security update
- ELSA-2026-6259 Important: Oracle Linux 10 gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update
- ELSA-2026-6256 Important: Oracle Linux 10 python3.12 security update
- ELBA-2026-6009 Oracle Linux 10 java-25-openjdk bug fix and enhancement update
- ELSA-2026-6301 Important: Oracle Linux 9 squid security update
- ELSA-2026-6340 Important: Oracle Linux 9 freerdp security update
- ELSA-2026-6286 Important: Oracle Linux 9 python3.11 security update
- ELSA-2026-6285 Important: Oracle Linux 9 python3.12 security update
- ELSA-2026-6266 Moderate: Oracle Linux 9 libxslt security update
- ELSA-2026-6153 Moderate: Oracle Linux 9 kernel security update
- ELSA-2026-6283 Important: Oracle Linux 8 python3.12 security update
- ELSA-2026-6281 Important: Oracle Linux 8 python3.11 security update
- ELSA-2026-6037 Moderate: Oracle Linux 8 kernel security update
Red Hat Enterprise Linux
Red Hat Product Security has released a series of security updates targeting various components on different RHEL versions. Affected software ranges from kernel tools and application platforms down to specific libraries like LibPNG. Severity ratings for these updates vary significantly since some advisories regarding Python versions carry an important rating while others are simply marked as moderate. The collective goal is to address vulnerabilities across multiple software packages used in their enterprise Linux distributions.
- RHSA-2026:6006: Moderate: opencryptoki security update
- RHSA-2026:6037: Moderate: kernel security update
- RHSA-2026:6005: Important: freerdp security update
- RHSA-2026:6007: Moderate: python security update
- RHSA-2026:6008: Moderate: python3 security update
- RHSA-2026:6011: Critical: Red Hat JBoss Enterprise Application Platform 7.3.17 security update
- RHSA-2026:6012: Important: Red Hat JBoss Enterprise Application Platform 7.1.14 security update
- RHSA-2026:6036: Moderate: kernel-rt security update
- RHSA-2026:6053: Moderate: kernel security update
- RHSA-2026:6191: Moderate: container-tools:rhel8 security update
- RHSA-2026:6234: Moderate: nginx security update
- RHSA-2026:6220: Moderate: 389-ds-base security update
- RHSA-2026:6193: Moderate: kernel security update
- RHSA-2026:6188: Important: thunderbird security update
- RHSA-2026:6164: Moderate: kernel security update
- RHSA-2026:6182: Moderate: nginx security update
- RHSA-2026:6153: Moderate: kernel security update
- RHSA-2026:6004: Important: freerdp security update
- RHSA-2026:6256: Important: python3.12 security update
- RHSA-2026:6259: Important: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update
- RHSA-2026:6268: Moderate: 389-ds:1.4 security update
- RHSA-2026:6283: Important: python3.12 security update
- RHSA-2026:6281: Important: python3.11 security update
- RHSA-2026:6277: Important: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update
- RHSA-2026:6266: Moderate: libxslt security update
- RHSA-2026:6253: Moderate: python3.11 security update
- RHSA-2026:6235: Moderate: nginx security update
- RHSA-2026:6285: Important: python3.12 security update
- RHSA-2026:6286: Important: python3.11 security update
- RHSA-2026:5877: Moderate: OpenShift Container Platform 4.19.27 bug fix and security update
- RHSA-2026:6342: Important: thunderbird security update
- RHSA-2026:5866: Important: OpenShift Container Platform 4.17.52 packages and security update
- RHSA-2026:5867: Moderate: OpenShift Container Platform 4.17.52 bug fix and security update
- RHSA-2026:6344: Important: grafana security update
- RHSA-2026:5876: Moderate: OpenShift Container Platform 4.19.27 packages and security update
- RHSA-2026:6341: Important: Red Hat build of Cryostat security update
- RHSA-2026:6340: Important: freerdp security update
- RHSA-2026:6278: Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
- RHSA-2026:6384: Important: freerdp security update
- RHSA-2026:6388: Important: grafana-pcp security update
- RHSA-2026:6395: Important: freerdp security update
- RHSA-2026:6385: Important: freerdp security update
- RHSA-2026:6407: Moderate: nginx:1.24 security update
- RHSA-2026:6408: Moderate: nginx security update
- RHSA-2026:6396: Important: freerdp security update
- RHSA-2026:6391: Moderate: mysql:8.4 security update
- RHSA-2026:6390: Moderate: rsync security update
- RHSA-2026:6383: Important: grafana-pcp security update
- RHSA-2026:6382: Important: grafana security update
- RHSA-2026:6311: Moderate: nginx security update
- RHSA-2026:6302: Moderate: nginx:1.24 security update
- RHSA-2026:6445: Important: libpng12 security update
- RHSA-2026:6439: Important: libpng15 security update
- RHSA-2026:6435: Moderate: mariadb:10.11 security update
- RHSA-2026:6436: Moderate: rsync security update
- RHSA-2026:6427: Moderate: nginx:1.26 security update
- RHSA-2026:6462: Important: openssh security update
- RHSA-2026:6470: Important: perl-YAML-Syck security update
- RHSA-2026:6469: Important: libpng15 security update
- RHSA-2026:6468: Important: libpng15 security update
- RHSA-2026:6463: Important: openssh security update
- RHSA-2026:6464: Moderate: python3 security update
- RHSA-2026:6473: Important: python3 security update
- RHSA-2026:5873: Moderate: OpenShift Container Platform 4.16.59 bug fix and security update
- RHSA-2026:6478: Important: Red Hat build of Keycloak 26.4.11 Images Update
- RHSA-2026:6477: Important: Red Hat build of Keycloak 26.4.11 Update
- RHSA-2026:6539: Important: vim security update
- RHSA-2026:6540: Important: vim security update
- RHSA-2026:6502: Important: vim security update
- RHSA-2026:6499: Moderate: libxslt security update
- RHSA-2026:6481: Important: Updated service-interconnect rhel9 container images for 1.8
- RHSA-2026:6476: Important: Red Hat build of Keycloak 26.2.15 Images Update
- RHSA-2026:6475: Important: Red Hat build of Keycloak 26.2.15 Update
- RHSA-2026:6461: Important: openssh security update
- RHSA-2026:6467: Important: libpng15 security update
- RHSA-2026:6466: Important: libpng15 security update
Rocky Linux
Rocky Linux 8 administrators should review two recent security notifications affecting their infrastructure. Although one title references MySQL, the details indicate that mecab-ipadic modules are actually the affected components needing updates. Separately, an update addresses MariaDB version 10.11 and labels that security gap as a moderate risk using CVSS standards. System administrators must install these fixes promptly to ensure safety.
- RLSA-2026:6391: Moderate: mysql:8.4 security update
- RLSA-2026:6435: Moderate: mariadb:10.11 security update
Slackware Linux
Slackware Linux just pushed urgent security updates for the xz package after critical flaws were discovered in versions 15.0 and current. Developers fixed a buffer overflow inside lzma_index_append alongside some memory access issues found when handling files. Meanwhile, the Security Team also issued advisories recently regarding Krita and Infozip applications to keep systems safe. Users running version 15.0 should install the new Krita package which resolves a heap based buffer overflow vulnerability during TGA file parsing.
SUSE Linux
Recent patches for SUSE Linux and openSUSE address vulnerabilities across multiple software packages including FreeIPMI and ImageMagick within the Tumbleweed distribution now available on GA media. While most advisories are marked as moderate in severity, specific tools like Thunderbird carry an urgent rating requiring prompt action from system managers. In the Chromium update on Leap 16.0, there are 21 specific vulnerabilities including buffer overflows that could allow attackers to execute arbitrary code if not patched immediately. Immediate action is required from administrators because unpatched systems remain exposed to potential exploits ranging from database issues to Python library flaws.
- openSUSE-SU-2026:10436-1: moderate: freeipmi-1.6.17-1.1 on GA media
- openSUSE-SU-2026:10431-1: moderate: python311-oci-sdk-2.168.3-1.1 on GA media
- openSUSE-SU-2026:10430-1: moderate: python311-lmdb-2.1.1-1.1 on GA media
- openSUSE-SU-2026:10427-1: moderate: jupyter-matplotlib-0.11.7-17.1 on GA media
- openSUSE-SU-2026:10429-1: moderate: jupyter-jupyterlab-templates-0.5.2-4.1 on GA media
- SUSE-SU-2026:1135-1: important: Security update for govulncheck-vulndb
- openSUSE-SU-2026:0109-1: moderate: Security update for obs-service-recompress, obs-service-tar_scm
- openSUSE-SU-2026:0108-1: moderate: Security update for obs-service-set_version
- openSUSE-SU-2026:0107-1: moderate: Security update for libjxl
- openSUSE-SU-2026:0106-1: moderate: Security update for libjxl
- openSUSE-SU-2026:10443-1: moderate: libsuricata8_0_4-8.0.4-1.1 on GA media
- openSUSE-SU-2026:10446-1: moderate: ImageMagick-7.1.2.18-1.1 on GA media
- openSUSE-SU-2026:10440-1: moderate: jupyter-nbclassic-1.3.3-1.1 on GA media
- openSUSE-SU-2026:10445-1: moderate: traefik2-2.11.42-1.1 on GA media
- openSUSE-SU-2026:10442-1: moderate: dovecot24-2.4.3-1.1 on GA media
- openSUSE-SU-2026:10444-1: moderate: traefik-3.6.12-1.1 on GA media
- openSUSE-SU-2026:10441-1: moderate: strongswan-6.0.5-1.1 on GA media
- openSUSE-SU-2026:10439-1: moderate: plexus-utils-4.0.2-2.1 on GA media
- openSUSE-SU-2026:10438-1: moderate: openbao-2.5.2-1.1 on GA media
- openSUSE-SU-2026:0110-1: important: Security update for perl-Crypt-URandom
- SUSE-SU-2026:1150-1: important: Security update for webkit2gtk3
- openSUSE-SU-2026:10449-1: moderate: gsl-2.8-5.1 on GA media
- openSUSE-SU-2026:10447-1: moderate: MozillaThunderbird-140.9.0-1.1 on GA media
- openSUSE-SU-2026:10456-1: moderate: tailscale-1.96.4-1.1 on GA media
- openSUSE-SU-2026:10452-1: moderate: libjavamapscript-8.6.1-1.1 on GA media
- openSUSE-SU-2026:10455-1: moderate: python311-requests-2.33.0-1.1 on GA media
- openSUSE-SU-2026:10448-1: moderate: bind-9.20.21-1.1 on GA media
- openSUSE-SU-2026:10450-1: moderate: incus-6.23-1.1 on GA media
- openSUSE-SU-2026:10453-1: moderate: libpolkit-agent-1-0-127-3.1 on GA media
- openSUSE-SU-2026:10451-1: moderate: libpng16-16-1.6.56-1.1 on GA media
- SUSE-SU-2026:1153-1: important: Security update for perl-XML-Parser
- openSUSE-SU-2026:0111-1: important: Security update for tinyproxy
- SUSE-SU-2026:1160-1: important: Security update for freerdp
- SUSE-SU-2026:1163-1: important: Security update for MozillaThunderbird
- openSUSE-SU-2026:10458-1: moderate: MozillaFirefox-149.0-1.1 on GA media
- openSUSE-SU-2026:10465-1: moderate: ImageMagick-7.1.2.18-2.1 on GA media
- openSUSE-SU-2026:10462-1: moderate: heroic-games-launcher-2.20.1-4.1 on GA media
- openSUSE-SU-2026:10466-1: moderate: expat-2.7.5-1.1 on GA media
- openSUSE-SU-2026:10461-1: moderate: python311-nltk-3.9.4-1.1 on GA media
- openSUSE-SU-2026:10463-1: moderate: netty-4.1.132-1.1 on GA media
- openSUSE-SU-2026:10457-1: moderate: xen-4.21.1_02-1.1 on GA media
- openSUSE-SU-2026:10459-1: moderate: freerdp2-2.11.7-6.1 on GA media
- openSUSE-SU-2026:20448-1: important: Security update for expat
- openSUSE-SU-2026:20449-1: important: Security update for postgresql13
- openSUSE-SU-2026:20452-1: important: Security update for kea
- openSUSE-SU-2026:20444-1: important: Security update for tomcat10
- openSUSE-SU-2026:20447-1: important: Security update for postgresql16
- openSUSE-SU-2026:20437-1: moderate: Security update for net-tools
- SUSE-SU-2026:1166-1: important: Security update for expat
- openSUSE-SU-2026:10476-1: moderate: python311-Pygments-2.20.0-2.1 on GA media
- openSUSE-SU-2026:10475-1: moderate: opensc-0.27.1-1.1 on GA media
- openSUSE-SU-2026:10474-1: moderate: ignition-2.26.0-3.1 on GA media
- openSUSE-SU-2026:10472-1: moderate: conftest-0.67.1-2.1 on GA media
- openSUSE-SU-2026:10468-1: moderate: python311-ecdsa-0.19.2-1.1 on GA media
- openSUSE-SU-2026:10467-1: moderate: ovmf-202602-6.1 on GA media
- openSUSE-SU-2026:10470-1: moderate: libXvnc-devel-1.16.1-2.1 on GA media
- openSUSE-SU-2026:10469-1: moderate: python315-3.15.0~a7-3.1 on GA media
- openSUSE-SU-2026:10473-1: moderate: dnsdist-2.0.3-1.1 on GA media
- openSUSE-SU-2026:0112-1: important: Security update for chromium
- openSUSE-SU-2026:0113-1: important: Security update for chromium
- SUSE-SU-2026:1177-1: important: Security update for tar
- SUSE-SU-2026:1178-1: moderate: Security update for libsoup
- SUSE-SU-2026:1179-1: moderate: Security update for libsoup2
- SUSE-SU-2026:1173-1: important: Security update for LibVNCServer
- openSUSE-SU-2026:0115-1: critical: Security update for osslsigncode
- openSUSE-SU-2026:0117-1: important: Security update for keybase-client
- openSUSE-SU-2026:0116-1: critical: Security update for osslsigncode
- openSUSE-SU-2026:10482-1: moderate: osslsigncode-2.13-1.1 on GA media
- openSUSE-SU-2026:10481-1: moderate: python314-3.14.3-4.1 on GA media
- openSUSE-SU-2026:10480-1: moderate: python313-3.13.12-3.1 on GA media
- openSUSE-SU-2026:20460-1: important: Security update for chromium
- openSUSE-SU-2026:20458-1: important: Security update for python-Pillow
- openSUSE-SU-2026:10485-1: moderate: python311-Flask-Cors-6.0.2-1.1 on GA media
Ubuntu Linux
Ubuntu recently released a series of security notices addressing vulnerabilities across GStreamer plugins and various Python libraries including PyJWT. Attackers could exploit these flaws to execute arbitrary code or bypass authentication checks through specially crafted input data. Specific updates fix decoding errors that could exhaust system resources while others address memory management flaws within libraries like Undertow and the kernel itself. Ultimately this protects the system from being compromised by malicious actors leveraging these known weaknesses across multiple versions of the operating system.
- [USN-8130-1] GStreamer Base Plugins vulnerability
- [USN-8129-1] pyasn1 vulnerability
- [USN-8131-1] GStreamer Good Plugins vulnerabilities
- [USN-8132-1] Roundcube Webmail vulnerabilities
- [USN-8133-1] PyJWT vulnerability
- [USN-8134-1] pyasn1 vulnerabilities
- [USN-8127-1] ImageMagick vulnerabilities
- [USN-8135-1] Pillow vulnerabilities
- [USN-8136-1] Dovecot vulnerabilities
- [USN-8137-1] Ruby vulnerability
- [USN-8089-2] Go Networking vulnerabilities
- [USN-8138-1] tar-rs vulnerability
- [USN-8139-1] cargo-c vulnerability
- [USN-8143-1] Linux kernel vulnerabilities
- [USN-8142-1] Linux kernel vulnerability
- [USN-8095-5] Linux kernel (Raspberry Pi) vulnerabilities
- [USN-8141-1] Linux kernel (Raspberry Pi) vulnerabilities
- [USN-8094-5] Linux kernel (Raspberry Pi) vulnerabilities
- [USN-8144-1] Undertow vulnerability
- [USN-8148-3] Linux kernel (Real-time) vulnerabilities
- [USN-8145-2] Linux kernel (FIPS) vulnerabilities
- [USN-8143-2] Linux kernel (FIPS) vulnerabilities
- [USN-8148-2] Linux kernel (FIPS) vulnerabilities
- [USN-8146-1] libjxl vulnerability
- [USN-8140-1] Cairo vulnerabilities
- [USN-8148-1] Linux kernel vulnerabilities
- [USN-8149-1] Linux kernel vulnerabilities
- [USN-8145-1] Linux kernel vulnerabilities
That is enough reading for today. Time to run your update commands before next morning arrives and a scanner flags the unpatched box.