Linux distributions released a wave of mass security patches this week, hitting core infrastructure packages like glibc, the Linux kernel, WebKitGTK, and .NET 8 through 10 to close active exploitation pathways. Enterprise admins on RHEL-family systems should prioritize the new advisories for OpenShift, SSSD, and the real-time kernel, while Fedora and Ubuntu users need to apply the latest Chromium, Firefox, and Python 3.14 hardening immediately. With high-severity flaws like CVE-2026-46323 and widespread memory corruption bugs targeting production workloads, delaying these updates is effectively leaving enterprise networks exposed to automated scanning. Running your package manager this week is the only safe move before your maintenance windows close.
Linux distributions push a massive coordinated wave of security patches across every major release
Linux distros didn't hold back this week. If you manage anything running AlmaLinux, Debian, Fedora, Oracle, RHEL, Rocky, Slackware, SUSE, or Ubuntu, your package repositories just received a heavy dose of hardening. The wave hit in late July 2026 and targets the exact libraries keeping your containers, servers, and workstations alive.
The updates cover the usual suspects, though this round reads like a synchronized upstream audit. glibc, the Linux kernel, WebKitGTK, glib2, and libtiff all received critical fixes. Apache httpd and nginx share the blame for another round of hardening. .NET 8 through 10, Node.js 22, and Python 3.14 are all getting patched. If you're running any of those on production hardware, you already know what to do.
Enterprise and RHEL-family distributions
Red Hat Product Security issued a torrent of RHSA advisories alongside Oracle and AlmaLinux. Administrators on RHEL 8, 9, and 10 are getting fixes for SSSD, glib2, the Ansible Automation Platform, and multiple OpenShift Container Platform versions. The kernel updates split across standard, real-time, NVIDIA, and Azure builds.
Rocky Linux mirrors the Red Hat playbook with RLSA-2026 notices that patch .NET 8 through 10, Node.js 22, and Python 3.14. AlmaLinux's batch is particularly heavy, covering CVE-2026-46323 and a straightforward XFS filesystem correction for version 9. Oracle Linux pushed fixes for .NET SDKs, glibc, httpd, and kernel maintenance across versions seven through ten on x86_64 and aarch64.
Debian issued DLA and DSA notices for stable and legacy LTS, fixing libnfs integer overflows, TIFF memory corruption, and cache poisoning in pdns-recursor. SUSE's advisory wave spans openSUSE Leap, Tumbleweed, SLE-15-SP7, and SLE-16.0, hitting Chromium, Suricata, Podman, and Python 3.11 through 3.14. Slackware kept it quieter, releasing SSA advisories for libssh, Mozilla Firefox, and Thunderbird 140.13 ESR.
Fedora and Ubuntu round out the week
Fedora 43 and 44 dropped patches for seventeen CVEs in dotnet8 alone. The project also shipped Firefox 153.0 and a Chromium update that patches SCP path traversal flaws in python-asyncssh. You'll also want to grab the latest nuclei, routinator, btrbk, and Skopeo updates before they show up on someone else's vulnerability scan.
Ubuntu's USN round runs from USN-8572 through USN-8603. They covered wget, Apache HTTP Server, nginx, PHP, FreeRDP, OpenSSH, CUPS, and ImageMagick. The kernel patches are split across standard builds, NVIDIA, IBM, Oracle, OEM, Tegra, and a separate sweep for Azure and Azure FDE on 26.04 LTS. UBports slipped in Ubuntu Touch OTA 2.0 alongside the desktop releases, moving the mobile OS to Ubuntu 24.04 LTS and upgrading Morph Browser to Chromium 134.
Latest Security Updates by Distribution
Here’s a complete breakdown of the security updates for AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux.
AlmaLinux
AlmaLinux issued several batches of security advisories across versions 8, 9, and 10. The updates patch dozens of high-risk flaws in widely used packages including Python 3, the Linux kernel, OpenJDK versions 8 through 21, OpenSSL, glibc, Apache httpd, and WebKitGTK. System administrators on these releases must apply the patches immediately to resolve issues like CVE-2026-46323, a use-after-free bug in the network subsystem, alongside an XFS filesystem correction for version 9. These coordinated releases safeguard critical database connections, core system libraries, and enterprise infrastructure from active exploitation.
- ALSA-2026:25902: fence-agents security update (Important)
- ALSA-2026:39323: pacemaker security update (Important)
- ALSA-2026:41892: libtiff security, bug fix, and enhancement update (Important)
- ALSA-2026:39309: capstone security update (Low)
- ALSA-2026:40831: hplip security update (Important)
- ALSA-2026:40856: python3.14 security update (Important)
- ALSA-2026:40895: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update (Important)
- ALSA-2026:40751: gimp security update (Important)
- ALSA-2026:40841: maven:3.8 security update (Important)
- ALSA-2026:40894: hplip security update (Important)
- ALSA-2026:36675: gstreamer1-plugins-good security update (Important)
- ALSA-2026:39547: perl-XML-LibXML security update (Important)
- ALSA-2026:36196: 389-ds-base security update (Important)
- ALSA-2026:39976: hplip security update (Important)
- ALSA-2026:36203: freerdp security update (Important)
- ALSA-2026:36673: gstreamer1-plugins-ugly-free security update (Moderate)
- ALSA-2026:39573: yggdrasil security update (Important)
- ALSA-2026:41988: dovecot security update (Important)
- ALSA-2026:42063: glib2 security update (Important)
- ALSA-2026:42096: c-ares security update (Important)
- ALSA-2026:41947: nodejs:22 security, bug fix, and enhancement update (Important)
- ALSA-2026:42088: webkit2gtk3 security update (Important)
- ALSA-2026:42090: glib2 security update (Important)
- ALSA-2026:42550: kernel-rt security, bug fix, and enhancement update (Important)
- ALSA-2026:42552: kernel security, bug fix, and enhancement update (Important)
- ALSA-2026:42062: webkit2gtk3 security update (Important)
- ALSA-2026:42089: glib2 security update (Important)
- ALSA-2026:41949: python3.14 security update (Important)
- ALSA-2026:41906: httpd security, bug fix, and enhancement update (Important)
- ALSA-2026:43420: acl security update (Important)
- ALSA-2026:43218: pki-deps:10.6 security update (Important)
- ALSA-2026:42733: glibc security update (Moderate)
- ALSA-2026:41948: javapackages-tools:201801 security update (Important)
- ALSA-2026:42828: httpd:2.4 security, bug fix, and enhancement update (Important)
- ALSA-2026:11507: grafana security update (Important)
- ALSA-2026:11514: grafana-pcp security update (Important)
- ALSA-2026:10704: go-toolset:rhel8 security update (Important)
- ALSA-2026:42694: glibc security update (Moderate)
- ALSA-2026:35826: grafana-pcp security update (Important)
- ALSA-2026:35832: golang-github-openprinting-ipp-usb security update (Important)
- ALSA-2026:36189: perl-HTTP-Daemon security update (Important)
- ALSA-2026:35827: grafana security update (Important)
- ALSA-2026:41937: sssd security update (Important)
- ALSA-2026:43400: dogtag-pki security update (Important)
- ALSA-2026:42739: acl security update (Important)
- ALSA-2026:41905: dovecot security update (Important)
- ALSA-2026:42736: acl security update (Important)
- ALSA-2026:42668: libtiff security update (Important)
- ALSA-2026:44391: libpq security update (Important)
- ALSA-2026:43505: mariadb-connector-c security update (Important)
- ALSA-2026:44308: libpq security update (Important)
- ALSA-2026:42952: glibc security update (Moderate)
- ALSA-2026:45115: kernel security update (Important)
- ALSA-2026:45116: kernel-rt security update (Important)
- ALSA-2026:42877: java-1.8.0-openjdk security update (Important)
- ALSA-2026:42895: java-21-openjdk security update (Important)
- ALSA-2026:42887: java-17-openjdk security update (Important)
- ALSA-2026:42877: java-1.8.0-openjdk security update (Important)
- ALSA-2026:43307: kernel security, bug fix, and enhancement update (Important)
- ALSA-2026:42887: java-17-openjdk security update (Important)
- ALSA-2026:42122: sssd security update (Important)
- ALSA-2026:42895: java-21-openjdk security update (Important)
- ALSA-2026:44438: compat-openssl11 security update (Important)
- ALSA-2026:42919: kernel security, bug fix, and enhancement update (Important)
- ALSA-2026:42895: java-21-openjdk security update (Important)
- ALSA-2026:44270: kernel security update (Important)
- ALBA-2026:39332: kernel bug fix and enhancement update (None)
Debian GNU/Linux
Debian issued a series of security advisories that fix dozens of vulnerabilities across stable and legacy Long Term Support distributions. The patches cover widely used packages including libnfs, Tiff, ImageMagick, the Linux kernel, Samba, NSS, Firefox ESR, Chromium, BIND9, pdns-recursor, Webkit2GTK, Squid, WordPress, spice-vdagent, GRUB2, and Exim4. Flaws in libnfs allow unchecked string lengths to trigger integer overflows, while malformed TIFF files processed by the updated library enable arbitrary code execution or system crashes. Additional fixes close cache poisoning risks in pdns-recursor, privilege escalation and denial of service issues in the Linux kernel, and path traversal vulnerabilities in spice-vdagent before administrators miss their installation deadlines.
- ELA-1775-1 libnfs security update (by )
- [DSA 6392-1] tiff security update
- [DSA 6391-1] roundcube security update
- ELA-1776-1 imagemagick security update
- [DLA 4691-1] rtpengine security update
- [DSA 6393-1] linux security update
- [DLA 4692-1] samba security update
- ELA-1777-1 tomcat8 security update (by )
- [DLA 4693-1] roundcube security update
- [DLA 4690-1] xz-utils security update
- ELA-1779-1 samba security update (by )
- ELA-1778-1 imagemagick security update (by )
- [DLA 4694-1] nss security update
- ELA-1781-1 nss security update
- ELA-1780-1 nss security update
- [DSA 6394-1] firefox-esr security update
- [DSA 6396-1] chromium security update
- [DSA 6395-1] bind9 security update
- [DLA 4695-1] firefox-esr security update
- [DSA 6397-1] pdns-recursor security update
- [DSA 6398-1] webkit2gtk security update
- [DLA 4697-1] squid security update
- [DSA 6399-1] wordpress security update
- ELA-1782-1 squid security update
- [DLA 4698-1] spice-vdagent security update
- [DLA 4696-1] imagemagick security update
- ELA-1783-1 grub2 security update (by )
- [DSA 6400-1] exim4 security update
Fedora Linux
The Fedora Project released coordinated security patches for Fedora 43 and Fedora 44, addressing dozens of vulnerabilities across a massive list of system packages including python-asyncssh, libseccomp, mbedtls, OpenSSH, Wireshark, the Linux kernel, Nginx, Chromium, .NET Runtime, Firefox, Docker Engine, and Core Utilities. Key advisories fix critical flaws such as SCP path traversal vulnerabilities in python-asyncssh that enable unauthorized file modifications, alongside seventeen documented CVEs in dotnet8 and security holes affecting nuclei, routinator dependencies, btrbk, mupdf, Skopeo, Netatalk, Mbed TLS, Perl DBI, xrdp, Libreswan, and PAM modules. These updates also bring maintenance improvements like the release of Firefox 153.0 and Cryptlib patches while closing gaps in widely deployed tools such as wget1, c-ares, libssh, LLVM compiler tools, Fractal messaging client, SSSD, and Django. Fedora administrators should apply these releases without delay to secure their environments against the reported exploits covering unauthorized writes, remote access risks, and container engine weaknesses described in the official documentation.
- Fedora 43 Update: python-asyncssh-2.23.1-1.fc43
- Fedora 44 Update: libseccomp-2.6.1-2.fc44
- Fedora 44 Update: python-asyncssh-2.24.0-1.fc44
- Fedora 44 Update: mbedtls-3.6.7-1.fc44
- Fedora 43 Update: python-pillow-11.3.0-10.fc43
- Fedora 43 Update: libseccomp-2.6.1-2.fc43
- Fedora 43 Update: openssh-10.0p1-11.fc43
- Fedora 43 Update: dnsx-1.3.0-1.fc43
- Fedora 43 Update: freerdp-3.30.0-1.fc43
- Fedora 43 Update: libtiff-4.7.2-1.fc43
- Fedora 43 Update: mingw-python-pip-26.1.2-1.fc43
- Fedora 43 Update: mingw-python-idna-3.18-1.fc43
- Fedora 43 Update: c-ares-1.34.8-1.fc43
- Fedora 44 Update: dnsx-1.3.0-1.fc44
- Fedora 44 Update: libreswan-5.3.2-2.fc44
- Fedora 44 Update: freerdp-3.30.0-1.fc44
- Fedora 44 Update: wget1-1.25.0-4.fc44
- Fedora 44 Update: wireshark-4.6.7-1.fc44
- Fedora 44 Update: gpsd-3.27.5-5.fc44
- Fedora 44 Update: mingw-python-pip-26.1.2-1.fc44
- Fedora 44 Update: mingw-python-idna-3.18-1.fc44
- Fedora 43 Update: nuclei-3.11.0-1.fc43
- Fedora 43 Update: kernel-7.1.4-102.fc43
- Fedora 43 Update: perl-Crypt-OpenSSL-X509-2.1.3-1.fc43
- Fedora 43 Update: rust-syslog-7.0.0-2.fc43
- Fedora 43 Update: rust-rpki-0.19.3-2.fc43
- Fedora 43 Update: rust-fern-0.7.1-6.fc43
- Fedora 43 Update: rust-routinator-0.15.2-1.fc43
- Fedora 44 Update: kernel-7.1.4-202.fc44
- Fedora 44 Update: btrbk-0.32.7-1.fc44
- Fedora 44 Update: mupdf-1.27.2-2.fc44
- Fedora 44 Update: nuclei-3.11.0-1.fc44
- Fedora 44 Update: perl-Crypt-OpenSSL-X509-2.1.3-1.fc44
- Fedora 44 Update: rust-rpki-0.19.3-2.fc44
- Fedora 44 Update: rust-fern-0.7.1-6.fc44
- Fedora 44 Update: rust-ifcfg-devname-1.1.1-5.fc44
- Fedora 44 Update: rust-syslog-7.0.0-2.fc44
- Fedora 44 Update: rust-routinator-0.15.2-1.fc44
- Fedora 44 Update: kernel-7.1.4-204.fc44
- Fedora 44 Update: llvm-22.1.8-4.fc44
- Fedora 44 Update: fractal-14.1-1.fc44
- Fedora 44 Update: srt-1.5.6-1.fc44
- Fedora 44 Update: libssh-0.12.1-1.fc44
- Fedora 44 Update: chromium-150.0.7871.128-1.fc44
- Fedora 44 Update: nginx-mod-vts-0.2.4-13.fc44
- Fedora 44 Update: perl-DBI-1.651-1.fc44
- Fedora 44 Update: nginx-mod-headers-more-0.40-3.fc44
- Fedora 44 Update: nginx-mod-js-challenge-0^20230517.gitda6852d-11.fc44
- Fedora 44 Update: nginx-mod-naxsi-1.6-21.fc44
- Fedora 44 Update: nginx-mod-fancyindex-0.6.0-8.fc44
- Fedora 44 Update: nginx-mod-modsecurity-1.0.4-16.fc44
- Fedora 44 Update: nginx-1.30.4-1.fc44
- Fedora 44 Update: nginx-mod-brotli-1.0.0~rc-13.fc44
- Fedora 44 Update: perl-YAML-Syck-1.47-1.fc44
- Fedora 44 Update: collectl-4.3.20.3-1.fc44
- Fedora 43 Update: kernel-7.1.4-104.fc43
- Fedora 43 Update: fractal-14.1-1.fc43
- Fedora 43 Update: libssh-0.11.5-1.fc43
- Fedora 43 Update: srt-1.5.6-1.fc43
- Fedora 43 Update: chromium-150.0.7871.128-1.fc43
- Fedora 43 Update: perl-DBI-1.651-1.fc43
- Fedora 43 Update: perl-YAML-Syck-1.47-1.fc43
- Fedora 43 Update: collectl-4.3.20.3-1.fc43
- Fedora 43 Update: dotnet9.0-9.0.119-1.fc43
- Fedora 43 Update: dotnet8.0-8.0.129-2.fc43
- Fedora 43 Update: cryptlib-3.4.9.3-1.fc43
- Fedora 44 Update: firefox-153.0-3.fc44
- Fedora 44 Update: dotnet8.0-8.0.129-2.fc44
- Fedora 44 Update: dotnet9.0-9.0.119-1.fc44
- Fedora 44 Update: cryptlib-3.4.9.3-1.fc44
- Fedora 44 Update: python-lsp-black-2.0.0-17.fc44
- Fedora 44 Update: python-black-26.5.1-1.fc44
- Fedora 44 Update: python-pytokens-0.4.1-4.fc44
- Fedora 43 Update: chromium-150.0.7871.181-1.fc43
- Fedora 43 Update: python-django5-5.2.16-1.fc43
- Fedora 43 Update: dotnet10.0-10.0.110-1.fc43
- Fedora 43 Update: mupdf-1.27.2-2.fc43
- Fedora 43 Update: sssd-2.12.0-3.fc43
- Fedora 43 Update: wget1-1.25.0-3.fc43
- Fedora 43 Update: mbedtls-3.6.7-1.fc43
- Fedora 44 Update: chromium-150.0.7871.181-1.fc44
- Fedora 44 Update: dotnet10.0-10.0.110-1.fc44
- Fedora 44 Update: skopeo-1.22.2-2.fc44
- Fedora 44 Update: netatalk-4.5.1-1.fc44
- Fedora 43 Update: firefox-153.0-3.fc43
- Fedora 43 Update: google-osconfig-agent-20260717.00-1.fc43
- Fedora 43 Update: moby-engine-29.6.2-1.fc43
- Fedora 43 Update: xrdp-0.10.6.1-3.fc43
- Fedora 43 Update: libreswan-5.3.2-2.fc43
- Fedora 43 Update: webkitgtk-2.52.5-1.fc43
- Fedora 43 Update: python-idna-3.18-1.fc43
- Fedora 43 Update: p11-kit-0.26.4-1.fc43
- Fedora 43 Update: pam-1.7.1-5.fc43
- Fedora 44 Update: GitPython-3.1.55-1.fc44
- Fedora 44 Update: google-osconfig-agent-20260717.00-1.fc44
- Fedora 44 Update: xrdp-0.10.6.1-3.fc44
- Fedora 44 Update: moby-engine-29.6.2-1.fc44
Oracle Linux
Oracle published multiple batches of errata and security advisories for versions seven through ten on x86_64 and aarch64 systems. The releases patch foundational components including the mainline and Unbreakable Enterprise kernels, glibc, httpd, Nginx, PHP, Python, .NET SDKs, PostgreSQL, Firefox, Thunderbird, Container Tools, and Vim. These coordinated advisories address hundreds of vulnerabilities, including seven distinct flaws patched in Vim such as code injection in netrw and command execution issues in python3complete and glob(). The updates keep enterprise workloads secure while maintaining compatibility across all supported Oracle Linux distributions.
- ELBA-2026-40261 Oracle Linux 8 squid:4 bug fix and enhancement update
- ELBA-2026-39332 Oracle Linux 9 kernel bug fix and enhancement update
- ELSA-2026-27740 Moderate: Oracle Linux 10 golang-github-openprinting-ipp-usb security update
- ELSA-2026-22528 Moderate: Oracle Linux 10 mod_http2 security update
- ELBA-2026-500010 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-22145 Important: Oracle Linux 10 .NET 10.0 security update
- ELSA-2026-33092 Moderate: Oracle Linux 10 glibc security, bug fix, and enhancement update
- ELSA-2026-39323 Important: Oracle Linux 9 pacemaker security update
- ELSA-2026-22937 Important: Oracle Linux 10 image-builder security update
- ELBA-2026-500008 Unbreakable Enterprise kernel bug fix update
- ELBA-2026-500009 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-25191 Critical: Oracle Linux 10 kernel security update
- ELSA-2026-40416 Low: Oracle Linux 9 php:8.2 security, bug fix, and enhancement update
- ELSA-2026-25225 Important: Oracle Linux 10 mod_http2 security update
- ELBA-2026-500010 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-41892 Important: Oracle Linux 10 libtiff security, bug fix, and enhancement update
- ELSA-2026-27733 Important: Oracle Linux 10 firefox security update
- ELBA-2026-500009 Oracle Linux 7 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-38901 Important: Oracle Linux 8 perl-DBI:1.641 security update
- ELSA-2026-38504 Important: Oracle Linux 8 container-tools:ol8 security update
- ELSA-2026-39179 Important: Oracle Linux 8 kernel security update
- ELBA-2026-500010 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
- ELBA-2026-500009 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-40894 Important: Oracle Linux 8 hplip security update
- ELSA-2026-36189 Important: Oracle Linux 10 perl-HTTP-Daemon security update
- ELBA-2026-500008 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-21433 Important: Oracle Linux 10 httpd security update
- ELSA-2026-22325 Important: Oracle Linux 10 thunderbird security update
- ELSA-2026-21754 Important: Oracle Linux 10 .NET 9.0 security update
- ELSA-2026-20606 Important: Oracle Linux 10 ruby4.0 security update
- ELSA-2026-19160 Important: Oracle Linux 10 firefox security update
- ELSA-2026-19157 Important: Oracle Linux 10 firefox security update
- ELSA-2026-19155 Important: Oracle Linux 10 python-markdown security update
- ELSA-2026-19144 Important: Oracle Linux 10 golang-github-openprinting-ipp-usb security update
- ELSA-2026-19139 Important: Oracle Linux 10 go-fdo-client security update
- ELSA-2026-19134 Important: Oracle Linux 10 grafana security update
- ELSA-2026-19154 Important: Oracle Linux 10 giflib security update
- ELSA-2026-19137 Important: Oracle Linux 10 go-fdo-server security update
- ELSA-2026-19136 Important: Oracle Linux 10 grafana-pcp security update
- ELSA-2026-18153 Moderate: Oracle Linux 10 systemd security update
- ELSA-2026-19131 Important: Oracle Linux 10 thunderbird security update
- ELBA-2026-33431 Oracle Linux 10 dracut bug fix and enhancement update
- ELBA-2026-28579 Oracle Linux 10 passt bug fix and enhancement update
- ELBA-2026-22539 Oracle Linux 10 systemd bug fix and enhancement update
- ELBA-2026-39305 Oracle Linux 10 iptables bug fix and enhancement update
- ELBA-2026-39295 Oracle Linux 10 libvirt bug fix and enhancement update
- ELBA-2026-39294 Oracle Linux 10 numpy bug fix and enhancement update
- ELBA-2026-39293 Oracle Linux 10 qemu-kvm bug fix and enhancement update
- ELBA-2026-34484 Oracle Linux 10 fontawesome4-fonts bug fix and enhancement update
- ELBA-2026-28580 Oracle Linux 10 rust-podman-sequoia bug fix and enhancement update
- ELBA-2026-28587 Oracle Linux 10 gdm bug fix and enhancement update
- ELBA-2026-26196 Oracle Linux 10 openscap bug fix and enhancement update
- ELBA-2026-25921 Oracle Linux 10 scap-security-guide bug fix and enhancement update
- ELBA-2026-25224 Oracle Linux 10 aide bug fix and enhancement update
- ELBA-2026-22537 Oracle Linux 10 cyrus-sasl bug fix and enhancement update
- ELBA-2026-22533 Oracle Linux 10 haproxy bug fix and enhancement update
- ELBA-2026-22532 Oracle Linux 10 nmstate bug fix and enhancement update
- ELBA-2026-22525 Oracle Linux 10 squid bug fix and enhancement update
- ELBA-2026-22524 Oracle Linux 10 gnome-desktop3 bug fix and enhancement update
- ELBA-2026-19140 Oracle Linux 10 bootc bug fix and enhancement update
- ELBA-2026-19804 Oracle Linux 10 python-pip bug fix and enhancement update
- ELBA-2026-500007 Oracle Linux 10 sos bug fix update
- ELSA-2026-42668 Important: Oracle Linux 9 libtiff security update
- ELSA-2026-42089 Important: Oracle Linux 9 glib2 security update
- ELSA-2026-42736 Important: Oracle Linux 9 acl security update
- ELSA-2026-42062 Important: Oracle Linux 9 webkit2gtk3 security update
- ELSA-2026-41906 Important: Oracle Linux 9 httpd security, bug fix, and enhancement update
- ELSA-2026-41905 Important: Oracle Linux 9 dovecot security update
- ELSA-2026-41898 Important: Oracle Linux 9 .NET 10.0 security, bug fix, and enhancement update
- ELSA-2026-38796 Important: Oracle Linux 9 plexus-utils security update
- ELSA-2026-41896 Important: Oracle Linux 9 .NET 9.0 security, bug fix, and enhancement update
- ELBA-2026-42071 Oracle Linux 9 qemu-kvm bug fix and enhancement update
- ELSA-2026-41894 Important: Oracle Linux 9 .NET 8.0 security, bug fix, and enhancement update
- ELBA-2026-39310 Oracle Linux 9 papi bug fix and enhancement update
- ELBA-2026-28258 Oracle Linux 9 systemd bug fix and enhancement update
- ELBA-2026-28249 Oracle Linux 9 cloud-init bug fix and enhancement update
- ELBA-2026-50369 Oracle Linux 9 image-builder bug fix update
- ELBA-2026-39179-1 Oracle Linux 8 kernel bug fix update
- ELBA-2026-39083-1 Oracle Linux 8 kernel bug fix update
- ELSA-2026-42090 Important: Oracle Linux 8 glib2 security update
- ELSA-2026-42088 Important: Oracle Linux 8 webkit2gtk3 security update
- ELSA-2026-41899 Important: Oracle Linux 8 .NET 9.0 security, bug fix, and enhancement update
- ELSA-2026-41901 Important: Oracle Linux 8 .NET 8.0 security, bug fix, and enhancement update
- ELSA-2026-41900 Important: Oracle Linux 8 .NET 10.0 security, bug fix, and enhancement update
- ELSA-2026-39322 Important: Oracle Linux 8 pacemaker security update
- ELSA-2026-35838 Important: Oracle Linux 7 python3 security update
- ELSA-2026-30843 Important: Oracle Linux 7 perl-IO-Compress security update
- ELSA-2026-27743 Important: Oracle Linux 10 postgresql16 security update
- ELBA-2026-25084 Oracle Linux 10 guestfs-tools bug fix and enhancement update
- ELSA-2026-27742 Important: Oracle Linux 10 postgresql18 security update
- ELSA-2026-38513 Important: Oracle Linux 10 perl-DBI security update
- ELSA-2026-39296 Moderate: Oracle Linux 10 libinput security update
- ELSA-2026-39272 Important: Oracle Linux 10 git-lfs security update
- ELSA-2026-19125 Important: Oracle Linux 10 xorg-x11-server-Xwayland security update
- ELSA-2026-28234 Low: Oracle Linux 10 libxml2 security update
- ELSA-2026-38499 Important: Oracle Linux 10 openexr security update
- ELSA-2026-18139 Moderate: Oracle Linux 10 glibc security update
- ELBA-2026-22541 Oracle Linux 10 emacs bug fix and enhancement update
- ELBA-2026-28230 Oracle Linux 10 nftables bug fix and enhancement update
- ELBA-2026-39300 Oracle Linux 10 man-pages bug fix and enhancement update
- ELSA-2026-36675 Important: Oracle Linux 10 gstreamer1-plugins-good security update
- ELSA-2026-20613 Important: Oracle Linux 10 gnutls security update
- ELSA-2026-36673 Moderate: Oracle Linux 10 gstreamer1-plugins-ugly-free security update
- ELSA-2026-39573 Important: Oracle Linux 10 yggdrasil security update
- ELSA-2026-36364 Important: Oracle Linux 10 nginx security, bug fix, and enhancement update
- ELBA-2026-39303 Oracle Linux 10 firewalld bug fix and enhancement update
- ELSA-2026-27842 Important: Oracle Linux 10 memcached security update
- ELSA-2026-20594 Moderate: Oracle Linux 10 glibc security update
- ELSA-2026-18536 Important: Oracle Linux 10 tomcat9 security update
- ELSA-2026-23388 Important: Oracle Linux 10 php security update
- ELSA-2026-38495 Important: Oracle Linux 10 podman security update
- ELSA-2026-26228 Important: Oracle Linux 10 hplip security update
- ELSA-2026-36211 Moderate: Oracle Linux 10 freeipmi security update
- ELSA-2026-36196 Important: Oracle Linux 10 389-ds-base security update
- ELSA-2026-38514 Important: Oracle Linux 10 plexus-utils security update
- ELSA-2026-19138 Important: Oracle Linux 10 fence-agents security update
- ELSA-2026-42063 Important: Oracle Linux 10 glib2 security update
- ELBA-2026-39306 Oracle Linux 10 ipset bug fix and enhancement update
- ELSA-2026-37436 Important: Oracle Linux 10 golang security, bug fix, and enhancement update
- ELSA-2026-22649 Important: Oracle Linux 10 php8.4 security update
- ELSA-2026-41897 Important: Oracle Linux 10 .NET 10.0 security, bug fix, and enhancement update
- ELSA-2026-36203 Important: Oracle Linux 10 freerdp security update
- ELSA-2026-39297 Moderate: Oracle Linux 10 edk2 security, bug fix, and enhancement update
- ELSA-2026-36782 Moderate: Oracle Linux 10 aardvark-dns security update
- ELBA-2026-28578 Oracle Linux 10 libuv bug fix and enhancement update
- ELSA-2026-19128 Important: Oracle Linux 10 yggdrasil-worker-package-manager security update
- ELBA-2026-28586 Oracle Linux 10 gnome-shell bug fix and enhancement update
- ELSA-2026-41893 Important: Oracle Linux 10 .NET 8.0 security, bug fix, and enhancement update
- ELSA-2026-28581 Important: Oracle Linux 10 python3.14 security, bug fix, and enhancement update
- ELSA-2026-19146 Important: Oracle Linux 10 openexr security update
- ELBA-2026-22138 Oracle Linux 10 libguestfs bug fix and enhancement update
- ELSA-2026-18326 Moderate: Oracle Linux 10 libvirt security update
- ELSA-2026-26456 Important: Oracle Linux 10 389-ds-base security, bug fix, and enhancement update
- ELSA-2026-39183 Important: Oracle Linux 10 python3.12 security update
- ELSA-2026-38494 Important: Oracle Linux 10 buildah security update
- ELSA-2026-19133 Important: Oracle Linux 10 git-lfs security update
- ELSA-2026-26532 Important: Oracle Linux 10 dracut security update
- ELBA-2026-39577 Oracle Linux 10 cifs-utils bug fix and enhancement update
- ELSA-2026-42739 Important: Oracle Linux 10 acl security update
- ELEA-2026-28585 Oracle Linux 10 libpfm bug fix and enhancement update
- ELSA-2026-33412 Important: Oracle Linux 10 galera and mariadb11.8 security, bug fix, and enhancement update
- ELSA-2026-36788 Important: Oracle Linux 10 tomcat security, bug fix, and enhancement update
- ELBA-2026-41035 Oracle Linux 10 fwupd-efi bug fix and enhancement update
- ELSA-2026-39976 Important: Oracle Linux 10 hplip security update
- ELSA-2026-19153 Important: Oracle Linux 10 thunderbird security update
- ELSA-2026-18134 Moderate: Oracle Linux 10 kernel security update
- ELSA-2026-39302 Moderate: Oracle Linux 10 cups security update
- ELSA-2026-24716 Important: Oracle Linux 10 yggdrasil security update
- ELBA-2026-22536 Oracle Linux 10 gnome-remote-desktop bug fix and enhancement update
- ELBA-2026-22523 Oracle Linux 10 java-21-openjdk bug fix update
- ELSA-2026-36320 Important: Oracle Linux 10 unbound security update
- ELSA-2026-39547 Important: Oracle Linux 10 perl-XML-LibXML security update
- ELSA-2026-19152 Important: Oracle Linux 10 rsync security update
- ELBA-2026-20536 Oracle Linux 10 tzdata bug fix and enhancement update
- ELSA-2026-23231 Important: Oracle Linux 10 unbound security update
- ELSA-2026-41937 Important: Oracle Linux 10 sssd security update
- ELSA-2026-38509 Important: Oracle Linux 10 vim security update
- ELSA-2026-39304 Low: Oracle Linux 10 libxml2 security update
- ELSA-2026-19159 Critical: Oracle Linux 10 nginx security update
- ELBA-2026-22137 Oracle Linux 10 virt-v2v bug fix and enhancement update
- ELSA-2026-36790 Important: Oracle Linux 10 tomcat9 security, bug fix, and enhancement update
- ELSA-2026-41895 Important: Oracle Linux 10 .NET 9.0 security, bug fix, and enhancement update
- ELSA-2026-32990 Important: Oracle Linux 10 cifs-utils security update
- ELSA-2026-36749 Important: Oracle Linux 10 gstreamer1-plugins-bad-free security update
- ELBA-2026-39301 Oracle Linux 10 libusb1 bug fix and enhancement update
- ELSA-2026-41988 Important: Oracle Linux 10 dovecot security update
- ELSA-2026-21380 Important: Oracle Linux 10 firefox security update
- ELSA-2026-22711 Moderate: Oracle Linux 10 vim security update
Red Hat Enterprise Linux
Red Hat Product Security issued a wave of RHSA-2026 advisories to address multiple vulnerabilities across RHEL versions 7 through 10. The patches target core infrastructure components including OpenShift Container Platform 4, the Linux kernel, httpd, glibc, PostgreSQL, and Java 17 OpenJDK. Administrators managing RHEL 8, 9, or 10 environments will also receive fixes for SSSD, glib2, Red Hat Satellite, and the Ansible Automation Platform. These coordinated releases combine security hardening with routine bug corrections to keep enterprise systems running safely across all supported versions.
- RHSA-2026:41892: Important: libtiff security, bug fix, and enhancement update
- RHSA-2026:36610: Important: OpenShift Container Platform 4.14.69 bug fix and security update
- RHSA-2026:42122: Important: sssd security update
- RHSA-2026:42089: Important: glib2 security update
- RHSA-2026:42240: Important: Satellite 6.19.2.1 Async Update
- RHSA-2026:42096: Important: c-ares security update
- RHSA-2026:42151: Important: Satellite 6.18.7.1 Async Update
- RHSA-2026:42150: Important: Satellite 6.17.9.1 Async Update
- RHSA-2026:42062: Important: webkit2gtk3 security update
- RHSA-2026:42088: Important: webkit2gtk3 security update
- RHSA-2026:42091: Important: dovecot security update
- RHSA-2026:42090: Important: glib2 security update
- RHSA-2026:42098: Moderate: Red Hat JBoss Enterprise Application Platform 8.1.7 XP 6.0.5.GA release
- RHSA-2026:42063: Important: glib2 security update
- RHSA-2026:42079: Important: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update
- RHSA-2026:42078: Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
- RHSA-2026:42076: Important: pacemaker security update
- RHSA-2026:42082: Important: Satellite 6.16.11 Async Update
- RHSA-2026:42075: Important: pacemaker security update
- RHSA-2026:42080: Important: Red Hat Ansible Automation Platform 2.7 Product Security and Bug Fix Update
- RHSA-2026:41949: Important: python3.14 security update
- RHSA-2026:42041: Important: pacemaker security update
- RHSA-2026:41947: Important: nodejs:22 security, bug fix, and enhancement update
- RHSA-2026:41988: Important: dovecot security update
- RHSA-2026:41948: Important: javapackages-tools:201801 security update
- RHSA-2026:41937: Important: sssd security update
- RHSA-2026:41951: Important: Red Hat Data Grid 8.6.2 security update
- RHSA-2026:41930: Important: rhc security update
- RHSA-2026:41906: Important: httpd security, bug fix, and enhancement update
- RHSA-2026:41921: Important: gnutls security update
- RHSA-2026:41920: Important: kernel security update
- RHSA-2026:41905: Important: dovecot security update
- RHSA-2026:41904: Important: evince security update
- RHSA-2026:42828: Important: httpd:2.4 security, bug fix, and enhancement update
- RHSA-2026:42739: Important: acl security update
- RHSA-2026:42875: Important: RHEL AI 3.5 RPM runtime CVE fix - aom
- RHSA-2026:42733: Moderate: glibc security update
- RHSA-2026:40779: Important: OpenShift Container Platform 4.21.25 bug fix and security update
- RHSA-2026:42694: Moderate: glibc security update
- RHSA-2026:42668: Important: libtiff security update
- RHSA-2026:42692: Important: evince security update
- RHSA-2026:42552: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:42555: Important: postgresql:13 security update
- RHSA-2026:42550: Important: kernel-rt security, bug fix, and enhancement update
- RHSA-2026:42946: Important: rhc-worker-playbook security, bug fix, and enhancement update
- RHSA-2026:42919: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:42736: Important: acl security update
- RHSA-2026:40787: Important: OpenShift Container Platform 4.20.30 bug fix and security update
- RHSA-2026:40764: Important: OpenShift Container Platform 4.22.6 bug fix and security update
- RHSA-2026:43711: Important: RHEL AI 3.5 RPM runtime CVE fix - ffmpeg
- RHSA-2026:43702: Moderate: libpng12 security update
- RHSA-2026:43537: Moderate: libtiff security update
- RHSA-2026:43575: Moderate: gnutls security update
- RHSA-2026:43505: Important: mariadb-connector-c security update
- RHSA-2026:43513: Moderate: openssl security update
- RHSA-2026:40762: Important: OpenShift Container Platform 4.19.39 bug fix and security update
- RHSA-2026:43401: Important: Red Hat JBoss Web Server 6.2.4 release and security update
- RHSA-2026:43402: Important: Red Hat JBoss Web Server 6.2.4 release and security update
- RHSA-2026:43425: Important: libreoffice security update
- RHSA-2026:43307: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:43460: Important: libreoffice security update
- RHSA-2026:43424: Important: libreoffice security update
- RHSA-2026:43461: Important: libreoffice security update
- RHSA-2026:43423: Important: libreoffice security update
- RHSA-2026:43420: Important: acl security update
- RHSA-2026:43400: Important: dogtag-pki security update
- RHSA-2026:43398: Important: evince security update
- RHSA-2026:43290: Moderate: libinput security update
- RHSA-2026:43231: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:43218: Important: pki-deps:10.6 security update
- RHSA-2026:42952: Moderate: glibc security update
- RHSA-2026:43606: Important: pacemaker security update
- RHSA-2026:42887: Important: java-17-openjdk security update
- RHSA-2026:44064: Important: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update
- RHSA-2026:44066: Important: pki-deps:10.6 security update
- RHSA-2026:44065: Important: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update
- RHSA-2026:44061: Important: pki-deps:10.6 security update
- RHSA-2026:44004: Important: kpatch-patch-4_18_0-553_109_1, kpatch-patch-4_18_0-553_125_1, kpatch-patch-4_18_0-553_53_1, kpatch-patch-4_18_0-553_72_1, and kpatch-patch-4_18_0-553_85_1 sec ...
- RHSA-2026:44063: Important: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update
- RHSA-2026:44062: Important: pki-deps:10.6 security update
- RHSA-2026:44007: Important: kpatch-patch-5_14_0-570_116_1, kpatch-patch-5_14_0-570_17_1, kpatch-patch-5_14_0-570_39_1, kpatch-patch-5_14_0-570_66_1, and kpatch-patch-5_14_0-570_94_1 secu ...
- RHSA-2026:44006: Important: kpatch-patch-5_14_0-427_100_1, kpatch-patch-5_14_0-427_113_1, kpatch-patch-5_14_0-427_126_1, kpatch-patch-5_14_0-427_68_2, and kpatch-patch-5_14_0-427_84_1 se ...
- RHSA-2026:44003: Important: kpatch-patch-5_14_0-284_117_1, kpatch-patch-5_14_0-284_134_1, kpatch-patch-5_14_0-284_148_1, kpatch-patch-5_14_0-284_158_1, and kpatch-patch-5_14_0-284_172_1 ...
- RHSA-2026:43847: Important: kpatch-patch-4_18_0-477_107_1, kpatch-patch-4_18_0-477_120_1, kpatch-patch-4_18_0-477_130_1, kpatch-patch-4_18_0-477_143_1, and kpatch-patch-4_18_0-477_97_1 s ...
- RHSA-2026:43825: Important: kpatch-patch-5_14_0-687_10_1 security update
- RHSA-2026:43826: Important: kpatch-patch-6_12_0-211_16_1 security update
- RHSA-2026:41898: Important: .NET 10.0 security, bug fix, and enhancement update
- RHSA-2026:41896: Important: .NET 9.0 security, bug fix, and enhancement update
- RHSA-2026:41894: Important: .NET 8.0 security, bug fix, and enhancement update
- RHSA-2026:41901: Important: .NET 8.0 security, bug fix, and enhancement update
- RHSA-2026:41897: Important: .NET 10.0 security, bug fix, and enhancement update
- RHSA-2026:41900: Important: .NET 10.0 security, bug fix, and enhancement update
- RHSA-2026:41895: Important: .NET 9.0 security, bug fix, and enhancement update
- RHSA-2026:40021: Important: OpenShift Container Platform 4.13.69 bug fix and security update
- RHSA-2026:44271: Important: dogtag-pki security update
- RHSA-2026:44438: Important: compat-openssl11 security update
- RHSA-2026:44480: Moderate: compat-openssl10 security update
- RHSA-2026:44385: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:44391: Important: libpq security update
- RHSA-2026:42876: Important: java-1.8.0-openjdk security update
- RHSA-2026:44420: Important: libpq security update
- RHSA-2026:42900: Important: OpenJDK 25.0.4 Security Update for Portable Linux Builds
- RHSA-2026:42897: Important: OpenJDK 21.0.12 Security Update for Portable Linux Builds
- RHSA-2026:42898: Important: OpenJDK 21.0.12 Security Update for Windows Builds
- RHSA-2026:42893: Important: OpenJDK 17.0.20 Security Update for Windows Builds
- RHSA-2026:42889: Important: OpenJDK 17.0.20 Security Update for Portable Linux Builds
- RHSA-2026:42878: Important: OpenJDK 8u502 Security Update for Portable Linux Builds
- RHSA-2026:42879: Important: OpenJDK 8u502 Windows Security Update
- RHSA-2026:44355: Important: dovecot security update
- RHSA-2026:44373: Important: dovecot security update
- RHSA-2026:44357: Important: dovecot security update
- RHSA-2026:44308: Important: libpq security update
- RHSA-2026:42882: Important: OpenJDK 11.0.32 ELS Security Update for Windows Builds
- RHSA-2026:42881: Important: OpenJDK 11.0.32 ELS Security Update for Portable Linux Builds
- RHSA-2026:44270: Important: kernel security update
- RHSA-2026:42880: Important: Java 11 OpenJDK ELS Security Update
- RHSA-2026:42895: Important: java-21-openjdk security update
- RHSA-2026:44694: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:42877: Important: java-1.8.0-openjdk security update
- RHSA-2026:44522: Moderate: kernel security update
- RHSA-2026:45192: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:45114: Important: kernel security update
- RHSA-2026:45115: Important: kernel security update
- RHSA-2026:45116: Important: kernel-rt security update
Rocky Linux
Rocky Linux administrators should install fresh errata covering security vulnerabilities and maintenance updates across versions 8, 9, and 10. The new advisories address performance improvements and bug fixes for widely used components including NodeJS 22, .NET 8 through 10, Python 3.14, Glibc, and httpd:2.4. Security patches specifically target the Webkit2GTK3 rendering engine, glib2 utility libraries, and core kernel modules to block known exploits.
- RLSA-2026:41947: Important: nodejs:22 security, bug fix, and enhancement update
- RLSA-2026:41948: Important: javapackages-tools:201801 security update
- RLSA-2026:42088: Important: webkit2gtk3 security update
- RLSA-2026:42090: Important: glib2 security update
- RLSA-2026:42828: Important: httpd:2.4 security, bug fix, and enhancement update
- RLBA-2026:39332: Important:kernel bug fix and enhancement update
- RLSA-2026:42739: Important: acl security update
- RLSA-2026:40833: Important: pacemaker security update
- RLSA-2026:41937: Important: sssd security update
- RLSA-2026:41892: Important: libtiff security, bug fix, and enhancement update
- RLSA-2026:42694: Moderate: glibc security update
- RLSA-2026:41988: Important: dovecot security update
- RLSA-2026:42063: Important: glib2 security update
- RLSA-2026:40856: Important: python3.14 security update
- RLSA-2026:42096: Important: c-ares security update
- RLSA-2026:42736: Important: acl security update
- RLSA-2026:42089: Important: glib2 security update
- RLSA-2026:42062: Important: webkit2gtk3 security update
- RLSA-2026:41905: Important: dovecot security update
- RLSA-2026:41949: Important: python3.14 security update
- RLSA-2026:41906: Important: httpd security, bug fix, and enhancement update
- RLSA-2026:42668: Important: libtiff security update
- RLSA-2026:42122: Important: sssd security update
- RLSA-2026:43218: Important: pki-deps:10.6 security update
- RLSA-2026:42550: Important: kernel-rt security, bug fix, and enhancement update
- RLSA-2026:43218: Important: pki-deps:10.6 security update
- RLSA-2026:42919: Important: kernel security, bug fix, and enhancement update
- RLSA-2026:43400: Important: dogtag-pki security update
- RLSA-2026:41895: Important: .NET 9.0 security, bug fix, and enhancement update
- RLSA-2026:43505: Important: mariadb-connector-c security update
- RLSA-2026:41897: Important: .NET 10.0 security, bug fix, and enhancement update
- RLSA-2026:41893: Important: .NET 8.0 security, bug fix, and enhancement update
- RLSA-2026:43307: Important: kernel security, bug fix, and enhancement update
- RLSA-2026:41894: Important: .NET 8.0 security, bug fix, and enhancement update
- RLSA-2026:41896: Important: .NET 9.0 security, bug fix, and enhancement update
- RLSA-2026:41898: Important: .NET 10.0 security, bug fix, and enhancement update
- RLSA-2026:42952: Moderate: glibc security update
- RLSA-2026:41900: Important: .NET 10.0 security, bug fix, and enhancement update
- RLSA-2026:41901: Important: .NET 8.0 security, bug fix, and enhancement update
- RLSA-2026:41899: Important: .NET 9.0 security, bug fix, and enhancement update
- RLSA-2026:43420: Important: acl security update
- RLSA-2026:39575: Important: cifs-utils security, bug fix, and enhancement update
Slackware Linux
Slackware Linux issued security patches for libssh, Mozilla Firefox, and Thunderbird 140.13 ESR targeting versions 15.0 and the current development branch. These packages resolve critical flaws documented under CVE identifiers ranging from CVE-2026-15370 through CVE-2026-59849, alongside additional Mozilla advisories and the specific Thunderbird bulletin SSA:2026-204-01. Users running either the stable release or rolling current branch should install these packages immediately to close known security gaps.
SUSE Linux
SUSE issued a series of coordinated security advisories patching dozens of vulnerabilities across openSUSE Leap, Tumbleweed, SLE-15-SP7, and SLE-16.0 environments. The patches resolve critical flaws in widely deployed software including Chromium, Python 3.11 and 3.13/3.14, the Linux kernel, ImageMagick, Perl DBI, Podman, FFmpeg, and Suricata that previously enabled remote code execution, memory corruption, heap overflows, and denial-of-service attacks. System administrators should apply these updates immediately to close known exploitation pathways and maintain compliance with enterprise security baselines. The release schedule covers both rolling community distributions and long-term support channels, reflecting SUSE's standard vulnerability management workflow for its entire product family.
- openSUSE-SU-2026:11306-1: moderate: kbfs-6.6.3-3.1 on GA media
- openSUSE-SU-2026:11305-1: moderate: containerized-data-importer1.65-api-1.65.0-2.1 on GA media
- openSUSE-SU-2026:11304-1: moderate: system-user-zabbix-7.0.28-1.1 on GA media
- openSUSE-SU-2026:11307-1: moderate: kubevirt1.8-container-disk-1.8.4-1.1 on GA media
- openSUSE-SU-2026:11298-1: moderate: perl-DBI-1.651.0-1.1 on GA media
- openSUSE-SU-2026:11300-1: moderate: php-composer2-2.10.2-2.1 on GA media
- openSUSE-SU-2026:11303-1: moderate: wget-1.25.0-4.1 on GA media
- openSUSE-SU-2026:0251-1: moderate: Security update for python-weasyprint
- openSUSE-SU-2026:0254-1: important: Security update for chromium
- openSUSE-SU-2026:0252-1: important: Security update for python-django-haystack
- SUSE-SU-2026:3132-1: important: Security update for python311
- SUSE-SU-2026:3133-1: important: Security update for gstreamer-plugins-bad
- SUSE-SU-2026:3136-1: important: Security update for 389-ds
- SUSE-SU-2026:3137-1: important: Security update for 389-ds
- SUSE-SU-2026:3126-1: important: Security update for podman
- openSUSE-SU-2026:11309-1: moderate: chromedriver-150.0.7871.128-1.1 on GA media
- openSUSE-SU-2026:11308-1: moderate: libsuricata8_0_6-8.0.6-1.1 on GA media
- SUSE-SU-2026:3125-1: important: Security update for gstreamer-plugins-bad
- SUSE-SU-2026:3123-1: important: Security update for shibboleth-sp
- openSUSE-SU-2026:21383-1: moderate: Security update for beets
- openSUSE-SU-2026:21382-1: important: Security update for chromium
- openSUSE-SU-2026:21380-1: important: Security update for opam
- openSUSE-SU-2026:21372-1: important: Security update for python-aiohttp
- openSUSE-SU-2026:21374-1: important: Security update for vim
- openSUSE-SU-2026:11317-1: moderate: iscsiuio-0.7.8.8-112.1 on GA media
- openSUSE-SU-2026:11316-1: moderate: libsoup-3_0-0-3.6.6-7.1 on GA media
- openSUSE-SU-2026:11315-1: moderate: libgit2-1_9-1.9.6-1.1 on GA media
- openSUSE-SU-2026:11311-1: moderate: MozillaFirefox-152.0.6-1.1 on GA media
- openSUSE-SU-2026:11313-1: moderate: avahi-0.8-45.1 on GA media
- openSUSE-SU-2026:11314-1: moderate: kubevirt1.8-container-disk-1.8.4-2.1 on GA media
- openSUSE-SU-2026:11312-1: moderate: acl-2.4.0-1.1 on GA media
- openSUSE-SU-2026:11310-1: moderate: ImageMagick-7.1.2.27-3.1 on GA media
- SUSE-SU-2026:3139-1: important: Security update for sssd
- SUSE-SU-2026:3140-1: important: Security update for libreoffice
- openSUSE-SU-2026:0255-1: important: Security update for libkrun
- SUSE-SU-2026:3151-1: important: Security update for go1.25-openssl
- SUSE-SU-2026:3152-1: important: Security update for aws-nitro-enclaves-cli
- SUSE-SU-2026:3153-1: moderate: Security update for nghttp2
- SUSE-SU-2026:3155-1: moderate: Security update for python-tornado6
- SUSE-SU-2026:3156-1: important: Security update for the Linux Kernel
- SUSE-SU-2026:3165-1: moderate: Security update for php7
- SUSE-SU-2026:3179-1: moderate: Security update for python-sqlparse
- SUSE-SU-2026:3180-1: moderate: Security update for python-sqlparse
- SUSE-SU-2026:3184-1: moderate: Security update for multipath-tools
- SUSE-SU-2026:3181-1: moderate: Security update for python3-sqlparse
- openSUSE-SU-2026:11319-1: moderate: 7zip-26.02-1.1 on GA media
- openSUSE-SU-2026:11323-1: moderate: python313-bleach-6.4.0-1.1 on GA media
- openSUSE-SU-2026:11321-1: moderate: perl-YAML-1.320.0-1.1 on GA media
- SUSE-SU-2026:3193-1: moderate: Security update for ImageMagick
- SUSE-SU-2026:3195-1: important: Security update for sssd
- openSUSE-SU-2026:21395-1: important: Security update for trivy
- openSUSE-SU-2026:21393-1: moderate: Security update for gawk
- openSUSE-SU-2026:21391-1: moderate: Security update for ImageMagick
- SUSE-SU-2026:3201-1: low: Security update for GraphicsMagick
- SUSE-SU-2026:3199-1: moderate: Security update for multipath-tools
- openSUSE-SU-2026:0257-1: important: Security update for chromium
- openSUSE-SU-2026:11327-1: moderate: apache-sshd-2.19.0-2.1 on GA media
- openSUSE-SU-2026:11331-1: moderate: google-osconfig-agent-20260708.00-2.1 on GA media
- openSUSE-SU-2026:11329-1: moderate: firefox-esr-140.13.0-1.1 on GA media
- openSUSE-SU-2026:11324-1: moderate: afterburn-5.10.0.git73.b97f772-2.1 on GA media
- openSUSE-SU-2026:21385-1: low: Security update for gpg2
- openSUSE-SU-2026:21388-1: important: Security update for the Linux Kernel
- openSUSE-SU-2026:21387-1: moderate: Security update for libgcrypt
- SUSE-SU-2026:3207-1: important: Security update for python-aiohttp
- openSUSE-SU-2026:21435-1: moderate: Security update for perl-XML-Bare
- openSUSE-SU-2026:21433-1: important: Security update for hauler
- openSUSE-SU-2026:21432-1: important: Security update for gh
- openSUSE-SU-2026:21426-1: important: Security update for ImageMagick
- openSUSE-SU-2026:21429-1: low: Security update for net-tools
- openSUSE-SU-2026:21427-1: moderate: Security update for perl-HTTP-Date
- openSUSE-SU-2026:21423-1: important: Security update for jline3
- openSUSE-SU-2026:21425-1: moderate: Security update for PackageKit
- openSUSE-SU-2026:21418-1: important: Security update for shibboleth-sp
- openSUSE-SU-2026:21422-1: important: Security update for helm
- openSUSE-SU-2026:21417-1: moderate: Security update for avahi
- openSUSE-SU-2026:21412-1: important: Security update for perl-DBI
- openSUSE-SU-2026:21409-1: important: Security update for mariadb-connector-c
- openSUSE-SU-2026:21410-1: important: Security update for glib2
- openSUSE-SU-2026:21411-1: important: Security update for perl
- openSUSE-SU-2026:21408-1: important: Security update for joe
- openSUSE-SU-2026:21406-1: important: Security update for aws-nitro-enclaves-cli
- openSUSE-SU-2026:11341-1: moderate: python313-pandas-3.0.3-1.2 on GA media
- openSUSE-SU-2026:11339-1: moderate: kernel-devel-7.1.4-1.1 on GA media
- openSUSE-SU-2026:11342-1: moderate: python313-3.13.14-1.1 on GA media
- openSUSE-SU-2026:11343-1: moderate: python314-3.14.6-2.1 on GA media
- openSUSE-SU-2026:11340-1: moderate: prometheus-ha_cluster_exporter-1.4.2-1.1 on GA media
- openSUSE-SU-2026:11335-1: moderate: java-11-openjdk-11.0.32.0-1.1 on GA media
- openSUSE-SU-2026:11334-1: moderate: helm3-3.21.3-3.1 on GA media
- openSUSE-SU-2026:11337-1: moderate: java-26-openjdk-26.0.2.0-1.1 on GA media
- openSUSE-SU-2026:0259-1: important: Security update for gh
- SUSE-SU-2026:3217-1: moderate: Security update for avahi
- SUSE-SU-2026:3219-1: important: Security update for ImageMagick
- SUSE-SU-2026:3218-1: moderate: Security update for avahi
- SUSE-SU-2026:3220-1: moderate: Security update for nmap
- SUSE-SU-2026:3224-1: important: Security update for SVT-AV1, libyuv0, libaom3
- openSUSE-SU-2026:11346-1: moderate: chromedriver-150.0.7871.181-1.1 on GA media
- openSUSE-SU-2026:11353-1: moderate: python313-astropy-8.0.1-1.1 on GA media
- openSUSE-SU-2026:11351-1: moderate: perl-XML-Bare-0.53-7.1 on GA media
- openSUSE-SU-2026:11350-1: moderate: perl-HTTP-Date-6.80.0-1.1 on GA media
- openSUSE-SU-2026:11352-1: moderate: proftpd-1.3.9c-1.1 on GA media
- openSUSE-SU-2026:11347-1: moderate: ffmpeg-8-8.1.2-2.1 on GA media
- openSUSE-SU-2026:11345-1: moderate: amazon-ecs-init-1.105.0-2.1 on GA media
- openSUSE-SU-2026:11349-1: moderate: google-osconfig-agent-20260708.00-3.1 on GA media
Ubuntu Linux
Ubuntu published a series of security advisories this week targeting critical flaws in wget, Apache HTTP Server, nginx, PHP, FreeRDP, OpenSSH, CUPS, ImageMagick, Exim, Kerberos, Gawk, Rsyslog, and PAM across multiple long-term support releases. The kernel patches cover the standard distribution alongside specialized builds for NVIDIA, IBM, Oracle, OEM hardware, and Tegra chips, with a separate update fixing over five hundred vulnerabilities in Azure and Azure FDE kernels running Ubuntu 26.04 LTS. UBports also delivered Ubuntu Touch OTA 2.0, moving the mobile operating system to Ubuntu 24.04 LTS and upgrading Morph Browser to Chromium 134 to resolve longstanding web compatibility issues. Organizations running these packages on production servers need to apply the patches immediately to close known attack vectors before threat actors exploit them remotely.
- [USN-8572-1] Wget vulnerability
- [USN-8573-1] libde265 vulnerabilities
- [USN-8571-1] Apache HTTP Server vulnerabilities
- [USN-8563-2] nginx regression
- [USN-8565-1] SQLite vulnerabilities
- [USN-8564-1] PHP vulnerabilities
- [USN-8561-1] FreeRDP vulnerabilities
- [USN-8563-1] nginx vulnerabilities
- [USN-8562-1] FreeType vulnerability
- [USN-8569-1] Linux kernel (HWE) vulnerabilities
- [USN-8570-1] Linux kernel vulnerabilities
- [USN-8560-1] libXfont vulnerabilities
- [USN-8559-1] rlottie vulnerabilities
- [USN-8568-1] Linux kernel (OEM) vulnerabilities
- [USN-8567-1] Linux kernel vulnerabilities
- [USN-8566-1] Linux kernel vulnerabilities
- [USN-8579-1] snapd vulnerabilities
- [USN-8576-1] Linux kernel (NVIDIA Tegra) vulnerabilities
- [USN-8575-1] Linux kernel vulnerabilities
- [USN-8574-1] Linux kernel (GCP FIPS) vulnerabilities
- [USN-8580-1] AccountsService vulnerabilities
- [USN-8577-1] OpenSSH vulnerability
- [USN-8578-1] CUPS control character injection vulnerability
- [USN-8580-2] AccountsService vulnerabilities
- [USN-8558-1] ImageMagick vulnerabilities
- [USN-8582-1] jbig2dec vulnerabilities
- [USN-8590-1] Exim vulnerabilities
- [USN-8477-3] tar regression
- [USN-8585-1] Kerberos vulnerabilities
- [USN-8584-1] GStreamer Good Plugins vulnerabilities
- [USN-8587-1] HTML-Parser vulnerability
- [USN-8586-1] libgphoto2 vulnerabilities
- [USN-8583-1] GIFLIB vulnerabilities
- [USN-8589-1] Apache HTTP Server vulnerabilities
- [USN-8588-1] Gawk vulnerabilities
- [USN-8581-1] libarchive vulnerabilities
- [USN-8591-1] AIOHTTP vulnerabilities
- [USN-8598-1] rsyslog vulnerabilities
- [USN-8599-1] HTTP-Date vulnerability
- [USN-8601-1] PAM vulnerability
- [USN-8600-1] libXpm vulnerability
- [USN-8596-1] Linux kernel (NVIDIA) vulnerabilities
- [USN-8597-1] Linux kernel (IBM) vulnerabilities
- [USN-8369-2] mod_jk regression
- [USN-8593-1] Linux kernel vulnerabilities
- [USN-8574-2] Linux kernel vulnerabilities
- [USN-8576-2] Linux kernel (NVIDIA Tegra) vulnerabilities
- [USN-8595-1] Linux kernel (Oracle) vulnerabilities
- [USN-8322-2] Apache Commons BeanUtils regression
- [USN-8594-1] Linux kernel (OEM) vulnerabilities
- [USN-8575-2] Linux kernel vulnerabilities
- UBports Ships Ubuntu Touch OTA 2.0 With Chromium 134 and 24.04 LTS
- [USN-8603-1] Linux kernel (Azure) vulnerabilities
How to apply these Linux security updates
Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.
Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.
Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.
Debian/Ubuntu (apt)
The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.
sudo apt update sudo apt upgrade -y
Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)
On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.
sudo dnf check-update sudo dnf upgrade -y
or on older releases
sudo yum check-update sudo yum update
SUSE (zypper)
SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.
sudo zypper refresh sudo zypper update -y
Slackware (slackpkg and pkgtool)
Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.
sudo slackpkg update sudo slackpkg upgrade-all
