Security 10973 Published by

Linux distributions released a wave of mass security patches this week, hitting core infrastructure packages like glibc, the Linux kernel, WebKitGTK, and .NET 8 through 10 to close active exploitation pathways. Enterprise admins on RHEL-family systems should prioritize the new advisories for OpenShift, SSSD, and the real-time kernel, while Fedora and Ubuntu users need to apply the latest Chromium, Firefox, and Python 3.14 hardening immediately. With high-severity flaws like CVE-2026-46323 and widespread memory corruption bugs targeting production workloads, delaying these updates is effectively leaving enterprise networks exposed to automated scanning. Running your package manager this week is the only safe move before your maintenance windows close.





Linux distributions push a massive coordinated wave of security patches across every major release

Linux distros didn't hold back this week. If you manage anything running AlmaLinux, Debian, Fedora, Oracle, RHEL, Rocky, Slackware, SUSE, or Ubuntu, your package repositories just received a heavy dose of hardening. The wave hit in late July 2026 and targets the exact libraries keeping your containers, servers, and workstations alive.

The updates cover the usual suspects, though this round reads like a synchronized upstream audit. glibc, the Linux kernel, WebKitGTK, glib2, and libtiff all received critical fixes. Apache httpd and nginx share the blame for another round of hardening. .NET 8 through 10, Node.js 22, and Python 3.14 are all getting patched. If you're running any of those on production hardware, you already know what to do.

Secpin

Enterprise and RHEL-family distributions

Red Hat Product Security issued a torrent of RHSA advisories alongside Oracle and AlmaLinux. Administrators on RHEL 8, 9, and 10 are getting fixes for SSSD, glib2, the Ansible Automation Platform, and multiple OpenShift Container Platform versions. The kernel updates split across standard, real-time, NVIDIA, and Azure builds.

Rocky Linux mirrors the Red Hat playbook with RLSA-2026 notices that patch .NET 8 through 10, Node.js 22, and Python 3.14. AlmaLinux's batch is particularly heavy, covering CVE-2026-46323 and a straightforward XFS filesystem correction for version 9. Oracle Linux pushed fixes for .NET SDKs, glibc, httpd, and kernel maintenance across versions seven through ten on x86_64 and aarch64.

Debian issued DLA and DSA notices for stable and legacy LTS, fixing libnfs integer overflows, TIFF memory corruption, and cache poisoning in pdns-recursor. SUSE's advisory wave spans openSUSE Leap, Tumbleweed, SLE-15-SP7, and SLE-16.0, hitting Chromium, Suricata, Podman, and Python 3.11 through 3.14. Slackware kept it quieter, releasing SSA advisories for libssh, Mozilla Firefox, and Thunderbird 140.13 ESR.

Fedora and Ubuntu round out the week

Fedora 43 and 44 dropped patches for seventeen CVEs in dotnet8 alone. The project also shipped Firefox 153.0 and a Chromium update that patches SCP path traversal flaws in python-asyncssh. You'll also want to grab the latest nuclei, routinator, btrbk, and Skopeo updates before they show up on someone else's vulnerability scan.

Ubuntu's USN round runs from USN-8572 through USN-8603. They covered wget, Apache HTTP Server, nginx, PHP, FreeRDP, OpenSSH, CUPS, and ImageMagick. The kernel patches are split across standard builds, NVIDIA, IBM, Oracle, OEM, Tegra, and a separate sweep for Azure and Azure FDE on 26.04 LTS. UBports slipped in Ubuntu Touch OTA 2.0 alongside the desktop releases, moving the mobile OS to Ubuntu 24.04 LTS and upgrading Morph Browser to Chromium 134.

Latest Security Updates by Distribution

Here’s a complete breakdown of the security updates for AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux.

AlmaLinux

AlmaLinux issued several batches of security advisories across versions 8, 9, and 10. The updates patch dozens of high-risk flaws in widely used packages including Python 3, the Linux kernel, OpenJDK versions 8 through 21, OpenSSL, glibc, Apache httpd, and WebKitGTK. System administrators on these releases must apply the patches immediately to resolve issues like CVE-2026-46323, a use-after-free bug in the network subsystem, alongside an XFS filesystem correction for version 9. These coordinated releases safeguard critical database connections, core system libraries, and enterprise infrastructure from active exploitation.

Debian GNU/Linux

Debian issued a series of security advisories that fix dozens of vulnerabilities across stable and legacy Long Term Support distributions. The patches cover widely used packages including libnfs, Tiff, ImageMagick, the Linux kernel, Samba, NSS, Firefox ESR, Chromium, BIND9, pdns-recursor, Webkit2GTK, Squid, WordPress, spice-vdagent, GRUB2, and Exim4. Flaws in libnfs allow unchecked string lengths to trigger integer overflows, while malformed TIFF files processed by the updated library enable arbitrary code execution or system crashes. Additional fixes close cache poisoning risks in pdns-recursor, privilege escalation and denial of service issues in the Linux kernel, and path traversal vulnerabilities in spice-vdagent before administrators miss their installation deadlines.

Fedora Linux

The Fedora Project released coordinated security patches for Fedora 43 and Fedora 44, addressing dozens of vulnerabilities across a massive list of system packages including python-asyncssh, libseccomp, mbedtls, OpenSSH, Wireshark, the Linux kernel, Nginx, Chromium, .NET Runtime, Firefox, Docker Engine, and Core Utilities. Key advisories fix critical flaws such as SCP path traversal vulnerabilities in python-asyncssh that enable unauthorized file modifications, alongside seventeen documented CVEs in dotnet8 and security holes affecting nuclei, routinator dependencies, btrbk, mupdf, Skopeo, Netatalk, Mbed TLS, Perl DBI, xrdp, Libreswan, and PAM modules. These updates also bring maintenance improvements like the release of Firefox 153.0 and Cryptlib patches while closing gaps in widely deployed tools such as wget1, c-ares, libssh, LLVM compiler tools, Fractal messaging client, SSSD, and Django. Fedora administrators should apply these releases without delay to secure their environments against the reported exploits covering unauthorized writes, remote access risks, and container engine weaknesses described in the official documentation.

Oracle Linux

Oracle published multiple batches of errata and security advisories for versions seven through ten on x86_64 and aarch64 systems. The releases patch foundational components including the mainline and Unbreakable Enterprise kernels, glibc, httpd, Nginx, PHP, Python, .NET SDKs, PostgreSQL, Firefox, Thunderbird, Container Tools, and Vim. These coordinated advisories address hundreds of vulnerabilities, including seven distinct flaws patched in Vim such as code injection in netrw and command execution issues in python3complete and glob(). The updates keep enterprise workloads secure while maintaining compatibility across all supported Oracle Linux distributions.

Red Hat Enterprise Linux

Red Hat Product Security issued a wave of RHSA-2026 advisories to address multiple vulnerabilities across RHEL versions 7 through 10. The patches target core infrastructure components including OpenShift Container Platform 4, the Linux kernel, httpd, glibc, PostgreSQL, and Java 17 OpenJDK. Administrators managing RHEL 8, 9, or 10 environments will also receive fixes for SSSD, glib2, Red Hat Satellite, and the Ansible Automation Platform. These coordinated releases combine security hardening with routine bug corrections to keep enterprise systems running safely across all supported versions.

Rocky Linux

Rocky Linux administrators should install fresh errata covering security vulnerabilities and maintenance updates across versions 8, 9, and 10. The new advisories address performance improvements and bug fixes for widely used components including NodeJS 22, .NET 8 through 10, Python 3.14, Glibc, and httpd:2.4. Security patches specifically target the Webkit2GTK3 rendering engine, glib2 utility libraries, and core kernel modules to block known exploits.

Slackware Linux

Slackware Linux issued security patches for libssh, Mozilla Firefox, and Thunderbird 140.13 ESR targeting versions 15.0 and the current development branch. These packages resolve critical flaws documented under CVE identifiers ranging from CVE-2026-15370 through CVE-2026-59849, alongside additional Mozilla advisories and the specific Thunderbird bulletin SSA:2026-204-01. Users running either the stable release or rolling current branch should install these packages immediately to close known security gaps.

SUSE Linux

SUSE issued a series of coordinated security advisories patching dozens of vulnerabilities across openSUSE Leap, Tumbleweed, SLE-15-SP7, and SLE-16.0 environments. The patches resolve critical flaws in widely deployed software including Chromium, Python 3.11 and 3.13/3.14, the Linux kernel, ImageMagick, Perl DBI, Podman, FFmpeg, and Suricata that previously enabled remote code execution, memory corruption, heap overflows, and denial-of-service attacks. System administrators should apply these updates immediately to close known exploitation pathways and maintain compliance with enterprise security baselines. The release schedule covers both rolling community distributions and long-term support channels, reflecting SUSE's standard vulnerability management workflow for its entire product family.

Ubuntu Linux

Ubuntu published a series of security advisories this week targeting critical flaws in wget, Apache HTTP Server, nginx, PHP, FreeRDP, OpenSSH, CUPS, ImageMagick, Exim, Kerberos, Gawk, Rsyslog, and PAM across multiple long-term support releases. The kernel patches cover the standard distribution alongside specialized builds for NVIDIA, IBM, Oracle, OEM hardware, and Tegra chips, with a separate update fixing over five hundred vulnerabilities in Azure and Azure FDE kernels running Ubuntu 26.04 LTS. UBports also delivered Ubuntu Touch OTA 2.0, moving the mobile operating system to Ubuntu 24.04 LTS and upgrading Morph Browser to Chromium 134 to resolve longstanding web compatibility issues. Organizations running these packages on production servers need to apply the patches immediately to close known attack vectors before threat actors exploit them remotely.

How to apply these Linux security updates

Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.

Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.

Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.

Debian/Ubuntu (apt)

The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.

sudo apt update
sudo apt upgrade -y

Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)

On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.

sudo dnf check-update
sudo dnf upgrade -y

or on older releases

sudo yum check-update
sudo yum update

SUSE (zypper)

SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.

sudo zypper refresh
sudo zypper update -y

Slackware (slackpkg and pkgtool)

Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.

sudo slackpkg update
sudo slackpkg upgrade-all