This week's Linux security updates deliver critical patches for widely used services like Nginx and Samba across nearly every major distribution. Enterprise-focused releases from Red Hat, AlmaLinux, Rocky, and Oracle include extensive fixes for .NET runtimes up to version 10, container tools, and hardened kernels. Debian and SUSE administrators should prioritize updates for ImageMagick, Exim4, Redis, and Podman to close dangerous infrastructure vulnerabilities. Meanwhile, Fedora and Ubuntu addressed memory corruption flaws in BIND and Chromium while rolling out specialized kernel variants and resolving recent package manager regressions.
Last Week's Linux Security Updates: Critical Patches for Nginx, Samba, and Kernels
System administrators face a massive backlog of linux security updates this week, driven by critical flaws in web servers, file sharing protocols, and kernels. Nginx and Samba took heavy hits across multiple distributions, leaving unpatched systems exposed to remote code execution and privilege escalation. Beyond the headline vulnerabilities, there is a wave of runtime updates for .NET, Python, and Java that affect everything from desktop workstations to cloud instances. Delaying these patches only increases the attack surface while prompt action keeps infrastructure secure.
Critical Fixes for Nginx and Samba
Nginx is the primary concern this week, with AlmaLinux, Rocky Linux, SUSE, and Ubuntu all releasing critical advisories. These updates address dangerous flaws that allow attackers to crash worker processes or execute code via crafted requests. If you run a reverse proxy or host content behind Nginx, verify the version immediately. Samba also received urgent patches on Debian, SUSE, and Ubuntu. File shares are prime targets for ransomware and data theft, so applying these fixes is non-negotiable for any system exposing SMB services.
RHEL Family Updates and .NET 10
AlmaLinux, Rocky Linux, Oracle Linux, and Red Hat all released updates that include .NET versions 8, 9, and even 10. Seeing .NET 10 in enterprise repositories this early is a sign of how fast the ecosystem moves now. These updates also cover Cockpit, Flatpak, and Thunderbird. Rocky Linux users should note version 10.2 just dropped with stricter x86_64-v3 hardware baselines for fresh installs, which might break compatibility on older machines if planning a clean install. Oracle Linux administrators need to apply patches for the Unbreakable Enterprise kernel alongside fixes for Firefox and Ruby modules.
Debian and SUSE Essentials
Debian pushed updates for ImageMagick, NodeJS, and Exim4 alongside the kernel. Mail admins using Exim should test this in staging first, as runtime updates can sometimes trip up custom configurations or break mail flow if dependencies shift unexpectedly. SUSE released critical advisories for Samba and Redis, along with fixes for Podman and Docker containers. If running containerized workloads on openSUSE or SLES, verify images against the new security baselines to prevent supply chain risks.
Fedora and Ubuntu Kernels
Fedora administrators managing versions 42 through 44 need to apply patches for BIND, Chromium, and Netatalk. The kernel updates here address memory corruption issues that could lead to heap overflows. Ubuntu has a sprawling list of kernel variants, including Low Latency, NVIDIA Tegra, and Azure builds. If running specialized hardware or cloud instances, make sure to grab the right kernel flavor. Ubuntu also fixed regressions in pip and Apache HTTP Server, which is a relief for Python developers who might have been stuck on broken package managers after previous updates.
Slackware Maintenance
Slackware users received a smaller but necessary update for version 15.0 and the development branch. The kernel fixes address CVE-2026-43503 and CVE-2026-46300 related to shared fragment markers, while Thunderbird received its own security refresh. Since Slackware moves at its own pace, these patches are essential for maintaining integrity on stable systems without introducing unnecessary changes.

Latest Security Patches by Distribution
Here’s a complete breakdown of the security updates:
AlmaLinux
AlmaLinux recently rolled out extensive security patches across versions 8 through 10 to address dozens of critical vulnerabilities. These updates target essential system components like Python, Glibc, Flatpak, and Apache HTTP Server while fixing dangerous flaws in the Linux kernel and various web applications. Administrators should prioritize installing these releases immediately since unpatched systems remain exposed to severe exploitation risks. The comprehensive wave of CVE fixes ensures that enterprise environments maintain a hardened posture against emerging threats without disrupting daily operations.
- ALSA-2026:19053: freeipmi security update (Moderate)
- ALSA-2026:19031: skopeo security update (Important)
- ALSA-2026:18421: luksmeta security update (Moderate)
- ALSA-2026:19158: dnsmasq security update (Important)
- ALSA-2026:19148: glib2 security update (Moderate)
- ALSA-2026:19134: grafana security update (Important)
- ALSA-2026:19032: buildah security update (Important)
- ALSA-2026:19160: firefox security update (Important)
- ALSA-2026:19135: opentelemetry-collector security update (Important)
- ALSA-2026:19157: firefox security update (Important)
- ALSA-2026:19153: thunderbird security update (Important)
- ALSA-2026:19151: jq security update (Important)
- ALSA-2026:19139: go-fdo-client security update (Important)
- ALSA-2026:19136: grafana-pcp security update (Important)
- ALSA-2026:19125: xorg-x11-server-Xwayland security update (Important)
- ALSA-2026:19126: yggdrasil security update (Important)
- ALSA-2026:19128: yggdrasil-worker-package-manager security update (Important)
- ALSA-2026:19130: libcap security update (Important)
- ALSA-2026:19133: git-lfs security update (Important)
- ALSA-2026:19067: sudo security update (Important)
- ALSA-2026:19034: python-tornado security update (Moderate)
- ALSA-2026:19013: delve security update (Moderate)
- ALSA-2026:18162: iputils security update (Moderate)
- ALSA-2026:19367: giflib update (Important)
- ALSA-2026:19374: nginx security update (Critical)
- ALSA-2026:19361: glib2 security update (Moderate)
- ALSA-2026:19372: nginx:1.26 security update (Critical)
- ALSA-2026:20574: firefox security update (Important)
- ALSA-2026:19181: golang security update (Important)
- ALSA-2026:18786: bind security update (Important)
- ALSA-2026:19371: nginx:1.24 security update (Critical)
- ALSA-2026:19180: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update (Important)
- ALSA-2026:19213: systemd security update (Moderate)
- ALSA-2026:19354: PackageKit security update (Important)
- ALSA-2026:18683: libssh security update (Moderate)
- ALSA-2026:19208: freeipmi security update (Moderate)
- ALSA-2026:19176: python3.14 security update (Important)
- ALSA-2026:19357: krb5 security update (Important)
- ALSA-2026:19368: rsync security update (Important)
- ALSA-2026:19224: vim security update (Important)
- ALSA-2026:19173: podman security update (Important)
- ALSA-2026:18772: qemu-kvm security update (Moderate)
- ALSA-2026:18748: libvirt security update (Moderate)
- ALSA-2026:19225: kernel security update (Important)
- ALSA-2026:19219: openssh security update (Important)
- ALSA-2026:18868: linux-sgx security update (Important)
- ALSA-2026:18705: mingw-glib2 security update (Moderate)
- ALSA-2026:18597: NetworkManager security update (Low)
- ALSA-2026:19370: firefox security update (Important)
- ALSA-2026:19218: openssl security update (Moderate)
- ALSA-2026:19363: libtiff security update (Important)
- ALSA-2026:19197: python-jwcrypto security update (Low)
- ALSA-2026:19216: python3.9 security update (Important)
- ALSA-2026:19175: python3.11 security update (Important)
- ALSA-2026:19177: python3.12 security update (Important)
- ALSA-2026:18599: p11-kit security update (Moderate)
- ALSA-2026:19365: jq security update (Important)
- ALSA-2026:19343: xorg-x11-server security update (Important)
- ALSA-2026:19210: gdk-pixbuf2 security update (Important)
- ALSA-2026:18931: unbound security update (Moderate)
- ALSA-2026:19610: libsndfile security update (Important)
- ALSA-2026:18824: luksmeta security update (Moderate)
- ALSA-2026:19373: dnsmasq security update (Important)
- ALSA-2026:19356: libsoup security update (Moderate)
- ALSA-2026:19345: LibRaw security update (Important)
- ALSA-2026:19359: openexr security update (Important)
- ALSA-2026:19346: libcap security update (Important)
- ALSA-2026:19344: xorg-x11-server-Xwayland security update (Important)
- ALSA-2026:19348: thunderbird security update (Important)
- ALSA-2026:19352: grafana security update (Important)
- ALSA-2026:19351: grafana-pcp security update (Important)
- ALSA-2026:19220: sudo security update (Important)
- ALSA-2026:19187: compat-openssl11 security update (Moderate)
- ALSA-2026:19178: crun security update (Moderate)
- ALSA-2026:19186: buildah security update (Important)
- ALSA-2026:19350: git-lfs security update (Important)
- ALSA-2026:19189: python-tornado security update (Moderate)
- ALSA-2026:18913: containernetworking-plugins security update (Important)
- ALSA-2026:20579: freeipmi security update (Moderate)
- ALSA-2026:19353: opentelemetry-collector security update (Important)
- ALSA-2026:20589: dnsmasq security update (Important)
- ALSA-2026:20585: compat-libtiff3 security update (Important)
- ALSA-2026:20586: thunderbird security update (Important)
- ALSA-2026:18143: p11-kit security update (Moderate)
- ALSA-2026:19152: rsync security update (Important)
- ALSA-2026:18326: libvirt security update (Moderate)
- ALSA-2026:19024: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update (Important)
- ALSA-2026:19054: tomcat security update (Important)
- ALSA-2026:19149: dovecot security update (Important)
- ALSA-2026:19073: vim security update (Important)
- ALSA-2026:19159: nginx security update (Critical)
- ALSA-2026:18465: edk2 security update (Important)
- ALSA-2026:18480: linux-sgx security update (Important)
- ALSA-2026:19145: krb5 security update (Important)
- ALSA-2026:18479: qemu-kvm security update (Important)
- ALSA-2026:19150: libtiff security update (Important)
- ALSA-2026:18160: libssh security update (Moderate)
- ALSA-2026:18142: NetworkManager security update (Low)
- ALSA-2026:19155: python-markdown security update (Important)
- ALSA-2026:18344: mingw-glib2 security update (Moderate)
- ALSA-2026:18556: unbound security update (Moderate)
- ALSA-2026:19042: python-jwcrypto security update (Low)
- ALSA-2026:19022: golang security update (Important)
- ALSA-2026:19068: systemd security update (Moderate)
- ALSA-2026:19020: crun security update (Moderate)
- ALSA-2026:19137: go-fdo-server security update (Important)
- ALSA-2026:19064: python3.12 security update (Important)
- ALSA-2026:19141: PackageKit security update (Important)
- ALSA-2026:19143: libsoup3 security update (Moderate)
- ALSA-2026:19560: libsndfile security update (Important)
- ALSA-2026:19017: podman security update (Important)
- ALSA-2026:19069: openssh security update (Important)
- ALSA-2026:19066: openssl security update (Moderate)
- ALSA-2026:19154: giflib security update (Important)
- ALSA-2026:19127: gdk-pixbuf2 security update (Important)
- ALSA-2026:19019: python3.14 security update (Important)
- ALSA-2026:19061: glibc security update (Moderate)
- ALSA-2026:19010: postgresql16 security update (Important)
- ALSA-2026:19074: kernel security update (Important)
- ALSA-2026:19009: postgresql18 security update (Important)
- ALSA-2026:20929: libexif security update (Moderate)
- ALSA-2026:20587: glibc security update (Moderate)
- ALSA-2026:20614: ruby:3.3 security update (Important)
- ALSA-2026:20611: gnutls security update (Important)
- ALSA-2026:20594: glibc security update (Moderate)
- ALSA-2026:20693: mysql8.4 security update (Moderate)
- ALSA-2026:20596: ruby:4.0 security update (Important)
- ALSA-2026:20566: firefox security update (Important)
- ALSA-2026:21756: flatpak security update (Important)
- ALSA-2026:21700: cockpit security update (Important)
- ALSA-2026:21745: kernel-rt security update (Important)
- ALSA-2026:21293: .NET 8.0 security update (Important)
- ALSA-2026:21291: .NET 8.0 security update (Important)
- ALSA-2026:21468: cockpit security update (Important)
- ALSA-2026:21706: kernel security update (Important)
- ALSA-2026:21286: .NET 8.0 security update (Important)
- ALSA-2026:21433: httpd security update (Important)
- ALSA-2026:21297: .NET 10.0 security update (Important)
- ALSA-2026:21381: thunderbird security update (Important)
- ALSA-2026:21296: .NET 9.0 security update (Important)
- ALSA-2026:21391: httpd security update (Important)
- ALSA-2026:21754: .NET 9.0 security update (Important)
- ALSA-2026:21380: firefox security update (Important)
- ALSA-2026:21676: cockpit security update (Important)
- ALSA-2026:21382: firefox security update (Important)
- ALSA-2026:21295: .NET 10.0 security update (Important)
- ALSA-2026:21294: .NET 9.0 security update (Important)
- ALSA-2026:21757: flatpak security update (Important)
- ALSA-2026:21755: flatpak security update (Important)
- ALSA-2026:21378: firefox security update (Important)
Debian GNU/Linux
Debian recently pushed out a heavy batch of security advisories that address critical flaws across dozens of essential packages. You should prioritize installing these updates right away since unpatched versions of the Linux kernel, ImageMagick, and NodeJS leave systems wide open to privilege escalation and data theft. Several other widely used tools like GnuTLS, Samba, and Varnish also received urgent fixes for bugs that could easily crash servers or let malicious actors run arbitrary code on your network. Delaying these patches only increases your exposure to dangerous exploits while prompt action keeps your entire infrastructure secure and running smoothly.
- [DLA 4598-1] nodejs security update
- ELA-1732-1 gnutls28 security update
- [DLA 4599-1] jq security update
- [DSA 6296-1] spip security update
- [DLA 4600-1] postorius security update
- [DSA 6297-1] samba security update
- [DSA 6300-1] node-shell-quote security update
- [DSA 6299-1] kdenlive security update
- [DSA 6298-1] imagemagick security update
- [DLA 4601-1] memcached security update
- ELA-1733-1 memcached security update
- [DSA 6304-1] unbound security update
- [DSA 6303-1] varnish security update
- [DSA 6302-1] starlette security update
- [DSA 6301-1] roundcube security update
- ELA-1736-1 erlang security update (by )
- [DLA 4603-1] krb5 security update
- ELA-1735-1 nghttp2 security update
- [DLA 4604-1] roundcube security update
- [DSA 6308-1] nagios4 security update
- [DLA 4602-1] lemonldap-ng security update
- [DLA 4605-1] python-flask-httpauth security update
- [DSA 6307-1] kitty security update
- [DSA 6306-1] linux security update
- [DSA 6305-1] linux security update
- ELA-1737-1 libexif security update (by )
- [DLA 4608-1] corosync security update
- [DSA 6311-1] php-twig security update
- [DSA 6310-1] imagemagick security update
- [DLA 4607-1] linux-6.1 security update
- [DLA 4606-1] linux security update
- [DSA 6309-1] exim4 security update
- ELA-1739-1 linux-6.1 security update (by )
- ELA-1738-1 linux-5.10 security update (by )
- [DLA 4609-1] imagemagick security update
- ELA-1740-1 nginx security update (by )
Fedora Linux
Fedora administrators managing versions 42 through 44 must immediately apply a coordinated wave of critical security patches across dozens of essential system packages. These updates address severe vulnerabilities in widely used tools like BIND, Chromium, the Linux kernel, and Netatalk that could otherwise allow remote code execution or heap buffer overflows. Many of the fixes focus on memory corruption flaws and policy bypasses that attackers frequently exploit to steal sensitive data or crash entire services. System operators should prioritize installing these releases right away to maintain network stability and protect against known exploitation paths.
- Fedora 42 Update: nodejs-aw-webui-0^20260516.8d9a7f8-1.fc42
- Fedora 42 Update: awatcher-0.3.3-2.fc42
- Fedora 42 Update: aw-server-rust-0.14.0^20260516.gitdf49b3d-1.fc42
- Fedora 43 Update: aw-server-rust-0.14.0^20260516.gitdf49b3d-1.fc43
- Fedora 43 Update: nodejs-aw-webui-0^20260516.8d9a7f8-1.fc43
- Fedora 43 Update: awatcher-0.3.3-2.fc43
- Fedora 44 Update: bind-dyndb-ldap-11.11-15.fc44
- Fedora 44 Update: bind-9.18.49-1.fc44
- Fedora 44 Update: aw-server-rust-0.14.0^20260516.gitdf49b3d-1.fc44
- Fedora 44 Update: awatcher-0.3.3-2.fc44
- Fedora 44 Update: nodejs-aw-webui-0^20260516.8d9a7f8-1.fc44
- Fedora 43 Update: bind-9.18.49-1.fc43
- Fedora 43 Update: bind-dyndb-ldap-11.11-13.fc43
- Fedora 43 Update: linux-firmware-20260519-1.fc43
- Fedora 43 Update: tor-0.4.9.8-1.fc43
- Fedora 44 Update: unbound-1.25.1-1.fc44
- Fedora 44 Update: tor-0.4.9.8-1.fc44
- Fedora 43 Update: chromium-148.0.7778.178-1.fc43
- Fedora 43 Update: perl-Crypt-DSA-1.20-1.fc43
- Fedora 43 Update: rust-eif_build-0.2.1-7.fc43
- Fedora 43 Update: haproxy-3.0.23-2.fc43
- Fedora 43 Update: rust-coreos-installer-0.26.0-2.fc43
- Fedora 43 Update: rust-sequoia-sqv-1.3.0-6.fc43
- Fedora 43 Update: rust-afterburn-5.10.0-7.fc43
- Fedora 43 Update: rust-sequoia-keystore-server-0.2.0-7.fc43
- Fedora 43 Update: rust-sequoia-sq-1.3.1-11.fc43
- Fedora 43 Update: rust-sequoia-sop-0.37.3-3.fc43
- Fedora 43 Update: rust-sequoia-openpgp-2.3.0-1.fc43
- Fedora 43 Update: rust-sequoia-git-0.6.0-2.fc43
- Fedora 43 Update: rust-sequoia-octopus-librnp-1.11.1-6.fc43
- Fedora 43 Update: rust-sequoia-chameleon-gnupg-0.13.1-12.fc43
- Fedora 43 Update: rust-rpm-sequoia-1.10.2-2.fc43
- Fedora 43 Update: curl-8.15.0-7.fc43
- Fedora 43 Update: uriparser-1.0.2-1.fc43
- Fedora 43 Update: editorconfig-0.12.11-1.fc43
- Fedora 42 Update: perl-Crypt-DSA-1.20-1.fc42
- Fedora 42 Update: haproxy-3.0.23-2.fc42
- Fedora 42 Update: rust-sequoia-octopus-librnp-1.11.1-6.fc42
- Fedora 42 Update: rust-sequoia-sq-1.3.1-11.fc42
- Fedora 42 Update: rust-sequoia-keystore-server-0.2.0-7.fc42
- Fedora 42 Update: rust-sequoia-git-0.6.0-2.fc42
- Fedora 42 Update: rust-rpm-sequoia-1.10.2-2.fc42
- Fedora 42 Update: rust-sequoia-sqv-1.3.0-6.fc42
- Fedora 42 Update: rust-sequoia-openpgp-2.3.0-1.fc42
- Fedora 42 Update: rust-sequoia-sop-0.37.3-3.fc42
- Fedora 42 Update: rust-sequoia-chameleon-gnupg-0.13.1-12.fc42
- Fedora 42 Update: editorconfig-0.12.11-1.fc42
- Fedora 42 Update: poppler-25.02.0-6.fc42
- Fedora 44 Update: perl-HTTP-Tiny-0.094-1.fc44
- Fedora 44 Update: perl-Crypt-DSA-1.20-1.fc44
- Fedora 44 Update: haproxy-3.0.23-2.fc44
- Fedora 44 Update: rust-eif_build-0.2.1-7.fc44
- Fedora 44 Update: rust-coreos-installer-0.26.0-2.fc44
- Fedora 44 Update: rust-afterburn-5.10.0-7.fc44
- Fedora 44 Update: editorconfig-0.12.11-1.fc44
- Fedora 42 Update: rrdtool-1.9.0-8.fc42
- Fedora 44 Update: kernel-7.0.10-201.fc44
- Fedora 44 Update: nginx-mod-naxsi-1.6-18.fc44
- Fedora 44 Update: nginx-mod-modsecurity-1.0.4-11.fc44
- Fedora 44 Update: nginx-mod-headers-more-0.39-10.fc44
- Fedora 44 Update: nginx-1.30.2-1.fc44
- Fedora 44 Update: nginx-mod-vts-0.2.4-10.fc44
- Fedora 44 Update: nginx-mod-fancyindex-0.6.0-5.fc44
- Fedora 44 Update: nginx-mod-js-challenge-0^20230517.gitda6852d-8.fc44
- Fedora 44 Update: nginx-mod-brotli-1.0.0~rc-10.fc44
- Fedora 44 Update: rrdtool-1.9.0-11.fc44
- Fedora 44 Update: rust-astral_async_zip-0.0.18~rc4-2.fc44
- Fedora 44 Update: rust-astral-tokio-tar-0.6.2-1.fc44
- Fedora 44 Update: uv-0.11.15-1.fc44
- Fedora 44 Update: rust-astral_async_http_range_reader-0.11.0-2.fc44
- Fedora 44 Update: python-uv-build-0.11.15-1.fc44
- Fedora 44 Update: perl-Imager-1.031-1.fc44
- Fedora 44 Update: xen-4.21.1-3.fc44
- Fedora 43 Update: rust-astral-tokio-tar-0.6.2-1.fc43
- Fedora 43 Update: rust-astral_async_zip-0.0.18~rc4-2.fc43
- Fedora 43 Update: python-uv-build-0.11.15-1.fc43
- Fedora 43 Update: rrdtool-1.9.0-8.fc43
- Fedora 43 Update: uv-0.11.15-1.fc43
- Fedora 43 Update: rust-astral_async_http_range_reader-0.11.0-2.fc43
- Fedora 43 Update: xen-4.20.3-3.fc43
- Fedora 43 Update: poppler-25.07.0-5.fc43
- Fedora 43 Update: kernel-7.0.10-101.fc43
- Fedora 43 Update: mapserver-8.6.3-1.fc43
- Fedora 43 Update: podofo-1.0.4-1.fc43
- Fedora 43 Update: mingw-qt6-qtsvg-6.10.3-2.fc43
- Fedora 43 Update: openbao-2.5.4-1.fc43
- Fedora 43 Update: perl-Sereal-Encoder-5.005-1.fc43
- Fedora 43 Update: perl-Sereal-Decoder-5.005-1.fc43
- Fedora 43 Update: perl-Sereal-5.005-1.fc43
- Fedora 43 Update: gmic-3.7.6-3.fc43
- Fedora 43 Update: CImg-3.7.6-2.fc43
- Fedora 44 Update: jpegxl-0.11.2-1.fc44
- Fedora 44 Update: libpng-1.6.58-1.fc44
- Fedora 44 Update: podofo-1.0.4-1.fc44
- Fedora 44 Update: openbao-2.5.4-1.fc44
- Fedora 44 Update: perl-Sereal-Encoder-5.005-1.fc44
- Fedora 44 Update: perl-Sereal-Decoder-5.005-1.fc44
- Fedora 44 Update: perl-Sereal-5.005-1.fc44
- Fedora 44 Update: haveged-1.9.21-1.fc44
- Fedora 43 Update: haveged-1.9.22-1.fc43
- Fedora 43 Update: djvulibre-3.5.30-1.fc43
- Fedora 43 Update: xrdp-0.10.6-2.fc43
- Fedora 43 Update: pdns-5.0.5-1.fc43
- Fedora 43 Update: docker-compose-5.1.4-1.fc43
- Fedora 44 Update: xrdp-0.10.6-2.fc44
- Fedora 44 Update: libssh2-1.11.1-6.fc44
- Fedora 44 Update: djvulibre-3.5.30-1.fc44
- Fedora 44 Update: pdns-5.0.5-1.fc44
- Fedora 44 Update: docker-compose-5.1.4-1.fc44
- Fedora 44 Update: giflib-6.1.3-2.fc44
- Fedora 43 Update: netatalk-4.4.3-1.fc43
- Fedora 43 Update: python-urllib3-2.7.0-2.fc43
- Fedora 44 Update: netatalk-4.4.3-1.fc44
- Fedora 44 Update: perl-libwww-perl-6.83-1.fc44
Oracle Linux
Oracle has issued a wide range of security advisories for Oracle Linux versions seven through ten to fix serious flaws in essential system packages. These critical updates target memory corruption issues and network buffer handling problems within the Unbreakable Enterprise kernel. Administrators will also find important patches for widely used applications like Firefox, Thunderbird, and Flatpak alongside development frameworks such as .NET and Ruby. The new releases are now available on the Unbreakable Linux Network to help organizations maintain secure and stable server environments without delay.
- ELSA-2026-19666 Important: Oracle Linux 8 kernel security update
- ELSA-2026-19588 Important: Oracle Linux 8 firefox security update
- ELSA-2026-50288 Important: Oracle Linux 7 Unbreakable Enterprise kernel security update : Fragnesia
- ELBA-2026-19666-1 Oracle Linux 8 kernel bug fix update
- ELSA-2026-50288 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update : Fragnesia
- ELSA-2026-50287 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update : Fragnesia
- ELSA-2026-50287 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update : Fragnesia
- ELSA-2026-50286 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update: Frafnesia
- ELSA-2026-50286 Important: Unbreakable Enterprise kernel security update
- ELSA-2026-50288 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update : Fragnesia
- ELBA-2026-20931 Oracle Linux 8 firewalld bug fix and enhancement update
- ELSA-2026-20566 Important: Oracle Linux 8 firefox security update
- ELSA-2026-20589 Important: Oracle Linux 8 dnsmasq security update
- ELSA-2026-20579 Moderate: Oracle Linux 8 freeipmi security update
- ELSA-2026-20585 Important: Oracle Linux 8 compat-libtiff3 security update
- ELSA-2026-50287 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update : Fragnesia
- ELBA-2026-20559 Oracle Linux 8 volume_key bug fix and enhancement update
- ELSA-2026-21294 Important: Oracle Linux 8 .NET 9.0 security update
- ELBA-2026-50289 Oracle Linux 9 oracle-ai-database-preinstall-26ai bug fix update
- ELSA-2026-21295 Important: Oracle Linux 8 .NET 10.0 security update
- ELSA-2026-20614 Important: Oracle Linux 8 ruby:3.3 security update
- ELSA-2026-20587 Moderate: Oracle Linux 8 glibc security update
- ELSA-2026-20586 Important: Oracle Linux 8 thunderbird security update
- ELBA-2026-20930 Oracle Linux 8 gnome-shell bug fix and enhancement update
- ELBA-2026-20928 Oracle Linux 8 unbound bug fix and enhancement update
- ELBA-2026-20927 Oracle Linux 8 gnome-screenshot bug fix and enhancement update
- ELBA-2026-20538 Oracle Linux 8 tzdata bug fix and enhancement update
- ELSA-2026-21700 Important: Oracle Linux 8 cockpit security update
- ELSA-2026-21291 Important: Oracle Linux 8 .NET 8.0 security update
- ELSA-2026-7292 Important: Oracle Linux 7 freerdp security update
- ELSA-2026-21756 Important: Oracle Linux 8 flatpak security update
- ELSA-2026-21382 Important: Oracle Linux 8 firefox security update
- ELSA-2026-20929 Moderate: Oracle Linux 8 libexif security update
- ELSA-2026-50275 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
- ELSA-2026-50275 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
- ELSA-2026-50275 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
Red Hat Enterprise Linux
Red Hat recently rolled out a broad collection of security advisories designed to patch known vulnerabilities across its enterprise Linux distributions. These updates hit foundational pieces like the kernel and glibc while also hardening container environments such as OpenShift. You will also notice important fixes for everyday tools including Squid, Grafana, Ruby modules, and Firefox that keep systems running smoothly. System administrators should prioritize installing these patches immediately to prevent potential exploits on RHEL versions eight through ten.
- RHSA-2026:20558: Important: xorg-x11-server security update
- RHSA-2026:20572: Moderate: python-tornado security update
- RHSA-2026:20561: Important: xorg-x11-server-Xwayland security update
- RHSA-2026:20565: Important: squid:4 security update
- RHSA-2026:20556: Important: grafana security update
- RHSA-2026:17789: Important: Red Hat build of Cryostat 4.2.0: new RHEL 9 container image security update
- RHSA-2026:20549: Moderate: libpng security update
- RHSA-2026:20552: Important: gimp:2.8 security update
- RHSA-2026:20563: Important: xorg-x11-server-Xwayland security update
- RHSA-2026:20569: Important: buildah security update
- RHSA-2026:20570: Important: podman security update
- RHSA-2026:20551: Moderate: libpng security update
- RHSA-2026:20577: Moderate: python-tornado security update
- RHSA-2026:20560: Important: xorg-x11-server-Xwayland security update
- RHSA-2026:20550: Moderate: libpng security update
- RHSA-2026:20574: Important: firefox security update
- RHSA-2026:20553: Important: gimp:2.8 security update
- RHSA-2026:20546: Moderate: freerdp security update
- RHSA-2026:20562: Important: xorg-x11-server-Xwayland security update
- RHSA-2026:20568: Important: jmc security update
- RHSA-2026:20810: Moderate: python-tornado security update
- RHSA-2026:20594: Moderate: glibc security update
- RHSA-2026:20587: Moderate: glibc security update
- RHSA-2026:20691: Important: gimp security update
- RHSA-2026:20596: Important: ruby:4.0 security update
- RHSA-2026:20614: Important: ruby:3.3 security update
- RHSA-2026:20676: Important: python-markdown security update
- RHSA-2026:20674: Important: python-markdown security update
- RHSA-2026:20670: Important: ruby security update
- RHSA-2026:20677: Important: python-markdown security update
- RHSA-2026:20593: Important: kernel security update
- RHSA-2026:20608: Important: containernetworking-plugins security update
- RHSA-2026:20607: Important: buildah security update
- RHSA-2026:20603: Important: rsync security update
- RHSA-2026:20588: Important: fence-agents security update
- RHSA-2026:20600: Important: wireshark security update
- RHSA-2026:20606: Important: ruby4.0 security update
- RHSA-2026:20610: Moderate: libssh security update
- RHSA-2026:20609: Important: skopeo security update
- RHSA-2026:20595: Important: libcap security update
- RHSA-2026:20604: Important: rsync security update
- RHSA-2026:20564: Important: squid:4 security update
- RHSA-2026:20555: Important: xorg-x11-server security update
- RHSA-2026:20589: Important: dnsmasq security update
- RHSA-2026:20586: Important: thunderbird security update
- RHSA-2026:20602: Important: rsync security update
- RHSA-2026:20605: Moderate: freerdp security update
- RHSA-2026:20576: Important: tigervnc security update
- RHSA-2026:20585: Important: compat-libtiff3 security update
- RHSA-2026:20592: Important: compat-libtiff3 security update
- RHSA-2026:20591: Important: compat-libtiff3 security update
- RHSA-2026:20590: Important: xorg-x11-server security update
- RHSA-2026:20584: Important: git-lfs security update
- RHSA-2026:20580: Important: squid:4 security update
- RHSA-2026:20601: Important: rsync security update
- RHSA-2026:20575: Important: tigervnc security update
- RHSA-2026:20548: Moderate: libpng security update
- RHSA-2026:20567: Important: qt6-qtdeclarative security update
- RHSA-2026:20579: Moderate: freeipmi security update
- RHSA-2026:20582: Important: git-lfs security update
- RHSA-2026:20583: Important: compat-libtiff3 security update
- RHSA-2026:20581: Important: git-lfs security update
- RHSA-2026:20554: Important: gimp:2.8 security update
- RHSA-2026:20571: Important: skopeo security update
- RHSA-2026:20547: Important: xorg-x11-server-Xwayland security update
- RHSA-2026:20573: Moderate: python-tornado security update
- RHSA-2026:20557: Important: xorg-x11-server security update
- RHSA-2026:20566: Important: firefox security update
- RHSA-2026:20405: Important: Red Hat JBoss Web Server 6.2.3 release and security update
- RHSA-2026:20406: Important: Red Hat JBoss Web Server 6.2.3 release and security update
- RHSA-2026:20916: Moderate: corosync security update
- RHSA-2026:20597: Moderate: glibc security update
- RHSA-2026:20693: Moderate: mysql8.4 security update
- RHSA-2026:20696: Important: rsync security update
- RHSA-2026:20929: Moderate: libexif security update
- RHSA-2026:20611: Important: gnutls security update
- RHSA-2026:21296: Important: .NET 9.0 security update
- RHSA-2026:21295: Important: .NET 10.0 security update
- RHSA-2026:21254: Important: libcap security update
- RHSA-2026:20322: Important: Red Hat build of MicroShift 4.19.32 security update
- RHSA-2026:21209: Important: kernel security update
- RHSA-2026:21297: Important: .NET 10.0 security update
- RHSA-2026:21294: Important: .NET 9.0 security update
- RHSA-2026:21293: Important: .NET 8.0 security update
- RHSA-2026:21298: Important: openssh security update
- RHSA-2026:21291: Important: .NET 8.0 security update
- RHSA-2026:21286: Important: .NET 8.0 security update
- RHSA-2026:21557: Important: kernel security update
- RHSA-2026:20436: Important: Red Hat build of MicroShift 4.16.63 security update
- RHSA-2026:21517: Important: fence-agents security update
- RHSA-2026:21516: Important: cockpit security update
- RHSA-2026:21515: Important: cockpit security update
- RHSA-2026:21468: Important: cockpit security update
- RHSA-2026:21431: Important: fence-agents security update
- RHSA-2026:21433: Important: httpd security update
- RHSA-2026:21391: Important: httpd security update
- RHSA-2026:21398: Important: openssh security update
- RHSA-2026:21394: Important: cockpit security update
- RHSA-2026:21395: Important: cockpit security update
- RHSA-2026:21378: Important: firefox security update
- RHSA-2026:21390: Important: cockpit security update
- RHSA-2026:21381: Important: thunderbird security update
- RHSA-2026:21380: Important: firefox security update
- RHSA-2026:21382: Important: firefox security update
- RHSA-2026:20040: Important: OpenShift Container Platform 4.19.32 bug fix and security update
- RHSA-2026:21718: Important: xorg-x11-server security update
- RHSA-2026:21716: Important: xorg-x11-server-Xwayland security update
- RHSA-2026:21712: Important: xorg-x11-server-Xwayland security update
- RHSA-2026:21700: Important: cockpit security update
- RHSA-2026:21699: Important: xorg-x11-server security update
- RHSA-2026:21682: Important: python3.9 security update
- RHSA-2026:21686: Moderate: libsoup security update
- RHSA-2026:21676: Important: cockpit security update
- RHSA-2026:21647: Important: cockpit security update
- RHSA-2026:21556: Important: kernel security update
- RHSA-2026:21755: Important: flatpak security update
- RHSA-2026:21757: Important: flatpak security update
- RHSA-2026:21756: Important: flatpak security update
- RHSA-2026:21754: Important: .NET 9.0 security update
- RHSA-2026:21745: Important: kernel-rt security update
- RHSA-2026:21743: Important: firefox security update
- RHSA-2026:21742: Important: xorg-x11-server security update
- RHSA-2026:21741: Important: tigervnc security update
- RHSA-2026:21392: Important: cockpit security update
- RHSA-2026:21715: Important: xorg-x11-server security update
- RHSA-2026:21706: Important: kernel security update
- RHSA-2026:20087: Important: OpenShift Container Platform 4.16.63 bug fix and security update
Rocky Linux
Rocky Linux administrators must apply a broad wave of critical security patches to protect systems running versions eight through ten. These urgent updates target essential components like the kernel, .NET framework, Firefox, Thunderbird, and various system libraries that power modern enterprise environments. Version 10.2 just dropped with stricter x86_64-v3 hardware baselines for fresh installs, though existing v10 machines can upgrade using a single command. Teams managing Flatpak, Cockpit, Golang, or Nginx should prioritize these fixes immediately to close newly discovered vulnerabilities before attackers exploit them.
- RLSA-2026:21295: Important: .NET 10.0 security update
- RLSA-2026:20586: Important: thunderbird security update
- RLSA-2026:21294: Important: .NET 9.0 security update
- RLSA-2026:20929: Moderate: libexif security update
- RLSA-2026:21382: Important: firefox security update
- RLSA-2026:20589: Important: dnsmasq security update
- RLSA-2026:21291: Important: .NET 8.0 security update
- RLSA-2026:20585: Important: compat-libtiff3 security update
- RLSA-2026:20611: Important: gnutls security update
- RLSA-2026:20587: Moderate: glibc security update
- RLSA-2026:20579: Moderate: freeipmi security update
- RLSA-2026:19167: Important: pcs security update
- RLSA-2026:18705: Moderate: mingw-glib2 security update
- RLSA-2026:19365: Important: jq security update
- RLSA-2026:19366: Important: python-markdown security update
- RLSA-2026:18824: Moderate: luksmeta security update
- RLSA-2026:18786: Important: bind security update
- RLSA-2026:18931: Moderate: unbound security update
- RLSA-2026:18597: Low: NetworkManager security update
- RLSA-2026:18772: Moderate: qemu-kvm security update
- RLSA-2026:21756: Important: flatpak security update
- RLSA-2026:21700: Important: cockpit security update
- RXSA-2024:3138: Moderate: kernel security, bug fix, and enhancement update
- RLSA-2025:11884: Important: unbound security update
- RLSA-2024:8834: Important: python-gevent security update
- RLBA-2025:0736: dnssec-trigger bug fix update
- RLBA-2024:3238: shim bug fix and enhancement update
- RLBA-2024:6979: stunnel bug fix update
- RLSA-2026:18480: Important: linux-sgx security update
- RLSA-2026:18344: Moderate: mingw-glib2 security update
- RLSA-2026:19151: Important: jq security update
- RLSA-2026:18162: Moderate: iputils security update
- RLSA-2026:19155: Important: python-markdown security update
- RLSA-2026:18153: Moderate: systemd security update
- RLSA-2026:19054: Important: tomcat security update
- RLSA-2026:19022: Important: golang security update
- RLSA-2026:19042: Low: python-jwcrypto security update
- RLSA-2026:18142: Low: NetworkManager security update
- RLSA-2026:19020: Moderate: crun security update
- RLSA-2026:19034: Moderate: python-tornado security update
- RLSA-2026:19024: Important: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update
- RLSA-2026:18465: Important: edk2 security update
- RLSA-2026:21745: Important: kernel-rt security update
- RLSA-2026:21706: Important: kernel security update
- RLSA-2026:20568: Important: jmc security update
- RLSA-2026:21381: Important: thunderbird security update
- RLSA-2026:20597: Moderate: glibc security update
- RLSA-2026:21296: Important: .NET 9.0 security update
- RLSA-2026:21391: Important: httpd security update
- RLSA-2026:21468: Important: cockpit security update
- RLSA-2026:21378: Important: firefox security update
- RLSA-2026:21556: Important: kernel security update
- RLSA-2026:19355: Important: fence-agents security update
- RLSA-2026:19374: Critical: nginx security update
- RLSA-2026:21293: Important: .NET 8.0 security update
- RLSA-2026:21297: Important: .NET 10.0 security update
- RLSA-2026:19176: Important: python3.14 security update
Slackware Linux
The Slackware Linux Security Team recently deployed essential security patches for both the stable version 15.0 release and its active development branch. These updates address critical network vulnerabilities by fixing how shared fragment markers interact with buffer transfer helpers, effectively resolving CVE-2026-43503 and CVE-2026-46300 in the new kernel packages. Administrators relying on email services will also benefit from refreshed Thunderbird builds that close additional security gaps without disrupting daily workflows. Users should apply these updates immediately to maintain system integrity across all supported environments.
SUSE Linux
SUSE recently distributed several major security update batches across openSUSE Tumbleweed, Leap, and enterprise Linux distributions to fix dozens of newly discovered flaws. These patches target essential software like the Linux kernel, Firefox, Nginx, Samba, and Podman by closing dangerous gaps that could easily trigger remote code execution or crash network services. System administrators need to install these fixes right away because unpatched machines remain highly vulnerable to memory corruption bugs and unauthorized access attempts. The comprehensive advisories cover both rolling development releases and stable enterprise branches to keep the entire SUSE ecosystem protected against modern threats.
- openSUSE-SU-2026:10845-1: moderate: mcphost-0.34.0-5.1 on GA media
- openSUSE-SU-2026:10846-1: moderate: perl-YAML-Syck-1.450.0-4.1 on GA media
- openSUSE-SU-2026:10842-1: moderate: apptainer-1.4.5-5.1 on GA media
- openSUSE-SU-2026:10843-1: moderate: hauler-1.4.3-3.1 on GA media
- openSUSE-SU-2026:10847-1: moderate: rqlite-10.1.0-1.1 on GA media
- openSUSE-SU-2026:10844-1: moderate: jfrog-cli-2.104.1-1.1 on GA media
- openSUSE-SU-2026:20792-1: moderate: Security update for perl-HTTP-Tiny
- openSUSE-SU-2026:20788-1: important: Security update for mcphost
- openSUSE-SU-2026:20789-1: important: Security update for MozillaFirefox
- openSUSE-SU-2026:20781-1: important: Security update for assimp
- openSUSE-SU-2026:20784-1: important: Security update for nginx
- openSUSE-SU-2026:20786-1: moderate: Security update for GraphicsMagick
- openSUSE-SU-2026:20778-1: important: Security update for gnutls
- openSUSE-SU-2026:20783-1: moderate: Security update for leancrypto
- openSUSE-SU-2026:20787-1: important: Security update for libsndfile
- openSUSE-SU-2026:10854-1: moderate: perl-XML-LibXML-2.0212-1.1 on GA media
- openSUSE-SU-2026:10856-1: moderate: rclone-1.74.2-1.1 on GA media
- openSUSE-SU-2026:10857-1: moderate: rsync-3.4.3-1.1 on GA media
- openSUSE-SU-2026:10851-1: moderate: nano-9.0-2.1 on GA media
- openSUSE-SU-2026:10849-1: moderate: azure-storage-azcopy-10.32.2-3.1 on GA media
- openSUSE-SU-2026:10853-1: moderate: libppsdocument4_0-6-50.1-2.1 on GA media
- openSUSE-SU-2026:10848-1: moderate: amazon-ecs-init-1.103.0-2.1 on GA media
- openSUSE-SU-2026:10852-1: moderate: nginx-1.31.1-1.1 on GA media
- openSUSE-SU-2026:10855-1: moderate: python311-ocrmypdf-17.4.2-1.1 on GA media
- SUSE-SU-2026:2053-1: important: Security update for busybox
- SUSE-SU-2026:2050-1: important: Security update for nginx
- SUSE-SU-2026:2051-1: important: Security update for xz
- SUSE-SU-2026:2055-1: important: Security update for python312
- SUSE-SU-2026:2067-1: important: Security update for python-urllib3_1
- SUSE-SU-2026:2071-1: critical: Security update for samba
- SUSE-SU-2026:2072-1: critical: Security update for samba
- SUSE-SU-2026:2074-1: critical: Security update for samba
- SUSE-SU-2026:2078-1: important: Security update for go1.26-openssl
- SUSE-SU-2026:2079-1: important: Security update for go1.25-openssl
- SUSE-SU-2026:2083-1: important: Security update for rsync
- SUSE-SU-2026:2082-1: important: Security update for podman
- SUSE-SU-2026:2087-1: important: Security update for gnutls
- SUSE-SU-2026:2091-1: important: Security update for php7
- SUSE-SU-2026:2094-1: important: Security update for bubblewrap
- openSUSE-SU-2026:20797-1: important: Security update for libarchive
- openSUSE-SU-2026:20796-1: important: Security update for nginx
- openSUSE-SU-2026:10862-1: moderate: yq-4.53.2-1.1 on GA media
- openSUSE-SU-2026:10860-1: moderate: hplip-3.26.4-1.1 on GA media
- openSUSE-SU-2026:10861-1: moderate: python311-pytest-html-4.2.0-2.1 on GA media
- SUSE-SU-2026:2096-1: important: Security update for yq
- SUSE-SU-2026:2097-1: important: Security update for redis7
- SUSE-SU-2026:2098-1: important: Security update for redis
- SUSE-SU-2026:2099-1: important: Security update for redis
- SUSE-SU-2026:2100-1: important: Security update for redis7
- SUSE-SU-2026:2102-1: important: Security update for xen
- SUSE-SU-2026:2103-1: important: Security update for apache2
- openSUSE-SU-2026:20816-1: important: Security update for alloy
- openSUSE-SU-2026:20815-1: important: Security update for google-osconfig-agent
- openSUSE-SU-2026:20813-1: important: Security update for xz
- openSUSE-SU-2026:20814-1: important: Security update for docker-stable
- openSUSE-SU-2026:20812-1: important: Security update for cups
- openSUSE-SU-2026:20810-1: important: Security update for apache2
- openSUSE-SU-2026:20809-1: important: Security update for trivy
- openSUSE-SU-2026:20811-1: important: Security update for bubblewrap
- openSUSE-SU-2026:20803-1: moderate: Security update for patterns-glibc-hwcaps
- openSUSE-SU-2026:20798-1: important: Security update for trivy
- openSUSE-SU-2026:10865-1: moderate: beets-2.11.0-1.1 on GA media
- openSUSE-SU-2026:10863-1: moderate: MozillaFirefox-151.0.1-1.1 on GA media
- openSUSE-SU-2026:10867-1: moderate: ffmpeg-7-7.1.4-2.1 on GA media
- openSUSE-SU-2026:10864-1: moderate: MozillaThunderbird-140.11.1-1.1 on GA media
- openSUSE-SU-2026:10866-1: moderate: ffmpeg-4-4.4.7-2.1 on GA media
- SUSE-SU-2026:2105-1: moderate: Security update for xdg-desktop-portal
- SUSE-SU-2026:2108-1: critical: Security update for samba
- SUSE-SU-2026:2107-1: important: Security update for podman
- SUSE-SU-2026:2115-1: important: Security update for gnutls
- SUSE-SU-2026:2116-1: moderate: Security update for csync2
- SUSE-SU-2026:2119-1: important: Security update for python-urllib3
- SUSE-SU-2026:2121-1: moderate: Security update for frr
- SUSE-SU-2026:2117-1: important: Security update for postgresql14
- openSUSE-SU-2026:0179-1: important: Security update for chromium
- openSUSE-SU-2026:20827-1: important: Security update for python-mistune
- openSUSE-SU-2026:20826-1: important: Security update for the Linux Kernel
- openSUSE-SU-2026:20839-1: important: Security update for python-pytest-html
- openSUSE-SU-2026:20833-1: important: Security update for trivy
- openSUSE-SU-2026:20831-1: important: Security update for python-Pillow
- openSUSE-SU-2026:20834-1: important: Security update for apptainer
- openSUSE-SU-2026:20828-1: important: Security update for vim
- openSUSE-SU-2026:20838-1: important: Security update for hauler
- openSUSE-SU-2026:20821-1: moderate: Security update for localsearch
- openSUSE-SU-2026:10874-1: moderate: bind-9.20.23-1.1 on GA media
- openSUSE-SU-2026:10878-1: moderate: gdk-pixbuf-loader-libheif-1.22.2-1.1 on GA media
- openSUSE-SU-2026:10879-1: moderate: libredwg-devel-0.13.4.8200-1.1 on GA media
- openSUSE-SU-2026:10876-1: moderate: helm-4.2.0-3.1 on GA media
- openSUSE-SU-2026:10875-1: moderate: hauler-1.4.3-4.1 on GA media
- openSUSE-SU-2026:10873-1: moderate: azure-storage-azcopy-10.32.4-1.1 on GA media
- openSUSE-SU-2026:10872-1: moderate: amazon-ssm-agent-3.3.4515.0-1.1 on GA media
- openSUSE-SU-2026:10877-1: moderate: helm3-3.21.0-2.1 on GA media
- openSUSE-SU-2026:10871-1: moderate: amazon-ecs-init-1.103.2-1.1 on GA media
- openSUSE-SU-2026:10887-1: moderate: apptainer-1.4.5-6.1 on GA media
- openSUSE-SU-2026:10883-1: moderate: python311-Authlib-1.7.2-1.1 on GA media
- openSUSE-SU-2026:10882-1: moderate: memcached-1.6.42-1.1 on GA media
- openSUSE-SU-2026:10881-1: moderate: libBasicUsageEnvironment2-2026.04.22-1.1 on GA media
- openSUSE-SU-2026:0180-1: moderate: Security update for perl-YAML-Syck
Ubuntu Linux
Ubuntu has released multiple urgent security notices that tackle severe vulnerabilities across dozens of popular software packages and specialized kernel builds. Malicious actors could exploit these weaknesses to crash systems, escalate privileges, or run unauthorized code by sending specially crafted network requests. The recent patches fix critical flaws in essential tools like the Apache HTTP Server, PHP runtime, Memcached, and various database utilities while also correcting regressions that accidentally broke previously stable modules. Linux administrators should deploy these updates right away to shield their infrastructure from exploitation and keep their systems running smoothly.
- [USN-8299-1] Rclone vulnerabilities
- [USN-8291-3] Linux kernel (Low Latency) vulnerabilities
- [USN-8296-2] Linux kernel (NVIDIA Tegra) vulnerabilities
- [USN-8301-1] SimpleEval vulnerability
- [USN-8300-1] ngtcp2 vulnerability
- [USN-8305-1] Linux kernel (Intel IoTG Real-time) vulnerabilities
- [USN-8279-3] Linux kernel (NVIDIA Tegra IGX) vulnerabilities
- [USN-8289-2] Linux kernel (NVIDIA) vulnerabilities
- [USN-8298-1] .NET vulnerability
- [USN-8302-1] NLTK vulnerabilities
- [USN-8304-1] Vim vulnerabilities
- [USN-8308-1] Dnsmasq vulnerability
- [USN-8309-1] libssh2 vulnerability
- [USN-8306-1] Samba vulnerabilities
- [USN-8303-1] GitPython vulnerabilities
- [USN-8167-2] xdg-dbus-proxy vulnerability
- [USN-8063-2] Protocol Buffers vulnerability
- [USN-7972-2] OpenCC vulnerability
- [USN-8307-1] ONNX vulnerability
- [USN-8280-3] Linux kernel (IoT) vulnerabilities
- [USN-8310-1] Linux kernel (Azure) vulnerabilities
- [USN-8278-2] Linux kernel (Azure) vulnerabilities
- [USN-8305-2] Linux kernel (Low Latency) vulnerabilities
- [USN-8314-1] Ayttm vulnerabilities
- [USN-8313-1] XML-RPC for C and C++ vulnerabilities
- [USN-8311-1] Dnsmasq vulnerability
- [USN-8321-1] Papers vulnerability
- [USN-8319-1] Libgcrypt vulnerabilities
- [USN-8320-1] Memcached vulnerabilities
- [USN-8317-1] GStreamer Good Plugins vulnerabilities
- [USN-8318-1] libcaca vulnerability
- [USN-8315-1] MediaWiki vulnerabilities
- [USN-8322-1] Apache Commons BeanUtils vulnerability
- [USN-8326-1] Foomuuri vulnerabilities
- [USN-8325-1] tgt vulnerability
- [USN-8324-1] Apache Tika vulnerabilities
- [USN-8323-1] Postorius vulnerability
- [USN-8316-1] CableSwig vulnerabilities
- [USN-8329-1] FFmpeg vulnerability
- [USN-8341-1] OpenJDK 26 vulnerabilities
- [USN-8342-1] Vim vulnerability
- [USN-8229-2] sed vulnerability
- [USN-8339-1] OpenJDK 25 vulnerabilities
- [USN-8344-1] pip vulnerabilities
- [USN-8340-1] LibreOffice vulnerability
- [USN-8343-1] multipart vulnerability
- [USN-8338-1] Apache HTTP Server vulnerabilities
- [USN-8328-1] OpenJDK 21 vulnerabilities
- [USN-8327-1] OpenJDK 17 vulnerabilities
- [USN-8333-1] CRaC JDK 21 vulnerabilities
- [USN-8334-1] CRaC JDK 25 vulnerabilities
- [USN-8332-1] CRaC JDK 17 vulnerabilities
- [USN-8330-1] OpenJDK 8 vulnerabilities
- [USN-8331-1] OpenJDK 11 vulnerabilities
- [USN-8337-1] QtSvg vulnerabilities
- [USN-8336-1] PHP vulnerabilities
- [USN-8335-1] pyOpenSSL vulnerability
- [USN-8338-2] Apache HTTP Server regression
- [USN-8344-2] pip regression
- [USN-8347-1] QT WebEngine vulnerability
- [USN-8345-1] GDAL vulnerability
- [USN-8346-1] Texmaker vulnerabilities
How to apply these Linux security updates safely
Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.
Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.
Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.
Debian/Ubuntu (apt)
The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.
sudo apt update sudo apt upgrade -y
Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)
On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.
sudo dnf check-update sudo dnf upgrade -y
or on older releases
sudo yum check-update sudo yum update
SUSE (zypper)
SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.
sudo zypper refresh sudo zypper update -y
Slackware (slackpkg and pkgtool)
Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.
sudo slackpkg update sudo slackpkg upgrade-all
Run your updates, check your logs for any service restarts, and don't forget to reboot if the kernel changed. Stay safe out there.