Here is the weekly Linux security roundup with a massive wave of security patches. Critical remote code execution flaws hit Nginx and Firefox ESR, while kernel memory corruption and PostgreSQL credential leaks forced emergency updates across RHEL, Debian, and Ubuntu.
Linux Security Roundup: Critical Patches Hit Nginx, Firefox, PostgreSQL, and the Kernel Across Major Distributions
Another massive wave of advisories rolls out for RHEL, Ubuntu, Fedora, Debian, and Oracle Linux. Time to run your update commands.
If you haven't executed a package manager update in the last forty-eight hours, you're probably already behind. This week's security bulletin is a mouthful: critical remote code execution flaws in Nginx and Firefox ESR, memory corruption in the kernel, privilege escalation vectors in PostgreSQL, and DNS cache poisoning across Debian and Ubuntu. Nine major distributions shipped fixes, and the severity ratings are stacking up fast.
Let's cut through the noise. Debian issued emergency advisories for bullseye, bookworm, and trixie, targeting Chromium, FFmpeg, and OpenVPN. Ubuntu pushed patches for containerd, xrdp, and the Linux kernel across LTS releases spanning 22.04 to 26.04. Red Hat and Oracle both called out high-severity kernel memory corruption alongside Firefox ESR flaws, while Fedora locked down twenty-nine separate memory corruption issues in Chromium alone.

The Usual Suspects, Upgraded
Nginx and PostgreSQL showed up on almost every single bulletin this week. Oracle Linux bumped PostgreSQL to 16.14, fixed Samba, patched Redis, and shipped Go 1.26.3 alongside PHP 8. RHEL's advisory list stretches into the high hundreds, covering .NET 8.0, OpenShift 4.18.45, and Keycloak 26.6.4. If your stack runs those, the clock is ticking.
Slackware kept things quiet this time around. Just one advisory: libarchive 3.8.8 for the 15.0 stable branch and current. Not bad for a release cycle that moves at its own pace. Meanwhile, SUSE and openSUSE rolled out a staggering number of kernel live patches for SLES 15 SP4 through SP7, alongside fixes for Podman, Apptainer, Node.js 22, and a string of Python libraries. You can live-patch the kernel on SUSE, which means fewer reboot windows this quarter.
Patch fatigue is real. I've seen sysadmins skip whole weeks because the bulletin boards look like a grocery list. The volume this time is genuinely higher than average, though. Debian's DSA and DLA numbers are climbing past the 6300s and 4600s. RHEL's RHSA IDs are pushing into the 30000s. That's not a coincidence. Someone found a lot of overlapping vulnerabilities across the board.
What Actually Needs Your Attention Today
Start with the kernel and your web stack. RHEL flagged a critical kernel patch, RHSA-2026:27719, for RHEL 9. Ubuntu's USN-8469-1 targets FFmpeg vulnerabilities, and Debian's DSA 6361-1 does the same. If you're running Nginx anywhere in your DMZ, Oracle Linux marked their nginx update as Critical (ELSA-2026:19374). Fedora's chromium update is already sitting at 149.0.7827.196, which closes those twenty-nine memory corruption CVEs.
PostgreSQL is another non-negotiable. RHEL shipped fixes for versions 12 through 18, and Rocky Linux is patching the exact same range. Credential recovery leaks and arbitrary code execution risks are the headline vulnerabilities here. Skip them at your peril.
On the container side, Red Hat, Oracle, Rocky, and SUSE all shipped runc, buildah, and containernetworking-plugins patches. Podman got its own round of fixes from SUSE. If you're building images or running Kubernetes on any of these boxes, treat this like a Tuesday morning task.
The severity spread is wide. Debian calls their updates emergency. Ubuntu's USN list runs into the double digits. RHEL and Oracle both mark multiple kernel and nginx patches as Critical. That's not a drill.
Run your package managers. Reboot where necessary. Use live patching where it's available. Keep an eye on Fedora and RHEL's bulletin boards over the next few days, since some advisories roll out in waves. Head to your distribution's security page for the exact advisory links and checksums.
Latest Security Updates by Distribution
Here’s a complete breakdown of the security updates for AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux.
AlmaLinux
AlmaLinux published multiple security advisories for versions 8, 9, and 10 that patch critical flaws across widely deployed system packages. The updates target sandbox escapes and memory safety issues in Firefox, use-after-free errors in libpng, arbitrary code execution risks in Nginx, and credential recovery leaks in PostgreSQL. Additional patches address remote denial-of-service vulnerabilities in the 389 Directory Server, input injection flaws in Golang, and base kernel security hardening. These errata deliver immediate fixes for moderate and important severity ratings to protect AlmaLinux production environments from unauthorized access and resource exhaustion.
- ALSA-2026:26459: 389-ds:1.4 security update (Important)
- ALSA-2026:27353: kernel security, bug fix, and enhancement update (Important)
- ALSA-2026:27354: kernel-rt security, bug fix, and enhancement update (Important)
- ALSA-2026:28000: python-urllib3 security update (Important)
- ALSA-2026:19200: corosync security update (Moderate)
- ALSA-2026:27734: firefox security update (Important)
- ALSA-2026:27789: kernel security, bug fix, and enhancement update (Important)
- ALSA-2026:27741: postgresql security update (Important)
- ALSA-2026:28074: skopeo security update (Important)
- ALSA-2026:27862: memcached security update (Important)
- ALSA-2026:27717: firefox security update (Important)
- ALSA-2026:26008: redis:6 security update (Important)
- ALSA-2026:27738: libpq security update (Important)
- ALSA-2026:27811: kernel security update (Important)
- ALSA-2026:27812: kernel-rt security update (Important)
- ALSA-2026:27733: firefox security update (Important)
- ALSA-2026:27743: postgresql16 security update (Important)
- ALSA-2026:27842: memcached security update (Important)
- ALSA-2026:27929: python3.14-urllib3 security update (Important)
- ALSA-2026:28143: postgresql:16 security update (Important)
- ALSA-2026:28208: postgresql:13 security update (Important)
- ALSA-2026:28553: vim security update (Moderate)
- ALSA-2026:19342: tigervnc security update (Important)
- ALSA-2026:28210: vim security update (Moderate)
- ALSA-2026:28234: libxml2 security update (Low)
- ALSA-2026:28233: libpng security update (Moderate)
- ALSA-2026:28235: libtasn1 security update (Low)
- ALSA-2026:28236: libsolv security update (Moderate)
- ALSA-2026:28581: python3.14 security, bug fix, and enhancement update (Important)
- ALSA-2026:28584: libxslt security update (Moderate)
- ALSA-2026:28159: python3.12-urllib3 security update (Important)
- ALSA-2026:28253: libtasn1 security update (Low)
- ALSA-2026:28973: nginx security update (Important)
- ALSA-2026:29455: buildah security update (Important)
- ALSA-2026:28922: libreoffice security update (Moderate)
- ALSA-2026:28921: nginx:1.24 security update (Important)
- ALSA-2026:28999: postgresql:12 security update (Important)
- ALSA-2026:28998: evince security update (Important)
- ALSA-2026:28923: tigervnc security update (Important)
- ALSA-2026:29035: skopeo security update (Important)
- ALSA-2026:29195: buildah security update (Important)
- ALSA-2026:29151: nginx:1.26 security update (Important)
- ALSA-2026:26323: tomcat security update (Important)
- ALSA-2026:28157: python3.14-urllib3 security update (Important)
- ALSA-2026:28209: vim security update (Moderate)
- ALSA-2026:28255: libpng security update (Moderate)
- ALSA-2026:28212: nginx:1.24 security update (Important)
- ALSA-2026:28243: libxslt security update (Moderate)
- ALSA-2026:28911: coreutils security update (Moderate)
- ALSA-2026:28247: python3.14 security, bug fix, and enhancement update (Important)
- ALSA-2026:29898: libpng security update (Moderate)
- ALSA-2026:28244: libpng15 security update (Moderate)
- ALSA-2026:29874: nginx security update (Important)
- ALSA-2026:28256: opencryptoki security update (Moderate)
- ALSA-2026:29940: thunderbird security update (Important)
- ALSA-2026:27288: kernel security, bug fix, and enhancement update (Important)
- ALSA-2026:29980: golang security, bug fix, and enhancement update (Moderate)
- ALSA-2026:30129: kernel security, bug fix, and enhancement update (Important)
Debian GNU/Linux
Debian issued a series of emergency security advisories to patch dozens of vulnerabilities across widely used system components and third-party applications. The updates target flaws in packages including the Linux kernel, FFmpeg, Chromium, OpenVPN, ImageMagick, and PostgreSQL that could otherwise allow attackers to escalate privileges, crash services, poison DNS caches, or execute arbitrary code. System administrators should apply these patches right away to block remote exploitation on active trixie, bullseye, and bookworm installations.
- [DSA 6355-1] linux security update
- [DLA 4638-1] libgd-perl security update
- [DSA 6356-1] imagemagick security update
- [DSA 6359-1] gst-plugins-good1.0 security update
- [DSA 6358-1] libhttp-daemon-perl security update
- [DSA 6357-1] pillow security update
- [DSA 6360-1] squid security update
- [DLA 4639-1] libhttp-daemon-perl security update
- [DLA 4640-1] mediawiki security update
- [DSA 6361-1] ffmpeg security update
- [DSA 6362-1] gst-plugins-bad1.0 security update
- [DSA 6363-1] python-urllib3 security update
- [DLA 4643-1] imagemagick security update
- [DLA 4642-1] u-boot security update
- [DLA 4641-1] beets security update
- [DLA 4644-1] libmatio security update
- ELA-1755-1 libhttp-daemon-perl security update (by )
- [DLA 4645-1] cloud-init - correct sources.list generation
- [DLA 4646-1] postgresql-13 security update
- [DLA 4647-1] yelp security update
- [DSA 6368-1] pdns security update
- [DSA 6367-1] dnsdist security update
- [DLA 4648-1] libtext-csv-xs-perl security update
- [DSA 6366-1] sogo security update
- [DSA 6365-1] libssh2 security update
- [DSA 6364-1] chromium security update
- [DSA 6369-1] pdns-recursor security update
- ELA-1756-1 libtext-csv-xs-perl security update
- [DLA 4650-1] giflib security update
- [DLA 4649-1] libdbi-perl security update
- [DLA 4651-1] python-urllib3 security update
- ELA-1758-1 libdbi-perl security update
- ELA-1757-1 giflib security update
- [DSA 6370-1] incus security update
- ELA-1759-1 ansible security update
- [DLA 4653-1] openvpn security update
- [DLA 4652-1] gdcm security update
- ELA-1761-1 python-urllib3 security update
- ELA-1760-1 yelp security update
- [DSA 6370-1] xorg-server security update
- ELA-1762-1 openvpn security update
- [DLA 4654-1] chromium security update
Fedora Linux
Fedora 43 and 44 issued multiple security advisories to patch known vulnerabilities across dozens of widely used Linux packages. The updates resolve eleven separate CVEs in TigerVNC, close twenty-nine memory corruption flaws in Chromium, and fix six protocol-layer issues in FreeRDP. Administrators will also need to apply patches for Nginx, Docker BuildKit, FFmpeg 8, Python 3.14, and several core Perl modules to fully secure their systems. Rolling out these advisories promptly removes active exploit paths and keeps production environments stable ahead of upcoming Fedora maintenance windows.
- Fedora 44 Update: buildah-1.43.2-1.fc44
- Fedora 44 Update: podman-5.8.3-1.fc44
- Fedora 44 Update: freerdp-3.27.1-1.fc44
- Fedora 44 Update: strongswan-6.0.7-1.fc44
- Fedora 44 Update: tigervnc-1.16.2-4.fc44
- Fedora 44 Update: ffmpeg-8.1.2-1.fc44
- Fedora 44 Update: thorvg-1.0.6-1.fc44
- Fedora 44 Update: prometheus-3.12.0-1.fc44
- Fedora 44 Update: erlang-26.2.5.21-3.fc44
- Fedora 44 Update: python-scrapy-2.14.2-1.fc44
- Fedora 44 Update: vips-8.18.3-2.fc44
- Fedora 44 Update: python3-docs-3.14.6-1.fc44
- Fedora 44 Update: python3.14-3.14.6-1.fc44
- Fedora 43 Update: thorvg-1.0.6-1.fc43
- Fedora 43 Update: prometheus-3.12.0-1.fc43
- Fedora 43 Update: vips-8.18.3-2.fc43
- Fedora 43 Update: python-scrapy-2.13.4-1.fc43
- Fedora 43 Update: erlang-26.2.5.21-3.fc43
- Fedora 43 Update: yt-dlp-2026.06.09-1.fc43
- Fedora 43 Update: chromium-149.0.7827.155-1.fc43
- Fedora 43 Update: materialx-1.39.5-1.fc43
- Fedora 43 Update: coturn-4.13.1-1.fc43
- Fedora 43 Update: perl-Crypt-DSA-1.21-1.fc43
- Fedora 44 Update: materialx-1.39.5-1.fc44
- Fedora 44 Update: coturn-4.13.1-1.fc44
- Fedora 44 Update: perl-Crypt-DSA-1.21-1.fc44
- Fedora 44 Update: frr-10.6.1-1.fc44
- Fedora 44 Update: grout-0.16.0-1.fc44
- Fedora 43 Update: goose-1.36.0-1.fc43
- Fedora 43 Update: strongswan-6.0.7-2.fc43
- Fedora 43 Update: httpd-2.4.68-1.fc43
- Fedora 44 Update: goose-1.36.0-1.fc44
- Fedora 43 Update: rsync-3.4.4-1.fc43
- Fedora 43 Update: librabbitmq-0.16.0-1.fc43
- Fedora 44 Update: perl-Socket-2.041-1.fc44
- Fedora 44 Update: perl-Compress-Raw-Bzip2-2.218-1.fc44
- Fedora 44 Update: perl-IO-Compress-2.221-1.fc44
- Fedora 44 Update: perl-DBI-1.648-1.fc44
- Fedora 44 Update: python-django-allauth-65.18.0-1.fc44
- Fedora 44 Update: chromium-149.0.7827.196-1.fc44
- Fedora 44 Update: thunderbird-152.0-1.fc44
- Fedora 44 Update: pacemaker-3.0.2-3.fc44
- Fedora 44 Update: tinyproxy-1.11.2-8.fc44
- Fedora 44 Update: docker-buildx-0.35.0-1.fc44
- Fedora 44 Update: docker-buildkit-0.31.0-1.fc44
- Fedora 44 Update: lighttpd-1.4.84-1.fc44
- Fedora 44 Update: nginx-mod-vts-0.2.4-11.fc44
- Fedora 44 Update: nginx-mod-modsecurity-1.0.4-12.fc44
- Fedora 44 Update: nginx-1.30.3-1.fc44
- Fedora 44 Update: nginx-mod-naxsi-1.6-19.fc44
- Fedora 44 Update: nginx-mod-headers-more-0.39-11.fc44
- Fedora 44 Update: nginx-mod-fancyindex-0.6.0-6.fc44
- Fedora 44 Update: nginx-mod-js-challenge-0^20230517.gitda6852d-9.fc44
- Fedora 44 Update: nginx-mod-brotli-1.0.0~rc-11.fc44
- Fedora 44 Update: openbao-2.5.5-1.fc44
- Fedora 44 Update: python-postorius-1.3.13-1.fc44
- Fedora 44 Update: liferea-1.16.12-1.fc44
- Fedora 43 Update: tinyproxy-1.11.2-8.fc43
- Fedora 43 Update: docker-buildx-0.35.0-1.fc43
- Fedora 43 Update: docker-buildkit-0.31.0-1.fc43
- Fedora 43 Update: tigervnc-1.16.2-4.fc43
- Fedora 43 Update: lighttpd-1.4.84-1.fc43
- Fedora 43 Update: pacemaker-3.0.2-3.fc43
- Fedora 43 Update: nginx-mod-headers-more-0.39-11.fc43
- Fedora 43 Update: nginx-mod-vts-0.2.4-11.fc43
- Fedora 43 Update: nginx-mod-fancyindex-0.6.0-6.fc43
- Fedora 43 Update: nginx-mod-brotli-1.0.0~rc-11.fc43
- Fedora 43 Update: nginx-1.30.3-1.fc43
- Fedora 43 Update: nginx-mod-naxsi-1.6-19.fc43
- Fedora 43 Update: nginx-mod-modsecurity-1.0.4-12.fc43
- Fedora 43 Update: openbao-2.5.5-1.fc43
- Fedora 43 Update: python-postorius-1.3.13-1.fc43
- Fedora 43 Update: python-jupyter-server-2.19.0-2.fc43
- Fedora 43 Update: util-linux-2.41.5-1.fc43
- Fedora 43 Update: ldns-1.9.2-1.fc43
- Fedora 43 Update: python3-docs-3.14.6-1.fc43
- Fedora 43 Update: python3.14-3.14.6-1.fc43
- Fedora 44 Update: python-pydantic-settings-2.14.2-1.fc44
- Fedora 44 Update: dotnet9.0-9.0.118-1.fc44
- Fedora 44 Update: moby-engine-29.6.0-1.fc44
- Fedora 44 Update: dotnet8.0-8.0.128-1.fc44
- Fedora 44 Update: krita-6.0.2.1-1.fc44
- Fedora 44 Update: dotnet10.0-10.0.109-1.fc44
- Fedora 44 Update: pgadmin4-9.16-1.fc44
- Fedora 44 Update: python-mistune-3.2.1-1.fc44
Oracle Linux
Oracle Linux administrators should apply a series of security advisories for versions 7, 8, and 9, which address critical vulnerabilities across the UEK kernel, core system libraries, and major application packages. The updates include version upgrades for PostgreSQL to 16.14, MySQL to 8, .NET spanning 8.0 through 10.0, Go 1.26.3, and PHP 8, alongside fixes for Nginx, Samba, Redis, Kubernetes tools, and Opencryptoki. High-severity issues resolve memory corruption and race conditions in the kernel, memory leaks in 389-ds, remote code execution risks in Firefox ESR, and flaws in glibc and gnutls that affect the base environment. These patches protect server infrastructure by closing open holes that could allow remote attacks, ensuring stability and security for both database servers and container environments running on Oracle Linux.
- ELSA-2026-50319 Important: Unbreakable Enterprise kernel security update
- ELSA-2026-50319 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
- ELSA-2026-26335 Important: Oracle Linux 8 hplip security update
- ELSA-2026-27717 Important: Oracle Linux 8 firefox security update
- ELBA-2026-26427-1 Oracle Linux 8 kernel bug fix update
- ELBA-2026-50333 Oracle Linux 8 leapp bug fix update
- ELSA-2026-26459 Important: Oracle Linux 8 389-ds:1.4 security update
- ELSA-2026-22468 Important: Oracle Linux 7 openssh security update
- ELSA-2026-26427 Important: Oracle Linux 8 kernel security update
- ELSA-2026-27353 Important: Oracle Linux 8 kernel security, bug fix, and enhancement update
- ELSA-2026-26534 Important: Oracle Linux 8 dracut security update
- ELSA-2026-26181 Important: Oracle Linux 8 postgresql:15 security update
- ELSA-2026-26008 Important: Oracle Linux 8 redis:6 security update
- ELBA-2026-50332 Oracle Linux 8 leapp-repository bug fix update
- ELSA-2026-28143 Important: Oracle Linux 8 postgresql:16 security update
- ELSA-2026-26180 Moderate: Oracle Linux 8 mysql:8.4 security update
- ELSA-2026-27738 Important: Oracle Linux 8 libpq security update
- ELSA-2026-13672 Important: Oracle Linux 9 fence-agents security update
- ELBA-2026-50326 Oracle Linux 9 leapp-repository bug fix update
- ELSA-2026-24369 Important: Oracle Linux 9 unbound security update
- ELSA-2026-24368 Important: Oracle Linux 9 bind9.18 security update
- ELSA-2026-22313 Moderate: Oracle Linux 9 compat-openssl11 security update
- ELSA-2026-21755 Important: Oracle Linux 9 flatpak security update
- ELSA-2026-21381 Important: Oracle Linux 9 thunderbird security update
- ELSA-2026-21468 Important: Oracle Linux 9 cockpit security update
- ELSA-2026-20568 Important: Oracle Linux 9 jmc security update
- ELSA-2026-21391 Important: Oracle Linux 9 httpd security update
- ELSA-2026-19374 Critical: Oracle Linux 9 nginx security update
- ELSA-2026-19610 Important: Oracle Linux 9 libsndfile security update
- ELSA-2026-19373 Important: Oracle Linux 9 dnsmasq security update
- ELBA-2026-50348 Oracle Linux 9 crash bug fix update
- ELSA-2026-19366 Important: Oracle Linux 9 python-markdown security update
- ELSA-2026-19362 Important: Oracle Linux 9 gimp security update
- ELSA-2026-19365 Important: Oracle Linux 9 jq security update
- ELSA-2026-19364 Important: Oracle Linux 9 dovecot security update
- ELSA-2026-50324 Moderate: Oracle Linux 9 pyOpenSSL security update
- ELSA-2026-19359 Important: Oracle Linux 9 openexr security update
- ELSA-2026-19358 Moderate: Oracle Linux 9 freerdp security update
- ELSA-2026-19356 Moderate: Oracle Linux 9 libsoup security update
- ELSA-2026-19352 Important: Oracle Linux 9 grafana security update
- ELSA-2026-19351 Important: Oracle Linux 9 grafana-pcp security update
- ELSA-2026-28923 Important: Oracle Linux 8 tigervnc security update
- ELSA-2026-28921 Important: Oracle Linux 8 nginx:1.24 security update
- ELSA-2026-28553 Moderate: Oracle Linux 8 vim security update
- ELSA-2026-27811 Important: Oracle Linux 8 kernel security update
- ELSA-2026-22121 Important: Oracle Linux 9 golang security update
- ELSA-2026-25057 Important: Oracle Linux 9 mod_http2 security update
- ELSA-2026-25222 Important: Oracle Linux 9 .NET 10.0 security update
- ELSA-2026-25049 Critical: Oracle Linux 9 samba security update
- ELSA-2026-25219 Important: Oracle Linux 9 redis:7 security update
- ELSA-2026-25221 Important: Oracle Linux 9 .NET 9.0 security update
- ELSA-2026-25220 Important: Oracle Linux 9 .NET 8.0 security update
- ELSA-2026-25058 Important: Oracle Linux 9 poppler security update
- ELSA-2026-23230 Important: Oracle Linux 9 expat security update
- ELSA-2026-22143 Important: Oracle Linux 9 php:8.2 security update
- ELSA-2026-19371 Critical: Oracle Linux 9 nginx:1.24 security update
- ELSA-2026-19363 Important: Oracle Linux 9 libtiff security update
- ELSA-2026-28998 Important: Oracle Linux 8 evince security update
- ELSA-2026-25919 Moderate: Oracle Linux 8 mysql:8.0 security update
- ELSA-2026-28256 Moderate: Oracle Linux 9 opencryptoki security update
- New Ksplice updates for UEKR6 5.4.17 on OL7 and OL8
- ELSA-2026-29844 Important: Oracle Linux 9 tigervnc security update
- ELSA-2026-29703 Important: Oracle Linux 9 containernetworking-plugins security update
- ELSA-2026-29702 Important: Oracle Linux 9 runc security update
- ELSA-2026-29455 Important: Oracle Linux 9 buildah security update
- ELSA-2026-28911 Moderate: Oracle Linux 9 coreutils security update
- ELSA-2026-28253 Low: Oracle Linux 9 libtasn1 security update
- ELSA-2026-28209 Moderate: Oracle Linux 9 vim security update
- ELSA-2026-28159 Important: Oracle Linux 9 python3.12-urllib3 security update
- ELSA-2026-28158 Important: Oracle Linux 9 python-urllib3 security update
- ELSA-2026-28157 Important: Oracle Linux 9 python3.14-urllib3 security update
- ELSA-2026-28074 Important: Oracle Linux 9 skopeo security update
- ELSA-2026-28037 Important: Oracle Linux 9 postgresql:15 security update
- ELSA-2026-27862 Important: Oracle Linux 9 memcached security update
- ELSA-2026-27819 Important: Oracle Linux 9 evince security update
- ELSA-2026-26610 Important: Oracle Linux 9 xorg-x11-server security, bug fix, and enhancement update
- ELSA-2026-26590 Important: Oracle Linux 9 xorg-x11-server-Xwayland security, bug fix, and enhancement update
- ELSA-2026-26455 Important: Oracle Linux 9 389-ds-base security, bug fix, and enhancement update
- ELSA-2026-26447 Important: Oracle Linux 9 podman security update
- ELSA-2026-26205 Important: Oracle Linux 9 postfix security update
- ELSA-2026-26297 Important: Oracle Linux 9 hplip security update
- ELSA-2026-26206 Important: Oracle Linux 9 fence-agents security update
- ELSA-2026-26203 Important: Oracle Linux 9 postgresql:16 security update
- ELSA-2026-25927 Important: Oracle Linux 9 webkit2gtk3 security update
- ELSA-2026-22553 Moderate: Oracle Linux 9 libexif security update
- ELSA-2026-19367 Important: Oracle Linux 9 giflib update
- ELSA-2026-19357 Important: Oracle Linux 9 krb5 security update
- ELSA-2026-19350 Important: Oracle Linux 9 git-lfs security update
- ELSA-2026-19346 Important: Oracle Linux 9 libcap security update
- ELSA-2026-19342 Important: Oracle Linux 9 tigervnc security update
- ELSA-2026-18693 Moderate: Oracle Linux 9 python3.9 security update
- ELBA-2026-25921 Oracle Linux 9 scap-security-guide bug fix and enhancement update
- ELSA-2026-28999 Important: Oracle Linux 8 postgresql:12 security update
- ELSA-2026-28208 Important: Oracle Linux 8 postgresql:13 security update
- OLAMBA-2026-0015 Oracle Linux 9 ol-automation-manager bug fix update
- ELBA-2026-24372 Oracle Linux 9 libvirt bug fix and enhancement update
- ELBA-2026-23257 Oracle Linux 9 php:8.3 bug fix and enhancement update
- ELBA-2026-22562 Oracle Linux 9 lvm2 bug fix and enhancement update
- ELBA-2026-22560 Oracle Linux 9 NetworkManager bug fix and enhancement update
- ELBA-2026-22559 Oracle Linux 9 libsolv bug fix and enhancement update
- ELBA-2026-22556 Oracle Linux 9 nftables bug fix and enhancement update
- ELBA-2026-22550 Oracle Linux 9 xorg-x11-drv-wacom bug fix and enhancement update
- ELBA-2026-22555 Oracle Linux 9 libeconf bug fix and enhancement update
- ELBA-2026-22548 Oracle Linux 9 iperf3 bug fix and enhancement update
- ELBA-2026-20537 Oracle Linux 9 tzdata bug fix and enhancement update
- ELBA-2026-19803 Oracle Linux 9 python-pip bug fix and enhancement update
- ELBA-2026-50347 Oracle Linux 9 mdadm bug fix update
- ELSA-2026-29898 Moderate: Oracle Linux 8 libpng security update
- ELSA-2026-28922 Moderate: Oracle Linux 8 libreoffice security update
- ELSA-2026-20597 Moderate: Oracle Linux 9 glibc security update
- ELSA-2026-22142 Important: Oracle Linux 9 php:8.3 security update
- ELSA-2026-29151 Important: Oracle Linux 9 nginx:1.26 security update
- ELBA-2026-28656 Oracle Linux 9 qemu-kvm bug fix and enhancement update
- ELEA-2026-22546 Oracle Linux 9 nmstate bug fix and enhancement update
- ELSA-2026-19355 Important: Oracle Linux 9 fence-agents security update
- ELSA-2026-25052 Moderate: Oracle Linux 9 mysql:8.4 security update
- ELSA-2026-24367 Important: Oracle Linux 9 bind security update
- ELBA-2026-24588 Oracle Linux 9 sos bug fix and enhancement update
- ELSA-2026-26445 Important: Oracle Linux 9 podman security update
- ELSA-2026-21293 Important: Oracle Linux 9 .NET 8.0 security update
- ELBA-2026-28241 Oracle Linux 9 gnome-shell bug fix and enhancement update
- ELSA-2026-24371 Important: Oracle Linux 9 frr security update
- ELSA-2026-26533 Important: Oracle Linux 9 dracut security update
- ELSA-2026-28254 Low: Oracle Linux 9 libxml2 security update
- ELBA-2026-28250 Oracle Linux 9 libusbx bug fix and enhancement update
- ELSA-2026-19361 Moderate: Oracle Linux 9 glib2 security update
- ELSA-2026-29940 Important: Oracle Linux 9 thunderbird security update
- ELBA-2026-28252 Oracle Linux 9 man-pages bug fix and enhancement update
- ELBA-2026-25054 Oracle Linux 9 python3.14 bug fix and enhancement update
- ELSA-2026-27789 Important: Oracle Linux 9 kernel security, bug fix, and enhancement update
- ELSA-2026-25925 Important: Oracle Linux 9 valkey security update
- ELSA-2026-20612 Important: Oracle Linux 9 gnutls security update
- ELSA-2026-27734 Important: Oracle Linux 9 firefox security update
- ELSA-2026-26410 Important: Oracle Linux 9 rsync security update
- ELSA-2026-22551 Moderate: Oracle Linux 9 mod_http2 security update
- ELSA-2026-21296 Important: Oracle Linux 9 .NET 9.0 security update
- ELBA-2026-25053 Oracle Linux 9 python3.12 bug fix and enhancement update
- ELSA-2026-28243 Moderate: Oracle Linux 9 libxslt security update
- ELBA-2026-28245 Oracle Linux 9 mutter bug fix and enhancement update
- ELSA-2026-26323 Important: Oracle Linux 9 tomcat security update
- ELSA-2026-28255 Moderate: Oracle Linux 9 libpng security update
- ELSA-2026-23229 Important: Oracle Linux 9 redis security update
- ELSA-2026-28247 Important: Oracle Linux 9 python3.14 security, bug fix, and enhancement update
Red Hat Enterprise Linux
Red Hat issued multiple security advisories for RHEL 8, 9, and 10 covering packages like the kernel, Firefox, PostgreSQL, Python, OpenShift, Keycloak, and nginx. These updates address newly discovered vulnerabilities with impact ratings that range from moderate to important. Live patching tools let administrators apply fixes directly into memory, so teams can skip server reboots and keep services running.
- RHSA-2026:27744: Moderate: openssl-fips-provider security update
- RHSA-2026:27734: Important: firefox security update
- RHSA-2026:27739: Low: libxml2 security update
- RHSA-2026:27737: Low: libxml2 security update
- RHSA-2026:27733: Important: firefox security update
- RHSA-2026:27705: Important: kernel security update
- RHSA-2026:27736: Low: libxml2 security update
- RHSA-2026:27728: Important: webkitgtk4 security update
- RHSA-2026:27717: Important: firefox security update
- RHSA-2026:27724: Important: poppler security update
- RHSA-2026:27720: Important: poppler security update
- RHSA-2026:27725: Important: poppler security update
- RHSA-2026:27719: Critical: kernel security update
- RHSA-2026:27712: Important: osbuild-composer security update
- RHSA-2026:27727: Important: poppler security update
- RHSA-2026:27716: Important: redis security update
- RHSA-2026:27707: Important: kernel security update
- RHSA-2026:27706: Important: kernel-rt security update
- RHSA-2026:27708: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:27741: Important: postgresql security update
- RHSA-2026:27735: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:27787: Important: redis:6 security update
- RHSA-2026:27785: Important: webkit2gtk3 security update
- RHSA-2026:27742: Important: postgresql18 security update
- RHSA-2026:27743: Important: postgresql16 security update
- RHSA-2026:27718: Important: postgresql16 security update
- RHSA-2026:27738: Important: libpq security update
- RHSA-2026:27731: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:27713: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:27721: Important: poppler security update
- RHSA-2026:27746: Moderate: openssl-fips-provider security update
- RHSA-2026:27729: Critical: kernel security, bug fix, and enhancement update
- RHSA-2026:27740: Moderate: golang-github-openprinting-ipp-usb security update
- RHSA-2026:27745: Moderate: openssl-fips-provider security update
- RHSA-2026:27723: Important: poppler security update
- RHSA-2026:27722: Important: poppler security update
- RHSA-2026:27732: Moderate: yggdrasil-worker-package-manager security update
- RHSA-2026:26566: Important: xorg-x11-server-Xwayland security, bug fix, and enhancement update
- RHSA-2026:27715: Important: firefox security update
- RHSA-2026:27704: Important: kernel security update
- RHSA-2026:27711: Moderate: osbuild-composer security update
- RHSA-2026:27709: Important: kernel security update
- RHSA-2026:27862: Important: memcached security update
- RHSA-2026:27842: Important: memcached security update
- RHSA-2026:27856: Important: osbuild-composer security update
- RHSA-2026:27819: Important: evince security update
- RHSA-2026:27789: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:27811: Important: kernel security update
- RHSA-2026:27812: Important: kernel-rt security update
- RHSA-2026:27804: Important: webkit2gtk3 security update
- RHSA-2026:27200: Important: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP4 security update
- RHSA-2026:27201: Important: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP4 security update
- RHSA-2026:28007: Important: .NET 8.0 security update
- RHSA-2026:28074: Important: skopeo security update
- RHSA-2026:28054: Important: samba security update
- RHSA-2026:28055: Important: samba security update
- RHSA-2026:28056: Important: samba security update
- RHSA-2026:28057: Important: samba security update
- RHSA-2026:28058: Important: samba security update
- RHSA-2026:28050: Important: vim security update
- RHSA-2026:28049: Important: vim security update
- RHSA-2026:28044: Important: Red Hat OpenStack Platform 17.1 (openstack-keystone) security update
- RHSA-2026:28047: Important: Red Hat OpenStack Platform 17.1 (etcd) security update
- RHSA-2026:28046: Moderate: Red Hat OpenStack Platform 17.1 (golang-uber-multierr) security update
- RHSA-2026:28043: Important: Red Hat OpenStack Platform 17.1 (python-urllib3) security update
- RHSA-2026:28042: Important: Red Hat OpenStack Platform 17.1 (python-pyasn1) security update
- RHSA-2026:28038: Important: gvisor-tap-vsock security update
- RHSA-2026:28037: Important: postgresql:15 security update
- RHSA-2026:28036: Moderate: crun security update
- RHSA-2026:28011: Important: .NET 8.0 security update
- RHSA-2026:28009: Important: .NET 9.0 security update
- RHSA-2026:28010: Important: Red Hat build of Cryostat security update
- RHSA-2026:28000: Important: python-urllib3 security update
- RHSA-2026:27929: Important: python3.14-urllib3 security update
- RHSA-2026:28158: Important: python-urllib3 security update
- RHSA-2026:28143: Important: postgresql:16 security update
- RHSA-2026:28148: Important: webkit2gtk3 security update
- RHSA-2026:28142: Important: redis:7 security update
- RHSA-2026:28139: Important: redis security update
- RHSA-2026:28133: Important: vim security update
- RHSA-2026:28132: Important: samba security update
- RHSA-2026:28114: Important: webkit2gtk3 security update
- RHSA-2026:28053: Important: samba security update
- RHSA-2026:28208: Important: postgresql:13 security update
- RHSA-2026:28157: Important: python3.14-urllib3 security update
- RHSA-2026:28159: Important: python3.12-urllib3 security update
- RHSA-2026:28146: Important: webkit2gtk3 security update
- RHSA-2026:28210: Moderate: vim security update
- RHSA-2026:28234: Low: libxml2 security update
- RHSA-2026:28227: Important: .NET 8.0 security update
- RHSA-2026:28385: Important: Satellite 6.18.6 Async Update
- RHSA-2026:28749: Critical: kpatch-patch-4_18_0-553_109_1, kpatch-patch-4_18_0-553_125_1, kpatch-patch-4_18_0-553_53_1, kpatch-patch-4_18_0-553_72_1, and kpatch-patch-4_18_0-553_85_1 secu ...
- RHSA-2026:28748: Critical: kpatch-patch-4_18_0-477_107_1, kpatch-patch-4_18_0-477_120_1, kpatch-patch-4_18_0-477_130_1, kpatch-patch-4_18_0-477_143_1, and kpatch-patch-4_18_0-477_97_1 se ...
- RHSA-2026:28750: Critical: kpatch-patch-5_14_0-284_117_1, kpatch-patch-5_14_0-284_134_1, kpatch-patch-5_14_0-284_148_1, kpatch-patch-5_14_0-284_158_1, and kpatch-patch-5_14_0-284_172_1 s ...
- RHSA-2026:28582: Moderate: keylime security update
- RHSA-2026:28253: Low: libtasn1 security update
- RHSA-2026:28254: Low: libxml2 security update
- RHSA-2026:28247: Important: python3.14 security, bug fix, and enhancement update
- RHSA-2026:28212: Important: nginx:1.24 security update
- RHSA-2026:28553: Moderate: vim security update
- RHSA-2026:28255: Moderate: libpng security update
- RHSA-2026:28457: Moderate: libpng15 security update
- RHSA-2026:28244: Moderate: libpng15 security update
- RHSA-2026:28243: Moderate: libxslt security update
- RHSA-2026:28458: Moderate: libpng15 security update
- RHSA-2026:28236: Moderate: libsolv security update
- RHSA-2026:28256: Moderate: opencryptoki security update
- RHSA-2026:28376: Critical: Red Hat Ansible Automation Platform 2.5 Product Security Update
- RHSA-2026:28231: Moderate: opencryptoki security update
- RHSA-2026:28377: Critical: Red Hat Ansible Automation Platform 2.6 Product Security Update
- RHSA-2026:28235: Low: libtasn1 security update
- RHSA-2026:28233: Moderate: libpng security update
- RHSA-2026:28209: Moderate: vim security update
- RHSA-2026:28581: Important: python3.14 security, bug fix, and enhancement update
- RHSA-2026:28584: Moderate: libxslt security update
- RHSA-2026:28741: Critical: kpatch-patch-5_14_0-687_10_1 security update
- RHSA-2026:28740: Critical: kpatch-patch-5_14_0-570_116_1, kpatch-patch-5_14_0-570_17_1, kpatch-patch-5_14_0-570_39_1, kpatch-patch-5_14_0-570_66_1, and kpatch-patch-5_14_0-570_94_1 secur ...
- RHSA-2026:28742: Critical: kpatch-patch-6_12_0-211_16_1 security update
- RHSA-2026:28738: Critical: kpatch-patch-5_14_0-427_100_1, kpatch-patch-5_14_0-427_113_1, kpatch-patch-5_14_0-427_126_1, kpatch-patch-5_14_0-427_68_2, and kpatch-patch-5_14_0-427_84_1 sec ...
- RHSA-2026:28290: Moderate: libreoffice security update
- RHSA-2026:28921: Important: nginx:1.24 security update
- RHSA-2026:28911: Moderate: coreutils security update
- RHSA-2026:29020: Moderate: libpng12 security update
- RHSA-2026:28922: Moderate: libreoffice security update
- RHSA-2026:28923: Important: tigervnc security update
- RHSA-2026:29110: Important: bind security update
- RHSA-2026:29035: Important: skopeo security update
- RHSA-2026:28999: Important: postgresql:12 security update
- RHSA-2026:28973: Important: nginx security update
- RHSA-2026:28998: Important: evince security update
- RHSA-2026:29018: Moderate: libpng12 security update
- RHSA-2026:29016: Moderate: libpng15 security update
- RHSA-2026:29019: Moderate: libpng15 security update
- RHSA-2026:29021: Moderate: libpng15 security update
- RHSA-2026:29022: Moderate: libpng12 security update
- RHSA-2026:26997: Important: OpenShift Container Platform 4.18.45 packages and security update
- RHSA-2026:28832: Moderate: openssl-fips-provider security update
- RHSA-2026:29210: Important: perl-IO-Compress security update
- RHSA-2026:29455: Important: buildah security update
- RHSA-2026:29195: Important: buildah security update
- RHSA-2026:29182: Important: perl-IO-Compress security update
- RHSA-2026:26999: Important: OpenShift Container Platform 4.19.35 packages and security update
- RHSA-2026:26541: Important: OpenShift Container Platform 4.13.68 packages and security update
- RHSA-2026:26542: Critical: OpenShift Container Platform 4.13.68 bug fix and security update
- RHSA-2026:29900: Moderate: libpng security update
- RHSA-2026:29814: Moderate: libxslt security update
- RHSA-2026:29811: Moderate: libxslt security update
- RHSA-2026:29867: Important: perl-IO-Compress security update
- RHSA-2026:26527: Important: OpenShift Container Platform 4.12.92 packages and security update
- RHSA-2026:29809: Moderate: libxslt security update
- RHSA-2026:26528: Critical: OpenShift Container Platform 4.12.92 bug fix and security update
- RHSA-2026:29151: Important: nginx:1.26 security update
- RHSA-2026:29702: Important: runc security update
- RHSA-2026:29212: Important: postgresql security update
- RHSA-2026:29953: Important: postgresql security update
- RHSA-2026:29952: Important: compat-poppler022 security update
- RHSA-2026:29844: Important: tigervnc security update
- RHSA-2026:29898: Moderate: libpng security update
- RHSA-2026:29807: Moderate: libxslt security update
- RHSA-2026:28147: Important: webkit2gtk3 security update
- RHSA-2026:29940: Important: thunderbird security update
- RHSA-2026:29980: Moderate: golang security, bug fix, and enhancement update
- RHSA-2026:29975: Moderate: libxslt security update
- RHSA-2026:30115: Important: perl-IO-Compress security update
- RHSA-2026:30086: Important: perl-IO-Compress security update
- RHSA-2026:30084: Important: Red Hat build of Keycloak 26.6.4 Images Security Update
- RHSA-2026:30083: Important: Red Hat build of Keycloak 26.6.4 Security Update
- RHSA-2026:30085: Important: perl-IO-Compress security update
- RHSA-2026:30129: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:30004: Important: gnutls security update
- RHSA-2026:28456: Moderate: libpng15 security update
- RHSA-2026:30050: Important: Red Hat build of Keycloak 26.4.13 Images Security Update
- RHSA-2026:30049: Important: Red Hat build of Keycloak 26.4.13 Security Update
- RHSA-2026:29981: Moderate: golang security, bug fix, and enhancement update
- RHSA-2026:30044: Important: poppler security update
- RHSA-2026:29976: Moderate: libxslt security update
- RHSA-2026:29904: Important: postgresql security update
- RHSA-2026:29941: Important: perl-IO-Compress security update
- RHSA-2026:29874: Important: nginx security update
- RHSA-2026:29817: Important: redis:6 security update
- RHSA-2026:29815: Important: postgresql:12 security update
- RHSA-2026:29901: Moderate: libpng security update
- RHSA-2026:29902: Moderate: libpng security update
- RHSA-2026:29703: Important: containernetworking-plugins security update
Rocky Linux
Rocky Linux administrators must install a series of RLSA security advisories across versions 8, 9, and 10 to patch known vulnerabilities. The latest releases address high-profile packages like kernel and kernel-rt, PostgreSQL versions 13 through 18, Nginx 1.24, Firefox, and Python 3.14. Severity ratings run from moderate to important, with certain advisories demanding immediate action on the newest Rocky Linux 10 systems. System operators should apply these fixes right away to keep core infrastructure and dependent software secure.
- RLSA-2026:27354: Important: kernel-rt security, bug fix, and enhancement update
- RLSA-2026:27288: Important: kernel security, bug fix, and enhancement update
- RLSA-2026:28037: Important: postgresql:15 security update
- RLSA-2026:28143: Important: postgresql:16 security update
- RLSA-2026:28208: Important: postgresql:13 security update
- RLSA-2026:28212: Important: nginx:1.24 security update
- RLSA-2026:28243: Moderate: libxslt security update
- RLSA-2026:28231: Moderate: opencryptoki security update
- RLSA-2026:28000: Important: python-urllib3 security update
- RLSA-2026:27740: Moderate: golang-github-openprinting-ipp-usb security update
- RLSA-2026:28234: Low: libxml2 security update
- RLSA-2026:27742: Important: postgresql18 security update
- RLSA-2026:27929: Important: python3.14-urllib3 security update
- RLSA-2026:28233: Moderate: libpng security update
- RLSA-2026:27842: Important: memcached security update
- RLSA-2026:26566: Important: xorg-x11-server-Xwayland security, bug fix, and enhancement update
- RLSA-2026:28236: Moderate: libsolv security update
- RLSA-2026:28235: Low: libtasn1 security update
- RLSA-2026:27733: Important: firefox security update
- RLSA-2026:28210: Moderate: vim security update
- RLSA-2026:27743: Important: postgresql16 security update
- RLSA-2026:28158: Important: python-urllib3 security update
- RLSA-2026:28256: Moderate: opencryptoki security update
- RLSA-2026:28255: Moderate: libpng security update
- RLSA-2026:28253: Low: libtasn1 security update
- RLSA-2026:28244: Moderate: libpng15 security update
- RLSA-2026:27734: Important: firefox security update
- RLSA-2026:28999: Important: postgresql:12 security update
- RLSA-2026:27812: Important: kernel-rt security update
- RLSA-2026:28923: Important: tigervnc security update
- RLSA-2026:28922: Moderate: libreoffice security update
- RLSA-2026:28998: Important: evince security update
- RLSA-2026:27717: Important: firefox security update
- RLSA-2026:27811: Important: kernel security update
- RLSA-2026:28553: Moderate: vim security update
- RLSA-2026:28999: Important: postgresql:12 security update
- RLSA-2026:29035: Important: skopeo security update
- RLSA-2026:28584: Moderate: libxslt security update
- RLSA-2026:28582: Moderate: keylime security update
- RLSA-2026:28911: Moderate: coreutils security update
- RLSA-2023:6621: Moderate: protobuf-c security update
- RLSA-2023:6482: Moderate: librabbitmq security update
- RLSA-2023:6566: Moderate: libmicrohttpd security update
- RLSA-2026:27789: Important: kernel security, bug fix, and enhancement update
- RLSA-2026:28290: Moderate: libreoffice security update
- RLSA-2023:6431: Moderate: libfastjson security update
- RLSA-2026:29151: Important: nginx:1.26 security update
- RLSA-2023:6661: Low: gmp security and enhancement update
- RLSA-2023:5048: Important: flac security update
- RLSA-2023:6369: Moderate: qt5 security and bug fix update
- RLSA-2023:7015: Moderate: wireshark security update
- RLSA-2023:2863: Moderate: ctags security update
- RLSA-2023:2851: Moderate: freerdp security update
- RLSA-2023:7139: Moderate: samba security, bug fix, and enhancement update
- RLSA-2023:7083: Moderate: emacs security update
- RLBA-2023:3052: Moderate:cifs-utils bug fix and enhancement update
- RLSA-2026:29898: Moderate: libpng security update
- RLSA-2026:29195: Important: buildah security update
- RLSA-2026:29980: Moderate: golang security, bug fix, and enhancement update
- RLSA-2026:29874: Important: nginx security update
- RLSA-2026:29703: Important: containernetworking-plugins security update
- RLSA-2026:29844: Important: tigervnc security update
- RLSA-2026:29940: Important: thunderbird security update
- RLSA-2026:29702: Important: runc security update
- RLSA-2026:29981: Moderate: golang security, bug fix, and enhancement update
- RLSA-2026:29455: Important: buildah security update
- RLSA-2023:6712: Moderate: python-wheel security update
- RLSA-2023:2860: Moderate: python27:2.7 security update
- RLSA-2023:2870: Moderate: freeradius:3.0 security update
- RLSA-2023:6976: Moderate: libfastjson security update
- RLSA-2023:2786: Moderate: wayland security, bug fix, and enhancement update
- RLSA-2026:30129: Important: kernel security, bug fix, and enhancement update
- RLSA-2026:28581: Important: python3.14 security, bug fix, and enhancement update
- RLSA-2023:2589: Moderate: autotrace security update
- RLSA-2022:2129: Moderate: lynx security update
- RLSA-2023:3067: Moderate: autotrace security update
- RLSA-2022:5597: Important: pandoc security update
- RLSA-2023:2873: Moderate: gcc-toolset-12-binutils security update
- RLSA-2023:7016: Low: libpq security update
- RLSA-2023:3087: Important: mysql:8.0 security, bug fix, and enhancement update
Slackware Linux
The Slackware Linux Security Team released libarchive 3.8.8 to patch multiple vulnerabilities across the 15.0 stable branch and the current development line. Users should install the package immediately to keep their compression utilities secure. Libarchive continues to handle nonstandard archive formats more reliably than competing tools on the platform.
SUSE Linux
SUSE and openSUSE have rolled out a massive wave of critical and important security patches spanning dozens of widely used enterprise packages. The advisories target core infrastructure components including the Linux kernel, OpenSSL, Node.js, Podman, Apptainer, and various Python libraries across SLES and openSUSE Leap releases. Each release closes dozens of independently tracked vulnerabilities affecting network routing tools, document rendering engines, and container management utilities. System administrators managing these distributions must download and apply the latest package builds immediately to prevent potential exploitation.
- openSUSE-SU-2026:11071-1: moderate: chromedriver-149.0.7827.155-1.1 on GA media
- SUSE-SU-2026:2475-1: important: Security update for openvswitch
- SUSE-SU-2026:2476-1: important: Security update for openvswitch3
- SUSE-SU-2026:2478-1: important: Security update for graphite2
- SUSE-SU-2026:2481-1: important: Security update for openvswitch
- SUSE-SU-2026:2483-1: important: Security update for python-python-multipart
- SUSE-SU-2026:2487-1: important: Security update for rmt-server
- SUSE-SU-2026:2486-1: important: Security update for python-urllib3
- openSUSE-SU-2026:0211-1: important: Security update for python-nltk
- SUSE-SU-2026:2489-1: moderate: Security update for postfix
- SUSE-SU-2026:2490-1: important: Security update for libarchive
- SUSE-SU-2026:2496-1: important: Security update for the Linux Kernel (Live Patch 52 for SUSE Linux Enterprise 15 SP4)
- SUSE-SU-2026:2520-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise 15 SP7)
- SUSE-SU-2026:2511-1: important: Security update for the Linux Kernel (Live Patch 53 for SUSE Linux Enterprise 15 SP4)
- openSUSE-SU-2026:0212-1: important: Security update for hamlib
- SUSE-SU-2026:2523-1: important: Security update for libinput
- SUSE-SU-2026:2530-1: important: Security update for libinput
- SUSE-SU-2026:2529-1: important: Security update for libinput
- SUSE-SU-2026:2553-1: important: Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise 15 SP6)
- SUSE-SU-2026:2532-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 15 SP7)
- SUSE-SU-2026:2567-1: important: Security update for the Linux Kernel (Live Patch 31 for SUSE Linux Enterprise 15 SP5)
- SUSE-SU-2026:2559-1: important: Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise 15 SP6)
- openSUSE-SU-2026:20965-1: important: Security update for the Linux Kernel
- openSUSE-SU-2026:20966-1: moderate: Security update for editorconfig-core-c
- openSUSE-SU-2026:20967-1: low: Security update for opensc
- openSUSE-SU-2026:11079-1: moderate: ghc-crypton-asn1-parse-0.10.0-1.1 on GA media
- openSUSE-SU-2026:11078-1: moderate: ghc-crypton-asn1-encoding-0.10.0-1.1 on GA media
- openSUSE-SU-2026:11075-1: moderate: docker-stable-24.0.9_ce-18.1 on GA media
- openSUSE-SU-2026:11077-1: moderate: ghc-aws-0.25.2-1.1 on GA media
- openSUSE-SU-2026:11081-1: moderate: ghc-crypton-pem-0.3.0-1.1 on GA media
- openSUSE-SU-2026:11074-1: moderate: containerized-data-importer1.65-api-1.65.0-1.1 on GA media
- openSUSE-SU-2026:11073-1: moderate: bitcoin-qt6-31.0-2.1 on GA media
- openSUSE-SU-2026:11080-1: moderate: ghc-crypton-asn1-types-0.4.1-1.1 on GA media
- openSUSE-SU-2026:11076-1: moderate: dracut-110+suse.35.g9834432-1.1 on GA media
- SUSE-SU-2026:2575-1: important: Security update for libsolv, libzypp, zypper
- SUSE-SU-2026:2580-1: important: Security update for ImageMagick
- SUSE-SU-2026:2584-1: moderate: Security update for exiv2
- SUSE-SU-2026:2590-1: important: Security update for libsolv, libzypp, zypper
- SUSE-SU-2026:2595-1: important: Security update for rekor
- SUSE-SU-2026:2597-1: important: Security update for podman
- SUSE-SU-2026:2596-1: important: Security update for podman
- SUSE-SU-2026:2598-1: important: Security update for openssl-3
- SUSE-SU-2026:2599-1: important: Security update for libarchive
- SUSE-SU-2026:2571-1: important: Security update for the Linux Kernel (Live Patch 39 for SUSE Linux Enterprise 15 SP5)
- SUSE-SU-2026:2588-1: important: Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise 15 SP6)
- SUSE-SU-2026:2601-1: important: Security update for the Linux Kernel (Live Patch 38 for SUSE Linux Enterprise 15 SP5)
- SUSE-SU-2026:2607-1: important: Security update for the Linux Kernel (Live Patch 44 for SUSE Linux Enterprise 15 SP4)
- SUSE-SU-2026:2608-1: important: Security update for the Linux Kernel (Live Patch 24 for SUSE Linux Enterprise 15 SP6)
- openSUSE-SU-2026:11084-1: moderate: ghc-crypton-x509-system-1.9.0-1.1 on GA media
- openSUSE-SU-2026:11091-1: moderate: kubevirt1.8-container-disk-1.8.3-1.1 on GA media
- openSUSE-SU-2026:11089-1: moderate: hamlib-4.7.2-1.1 on GA media
- openSUSE-SU-2026:11088-1: moderate: gstreamer-plugins-bad-1.28.4+24-1.1 on GA media
- openSUSE-SU-2026:11083-1: moderate: ghc-crypton-x509-store-1.9.0-1.1 on GA media
- SUSE-SU-2026:2613-1: important: Security update for xen
- SUSE-SU-2026:2609-1: important: Security update for apptainer
- SUSE-SU-2026:2616-1: important: Security update for bind
- SUSE-SU-2026:2614-1: important: Security update for openssl-1_1
- SUSE-SU-2026:2617-1: important: Security update for bind
- SUSE-SU-2026:2620-1: low: Security update for iproute2
- SUSE-SU-2026:2621-1: important: Security update for openssl-1_1-livepatches
- SUSE-SU-2026:2610-1: important: Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise 15 SP6)
- SUSE-SU-2026:2625-1: moderate: Security update for GraphicsMagick
- openSUSE-SU-2026:0214-1: important: Security update for mbedtls
- openSUSE-SU-2026:0213-1: important: Security update for mbedtls-2
- openSUSE-SU-2026:0215-1: moderate: Security update for python-biopython
- SUSE-SU-2026:2626-1: important: Security update for python-PyJWT
- SUSE-SU-2026:2630-1: important: Security update for the Linux Kernel
- openSUSE-SU-2026:11099-1: moderate: python311-python-multipart-0.0.32-1.1 on GA media
- openSUSE-SU-2026:11100-1: moderate: python312-3.12.13-6.1 on GA media
- openSUSE-SU-2026:11094-1: moderate: libnilfs3-2.3.1-1.1 on GA media
- openSUSE-SU-2026:11098-1: moderate: python311-nltk-3.10.0rc1-1.1 on GA media
- openSUSE-SU-2026:11097-1: moderate: python311-aiohttp-3.14.1-1.1 on GA media
- openSUSE-SU-2026:11093-1: moderate: lrzip-0.660-1.1 on GA media
- openSUSE-SU-2026:11096-1: moderate: libopenbabel8-3.2.0-2.1 on GA media
- openSUSE-SU-2026:11101-1: moderate: python315-3.15.0~b2-1.1 on GA media
- openSUSE-SU-2026:11095-1: moderate: ofono-2.19-3.1 on GA media
- openSUSE-SU-2026:11092-1: moderate: libtar-1.2.20-3.1 on GA media
- SUSE-SU-2026:2632-1: important: Security update for the Linux Kernel
- SUSE-SU-2026:2634-1: important: Security update for python-pip
- SUSE-SU-2026:2636-1: important: Security update for podman
- openSUSE-SU-2026:0217-1: moderate: Security update for perl-Net-Dropbox-API
- SUSE-SU-2026:2638-1: important: Security update for the Linux Kernel
- openSUSE-SU-2026:11106-1: moderate: asn1c-0.9.29-1.1 on GA media
- openSUSE-SU-2026:11111-1: moderate: pacemaker-3.0.2+20260616.4544f351-1.1 on GA media
- openSUSE-SU-2026:11102-1: moderate: trivy-0.71.2-1.1 on GA media
- openSUSE-SU-2026:11109-1: moderate: libssh2-1-1.11.1-3.1 on GA media
- openSUSE-SU-2026:11104-1: moderate: NetworkManager-applet-openvpn-1.12.5-1.1 on GA media
- SUSE-SU-2026:2644-1: important: Security update for frr
- SUSE-SU-2026:2647-1: important: Security update for nodejs22
- SUSE-SU-2026:2653-1: moderate: Security update for util-linux
- SUSE-SU-2026:2651-1: important: Security update for haproxy
- SUSE-SU-2026:2654-1: moderate: Security update for libsoup2
- SUSE-SU-2026:2652-1: important: Security update for haproxy
- SUSE-SU-2026:2657-1: important: Security update for opensc
- SUSE-SU-2026:2658-1: important: Security update for the Linux Kernel
- openSUSE-SU-2026:11121-1: moderate: corepack24-24.17.0-1.1 on GA media
- openSUSE-SU-2026:11120-1: moderate: nano-9.1-1.1 on GA media
- openSUSE-SU-2026:11115-1: moderate: GraphicsMagick-1.3.47-3.1 on GA media
- openSUSE-SU-2026:11112-1: moderate: python311-py7zr-1.1.3-1.1 on GA media
- openSUSE-SU-2026:11114-1: moderate: gvim-9.2.0530-1.1 on GA media
- openSUSE-SU-2026:11113-1: moderate: python311-pypdf-6.14.0-1.1 on GA media
- openSUSE-SU-2026:0220-1: moderate: Security update for openbabel
Ubuntu Linux
Ubuntu distributed a fresh batch of security patches for LTS releases ranging from 22.04 through 26.04 to fix serious flaws in widely deployed infrastructure tools. The notices target packages including Nginx, MySQL, HAProxy, ImageMagick, containerd, xrdp, and the Linux kernel, addressing issues that span memory corruption, authentication bypasses, and arbitrary code execution. Administrators running these systems should install the updates right away, since unauthenticated attackers can crash databases, hijack sessions, or run malicious payloads without proper credentials.
- [USN-8455-1] Netatalk vulnerabilities
- [USN-8458-1] nginx vulnerabilities
- [USN-8459-1] HAProxy vulnerabilities
- [USN-8457-1] MySQL vulnerabilities
- [USN-8447-3] Google Guest Agent vulnerabilities
- [USN-8462-1] Linux kernel (Oracle) vulnerabilities
- [USN-8388-2] Linux kernel vulnerabilities
- [USN-8461-1] Linux kernel (Azure) vulnerabilities
- [USN-8460-1] libxml2 vulnerabilities
- [USN-8463-1] LibVNCServer vulnerabilities
- [USN-8464-1] LIBNFS vulnerability
- [USN-8193-2] libcap vulnerability
- [USN-8457-2] MySQL vulnerabilities
- [USN-8456-1] libxml2 vulnerability
- [USN-8467-1] Perl vulnerabilities
- [USN-8466-1] Perl DBI module vulnerabilities
- [USN-8469-1] FFmpeg vulnerabilities
- [USN-8470-1] cpp-httplib vulnerability
- [USN-8468-1] ImageMagick vulnerabilities
- [USN-8474-1] NSD vulnerabilities
- [USN-8452-1] pbkdf2 vulnerability
- [USN-8472-1] containerd vulnerabilities
- [USN-8465-1] Apache MINA vulnerabilities
- [USN-8473-1] containerd-stable vulnerabilities
- [USN-8471-1] containerd vulnerabilities
- [USN-8476-1] xrdp vulnerabilities
- [USN-8475-1] AMD Microcode vulnerabilities
How to apply these Linux security updates safely
Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.
Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.
Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.
Debian/Ubuntu (apt)
The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.
sudo apt update sudo apt upgrade -y
Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)
On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.
sudo dnf check-update sudo dnf upgrade -y
or on older releases
sudo yum check-update sudo yum update
SUSE (zypper)
SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.
sudo zypper refresh sudo zypper update -y
Slackware (slackpkg and pkgtool)
Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.
sudo slackpkg update sudo slackpkg upgrade-all
This week's bulletin is a textbook case of patch fatigue hitting head-on. The sheer volume of Critical and Important ratings across RHEL, Oracle, Debian, and Ubuntu leaves no room for procrastination. Nginx and PostgreSQL showed up on nearly every single list, which means your DMZ and your databases are sitting on unpatched RCE and privilege escalation vectors if you haven't run a dnf upgrade or apt full-upgrade yet.
Not cheap in terms of operational overhead, but the alternative is letting attackers test those Chromium memory corruption flaws and kernel race conditions against your infrastructure. Prioritize the kernel and web stack first. Lean on live patching for SUSE and RHEL to keep your SLAs intact, and don't wait for the weekend maintenance window. The attack surface this week is wider than usual. Patch early, patch hard.