Security 10974 Published by

This week brought a massive wave of Linux security advisories with critical patches targeting the Linux kernel, glibc, OpenSSH, Node.js, and OpenSSL. Debian, Red Hat, Fedora, and Ubuntu alone pushed dozens of updates for infrastructure staples like Samba, Unbound, and Chromium, while Qubes OS addressed four specific Xen vulnerabilities that could allow malicious VMs to escape isolation. Beyond the standard patching cycle, Ubuntu rolled out specialized cloud kernel updates for Azure, AWS, and Oracle environments. With nearly identical CVEs surfacing across multiple distros, system administrators should prioritize OpenSSH, glibc, Node.js, and Chromium first, then plan dedicated maintenance windows to handle the heavy restart volume without breaking production.





Weekly Linux Security Roundup: Kernels, OpenSSL, and Node.js dominate a massive patch week

If you manage Linux infrastructure and haven't queued up your package manager yet, you should probably start. This week's security advisories read like a census of the modern attack surface. Every major distribution dropped critical patches for the Linux kernel, glibc, OpenSSH, Node.js, OpenSSL, and a dozen infrastructure staples like Samba, Unbound, and Dovecot.

It's not just a handful of CVEs. Debian addressed vulnerabilities across Chromium, php-phpseclib, Samba, NSS, Expat, ImageMagick, Starlette, and more. Red Hat published advisories spanning kernel-rt, kpatch-patch modules, OpenShift 4.18 through 4.22, and Python 3.12. Fedora pushed fixes for systemd, skopeo, and a staggering amount of GStreamer plugin vulnerabilities across both Fedora 43 and 44. Even Slackware and Qubes OS kept their quieter corners busy. Qubes specifically addressed four Xen vulnerabilities (XSA-500, XSA-505, XSA-506, and XSA-507) that could let malicious VMs escape isolation and leak memory across qubes.

Secpin

The glibc, SSH, and Node.js trifecta

The heavy hitters this week were predictable but far from harmless. The glibc patches in Ubuntu's USN-8611-1 closed seven distinct flaws, including heap buffer overflows in scanf and broken DNS response parsing that could trigger arbitrary code execution. OpenSSH saw multiple advisories across RHEL, Rocky, SUSE, and Fedora. Node.js 22 and 24 got hit hard by Oracle, AlmaLinux, Rocky, and SUSE, with memory corruption and remote code execution risks flagged in upstream releases.

Next, Chromium. Debian's DLA-4701-1 patched 18 vulnerabilities across Chromium 150, while Fedora's weekly batch covered over a hundred flaws. If you run browser-based admin panels or internal corporate portals, those are non-negotiable.

The GStreamer situation deserves a moment of side-eye too. The modular plugin split was originally designed to keep media pipelines lean, a decision that now backfires as attackers catalog every -bad and -good module for RCE vectors. Five distros independently flagged the same gstreamer1-plugins-bad-free vulnerabilities across RLSA-2026, RHSA-2026, and openSUSE-SU-2026. That's upstream saying something nasty is out there. Ignoring the backlog isn't bravery. It's just a delayed incident.

Container, Cloud, and the AI Shift

Ubuntu's cloud-focused kernel advisories also stood out. USN-8605 through USN-8610 covered Azure CVM, Azure FIPS, AWS, and Oracle cloud kernels, plus a regression fix in FreeRDP. If you're running hybrid cloud deployments, those kernel variants often live in their own update channel. Don't assume standard apt upgrade catches them.

It's a heavy week. The patches are broadly important to critical, and the advisory numbering system across the RHEL family shows just how many sub-tracks got hit. Rocky and AlmaLinux mirrored most of the upstream CVEs with their own advisories, which is exactly what you want from enterprise-adjacent distros. The downside is obvious. The volume means testing windows get tighter, and rolling restarts pile up. Plan maintenance windows. Verify your patch management tooling actually pulled the latest package versions.

If you haven't already, run your security scanning tools against your patch baseline this week. Focus on OpenSSH, glibc, Node.js, and Chromium first. Then work through the kernel and container stack. Head here to track individual advisories, or check your distro's official security mailing lists if you prefer digest-style updates. The CVEs aren't going away. Neither should your patching cadence.

Latest Security Updates by Distribution

Here’s a complete breakdown of the security updates for AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Qubes OS, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux.

AlmaLinux

AlmaLinux issued extensive security errata for versions eight through ten, updating core packages including Node.js, OpenSSH, the Linux kernel, Grafana, Libreswan, Dovecot, gstreamer1-plugins-bad-free, rest, libtiff, sssd, go-fdo-server, unbound DNS resolver, .NET, and Vim. These patches close critical vulnerabilities that previously enabled remote code execution, denial of service attacks, and daemon crashes through malformed IKE packets or memory corruption bugs. The coordinated releases address dozens of known flaws across network security, memory management, and storage subsystems to harden production environments. System operators managing AlmaLinux 8, 9, and 10 deployments now have access to the updated packages that resolve these specific attack vectors.

Debian GNU/Linux

Debian administrators received a coordinated wave of security advisories targeting dozens of widely used system packages across stable, Long Term Support, and Freexian Extended distributions. The patches address critical flaws in the Linux kernel, Chromium browser, BIND9 DNS server, Samba file sharing, OpenJDK runtimes, ImageMagick, Ruby-Rack, PHP 8.4, Calibre, NSS, and several other libraries. Each advisory resolves numerous CVE-identified vulnerabilities that could otherwise allow remote attackers to execute arbitrary code, bypass authentication checks, trigger heap buffer overflows, or steal sensitive information through crafted files and network traffic. System operators should apply these updates immediately to maintain system integrity across their Debian infrastructure.

Fedora Linux

Fedora 43 and Fedora 44 administrators must install extensive security advisories that patch dozens of critical vulnerabilities across core system packages like systemd, Chromium, WordPress, PostgreSQL 16, and Nginx. These rolling updates address well over thirty confirmed CVEs distributed among networking utilities, databases, scripting frameworks, and container management tools. System operators should apply these patches through standard package managers immediately to maintain secure and stable infrastructure environments.

Oracle Linux

Oracle Linux published a series of security advisories covering operating system versions seven through ten to patch dozens of publicly disclosed vulnerabilities. The updates replace core infrastructure packages including the Unbreakable Enterprise kernel, OpenSSL, OpenSSH, Node.js, Java, and several developer toolchains across both x86_64 and aarch64 architectures. These patches apply to stability and long-term support release tracks while addressing critical security flaws and resolving functional performance issues in widely used system components. The coordinated rollout delivers the necessary package replacements for administrators managing Oracle Linux deployments on current hardware generations.

Qubes OS

Qubes Security Bulletin 116 introduces four new Xen kernel patches designed to fix critical isolation failures in the Qubes OS environment. The updates target XSA-500, XSA-505, XSA-506, and XSA-507, flaws that previously allowed hostile virtual machines to access host memory or read information from other isolated domains. Without these updates, attackers could bypass Qubes OS isolation rules and extract credentials or private files from unrelated virtual environments. System administrators should apply the latest Qubes OS release immediately to restore strict memory separation between all running instances.

Red Hat Enterprise Linux

Red Hat Product Security published a series of Important-rated advisories covering Red Hat Enterprise Linux versions 7 through 10. The updates address confirmed vulnerabilities across a broad set of packages, including the Linux kernel, OpenShift Container Platform, LibreOffice, Node.js, TigerVNC, Grafana, Dovecot, and various SSH utilities. System administrators should apply these patches immediately to close security gaps on both standard deployments and specialized environments like RHEL SAP, EUS, and kernel-RT builds. Each advisory details the specific flaw and provides direct upgrade paths for affected software components.

Rocky Linux

Rocky Linux released a wave of security errata across versions 8, 9, and 10 for both standard and SIG Cloud distributions. These advisories close known vulnerabilities in widely deployed software including Java 25, Node.js 22/24, OpenSSH, Firefox, PHP, Nginx, Grafana, Dovecot, SSSD, Unbound, LibreSwan, Python-pillow, firewalld, Vim, Perl, fence-agents, osbuild-composer, and multiple kernel builds. System administrators should install every listed patch immediately to prevent unauthorized access and maintain baseline operational stability. Administrators can locate every required fix under advisory identifiers ranging from RLSA-2026:42887 through RLBA-2026:47115.

Slackware Linux

The Slackware Linux Security Team published advisory SSA:2026-209 to address critical flaws across three major projects. System administrators running Slackware 15.0 or the rolling current branch should apply these updates immediately. The patches resolve known security vulnerabilities in libarchive, Samba, and SeaMonkey. Users can install the corrected packages from their distribution mirrors to keep their systems secure.

SUSE Linux

SUSE administrators must apply multiple security patches across openSUSE and SLE distributions after recent advisories identified vulnerabilities in widely used packages like Java, Nginx, Chromium, OpenSSH, Tomcat, and Python libraries. The updates address memory corruption flaws and denial of service risks across SUSE Linux Enterprise versions 15 SP4 through SP7, alongside fixes for core system components like systemd and glib2. Severity ratings range from moderate to important, with certain Chromium and kernel live patch releases requiring immediate installation to prevent exploitation. System operators should apply these advisories promptly to maintain secure production environments without disrupting active workloads.

Ubuntu Linux

Ubuntu issued a series of security notices across its long-term support releases to patch critical vulnerabilities in the Linux kernel. These patches cover specialized hardware and cloud environments including NVIDIA, IBM, Azure FIPS, Raspberry Pi, KVM, Intel IoT drivers, as well as major public cloud providers like AWS and Oracle. Additional updates resolve flaws in Glibc, Roc Toolkit, FreeIPMI, Samba, FreeRDP, Ruby-Sinatra, libinput, Python 2.7/3.5, and OpenSSL that could enable denial of service attacks or arbitrary code execution. System administrators should deploy these fixes immediately to protect their infrastructure from active exploitation attempts.

How to apply these Linux security updates

Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.

Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.

Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.

Debian/Ubuntu (apt)

The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.

sudo apt update
sudo apt upgrade -y

Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)

On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.

sudo dnf check-update
sudo dnf upgrade -y

or on older releases

sudo yum check-update
sudo yum update

SUSE (zypper)

SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.

sudo zypper refresh
sudo zypper update -y

Slackware (slackpkg and pkgtool)

Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.

sudo slackpkg update
sudo slackpkg upgrade-all