This week brought a massive wave of Linux security advisories with critical patches targeting the Linux kernel, glibc, OpenSSH, Node.js, and OpenSSL. Debian, Red Hat, Fedora, and Ubuntu alone pushed dozens of updates for infrastructure staples like Samba, Unbound, and Chromium, while Qubes OS addressed four specific Xen vulnerabilities that could allow malicious VMs to escape isolation. Beyond the standard patching cycle, Ubuntu rolled out specialized cloud kernel updates for Azure, AWS, and Oracle environments. With nearly identical CVEs surfacing across multiple distros, system administrators should prioritize OpenSSH, glibc, Node.js, and Chromium first, then plan dedicated maintenance windows to handle the heavy restart volume without breaking production.
Weekly Linux Security Roundup: Kernels, OpenSSL, and Node.js dominate a massive patch week
If you manage Linux infrastructure and haven't queued up your package manager yet, you should probably start. This week's security advisories read like a census of the modern attack surface. Every major distribution dropped critical patches for the Linux kernel, glibc, OpenSSH, Node.js, OpenSSL, and a dozen infrastructure staples like Samba, Unbound, and Dovecot.
It's not just a handful of CVEs. Debian addressed vulnerabilities across Chromium, php-phpseclib, Samba, NSS, Expat, ImageMagick, Starlette, and more. Red Hat published advisories spanning kernel-rt, kpatch-patch modules, OpenShift 4.18 through 4.22, and Python 3.12. Fedora pushed fixes for systemd, skopeo, and a staggering amount of GStreamer plugin vulnerabilities across both Fedora 43 and 44. Even Slackware and Qubes OS kept their quieter corners busy. Qubes specifically addressed four Xen vulnerabilities (XSA-500, XSA-505, XSA-506, and XSA-507) that could let malicious VMs escape isolation and leak memory across qubes.
The glibc, SSH, and Node.js trifecta
The heavy hitters this week were predictable but far from harmless. The glibc patches in Ubuntu's USN-8611-1 closed seven distinct flaws, including heap buffer overflows in scanf and broken DNS response parsing that could trigger arbitrary code execution. OpenSSH saw multiple advisories across RHEL, Rocky, SUSE, and Fedora. Node.js 22 and 24 got hit hard by Oracle, AlmaLinux, Rocky, and SUSE, with memory corruption and remote code execution risks flagged in upstream releases.
Next, Chromium. Debian's DLA-4701-1 patched 18 vulnerabilities across Chromium 150, while Fedora's weekly batch covered over a hundred flaws. If you run browser-based admin panels or internal corporate portals, those are non-negotiable.
The GStreamer situation deserves a moment of side-eye too. The modular plugin split was originally designed to keep media pipelines lean, a decision that now backfires as attackers catalog every -bad and -good module for RCE vectors. Five distros independently flagged the same gstreamer1-plugins-bad-free vulnerabilities across RLSA-2026, RHSA-2026, and openSUSE-SU-2026. That's upstream saying something nasty is out there. Ignoring the backlog isn't bravery. It's just a delayed incident.
Container, Cloud, and the AI Shift
Ubuntu's cloud-focused kernel advisories also stood out. USN-8605 through USN-8610 covered Azure CVM, Azure FIPS, AWS, and Oracle cloud kernels, plus a regression fix in FreeRDP. If you're running hybrid cloud deployments, those kernel variants often live in their own update channel. Don't assume standard apt upgrade catches them.
It's a heavy week. The patches are broadly important to critical, and the advisory numbering system across the RHEL family shows just how many sub-tracks got hit. Rocky and AlmaLinux mirrored most of the upstream CVEs with their own advisories, which is exactly what you want from enterprise-adjacent distros. The downside is obvious. The volume means testing windows get tighter, and rolling restarts pile up. Plan maintenance windows. Verify your patch management tooling actually pulled the latest package versions.
If you haven't already, run your security scanning tools against your patch baseline this week. Focus on OpenSSH, glibc, Node.js, and Chromium first. Then work through the kernel and container stack. Head here to track individual advisories, or check your distro's official security mailing lists if you prefer digest-style updates. The CVEs aren't going away. Neither should your patching cadence.
Latest Security Updates by Distribution
Here’s a complete breakdown of the security updates for AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Qubes OS, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux.
AlmaLinux
AlmaLinux issued extensive security errata for versions eight through ten, updating core packages including Node.js, OpenSSH, the Linux kernel, Grafana, Libreswan, Dovecot, gstreamer1-plugins-bad-free, rest, libtiff, sssd, go-fdo-server, unbound DNS resolver, .NET, and Vim. These patches close critical vulnerabilities that previously enabled remote code execution, denial of service attacks, and daemon crashes through malformed IKE packets or memory corruption bugs. The coordinated releases address dozens of known flaws across network security, memory management, and storage subsystems to harden production environments. System operators managing AlmaLinux 8, 9, and 10 deployments now have access to the updated packages that resolve these specific attack vectors.
- ALSA-2026:46398: libreswan security update (Important)
- ALSA-2026:46397: libreswan security update (Important)
- ALSA-2026:46391: grafana security, bug fix, and enhancement update (Important)
- ALSA-2026:46396: libreswan security update (Important)
- ALSA-2026:46990: sssd security, bug fix, and enhancement update (Important)
- ALSA-2026:47011: kernel security update (Important)
- ALSA-2026:47010: kernel-rt security update (Important)
- ALSA-2026:46532: dovecot security update (Important)
- ALSA-2026:46395: go-fdo-server security update (Important)
- ALSA-2026:46394: go-fdo-client security update (Important)
- ALSA-2026:47180: gstreamer1-plugins-bad-free security update (Important)
- ALSA-2026:47079: libXfont2 security update (Important)
- ALSA-2026:47085: rest security update (Important)
- ALSA-2026:47059: nodejs:22 security update (Important)
- ALSA-2026:47060: nodejs:24 security update (Important)
- ALSA-2026:47184: libtiff security update (Important)
- ALSA-2026:47731: gstreamer1-plugins-bad-free security update (Important)
- ALSA-2026:47103: libXfont2 security update (Important)
- ALSA-2026:48034: nodejs24 security update (Important)
- ALSA-2026:48032: nodejs-nodemon security update (Important)
- ALSA-2026:48033: nodejs22 security update (Important)
- ALSA-2026:47757: openssh security update (Important)
- ALSA-2026:48703: vim security update (Important)
- ALSA-2026:47755: openssh security update (Moderate)
- ALSA-2026:36320: unbound security update (Important)
- ALSA-2026:41897: .NET 10.0 security, bug fix, and enhancement update (Important)
- ALSA-2026:41895: .NET 9.0 security, bug fix, and enhancement update (Important)
- ALSA-2026:45192: kernel security, bug fix, and enhancement update (Important)
- ALSA-2026:36777: unbound security update (Important)
- ALSA-2026:41898: .NET 10.0 security, bug fix, and enhancement update (Important)
- ALSA-2026:39311: qemu-kvm security update (Low)
- ALSA-2026:41896: .NET 9.0 security, bug fix, and enhancement update (Important)
- ALSA-2026:41894: .NET 8.0 security, bug fix, and enhancement update (Important)
- ALSA-2026:47756: openssh security update (Important)
- ALSA-2026:41893: .NET 8.0 security, bug fix, and enhancement update (Important)
- ALSA-2026:47982: vim security update (Important)
- ALSA-2026:48585: fence-agents security update (Important)
- ALSA-2026:47083: pipewire security update (Important)
- ALSA-2026:45114: kernel security update (Important)
- ALSA-2026:47040: kernel security, bug fix, and enhancement update (Important)
Debian GNU/Linux
Debian administrators received a coordinated wave of security advisories targeting dozens of widely used system packages across stable, Long Term Support, and Freexian Extended distributions. The patches address critical flaws in the Linux kernel, Chromium browser, BIND9 DNS server, Samba file sharing, OpenJDK runtimes, ImageMagick, Ruby-Rack, PHP 8.4, Calibre, NSS, and several other libraries. Each advisory resolves numerous CVE-identified vulnerabilities that could otherwise allow remote attackers to execute arbitrary code, bypass authentication checks, trigger heap buffer overflows, or steal sensitive information through crafted files and network traffic. System operators should apply these updates immediately to maintain system integrity across their Debian infrastructure.
- [DLA 4700-1] linux-6.1 security update
- [DLA 4699-1] hplip security update
- ELA-1784-1 hplip security update
- ELA-1786-1 bind9 security update
- ELA-1785-1 php-phpseclib security update (by )
- [SECURITY] [DLA 4701-1] chromium security update
- [DSA 6401-1] samba security update
- [DLA 4703-1] openjdk-17 security update
- [DLA 4702-1] openjdk-11 security update
- ELA-1787-1 openjdk-11 security update (by )
- [DSA 6402-1] hplip security update
- ELA-1788-1 libxfont1 security update (by )
- [DLA 4704-1] libraw security update
- [DLA 4705-1] calibre security update
- [DSA 6403-1] nss security update
- [DSA 6404-1] expat security update
- ELA-1790-1 libraw security update (by )
- ELA-1789-1 imagemagick security update (by )
- [DLA 4707-1] gsasl security update
- [DLA 4706-1] ruby-rack security update
- [DLA 4708-1] python-authlib security update
- [DSA 6405-1] linux security update
- [DSA 6408-1] chromium security update
- [DLA 4709-1] poppler security update
- [DSA 6407-1] incus security update
- [DSA 6406-1] php8.4 security update
- [DLA 4712-1] node-tar security update
- [DLA 4711-1] starlette security update
- [DSA 6409-1] libgd2 security update
- [DLA 4710-1] chromium security update
- [DLA 4713-1] sslh security update
- [DLA 4714-1] libmodbus security update
Fedora Linux
Fedora 43 and Fedora 44 administrators must install extensive security advisories that patch dozens of critical vulnerabilities across core system packages like systemd, Chromium, WordPress, PostgreSQL 16, and Nginx. These rolling updates address well over thirty confirmed CVEs distributed among networking utilities, databases, scripting frameworks, and container management tools. System operators should apply these patches through standard package managers immediately to maintain secure and stable infrastructure environments.
- Fedora 43 Update: systemd-258.10-1.fc43
- Fedora 43 Update: skopeo-1.22.2-2.fc43
- Fedora 43 Update: trafficserver-10.1.3-1.fc43
- Fedora 43 Update: libwebsockets-4.5.8-2.fc43
- Fedora 44 Update: systemd-259.8-1.fc44
- Fedora 44 Update: rust-libgit2-sys-0.18.7-1.fc44
- Fedora 44 Update: libgit2-1.9.6-1.fc44
- Fedora 44 Update: lego-5.3.1-2.fc44
- Fedora 44 Update: trafficserver-10.1.3-1.fc44
- Fedora 44 Update: libwebsockets-4.5.8-1.fc44
- Fedora 43 Update: perl-Mojolicious-9.48-1.fc43
- Fedora 43 Update: rpm-6.0.2-1.fc43
- Fedora 43 Update: opkssh-0.16.0-1.fc43
- Fedora 44 Update: opkssh-0.16.0-1.fc44
- Fedora 44 Update: perl-Mojolicious-9.48-1.fc44
- Fedora 44 Update: rpm-6.0.2-1.fc44
- Fedora 43 Update: chromium-150.0.7871.186-1.fc43
- Fedora 43 Update: restic-0.19.1-1.fc43
- Fedora 43 Update: kronosnet-1.35-1.fc43
- Fedora 43 Update: btrbk-0.32.7-1.fc43
- Fedora 43 Update: gpsd-3.26.1-7.fc43
- Fedora 44 Update: chromium-150.0.7871.186-1.fc44
- Fedora 44 Update: kronosnet-1.35-1.fc44
- Fedora 44 Update: restic-0.19.1-1.fc44
- Fedora 44 Update: libssh-0.12.2-1.fc44
- Fedora 44 Update: unbound-1.25.2-1.fc44
- Fedora 44 Update: proftpd-1.3.9c-3.fc44
- Fedora 44 Update: squid-7.6-1.fc44
- Fedora 44 Update: nodejs24-24.18.0-1.fc44
- Fedora 44 Update: wordpress-6.9.5-1.fc44
- Fedora 43 Update: proftpd-1.3.9c-3.fc43
- Fedora 43 Update: wordpress-6.9.5-1.fc43
- Fedora 43 Update: nginx-mod-fancyindex-0.6.0-8.fc43
- Fedora 43 Update: nginx-mod-vts-0.2.4-13.fc43
- Fedora 43 Update: nginx-mod-modsecurity-1.0.4-16.fc43
- Fedora 43 Update: nginx-mod-brotli-1.0.0~rc-13.fc43
- Fedora 43 Update: nginx-1.30.4-1.fc43
- Fedora 43 Update: nginx-mod-naxsi-1.6-21.fc43
- Fedora 43 Update: nginx-mod-headers-more-0.40-3.fc43
- Fedora 43 Update: perl-HTTP-Date-6.08-1.fc43
- Fedora 43 Update: unbound-1.25.2-1.fc43
- Fedora 43 Update: dokuwiki-20250514b-4.fc43
- Fedora 43 Update: pack-0.40.8-1.fc43
- Fedora 43 Update: nasm-2.16.03-5.fc43
- Fedora 43 Update: valkey-8.1.9-1.fc43
- Fedora 43 Update: lego-5.3.1-2.fc43
- Fedora 43 Update: libnbd-1.24.3-1.fc43
- Fedora 44 Update: dokuwiki-20250514b-6.fc44
- Fedora 44 Update: pack-0.40.8-1.fc44
- Fedora 44 Update: valkey-9.0.5-1.fc44
- Fedora 44 Update: fuse-overlayfs-1.17-1.fc44
- Fedora 44 Update: python3.12-3.12.13-6.fc44
- Fedora 44 Update: php-8.5.9-1.fc44
- Fedora 44 Update: nextcloud-34.0.2-1.fc44
- Fedora 44 Update: exim-4.99.5-1.fc44
- Fedora 44 Update: postgresql16-16.14-1.fc44
- Fedora 44 Update: rabbitmq-server-4.2.9-2.fc44
- Fedora 43 Update: rust-libgit2-sys-0.18.7-1.fc43
- Fedora 43 Update: libgit2-1.9.6-1.fc43
- Fedora 43 Update: nextcloud-34.0.2-1.fc43
- Fedora 43 Update: exim-4.99.5-1.fc43
- Fedora 43 Update: GitPython-3.1.55-1.fc43
- Fedora 43 Update: lemonldap-ng-2.23.2-1.fc43
- Fedora 43 Update: postgresql16-16.14-1.fc43
- Fedora 43 Update: coturn-4.15.0-1.fc43
- Fedora 44 Update: curl-8.18.0-8.fc44
- Fedora 44 Update: gh-2.97.0-2.fc44
- Fedora 44 Update: xen-4.21.2-1.fc44
- Fedora 44 Update: lemonldap-ng-2.23.2-1.fc44
- Fedora 44 Update: coturn-4.15.0-1.fc44
Oracle Linux
Oracle Linux published a series of security advisories covering operating system versions seven through ten to patch dozens of publicly disclosed vulnerabilities. The updates replace core infrastructure packages including the Unbreakable Enterprise kernel, OpenSSL, OpenSSH, Node.js, Java, and several developer toolchains across both x86_64 and aarch64 architectures. These patches apply to stability and long-term support release tracks while addressing critical security flaws and resolving functional performance issues in widely used system components. The coordinated rollout delivers the necessary package replacements for administrators managing Oracle Linux deployments on current hardware generations.
- ELSA-2026-46395 Important: Oracle Linux 10 go-fdo-server security update
- ELSA-2026-43400 Important: Oracle Linux 10 dogtag-pki security update
- ELSA-2026-44391 Important: Oracle Linux 10 libpq security update
- ELSA-2026-42919 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
- ELSA-2026-44270 Important: Oracle Linux 10 kernel security update
- ELSA-2026-42096 Important: Oracle Linux 10 c-ares security update
- ELSA-2026-30855 Important: Oracle Linux 10 git-lfs security update
- ELSA-2026-29195 Important: Oracle Linux 10 buildah security update
- ELSA-2026-24470 Important: Oracle Linux 10 podman security update
- ELSA-2026-28210 Moderate: Oracle Linux 10 vim security update
- ELSA-2026-25341 Important: Oracle Linux 10 tomcat9 update
- ELSA-2026-22314 Moderate: Oracle Linux 10 openssl security update
- ELSA-2026-22120 Important: Oracle Linux 10 golang security update
- ELSA-2026-21286 Important: Oracle Linux 10 .NET 8.0 security update
- ELSA-2026-20693 Moderate: Oracle Linux 10 mysql8.4 security update
- ELSA-2026-18537 Important: Oracle Linux 10 tomcat security update
- ELSA-2026-19126 Important: Oracle Linux 10 yggdrasil security update
- ELSA-2026-19569 Important: Oracle Linux 10 kernel security update
- ELSA-2026-18320 Moderate: Oracle Linux 10 edk2 security update
- ELBA-2026-500089 Oracle Linux 10 ignition bug fix update
- ELBA-2026-25086 Oracle Linux 10 cloud-init bug fix and enhancement update
- ELBA-2026-500050 Oracle Linux 10 fips-provider-next bug fix update
- ELBA-2026-500087 Oracle Linux 9 xfsprogs bug fix update
- ELBA-2026-500062 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
- ELBA-2026-500088 Oracle Linux 9 xfsprogs bug fix update
- ELSA-2026-44308 Important: Oracle Linux 9 libpq security update
- ELSA-2026-43307 Important: Oracle Linux 9 kernel security, bug fix, and enhancement update
- ELSA-2026-42122 Important: Oracle Linux 9 sssd security update
- ELSA-2026-44438 Important: Oracle Linux 9 compat-openssl11 security update
- ELSA-2026-42952 Moderate: Oracle Linux 9 glibc security update
- ELSA-2026-41949 Important: Oracle Linux 9 python3.14 security update
- ELSA-2026-40895 Important: Oracle Linux 9 jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update
- ELSA-2026-19345 Important: Oracle Linux 9 LibRaw security update
- ELBA-2026-500052 Oracle Linux 9 NetworkManager bug fix update
- ELBA-2026-500061 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
- ELBA-2026-42552-1 Oracle Linux 8 kernel bug fix update
- ELSA-2026-43420 Important: Oracle Linux 8 acl security update
- ELSA-2026-42828 Important: Oracle Linux 8 httpd:2.4 security, bug fix, and enhancement update
- ELSA-2026-42552 Important: Oracle Linux 8 kernel security, bug fix, and enhancement update
- ELSA-2026-41947 Important: Oracle Linux 8 nodejs:22 security, bug fix, and enhancement update
- ELSA-2026-40841 Important: Oracle Linux 8 maven:3.8 security update
- ELSA-2026-39868 Important: Oracle Linux 8 nodejs:24 security, bug fix, and enhancement update
- ELBA-2026-500061 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
- ELBA-2026-500061 Oracle Linux 7 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-30044 Important: Oracle Linux 7 poppler security update
- ELSA-2026-29952 Important: Oracle Linux 7 compat-poppler022 security update
- ELSA-2026-28132 Important: Oracle Linux 7 samba security update
- ELSA-2026-43505 Important: Oracle Linux 10 mariadb-connector-c security update
- ELBA-2026-500062 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-46398 Important: Oracle Linux 10 libreswan security update
- New Ksplice updates for UEKR6 5.4.17 on OL7 and OL8
- ELSA-2026-29980 Moderate: Oracle Linux 10 golang security, bug fix, and enhancement update
- ELBA-2026-39326 Oracle Linux 10 openssl bug fix and enhancement update
- ELSA-2026-24386 Important: Oracle Linux 10 podman security update
- ELSA-2026-18289 Important: Oracle Linux 10 podman security update
- ELSA-2026-19142 Moderate: Oracle Linux 10 freerdp security update
- ELSA-2026-29874 Important: Oracle Linux 10 nginx security update
- ELBA-2026-500086 xfsprogs bug fix update
- ELSA-2026-46394 Important: Oracle Linux 10 go-fdo-client security update
- ELSA-2026-37072 Important: Oracle Linux 10 podman security, bug fix, and enhancement update
- New glibc updates available via Ksplice (ELSA-2026-42952)
- ELSA-2026-47757 Important: Oracle Linux 10 openssh security update
- ELSA-2026-47180 Important: Oracle Linux 10 gstreamer1-plugins-bad-free security update
- ELSA-2026-47083 Important: Oracle Linux 10 pipewire security update
- ELSA-2026-47085 Important: Oracle Linux 10 rest security update
- ELSA-2026-47079 Important: Oracle Linux 10 libXfont2 security update
- ELBA-2026-500051 Oracle Linux 8 oVirt 4.5 vdsm-jsonrpc-java bug fix update
- ELSA-2026-47177 Important: Oracle Linux 8 yelp security update
- ELSA-2026-47058 Important: Oracle Linux 9 nodejs:22 security update
- ELSA-2026-47057 Important: Oracle Linux 9 nodejs:24 security update
- ELSA-2026-47736 Important: Oracle Linux 8 fence-agents security update
- ELSA-2026-47731 Important: Oracle Linux 8 gstreamer1-plugins-bad-free security update
- ELSA-2026-47184 Important: Oracle Linux 8 libtiff security update
- ELSA-2026-47183 Important: Oracle Linux 8 compat-libtiff3 security update
- ELSA-2026-47117 Moderate: Oracle Linux 8 libgcrypt security update
- ELSA-2026-47105 Important: Oracle Linux 8 firefox security update
- ELSA-2026-47103 Important: Oracle Linux 8 libXfont2 security update
- ELBA-2026-47122 Oracle Linux 8 samba bug fix and enhancement update
- ELBA-2026-47115 Oracle Linux 8 coreutils bug fix and enhancement update
- ELSA-2026-48703 Important: Oracle Linux 8 vim security update
- ELSA-2026-48021 Important: Oracle Linux 8 python-pillow security update
- ELSA-2026-46532 Important: Oracle Linux 8 dovecot security update
- ELSA-2026-46990 Important: Oracle Linux 8 sssd security, bug fix, and enhancement update
- ELSA-2026-46391 Important: Oracle Linux 8 grafana security, bug fix, and enhancement update
- ELSA-2026-45115 Important: Oracle Linux 8 kernel security update
- ELSA-2026-42733 Moderate: Oracle Linux 8 glibc security update
- ELSA-2026-48585 Important: Oracle Linux 10 fence-agents security update
- ELSA-2026-45114 Important: Oracle Linux 10 kernel security update
- ELSA-2026-48650 Important: Oracle Linux 10 vim security update
- ELSA-2026-36199 Important: Oracle Linux 10 buildah security update
- ELSA-2026-25237 Important: Oracle Linux 10 openssl security update
- ELSA-2026-21557 Important: Oracle Linux 10 kernel security update
- ELBA-2026-46512 Oracle Linux 10 openssl bug fix and enhancement update
- ELSA-2026-26168 Important: Oracle Linux 7 gimp security update
- ELSA-2026-22146 Important: Oracle Linux 7 PackageKit security update
- ELBA-2026-500093 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
- ELBA-2026-500092 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
- ELBA-2026-500093 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
- ELBA-2026-500092 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-47982 Important: Oracle Linux 9 vim security update
- ELSA-2026-47179 Important: Oracle Linux 9 gstreamer1-plugins-bad-free security update
- ELSA-2026-47084 Important: Oracle Linux 9 libXfont2 security update
- ELSA-2026-47178 Important: Oracle Linux 9 yelp security update
- ELSA-2026-47104 Important: Oracle Linux 9 firefox security update
- ELBA-2026-500093 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
- ELBA-2026-500092 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-45192 Important: Oracle Linux 9 kernel security, bug fix, and enhancement update
- ELBA-2026-46513 Oracle Linux 9 openssl bug fix and enhancement update
- ELBA-2026-500111 Oracle Linux 9 xfsprogs bug fix update
- ELBA-2026-500113 xfsprogs bug fix update
- ELBA-2026-500112 Oracle Linux 9 xfsprogs bug fix update
- ELSA-2026-47040 Important: Oracle Linux 9 kernel security, bug fix, and enhancement update
- ELSA-2026-42899 Important: Oracle Linux 10 java-25-openjdk security update
- ELSA-2026-47755 Moderate: Oracle Linux 8 openssh security update
- ELSA-2026-35841 Important: Oracle Linux 10 nodejs24 security, bug fix, and enhancement update
- ELSA-2026-47011 Important: Oracle Linux 8 kernel security update
- ELSA-2026-47017 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
Qubes OS
Qubes Security Bulletin 116 introduces four new Xen kernel patches designed to fix critical isolation failures in the Qubes OS environment. The updates target XSA-500, XSA-505, XSA-506, and XSA-507, flaws that previously allowed hostile virtual machines to access host memory or read information from other isolated domains. Without these updates, attackers could bypass Qubes OS isolation rules and extract credentials or private files from unrelated virtual environments. System administrators should apply the latest Qubes OS release immediately to restore strict memory separation between all running instances.
Red Hat Enterprise Linux
Red Hat Product Security published a series of Important-rated advisories covering Red Hat Enterprise Linux versions 7 through 10. The updates address confirmed vulnerabilities across a broad set of packages, including the Linux kernel, OpenShift Container Platform, LibreOffice, Node.js, TigerVNC, Grafana, Dovecot, and various SSH utilities. System administrators should apply these patches immediately to close security gaps on both standard deployments and specialized environments like RHEL SAP, EUS, and kernel-RT builds. Each advisory details the specific flaw and provides direct upgrade paths for affected software components.
- RHSA-2026:46397: Important: libreswan security update
- RHSA-2026:46387: Important: libreoffice security update
- RHSA-2026:46389: Important: freerdp security update
- RHSA-2026:46396: Important: libreswan security update
- RHSA-2026:46382: Important: tigervnc security update
- RHSA-2026:46391: Important: grafana security, bug fix, and enhancement update
- RHSA-2026:46393: Important: freerdp security update
- RHSA-2026:46381: Important: dovecot security update
- RHSA-2026:46395: Important: go-fdo-server security update
- RHSA-2026:46383: Important: freerdp security update
- RHSA-2026:46377: Important: tigervnc security update
- RHSA-2026:46379: Important: dovecot security update
- RHSA-2026:46380: Important: dovecot security update
- RHSA-2026:46461: Moderate: kernel-rt security update
- RHSA-2026:46460: Important: tigervnc security update
- RHSA-2026:46456: Important: tigervnc security update
- RHSA-2026:46482: Important: sssd security update
- RHSA-2026:46473: Important: tigervnc security update
- RHSA-2026:46467: Important: evince security update
- RHSA-2026:46398: Important: libreswan security update
- RHSA-2026:46392: Important: tigervnc security update
- RHSA-2026:46388: Important: freerdp security update
- RHSA-2026:46385: Important: tigervnc security update
- RHSA-2026:46386: Important: libreoffice security update
- RHSA-2026:46384: Important: freerdp security update
- RHSA-2026:46394: Important: go-fdo-client security update
- RHSA-2026:47011: Important: kernel security update
- RHSA-2026:47010: Important: kernel-rt security update
- RHSA-2026:46990: Important: sssd security, bug fix, and enhancement update
- RHSA-2026:46986: Important: libreswan security update
- RHSA-2026:46951: Important: kpatch-patch security update
- RHSA-2026:46532: Important: dovecot security update
- RHSA-2026:47069: Important: gstreamer1-plugins-bad-free security update
- RHSA-2026:47090: Important: libpq security update
- RHSA-2026:47085: Important: rest security update
- RHSA-2026:47079: Important: libXfont2 security update
- RHSA-2026:44262: Important: OpenShift Container Platform 4.21.26 bug fix and security update
- RHSA-2026:44259: Important: OpenShift Container Platform 4.20.31 bug fix and security update
- RHSA-2026:47076: Important: gstreamer1-plugins-bad-free security update
- RHSA-2026:47091: Moderate: resource-agents security update
- RHSA-2026:47049: Important: freerdp security update
- RHSA-2026:47051: Important: gstreamer1-plugins-good security update
- RHSA-2026:47048: Important: freerdp security update
- RHSA-2026:47052: Important: gstreamer1-plugins-good security update
- RHSA-2026:47046: Important: httpd security update
- RHSA-2026:47017: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:47032: Important: gstreamer1-plugins-good security update
- RHSA-2026:47174: Important: gstreamer1-plugins-good security update
- RHSA-2026:47083: Important: pipewire security update
- RHSA-2026:47071: Important: gstreamer1-plugins-bad-free security update
- RHSA-2026:47070: Important: gstreamer1-plugins-bad-free security update
- RHSA-2026:47060: Important: nodejs:24 security update
- RHSA-2026:47096: Moderate: compat-openssl10 security update
- RHSA-2026:47075: Important: gstreamer1-plugins-bad-free security update
- RHSA-2026:47040: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:47092: Moderate: resource-agents security update
- RHSA-2026:44232: Critical: OpenShift Container Platform 4.22.7 bug fix and security update
- RHSA-2026:47050: Important: gstreamer1-plugins-good security update
- RHSA-2026:47180: Important: gstreamer1-plugins-bad-free security update
- RHSA-2026:47176: Important: gstreamer1-plugins-bad-free security update
- RHSA-2026:47103: Important: libXfont2 security update
- RHSA-2026:47105: Important: firefox security update
- RHSA-2026:47248: Important: kernel security update
- RHSA-2026:47201: Important: freerdp security update
- RHSA-2026:47059: Important: nodejs:22 security update
- RHSA-2026:47101: Important: firefox security update
- RHSA-2026:47189: Important: Red Hat build of Quarkus 3.27.4.SP3 security update
- RHSA-2026:47869: Important: kernel security update
- RHSA-2026:47620: Important: kernel security update
- RHSA-2026:47998: Important: kpatch-patch security update
- RHSA-2026:47983: Important: kpatch-patch security update
- RHSA-2026:47997: Important: kpatch-patch security update
- RHSA-2026:48016: Important: kpatch-patch security update
- RHSA-2026:47984: Important: kpatch-patch security update
- RHSA-2026:44230: Important: OpenShift Container Platform 4.18.50 bug fix and security update
- RHSA-2026:44231: Important: OpenShift Container Platform 4.19.40 bug fix and security update
- RHSA-2026:47755: Moderate: openssh security update
- RHSA-2026:47731: Important: gstreamer1-plugins-bad-free security update
- RHSA-2026:47718: Important: gstreamer1-plugins-bad-free security update
- RHSA-2026:47632: Important: kernel-rt security, bug fix, and enhancement update
- RHSA-2026:48225: Important: perl:5.32 security update
- RHSA-2026:48036: Important: osbuild-composer security update
- RHSA-2026:47722: Important: grafana security, bug fix, and enhancement update
- RHSA-2026:47772: Important: mariadb-connector-c security update
- RHSA-2026:47905: Moderate: container-selinux and crun security, bug fix, and enhancement update
- RHSA-2026:48033: Important: nodejs22 security update
- RHSA-2026:48603: Important: hplip security update
- RHSA-2026:48615: Important: fence-agents security update
- RHSA-2026:48606: Important: hplip security, bug fix, and enhancement update
- RHSA-2026:47757: Important: openssh security update
- RHSA-2026:47736: Important: fence-agents security update
- RHSA-2026:47633: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:47172: Important: Red Hat build of Quarkus 3.33.2.SP3 security update
- RHSA-2026:47756: Important: openssh security update
- RHSA-2026:47739: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:48171: Important: hplip security update
- RHSA-2026:47712: Important: golang security, bug fix, and enhancement update
- RHSA-2026:47716: Important: grafana-pcp security, bug fix, and enhancement update
- RHSA-2026:47910: Important: osbuild-composer security update
- RHSA-2026:47714: Important: grafana security, bug fix, and enhancement update
- RHSA-2026:47721: Important: grafana-pcp security, bug fix, and enhancement update
- RHSA-2026:48222: Important: kernel-rt security update
- RHSA-2026:47939: Important: python3.12 security update
- RHSA-2026:48021: Important: python-pillow security update
- RHSA-2026:47719: Important: golang security, bug fix, and enhancement update
- RHSA-2026:47717: Important: gstreamer1-plugins-bad-free security update
- RHSA-2026:48151: Important: Red Hat build of Cryostat security update
- RHSA-2026:47982: Important: vim security update
- RHSA-2026:48034: Important: nodejs24 security update
- RHSA-2026:48095: Important: RHCS 10.8 bug fix and enhancement update
- RHSA-2026:48032: Important: nodejs-nodemon security update
- RHSA-2026:47981: Important: kpatch-patch security update
- RHSA-2026:48118: Important: Red Hat Build of Apache Camel 4.18.3 for Quarkus 3.33 update is now available (RHBQ 3.33.2.SP3)
- RHSA-2026:48605: Important: fence-agents security update
- RHSA-2026:48586: Important: hplip security update
- RHSA-2026:48604: Important: fence-agents security update
- RHSA-2026:48845: Important: OpenJDK 25.0.4 Security Update for Windows Builds
- RHSA-2026:48815: Moderate: libsolv security update
- RHSA-2026:48703: Important: vim security update
- RHSA-2026:48760: Important: python-pillow security update
- RHSA-2026:49031: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:48864: Important: abrt security update
- RHSA-2026:48585: Important: fence-agents security update
- RHSA-2026:43225: Important: OpenShift Container Platform 4.15.67 packages and security update
- RHSA-2026:49030: Moderate: kernel security update
- RHSA-2026:49032: Important: kernel security update
- RHSA-2026:49033: Important: kernel security update
- RHSA-2026:48386: Important: kernel security update
- RHSA-2026:49214: Important: kernel security update
- RHSA-2026:49213: Important: kernel-rt security update
- RHSA-2026:48866: Important: abrt security update
- RHSA-2026:48826: Moderate: freeipmi security update
- RHSA-2026:48819: Important: abrt security update
- RHSA-2026:48818: Moderate: libsolv security update
- RHSA-2026:48865: Important: abrt security update
- RHSA-2026:48814: Moderate: libsolv security update
- RHSA-2026:49212: Important: kernel security update
- RHSA-2026:49211: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:48817: Moderate: libsolv security update
- RHSA-2026:48816: Moderate: libsolv security update
- RHSA-2026:48811: Moderate: libsolv security update
- RHSA-2026:48813: Moderate: libsolv security update
- RHSA-2026:48650: Important: vim security update
- RHSA-2026:48790: Important: osbuild-composer security update
- RHSA-2026:48759: Important: python-pillow security update
- RHSA-2026:43252: Important: OpenShift Container Platform 4.14.70 bug fix and security update
- RHSA-2026:43226: Important: OpenShift Container Platform 4.15.67 bug fix and security update
Rocky Linux
Rocky Linux released a wave of security errata across versions 8, 9, and 10 for both standard and SIG Cloud distributions. These advisories close known vulnerabilities in widely deployed software including Java 25, Node.js 22/24, OpenSSH, Firefox, PHP, Nginx, Grafana, Dovecot, SSSD, Unbound, LibreSwan, Python-pillow, firewalld, Vim, Perl, fence-agents, osbuild-composer, and multiple kernel builds. System administrators should install every listed patch immediately to prevent unauthorized access and maintain baseline operational stability. Administrators can locate every required fix under advisory identifiers ranging from RLSA-2026:42887 through RLBA-2026:47115.
- RLSA-2026:42887: Important: java-17-openjdk security update
- RLSA-2026:45116: Important: kernel-rt security update
- RLSA-2026:45115: Important: kernel security update
- RLSA-2026:45114: Important: kernel security update
- RLSA-2026:44391: Important: libpq security update
- RLSA-2026:44308: Important: libpq security update
- RLSA-2026:44438: Important: compat-openssl11 security update
- RLSA-2026:46397: Important: libreswan security update
- RXSA-2026:45192: Important: kernel security, bug fix, and enhancement update
- RXSA-2026:45115: Important: kernel security update
- RLSA-2026:45192: Important: kernel security, bug fix, and enhancement update
- RLSA-2026:46396: Important: libreswan security update
- RLSA-2026:46391: Important: grafana security, bug fix, and enhancement update
- RLSA-2026:46532: Important: dovecot security update
- RLSA-2026:46990: Important: sssd security, bug fix, and enhancement update
- RLSA-2026:46394: Important: go-fdo-client security update
- RLSA-2026:46395: Important: go-fdo-server security update
- RLSA-2026:36320: Important: unbound security update
- RLSA-2026:46398: Important: libreswan security update
- RLSA-2026:36777: Important: unbound security update
- RLSA-2026:37282: Important: unbound security update
- RLSA-2026:47060: Important: nodejs:24 security update
- RLSA-2026:47059: Important: nodejs:22 security update
- RLSA-2026:47010: Important: kernel-rt security update
- RLSA-2026:47103: Important: libXfont2 security update
- RLSA-2026:47011: Important: kernel security update
- RLSA-2026:47731: Important: gstreamer1-plugins-bad-free security update
- RLSA-2026:48225: Important: perl:5.32 security update
- RLSA-2019:3702: Moderate: openssh security, bug fix, and enhancement update
- RLSA-2026:47180: Important: gstreamer1-plugins-bad-free security update
- RLSA-2026:47079: Important: libXfont2 security update
- RLSA-2026:47083: Important: pipewire security update
- RLSA-2026:47085: Important: rest security update
- RLSA-2026:47017: Important: kernel security, bug fix, and enhancement update
- RLSA-2026:27741: Important: postgresql security update
- RLSA-2026:33449: Important: php security update
- RLSA-2026:38796: Important: plexus-utils security update
- RLSA-2026:36331: Important: nginx security, bug fix, and enhancement update
- RLSA-2026:33512: Important: ruby security update
- RLSA-2026:47105: Important: firefox security update
- RLSA-2026:30852: Important: perl-Archive-Tar security update
- RLSA-2026:30858: Important: perl-IO-Compress security update
- RLSA-2026:36732: Moderate: python-urllib3 security update
- RLBA-2026:47115: Moderate:coreutils bug fix and enhancement update
- RLSA-2026:47040: Important: kernel security, bug fix, and enhancement update
- RLSA-2026:47756: Important: openssh security update
- RLSA-2026:47757: Important: openssh security update
- RLBA-2026:28238: Moderate:firewalld bug fix and enhancement update
- RLSA-2026:47101: Important: firefox security update
- RLSA-2026:48032: Important: nodejs-nodemon security update
- RLSA-2026:47982: Important: vim security update
- RLSA-2026:47736: Important: fence-agents security update
- RLSA-2026:47755: Moderate: openssh security update
- RLSA-2026:48021: Important: python-pillow security update
- RLSA-2026:48225: Important: perl:5.32 security update
- RLSA-2026:42899: Important: java-25-openjdk security update
- RLSA-2026:48034: Important: nodejs24 security update
- RLSA-2026:48585: Important: fence-agents security update
- RLSA-2026:48033: Important: nodejs22 security update
- RLSA-2026:48703: Important: vim security update
- RLSA-2026:48650: Important: vim security update
- RLSA-2026:48790: Important: osbuild-composer security update
- RLSA-2026:49211: Important: kernel security, bug fix, and enhancement update
- RLSA-2026:49212: Important: kernel security update
Slackware Linux
The Slackware Linux Security Team published advisory SSA:2026-209 to address critical flaws across three major projects. System administrators running Slackware 15.0 or the rolling current branch should apply these updates immediately. The patches resolve known security vulnerabilities in libarchive, Samba, and SeaMonkey. Users can install the corrected packages from their distribution mirrors to keep their systems secure.
SUSE Linux
SUSE administrators must apply multiple security patches across openSUSE and SLE distributions after recent advisories identified vulnerabilities in widely used packages like Java, Nginx, Chromium, OpenSSH, Tomcat, and Python libraries. The updates address memory corruption flaws and denial of service risks across SUSE Linux Enterprise versions 15 SP4 through SP7, alongside fixes for core system components like systemd and glib2. Severity ratings range from moderate to important, with certain Chromium and kernel live patch releases requiring immediate installation to prevent exploitation. System operators should apply these advisories promptly to maintain secure production environments without disrupting active workloads.
- openSUSE-SU-2026:21440-1: important: Security update for java-17-openjdk
- openSUSE-SU-2026:21439-1: important: Security update for nginx
- openSUSE-SU-2026:11358-1: moderate: MozillaFirefox-153.0-1.1 on GA media
- openSUSE-SU-2026:11359-1: moderate: MozillaThunderbird-140.13.0-1.1 on GA media
- openSUSE-SU-2026:11363-1: moderate: java-25-openjdk-25.0.4.0-1.1 on GA media
- openSUSE-SU-2026:11361-1: moderate: ffmpeg-7-7.1.4-5.1 on GA media
- openSUSE-SU-2026:11357-1: moderate: libsrt1_5-1.5.6-1.1 on GA media
- openSUSE-SU-2026:11356-1: moderate: python313-urwid-4.0.5-1.1 on GA media
- SUSE-SU-2026:3235-1: important: Security update for glib2
- SUSE-SU-2026:3238-1: important: Security update for python-pyasn1
- SUSE-SU-2026:3240-1: important: Security update for python-soupsieve
- SUSE-SU-2026:3243-1: low: Security update for gpg2
- SUSE-SU-2026:3244-1: moderate: Security update for systemd
- SUSE-SU-2026:3254-1: important: Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise 15 SP6)
- SUSE-SU-2026:3256-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 15 SP7)
- openSUSE-SU-2026:0263-1: important: Security update for trivy
- openSUSE-SU-2026:0264-1: important: Security update for chromium
- openSUSE-SU-2026:11366-1: moderate: mcphost-0.34.0-9.1 on GA media
- openSUSE-SU-2026:11369-1: moderate: opennlp-1.9.5-2.1 on GA media
- openSUSE-SU-2026:11364-1: moderate: libknet-devel-1.33-2.1 on GA media
- SUSE-SU-2026:3268-1: important: Security update for python-Pillow
- SUSE-SU-2026:3270-1: moderate: Security update for alsa
- SUSE-SU-2026:3289-1: important: Security update for the Linux Kernel (Live Patch 29 for SUSE Linux Enterprise 15 SP5)
- openSUSE-SU-2026:11381-1: moderate: valkey-9.1.1-1.1 on GA media
- openSUSE-SU-2026:11378-1: moderate: python313-CherryPy-18.10.0-4.1 on GA media
- openSUSE-SU-2026:11377-1: moderate: libssh-config-0.11.5-1.1 on GA media
- openSUSE-SU-2026:11376-1: moderate: ignition-2.26.0-5.1 on GA media
- SUSE-SU-2026:3319-1: important: Security update for the Linux Kernel (Live Patch 35 for SUSE Linux Enterprise 15 SP5)
- SUSE-SU-2026:3300-1: important: Security update for ignition
- SUSE-SU-2026:3316-1: important: Security update for the Linux Kernel RT (Live Patch 2 for SUSE Linux Enterprise 15 SP7)
- SUSE-SU-2026:3327-1: important: Security update for yq
- SUSE-SU-2026:3329-1: important: Security update for nginx
- SUSE-SU-2026:3330-1: moderate: Security update for libssh
- SUSE-SU-2026:3332-1: important: Security update for java-21-openjdk
- SUSE-SU-2026:3335-1: important: Security update for ImageMagick
- SUSE-SU-2026:3338-1: important: Security update for webkit2gtk3
- SUSE-SU-2026:3340-1: moderate: Security update for nmap
- SUSE-SU-2026:3341-1: important: Security update for glib2
- SUSE-SU-2026:3350-1: important: Security update for the Linux Kernel (Live Patch 42 for SUSE Linux Enterprise 15 SP5)
- SUSE-SU-2026:3351-1: important: Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise 15 SP5)
- SUSE-SU-2026:3344-1: important: Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise 15 SP6)
- SUSE-SU-2026:3345-1: important: Security update for the Linux Kernel (Live Patch 46 for SUSE Linux Enterprise 15 SP4)
- openSUSE-SU-2026:21453-1: important: Security update for chromium
- openSUSE-SU-2026:21448-1: important: Security update for agama-web-ui
- SUSE-SU-2026:3362-1: important: Security update for samba
- SUSE-SU-2026:3364-1: important: Security update for samba
- SUSE-SU-2026:3365-1: important: Security update for samba
- SUSE-SU-2026:3366-1: important: Security update for samba
- SUSE-SU-2026:3368-1: moderate: Security update for sssd
- SUSE-SU-2026:3354-1: important: Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise 15 SP4)
- SUSE-SU-2026:3372-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP7)
- SUSE-SU-2026:3398-1: important: Security update for rsyslog
- SUSE-SU-2026:3399-1: important: Security update for gimp
- openSUSE-SU-2026:0265-1: important: Security update for nsd
- SUSE-SU-2026:3395-1: low: Security update for GraphicsMagick
- SUSE-SU-2026:3396-1: important: Security update for webkit2gtk3
- SUSE-SU-2026:3397-1: moderate: Security update for python-urllib3
- SUSE-SU-2026:3402-1: important: Security update for python-ujson
- SUSE-SU-2026:3404-1: moderate: Security update for PackageKit
- SUSE-SU-2026:3406-1: important: Security update for java-17-openjdk
- SUSE-SU-2026:3407-1: important: Security update for openvpn
- SUSE-SU-2026:3409-1: important: Security update for xen
- SUSE-SU-2026:3424-1: low: Security update for python3-pyOpenSSL
- SUSE-SU-2026:3425-1: important: Security update for python-urwid
- SUSE-SU-2026:3429-1: moderate: Security update for libarchive
- SUSE-SU-2026:3430-1: important: Security update for tomcat11
- openSUSE-SU-2026:21473-1: important: Security update for apptainer
- openSUSE-SU-2026:21471-1: low: Security update for keybase-client
- openSUSE-SU-2026:21474-1: moderate: Security update for s2n
- openSUSE-SU-2026:21468-1: low: Security update for GraphicsMagick
- openSUSE-SU-2026:21467-1: important: Security update for java-25-openjdk
- openSUSE-SU-2026:21459-1: important: Security update for python313, python3
- openSUSE-SU-2026:11393-1: moderate: logcli-3.7.4-1.1 on GA media
- openSUSE-SU-2026:11392-1: moderate: kubevirt1.8-container-disk-1.8.4-3.1 on GA media
- openSUSE-SU-2026:11384-1: moderate: ffmpeg-7-7.1.5-1.1 on GA media
- openSUSE-SU-2026:11389-1: moderate: kubernetes1.34-apiserver-1.34.10-1.1 on GA media
- openSUSE-SU-2026:11391-1: moderate: kubernetes1.36-apiserver-1.36.3-1.1 on GA media
- openSUSE-SU-2026:11390-1: moderate: kubernetes1.35-apiserver-1.35.7-1.1 on GA media
- openSUSE-SU-2026:11386-1: moderate: helm-4.2.3-4.1 on GA media
- openSUSE-SU-2026:11385-1: moderate: freerdp-3.30.0-1.1 on GA media
- SUSE-SU-2026:3413-1: moderate: Security update for ImageMagick
- SUSE-SU-2026:3415-1: important: Security update for perl-DBI
- SUSE-SU-2026:3417-1: important: Security update for apptainer
- SUSE-SU-2026:3420-1: important: Security update for liboqs, oqs-provider
- SUSE-SU-2026:3422-1: important: Security update for python-sh
- SUSE-SU-2026:3423-1: important: Security update for xen
- openSUSE-SU-2026:21500-1: important: Security update for yq
- openSUSE-SU-2026:21489-1: important: Security update for bind
- openSUSE-SU-2026:21496-1: moderate: Security update for perl-Mojolicious
- openSUSE-SU-2026:21482-1: important: Security update for ignition
- openSUSE-SU-2026:21490-1: important: Security update for tomcat11
- openSUSE-SU-2026:21485-1: important: Security update for valkey
- openSUSE-SU-2026:21488-1: important: Security update for openvpn
- openSUSE-SU-2026:21483-1: important: Security update for govulncheck-vulndb
- openSUSE-SU-2026:21477-1: important: Security update for openssh
- openSUSE-SU-2026:21476-1: important: Security update for google-guest-agent
- openSUSE-SU-2026:21479-1: important: Security update for libpng16
- openSUSE-SU-2026:11400-1: moderate: tomcat10-10.1.57-1.1 on GA media
- openSUSE-SU-2026:11399-1: moderate: tomcat-9.0.120-1.1 on GA media
- openSUSE-SU-2026:11403-1: moderate: traefik2-2.11.53-1.1 on GA media
- openSUSE-SU-2026:0267-1: moderate: Security update for nano
- openSUSE-SU-2026:0268-1: moderate: Security update for kronosnet
- SUSE-SU-2026:3434-1: moderate: Security update for python-sqlparse
- SUSE-SU-2026:3435-1: moderate: Security update for python-sqlparse
- openSUSE-SU-2026:0269-1: important: Security update for python-nltk
- openSUSE-SU-2026:11411-1: moderate: dnsdist-2.0.7-1.1 on GA media
- openSUSE-SU-2026:11408-1: moderate: libblkid-devel-2.42.2-1.1 on GA media
- openSUSE-SU-2026:11406-1: moderate: PackageKit-1.3.6-1.1 on GA media
- openSUSE-SU-2026:11404-1: moderate: warewulf4-4.7.0-4.1 on GA media
- openSUSE-SU-2026:11405-1: moderate: ImageMagick-7.1.2.28-1.1 on GA media
- openSUSE-SU-2026:0272-1: Security update for keybase-client
- openSUSE-SU-2026:0271-1: important: Security update for chromium
Ubuntu Linux
Ubuntu issued a series of security notices across its long-term support releases to patch critical vulnerabilities in the Linux kernel. These patches cover specialized hardware and cloud environments including NVIDIA, IBM, Azure FIPS, Raspberry Pi, KVM, Intel IoT drivers, as well as major public cloud providers like AWS and Oracle. Additional updates resolve flaws in Glibc, Roc Toolkit, FreeIPMI, Samba, FreeRDP, Ruby-Sinatra, libinput, Python 2.7/3.5, and OpenSSL that could enable denial of service attacks or arbitrary code execution. System administrators should deploy these fixes immediately to protect their infrastructure from active exploitation attempts.
- [USN-8612-1] Roc Toolkit vulnerability
- [USN-8611-1] GNU C Library vulnerabilities
- [USN-8613-1] FreeIPMI vulnerabilities
- [USN-8621-1] Samba vulnerabilities
- [USN-8605-1] Linux kernel (Azure CVM) vulnerabilities
- [USN-8607-1] Linux kernel (Azure CVM) vulnerabilities
- [USN-8606-1] Linux kernel (Azure) vulnerabilities
- [USN-8610-1] Linux kernel (Azure CVM) vulnerabilities
- [USN-8608-1] Linux kernel (Azure FIPS) vulnerabilities
- [USN-8595-2] Linux kernel (AWS) vulnerabilities
- [USN-8575-3] Linux kernel vulnerabilities
- [USN-8609-1] Linux kernel (Azure CVM) vulnerabilities
- [USN-8604-1] Linux kernel (Azure) vulnerabilities
- [USN-8619-1] Linux kernel (HWE) vulnerabilities
- [USN-8574-3] Linux kernel vulnerabilities
- [USN-8595-3] Linux kernel (AWS) vulnerabilities
- [USN-8618-1] Linux kernel vulnerabilities
- [USN-8570-2] Linux kernel (Oracle) vulnerabilities
- [USN-8620-1] Linux kernel vulnerabilities
- [USN-8561-2] FreeRDP regression
- [USN-8623-1] Linux kernel (NVIDIA) vulnerabilities
- [USN-8622-1] Linux kernel (NVIDIA) vulnerabilities
- [USN-8615-1] Linux kernel vulnerabilities
- [USN-8616-1] Linux kernel (IBM) vulnerabilities
- [USN-8620-2] Linux kernel (Azure FIPS) vulnerabilities
- [USN-8547-2] Linux kernel (Azure FIPS) vulnerabilities
- [USN-8615-2] Linux kernel (Raspberry Pi) vulnerabilities
- [USN-8617-1] Linux kernel (KVM) vulnerabilities
- [USN-8624-1] Sinatra vulnerability
- [USN-8602-1] libinput vulnerability
- [USN-8614-1] Python vulnerabilities
- [USN-8625-1] OpenSSL vulnerability
- [USN-8620-4] Linux kernel (Intel IoTG) vulnerabilities
- [USN-8620-3] Linux kernel (Intel IoTG) vulnerabilities
How to apply these Linux security updates
Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.
Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.
Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.
Debian/Ubuntu (apt)
The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.
sudo apt update sudo apt upgrade -y
Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)
On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.
sudo dnf check-update sudo dnf upgrade -y
or on older releases
sudo yum check-update sudo yum update
SUSE (zypper)
SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.
sudo zypper refresh sudo zypper update -y
Slackware (slackpkg and pkgtool)
Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.
sudo slackpkg update sudo slackpkg upgrade-all
