Linux distributions just pushed a massive wave of security advisories covering everything from the standard kernel and Thunderbird to niche tools like stunnel and goaccess. SUSE flagged a critical WebKit2GTK3 flaw, Fedora plugged a heap overflow in goaccess while trimming memory overhead, and Debian kept ELTS systems like kernel 5.10 and OpenJDK 8 patched for legacy deployments. The heavy overlap between AlmaLinux, Oracle, Rocky, and RHEL means a single maintenance window will likely clear most server fleets, though Slackware and Debian ELTS operators need to tackle their trees first. Pull the exact advisory numbers for your release, apply the updates, and verify your services before rolling out to the next cluster.
Linux Security Roundup: Patch Tuesday Just Won't Quit This Week
From critical WebKit flaws on SUSE to heap overflows in Fedora's goaccess, the enterprise Linux ecosystem just got a massive dose of fixes.
If your server fleet has been quiet this week, it's probably time to check your package manager. Linux distributions just pushed a combined wave of security advisories that touches every major line from Slackware to Red Hat Enterprise Linux.
What stands out is not just the volume. It's the recurring cast of characters. The standard lineup of kernel updates, Thunderbird patches, Firefox refreshes, and Node.js fixes shows up on nearly every list. But this cycle brought some distinct headaches alongside the usual suspects. SUSE flagged a critical WebKit2GTK3 vulnerability. Fedora's goaccess dropped a heap overflow alongside a memory optimization. Debian is backporting fixes to kernel 5.10 on Debian 9, because ELTS distributions never actually die.
Hardly a quiet week.
The Usual Suspects (and a Few New Faces)
AlmaLinux, Oracle Linux, and Rocky Linux are all shipping overlapping advisories for their v8, v9, and v10 trees. The common thread is the .NET 8 through 10 stack, perl-DBI, and fence-agents. I remember wrestling with fence-agents on a lab cluster back in 2023, and it still shows up in these monthly rollouts. The package never really stopped being the backbone of Linux HA clusters. Oracle Linux even threw in a Bouncy Castle patch alongside GnuTLS and timezone data fixes for OL7 through OL10. If you are running Oracle's Unbreakable Enterprise Kernel, there is a separate batch just for it.
Rocky's SIG Cloud deployments got a specific callout for firmware and routing fixes. Slackware's security team kept things tight. They shipped stunnel 5.80 to close an out-of-bounds memory access when logging messages over 1,024 bytes, plus wpa_supplicant 2.12 for Wi-Fi auth gaps. Slackware moves slow. When it does move, though, you want to be right there with it.
Desktop and Server Tools Take Center Stage
Debian's advisory list is unusually long this cycle. Ruby 2.7's ERB deserialization gets patched, PowerDNS components clear up arbitrary code execution risks, and OpenJDK 8 finally gets a hardening pass on Extended Long-Term Support. Nginx and Chromium join Thunderbird in the general hardening sweep.
Fedora 43 and 44 administrators are looking at a different kind of maintenance window. The coordinated advisories hit Chromium, Samba, PHP, Erlang, Perl, and RabbitMQ. The goaccess update is worth noting specifically. It trims memory overhead, speeds up parsing, and plugs a heap overflow in one shot. Server operators running log analysis at scale will appreciate the performance bump alongside the security fix.
RHEL's rollout covers the broadest enterprise surface area. JBoss EAP 8.1.7, OpenShift Container Platform, systemd, Python 3, SSSD, and several Satellite async updates land alongside the expected kernel and Thunderbird patches. Severity ratings range from Moderate to Critical, with dedicated advisories for SAP workloads on RHEL 9.
SUSE rounded out the week with what might be the most operationally heavy batch. Critical patches for WebKit2GTK3 and PHP 7 or 8 sit alongside Django 4, Node.js 22, and OpenSSL 1.1. Nginx, BIND DNS, the Xen hypervisor, and Azure AzCopy also cleared their security gates.
Keep in mind that overlap means you can probably roll these out together. Most advisories from AlmaLinux, Oracle, Rocky, and RHEL will land cleanly in a single maintenance window. Slackware users on 15.0 and -current should grab the stunnel and wpa_supplicant updates first. Debian ELTS operators still need to watch for kernel 5.10 and 6.1 patches long after mainstream support ends.
Latest Security Updates by Distribution
Here’s a complete breakdown of the security updates for AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, and SUSE Linux.
AlmaLinux
AlmaLinux released a series of security errata covering operating system versions 8, 9, and 10. The patches resolve critical vulnerabilities in the standard and real-time Linux kernels, alongside fixes for networking and multimedia utilities. Administrators will also find patched flaws in developer tools such as Node.js, Perl modules, and .NET frameworks, plus updates for Firefox, Thunderbird, and GIMP. These advisories address memory management errors, double-free conditions, and use-after-free risks across dozens of core packages.
- ALSA-2026:49214: kernel security update (Important)
- ALSA-2026:49213: kernel-rt security update (Important)
- ALSA-2026:37282: unbound security update (Important)
- ALSA-2026:41899: .NET 9.0 security, bug fix, and enhancement update (Important)
- ALSA-2026:47736: fence-agents security update (Important)
- ALSA-2026:41901: .NET 8.0 security, bug fix, and enhancement update (Important)
- ALSA-2026:41900: .NET 10.0 security, bug fix, and enhancement update (Important)
- ALSA-2026:48225: perl:5.32 security update (Important)
- ALBA-2026:47115: coreutils bug fix and enhancement update (None)
- ALSA-2026:48021: python-pillow security update (Important)
- ALSA-2026:48790: osbuild-composer security update (Important)
- ALSA-2026:47017: kernel security, bug fix, and enhancement update (Important)
- ALSA-2026:48650: vim security update (Important)
- ALSA-2026:49514: perl-DBI security update (Important)
- ALSA-2026:49525: perl-Archive-Tar security update (Important)
- ALSA-2026:49520: ldns security update (Important)
- ALSA-2026:49524: perl-Archive-Tar security update (Important)
- ALSA-2026:49511: frr security update (Important)
- ALSA-2026:49512: mingw-glib2 security update (Important)
- ALSA-2026:49668: p11-kit security update (Moderate)
- ALSA-2026:49508: gstreamer1-plugins-good security update (Important)
- ALSA-2026:49612: perl-DBI security update (Important)
- ALSA-2026:49523: perl-Archive-Tar security update (Important)
- ALSA-2026:49927: fence-agents security update (Moderate)
- ALSA-2026:49857: kernel security, bug fix, and enhancement update (Moderate)
- ALSA-2026:49851: kernel-rt security, bug fix, and enhancement update (Moderate)
- ALSA-2026:49922: thunderbird security update (Important)
- ALSA-2026:47117: libgcrypt security update (Moderate)
- ALSA-2026:47126: resource-agents security update (Moderate)
- ALSA-2026:47177: yelp security update (Important)
- ALSA-2026:47183: compat-libtiff3 security update (Important)
- ALSA-2026:50978: kernel security, bug fix, and enhancement update (Important)
- ALSA-2026:50979: kernel-rt security, bug fix, and enhancement update (Important)
- ALSA-2026:49870: kernel security, bug fix, and enhancement update (Low)
- ALSA-2026:47058: nodejs:22 security update (Important)
- ALSA-2026:50141: sg3_utils security, bug fix, and enhancement update (Important)
- ALSA-2026:49527: frr security, bug fix, and enhancement update (Important)
- ALSA-2026:49212: kernel security update (Important)
- ALSA-2026:49667: p11-kit security update (Moderate)
- ALSA-2026:50108: ldns security update (Important)
- ALSA-2026:47178: yelp security update (Important)
- ALSA-2026:47082: pipewire security update (Important)
- ALSA-2026:49921: thunderbird security update (Important)
- ALSA-2026:47084: libXfont2 security update (Important)
- ALSA-2026:50317: fence-agents security update (Important)
- ALSA-2026:42899: java-25-openjdk security update (Important)
- ALSA-2026:47057: nodejs:24 security update (Important)
- ALSA-2026:47179: gstreamer1-plugins-bad-free security update (Important)
- ALSA-2026:50817: gimp security update (Important)
- ALSA-2026:49621: thunderbird security update (Important)
- ALSA-2026:49211: kernel security, bug fix, and enhancement update (Important)
- ALSA-2026:42899: java-25-openjdk security update (Important)
- ALSA-2026:47101: firefox security update (Important)
- ALSA-2026:49836: ldns security update (Important)
- ALSA-2026:50747: freerdp security update (Important)
- ALSA-2026:50142: sg3_utils security, bug fix, and enhancement update (Important)
- ALSA-2026:50144: libgcrypt security update (Moderate)
- ALSA-2026:49871: kernel security, bug fix, and enhancement update (Moderate)
- ALSA-2026:51105: LibRaw security update (Important)
- ALSA-2026:45192: kernel security, bug fix, and enhancement update (Important)
- ALSA-2026:51035: kernel security, bug fix, and enhancement update (Moderate)
- ALSA-2026:50147: libgcrypt security update (Moderate)
- ALSA-2026:38512: perl-DBI security update (Important)
- ALSA-2026:37435: golang security, bug fix, and enhancement update (Important)
- ALSA-2026:45116: kernel-rt security update (Important)
- ALSA-2026:45115: kernel security update (Important)
- ALSA-2026:39180: kernel-rt security update (Important)
- ALSA-2026:47105: firefox security update (Important)
- ALSA-2026:39179: kernel security update (Important)
Debian GNU/Linux
Debian administrators face a wave of security advisories targeting widely used software across current and legacy releases. Key patches address critical vulnerabilities in the Linux kernel versions 5.10 and 6.1, fixing dozens of CVEs related to privilege escalation, denial of service, and information leaks on Debian 9 through 11. Additional updates fix remote code execution risks in Ruby 2.7's ERB deserialization, DNS decompression flaws triggering denial of service, and arbitrary code execution vulnerabilities in PowerDNS components. The advisories also require immediate attention for OpenJDK 8 and Poppler on Extended Long-Term Support distributions, alongside security hardening for Nginx, Thunderbird, Chromium, and various other packages like Kissfft, Redis, and libssh.
- [DLA 4715-1] kissfft security update
- [DSA 6410-1] libssh security update
- ELA-1791-1 openjdk-8 security update (by )
- ELA-1792-1 poppler security update (by )
- [DLA 4716-1] ruby2.7 security update
- [DSA 6412-1] botan3 security update
- [DSA 6411-1] aom security update
- [DLA 4717-1] linux security update
- ELA-1793-1 linux-5.10 security update (by )
- [DLA 4720-1] linux security update
- [DLA 4719-1] p7zip security update
- [DLA 4718-1] 7zip security update
- ELA-1794-1 p7zip security update (by )
- ELA-1794-1 p7zip security update (by )
- [DSA 6413-1] libde265 security update
- [DSA 6414-1] udisks2 security update
- [DLA 4721-1] async-http-client security update
- [DSA 6415-1] linux security update
- [DSA 6416-1] jq security update
- [DLA 4722-1] redis security update
- [DLA 4724-1] linux-6.12 new package
- [DLA 4723-1] linux-6.1 security update
- ELA-1796-1 linux-6.1 security update (by )
- ELA-1795-1 redis security update (by )
- [DSA 6417-1] libheif security update
- [DSA 6418-1] thunderbird security update
- ELA-1797-1 nginx security update (by )
- [DSA 6421-1] pdns-recursor security update
- [DSA 6420-1] pdns security update
- [DSA 6419-1] dnsdist security update
- ELA-1797-1 nginx security update (by )
- [DSA 6422-1] chromium security update
- [DLA 4725-1] bind9 security update
Fedora Linux
Fedora 43 and 44 administrators received a wave of coordinated security advisories covering dozens of system packages this week. The patches address critical vulnerabilities in core software like Chromium, Samba, PHP, the Linux kernel, Python, Erlang, Perl, RabbitMQ, and several database and networking tools. Performance gains accompany some releases, with goaccess dropping memory overhead and accelerating parsing while fixing heap overflow bugs. Server operators need to apply the exact version upgrades immediately to close active security gaps and maintain stable Fedora environments.
- Fedora 43 Update: goaccess-1.11-1.fc43
- Fedora 43 Update: nsd-4.15.0-1.fc43
- Fedora 44 Update: borgbackup-1.4.5-1.fc44
- Fedora 44 Update: goaccess-1.11-1.fc44
- Fedora 43 Update: borgbackup-1.4.5-1.fc43
- Fedora 44 Update: seamonkey-2.53.24-1.fc44
- Fedora 44 Update: python-nh3-0.3.6-4.fc44
- Fedora 44 Update: rust-ammonia-4.1.4-1.fc44
- Fedora 44 Update: nebula-1.11.0-1.fc44
- Fedora 43 Update: open62541-1.5.6-1.fc43
- Fedora 43 Update: doctl-1.164.0-1.fc43
- Fedora 44 Update: kernel-7.1.6-201.fc44
- Fedora 44 Update: perl-PAR-Packer-1.064-6.fc44
- Fedora 44 Update: polymake-4.15-11.fc44
- Fedora 44 Update: perl-5.42.3-525.fc44
- Fedora 44 Update: perl-Devel-Cover-1.52-4.fc44
- Fedora 44 Update: abrt-2.17.9-1.fc44
- Fedora 44 Update: coreutils-9.10-5.fc44
- Fedora 44 Update: open62541-1.5.6-1.fc44
- Fedora 44 Update: doctl-1.164.0-1.fc44
- Fedora 44 Update: libXfont2-2.0.9-1.fc44
- Fedora 44 Update: samba-4.24.5-1.fc44
- Fedora 44 Update: freeipa-4.13.2-1.fc44
- Fedora 44 Update: chromium-151.0.7922.71-1.fc44
- Fedora 44 Update: trafficserver-10.1.4-1.fc44
- Fedora 44 Update: tcpreplay-4.6.0-2.fc44
- Fedora 43 Update: kernel-7.1.6-101.fc43
- Fedora 43 Update: chromium-151.0.7922.71-1.fc43
- Fedora 43 Update: trafficserver-10.1.4-1.fc43
- Fedora 43 Update: tcpreplay-4.6.0-2.fc43
- Fedora 43 Update: ImageMagick-7.1.2.27-1.fc43
- Fedora 43 Update: libXfont2-2.0.9-1.fc43
- Fedora 43 Update: samba-4.23.10-1.fc43
- Fedora 43 Update: freeipa-4.13.2-1.fc43
- Fedora 43 Update: curl-8.15.0-8.fc43
- Fedora 43 Update: coreutils-9.7-10.fc43
- Fedora 43 Update: abrt-2.17.9-1.fc43
- Fedora 43 Update: php-8.4.24-1.fc43
- Fedora 44 Update: gstreamer1-plugins-bad-free-1.28.6-1.fc44
- Fedora 44 Update: gstreamer1-plugins-good-1.28.6-1.fc44
- Fedora 44 Update: gstreamer1-rtsp-server-1.28.6-1.fc44
- Fedora 44 Update: gstreamer1-plugin-libav-1.28.6-1.fc44
- Fedora 44 Update: gst-editing-services-1.28.6-1.fc44
- Fedora 44 Update: python-gstreamer1-1.28.6-1.fc44
- Fedora 44 Update: gst-devtools-1.28.6-1.fc44
- Fedora 44 Update: gstreamer1-plugins-ugly-free-1.28.6-1.fc44
- Fedora 44 Update: gstreamer1-plugins-base-1.28.6-1.fc44
- Fedora 44 Update: gstreamer1-doc-1.28.6-1.fc44
- Fedora 44 Update: gstreamer1-1.28.6-1.fc44
- Fedora 44 Update: udisks2-2.11.2-1.fc44
- Fedora 44 Update: kernel-7.1.7-200.fc44
- Fedora 44 Update: p11-kit-0.26.5-1.fc44
- Fedora 44 Update: erlang-26.2.5.21-5.fc44
- Fedora 44 Update: mingw-glib2-2.88.3-1.fc44
- Fedora 43 Update: kernel-7.1.7-100.fc43
- Fedora 43 Update: perl-PAR-Packer-1.064-5.fc43
- Fedora 43 Update: polymake-4.15-6.fc43
- Fedora 43 Update: perl-5.42.3-524.fc43
- Fedora 43 Update: perl-Devel-Cover-1.51-4.fc43
- Fedora 43 Update: seamonkey-2.53.24-1.fc43
- Fedora 43 Update: erlang-26.2.5.21-5.fc43
- Fedora 43 Update: python3.12-3.12.13-6.fc43
- Fedora 43 Update: rabbitmq-server-4.0.9-5.fc43
- Fedora 43 Update: python-nh3-0.2.21-9.fc43
- Fedora 43 Update: rust-ammonia-4.1.4-1.fc43
- Fedora 43 Update: udisks2-2.11.2-1.fc43
- Fedora 43 Update: pgadmin4-9.17-1.fc43
- Fedora 43 Update: bird-3.3.2-1.fc43
- Fedora 44 Update: nghttp2-1.68.0-5.fc44
- Fedora 44 Update: pgadmin4-9.17-1.fc44
- Fedora 44 Update: bird-3.3.2-1.fc44
Oracle Linux
Oracle Linux administrators must apply multiple ELSA and ELBA patch batches released for versions 7 through 10 to close dozens of security vulnerabilities and resolve runtime issues. The updates target the Unbreakable Enterprise Kernel, Firefox, Thunderbird, Node.js, PHP, Perl, Java, GnuTLS, and Bouncy Castle across both x86_64 and aarch64 systems. These advisories address memory corruption flaws, networking stack weaknesses, hypervisor bugs, and timezone data errors while delivering standard performance enhancements.
- ELSA-2026-49668 Moderate: Oracle Linux 10 p11-kit security update
- ELSA-2026-49523 Important: Oracle Linux 10 perl-Archive-Tar security update
- ELSA-2026-49514 Important: Oracle Linux 10 perl-DBI security update
- ELSA-2026-49508 Important: Oracle Linux 10 gstreamer1-plugins-good security update
- ELSA-2026-48170 Low: Oracle Linux 10 php security, bug fix, and enhancement update
- ELSA-2026-49525 Important: Oracle Linux 9 perl-Archive-Tar security update
- ELSA-2026-49612 Important: Oracle Linux 9 perl-DBI security update
- ELSA-2026-49527 Important: Oracle Linux 9 frr security, bug fix, and enhancement update
- ELSA-2026-46397 Important: Oracle Linux 9 libreswan security update
- ELBA-2026-500114 Oracle Linux 9 scap-security-guide bug fix update
- ELSA-2026-41948 Important: Oracle Linux 8 javapackages-tools:201801 security update
- ELSA-2026-47060 Important: Oracle Linux 8 nodejs:24 security update
- ELSA-2026-47059 Important: Oracle Linux 8 nodejs:22 security update
- ELSA-2026-43218 Important: Oracle Linux 8 pki-deps:10.6 security update
- ELBA-2026-47116 Oracle Linux 8 xfsdump bug fix and enhancement update
- ELBA-2026-47120 Oracle Linux 8 fence-agents bug fix and enhancement update
- ELBA-2026-47175 Oracle Linux 8 grubby bug fix and enhancement update
- ELSA-2026-24992 Important: Oracle Linux 7 compat-libtiff3 security update
- ELSA-2026-24342 Moderate: Oracle Linux 7 python-tornado security update
- ELSA-2026-49621 Important: Oracle Linux 10 thunderbird security update
- ELSA-2026-48033 Important: Oracle Linux 10 nodejs22 security update
- ELSA-2026-48032 Important: Oracle Linux 10 nodejs-nodemon security update
- ELSA-2026-47101 Important: Oracle Linux 10 firefox security update
- ELSA-2026-35842 Important: Oracle Linux 10 nodejs22 security, bug fix, and enhancement update
- ELSA-2026-23329 Important: Oracle Linux 10 kernel security update
- ELBA-2026-42741 Oracle Linux 9 tuned bug fix and enhancement update
- ELSA-2026-49524 Important: Oracle Linux 8 perl-Archive-Tar security update
- ELSA-2026-47750 Low: Oracle Linux 8 php:7.4 security, bug fix, and enhancement update
- ELSA-2026-49511 Important: Oracle Linux 8 frr security update
- ELSA-2026-47749 Low: Oracle Linux 8 php:8.2 security, bug fix, and enhancement update
- ELSA-2026-46396 Important: Oracle Linux 8 libreswan security update
- ELBA-2026-500115 Oracle Linux 8 glibc bug fix update
- ELBA-2026-500114 Oracle Linux 8 scap-security-guide bug fix update
- ELSA-2026-500121 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
- ELSA-2026-25172 Important: Oracle Linux 7 rsync security update
- ELBA-2026-500116 Oracle Linux 7 linux-firmware bug fix update
- ELBA-2026-20539 Oracle Linux 7 tzdata bug fix and enhancement update
- ELSA-2026-49838 Important: Oracle Linux 9 osbuild-composer security, bug fix, and enhancement update
- ELSA-2026-50108-0 Important: Oracle Linux 9 ldns security update
- ELSA-2026-49214 Important: Oracle Linux 8 kernel security update
- ELSA-2026-49921 Important: Oracle Linux 9 thunderbird security update
- ELSA-2026-500121 Important: Oracle Linux 7 Unbreakable Enterprise kernel security update
- ELSA-2026-49520 Important: Oracle Linux 8 ldns security update
- ELSA-2026-49927 Moderate: Oracle Linux 8 fence-agents security update
- ELSA-2026-49512 Important: Oracle Linux 8 mingw-glib2 security update
- ELSA-2026-49922 Important: Oracle Linux 8 thunderbird security update
- ELBA-2026-48843 Oracle Linux 8 fwupd bug fix and enhancement update
- ELBA-2026-48830 Oracle Linux 8 libxmlb bug fix and enhancement update
- ELSA-2026-50141-0 Important: Oracle Linux 9 sg3_utils security, bug fix, and enhancement update
- ELSA-2026-49667 Moderate: Oracle Linux 9 p11-kit security update
- ELSA-2026-500121 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
- ELSA-2026-50147-0 Moderate: Oracle Linux 9 libgcrypt security update
- ELSA-2026-50317-0 Important: Oracle Linux 9 fence-agents security update
- ELBA-2026-50153-0 Oracle Linux 10 rust-bootupd bug fix and enhancement update
- ELBA-2026-500126 Oracle Linux 10 kdump-utils bug fix update
- ELBA-2026-50138-0 Oracle Linux 9 conmon bug fix and enhancement update
- ELBA-2026-500128 Oracle Linux 10 osbuild bug fix update
- ELBA-2026-26196 Oracle Linux 9 openscap bug fix and enhancement update
- ELSA-2026-49211 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
- ELBA-2026-50135-0 Oracle Linux 10 policycoreutils bug fix and enhancement update
- ELBA-2026-500091 Oracle Linux 9 oracle-database-preinstall-19c bug fix update
- ELBA-2026-50166-0 Oracle Linux 9 linuxptp bug fix and enhancement update
- ELSA-2026-50142-0 Important: Oracle Linux 10 sg3_utils security, bug fix, and enhancement update
- ELSA-2026-49607 Important: Oracle Linux 9 frr10 security, bug fix, and enhancement update
- ELSA-2026-49212 Important: Oracle Linux 9 kernel security update
- ELSA-2026-42899 Important: Oracle Linux 9 java-25-openjdk security update
- ELBA-2026-50136-0 Oracle Linux 9 gnutls bug fix and enhancement update
- ELBA-2026-50150-0 Oracle Linux 9 rust-bootupd bug fix and enhancement update
- ELBA-2026-50159-0 Oracle Linux 9 keylime bug fix and enhancement update
- ELSA-2026-49836 Important: Oracle Linux 10 ldns security update
- ELBA-2026-49518 Oracle Linux 9 glibc bug fix and enhancement update
- ELBA-2026-50133-0 Oracle Linux 9 autofs bug fix and enhancement update
- ELBA-2026-50171-0 Oracle Linux 10 gdm bug fix and enhancement update
- ELSA-2026-48034 Important: Oracle Linux 10 nodejs24 security update
- ELSA-2026-50144-0 Moderate: Oracle Linux 10 libgcrypt security update
- ELSA-2026-49914 Low: Oracle Linux 10 php8.4 security, bug fix, and enhancement update
- ELSA-2026-49870 Low: Oracle Linux 9 kernel security, bug fix, and enhancement update
- ELBA-2026-50168-0 Oracle Linux 9 firewalld bug fix and enhancement update
- ELBA-2026-50173-0 Oracle Linux 9 egl-wayland bug fix and enhancement update
- ELBA-2026-50174-0 Oracle Linux 9 NetworkManager bug fix and enhancement update
- ELBA-2026-50177-0 Oracle Linux 9 passt bug fix and enhancement update
- ELBA-2026-500095 Oracle Linux 8 oVirt 4.5 ovirt-log-collector bug fix update
- ELBA-2026-45115-1 Oracle Linux 8 kernel bug fix update
- ELSA-2026-49857 Moderate: Oracle Linux 8 kernel security, bug fix, and enhancement update
- ELBA-2026-500090 Oracle Linux 8 oracle-database-preinstall-19c bug fix update
- ELBA-2026-50178-0 Oracle Linux 10 passt bug fix and enhancement update
- ELBA-2026-50161-0 Oracle Linux 10 virt-v2v bug fix and enhancement update
- ELSA-2026-50817 Important: Oracle Linux 9 gimp security update
- ELBA-2026-50158-0 Oracle Linux 10 httpd bug fix and enhancement update
- ELBA-2026-50169-0 Oracle Linux 10 NetworkManager bug fix and enhancement update
- ELBA-2026-50163-0 Oracle Linux 10 libguestfs bug fix and enhancement update
- ELSA-2026-50747 Important: Oracle Linux 10 freerdp security update
- ELSA-2026-27288 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
- ELSA-2026-22714 Important: Oracle Linux 9 osbuild-composer security update
- ELSA-2026-500135 Important: Unbreakable Enterprise kernel security update
- ELSA-2026-51075 Important: Oracle Linux 10 gpsd security update
- ELSA-2026-500135 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
- ELSA-2026-500137 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
- ELSA-2026-500137 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
- ELSA-2026-500137 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
- ELSA-2026-500136 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
- ELSA-2026-500136 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
- ELSA-2026-500136 Important: Oracle Linux 7 Unbreakable Enterprise kernel security update
- New Ksplice updates for UEKR6 5.4.17 on OL7 and OL8 (ELSA-2026-500136)
- New Ksplice updates for RHCK 9 (ELSA-2026-19225)
- ELSA-2026-49871 Moderate: Oracle Linux 10 kernel security, bug fix, and enhancement update
- ELSA-2026-30129 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
- ELBA-2026-51069 Oracle Linux 10 tzdata bug fix and enhancement update
- ELSA-2026-51105 Important: Oracle Linux 9 LibRaw security update
- ELSA-2026-51035 Moderate: Oracle Linux 9 kernel security, bug fix, and enhancement update
- ELBA-2026-51069 Oracle Linux 9 tzdata bug fix and enhancement update
- ELBA-2026-50156-0 Oracle Linux 9 linux-firmware bug fix and enhancement update
- ELSA-2026-50978 Important: Oracle Linux 8 kernel security, bug fix, and enhancement update
- ELBA-2026-51069 Oracle Linux 8 tzdata bug fix and enhancement update
- ELSA-2026-34372 Important: Oracle Linux 7 gnutls security update
Red Hat Enterprise Linux
Red Hat Product Security issued a series of RHSA advisories in 2026 to patch vulnerabilities across Red Hat Enterprise Linux versions 7 through 10. The releases cover dozens of widely used infrastructure and development tools, including the kernel, systemd, Python, JBoss EAP, Thunderbird, and OpenShift. Severity ratings for the identified flaws span from Moderate to Critical, with several advisories targeting specialized environments like SAP workloads on RHEL 9.
- RHSA-2026:49523: Important: perl-Archive-Tar security update
- RHSA-2026:49525: Important: perl-Archive-Tar security update
- RHSA-2026:49514: Important: perl-DBI security update
- RHSA-2026:49524: Important: perl-Archive-Tar security update
- RHSA-2026:49513: Important: dovecot security update
- RHSA-2026:49519: Important: tigervnc security update
- RHSA-2026:49508: Important: gstreamer1-plugins-good security update
- RHSA-2026:49509: Important: rhc security update
- RHSA-2026:49512: Important: mingw-glib2 security update
- RHSA-2026:49715: Important: RHEL AI 3.5 RPM runtime CVE fix - thrift
- RHSA-2026:49703: Important: delve security, bug fix, and enhancement update
- RHSA-2026:49700: Important: Red Hat JBoss Enterprise Application Platform 8.1.7 security update
- RHSA-2026:49668: Moderate: p11-kit security update
- RHSA-2026:49671: Important: libtiff security, bug fix, and enhancement update
- RHSA-2026:48959: Important: hplip security update
- RHSA-2026:48960: Important: hplip security update
- RHSA-2026:48961: Important: hplip security update
- RHSA-2026:49666: Important: libyang security update
- RHSA-2026:49621: Important: thunderbird security update
- RHSA-2026:49612: Important: perl-DBI security update
- RHSA-2026:49607: Important: frr10 security, bug fix, and enhancement update
- RHSA-2026:49608: Important: xorg-x11-server security update
- RHSA-2026:49606: Important: xorg-x11-server security update
- RHSA-2026:49605: Important: xorg-x11-server security update
- RHSA-2026:49604: Important: gstreamer1-plugins-good security update
- RHSA-2026:49603: Important: gstreamer1-plugins-good security update
- RHSA-2026:49602: Important: gstreamer1-plugins-good security update
- RHSA-2026:47057: Important: nodejs:24 security update
- RHSA-2026:47084: Important: libXfont2 security update
- RHSA-2026:47058: Important: nodejs:22 security update
- RHSA-2026:47082: Important: pipewire security update
- RHSA-2026:47178: Important: yelp security update
- RHSA-2026:47179: Important: gstreamer1-plugins-bad-free security update
- RHSA-2026:47104: Important: firefox security update
- RHSA-2026:47177: Important: yelp security update
- RHSA-2026:47183: Important: compat-libtiff3 security update
- RHSA-2026:47184: Important: libtiff security update
- RHSA-2026:49600: Important: rhc security update
- RHSA-2026:49527: Important: frr security, bug fix, and enhancement update
- RHSA-2026:49520: Important: ldns security update
- RHSA-2026:49526: Important: osbuild-composer security update
- RHSA-2026:49521: Important: postgresql security update
- RHSA-2026:49517: Important: gstreamer-plugins-bad-free security update
- RHSA-2026:49516: Important: xorg-x11-server security update
- RHSA-2026:49522: Important: mariadb10.11 security update
- RHSA-2026:49511: Important: frr security update
- RHSA-2026:49515: Important: xorg-x11-server security update
- RHSA-2026:49871: Moderate: kernel security, bug fix, and enhancement update
- RHSA-2026:49839: Important: sssd security update
- RHSA-2026:49843: Important: sssd security update
- RHSA-2026:49840: Important: sssd security update
- RHSA-2026:49851: Moderate: kernel-rt security, bug fix, and enhancement update
- RHSA-2026:49842: Important: sssd security update
- RHSA-2026:49844: Important: sssd security update
- RHSA-2026:49841: Important: sssd security update
- RHSA-2026:49836: Important: ldns security update
- RHSA-2026:49775: Moderate: libsolv security update
- RHSA-2026:49758: Critical: perl-GD security update
- RHSA-2026:49716: Important: RHEL AI 3.4 RPM runtime CVE fix - thrift
- RHSA-2026:49701: Important: Red Hat JBoss Enterprise Application Platform 8.1.7 security update
- RHSA-2026:49667: Moderate: p11-kit security update
- RHSA-2026:49908: Important: libpq security update
- RHSA-2026:49870: Low: kernel security, bug fix, and enhancement update
- RHSA-2026:50077: Moderate: systemd security update
- RHSA-2026:50065: Important: python3 security update
- RHSA-2026:50050: Moderate: systemd security update
- RHSA-2026:49944: Important: container-tools:rhel8 security, bug fix, and enhancement update
- RHSA-2026:49922: Important: thunderbird security update
- RHSA-2026:49910: Moderate: systemd security, bug fix, and enhancement update
- RHSA-2026:49909: Important: libpq security update
- RHSA-2026:49911: Important: fence-agents security update
- RHSA-2026:49857: Moderate: kernel security, bug fix, and enhancement update
- RHSA-2026:49838: Important: osbuild-composer security, bug fix, and enhancement update
- RHSA-2026:50538: Important: mod_http2 security update
- RHSA-2026:50317: Important: fence-agents security update
- RHSA-2026:50147: Moderate: libgcrypt security update
- RHSA-2026:50141: Important: sg3_utils security, bug fix, and enhancement update
- RHSA-2026:50144: Moderate: libgcrypt security update
- RHSA-2026:50142: Important: sg3_utils security, bug fix, and enhancement update
- RHSA-2026:50336: Important: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update
- RHSA-2026:50319: Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
- RHSA-2026:50262: Important: perl:5.32 security update
- RHSA-2026:50318: Important: Red Hat Ansible Automation Platform 2.7 Product Security and Bug Fix Update
- RHSA-2026:50117: Important: xorg-x11-server security update
- RHSA-2026:50108: Important: ldns security update
- RHSA-2026:50119: Important: postgresql security update
- RHSA-2026:50116: Important: xorg-x11-server security update
- RHSA-2026:50109: Important: sssd security update
- RHSA-2026:50263: Important: Satellite 6.18.8 Async Update
- RHSA-2026:50223: Important: Satellite 6.16.12 Async Update
- RHSA-2026:50222: Important: Satellite 6.17.10 Async Update
- RHSA-2026:50221: Important: Satellite 6.19.3 Async Update
- RHSA-2026:50100: Important: xorg-x11-server-Xwayland security update
- RHSA-2026:50085: Important: Red Hat JBoss Enterprise Application Platform 8.1.7.1 XP 6.0.5.1 release
- RHSA-2026:50064: Important: python3 security update
- RHSA-2026:50051: Moderate: systemd security update
- RHSA-2026:49927: Moderate: fence-agents security update
- RHSA-2026:49921: Important: thunderbird security update
- RHSA-2026:50817: Important: gimp security update
- RHSA-2026:50816: Important: python3 security update
- RHSA-2026:50808: Moderate: libpng security update
- RHSA-2026:49951: Moderate: Red Hat JBoss Web Server 7.0.1 release and security update
- RHSA-2026:50774: Important: libtiff security update
- RHSA-2026:50779: Important: libpq security update
- RHSA-2026:50771: Important: python3.12 security update
- RHSA-2026:50772: Moderate: freeipmi security update
- RHSA-2026:50718: Important: xorg-x11-server-Xwayland security update
- RHSA-2026:50691: Moderate: gstreamer1-plugins-ugly-free security update
- RHSA-2026:50655: Important: fence-agents security update
- RHSA-2026:50688: Moderate: gstreamer1-plugins-ugly-free security update
- RHSA-2026:50654: Important: fence-agents security update
- RHSA-2026:50653: Important: fence-agents security update
- RHSA-2026:50572: Important: mod_http2 security update
- RHSA-2026:50849: Important: Red Hat build of Keycloak 26.6.5 Images Security Update
- RHSA-2026:50847: Important: Red Hat build of Keycloak 26.4.14 Images Security Update
- RHSA-2026:50846: Important: Red Hat build of Keycloak 26.4.14 Security Update
- RHSA-2026:50848: Important: Red Hat build of Keycloak 26.6.5 Security Update
- RHSA-2026:50978: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:50964: Important: postfix security update
- RHSA-2026:50963: Important: postfix security update
- RHSA-2026:50863: Important: libpq security update
- RHSA-2026:50811: Important: postgresql security update
- RHSA-2026:49952: Moderate: Red Hat JBoss Web Server 7.0.1 release and security update
- RHSA-2026:50770: Important: python3.12 security update
- RHSA-2026:50769: Moderate: freeipmi security update
- RHSA-2026:50747: Important: freerdp security update
- RHSA-2026:50729: Moderate: freeipmi security update
- RHSA-2026:50979: Important: kernel-rt security, bug fix, and enhancement update
- RHSA-2026:51045: Moderate: fence-agents security update
- RHSA-2026:51062: Important: libXfont2 security update
- RHSA-2026:51060: Important: libXfont2 security update
- RHSA-2026:51061: Important: libXfont2 security update
- RHSA-2026:51035: Moderate: kernel security, bug fix, and enhancement update
- RHSA-2026:47702: Important: OpenShift Container Platform 4.12.95 bug fix and security update
- RHSA-2026:51034: Important: postfix security update
- RHSA-2026:51075: Important: gpsd security update
- RHSA-2026:51063: Important: libXfont2 security update
- RHSA-2026:51146: Important: RHEL AI 3.4 RPM runtime CVE fix - aom
- RHSA-2026:47727: Important: OpenShift Container Platform 4.17.56 bug fix and security update
- RHSA-2026:51180: Important: Backport fixes for CVE-2026-64835 and CVE-2026-58049
- RHSA-2026:51112: Important: grafana security update
- RHSA-2026:51152: Moderate: fence-agents security update
- RHSA-2026:51182: Important: glib2 security update
- RHSA-2026:51187: Important: yggdrasil security update
- RHSA-2026:51176: Important: glib2 security update
- RHSA-2026:51181: Important: glib2 security update
- RHSA-2026:51184: Important: glib2 security update
- RHSA-2026:51105: Important: LibRaw security update
- RHSA-2026:51157: Moderate: fence-agents security update
- RHSA-2026:51134: Moderate: systemd security, bug fix, and enhancement update
- RHSA-2026:51100: Important: RHEL AI 3.3 RPM runtime CVE fix - aom
- RHSA-2026:51059: Important: libXfont2 security update
- RHSA-2026:51066: Important: libXfont2 security update
- RHSA-2026:51067: Important: libXfont2 security update
- RHSA-2026:51058: Important: libXfont2 security update
- RHSA-2026:51064: Important: pipewire security update
- RHSA-2026:51436: Important: postfix security update
- RHSA-2026:51295: Moderate: kernel security, bug fix, and enhancement update
- RHSA-2026:51368: Important: libyang security update
- RHSA-2026:51351: Important: libyang security update
- RHSA-2026:51339: Important: libyang security update
- RHSA-2026:51277: Moderate: systemd security, bug fix, and enhancement update
- RHSA-2026:51175: Important: glib2 security update
- RHSA-2026:51358: Important: RHEL AI 3.6 RPM runtime CVE fix - thrift
- RHSA-2026:51288: Important: container-tools:rhel8 security update
- RHSA-2026:51153: Important: gpsd-minimal security update
- RHSA-2026:51177: Important: glib2 security update
- RHSA-2026:51185: Important: glib2 security update
- RHSA-2026:51183: Important: glib2 security update
- RHSA-2026:51603: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:51604: Important: kernel-rt security, bug fix, and enhancement update
- RHSA-2026:51746: Important: kernel security, bug fix, and enhancement update
Rocky Linux
Rocky Linux published a series of security advisories for versions 8, 9, and 10 to patch confirmed vulnerabilities across Node.js, Firefox, PipeWire, the Linux kernel, Perl, Thunderbird, and libgcrypt. The errata address both high-priority and moderate severity issues, including specialized firmware and routing fixes for SIG Cloud deployments. System administrators should install these packages immediately to close active vulnerability windows and preserve production server stability.
- RLSA-2026:47058: Important: nodejs:22 security update
- RLSA-2026:47057: Important: nodejs:24 security update
- RLSA-2026:47104: Important: firefox security update
- RLSA-2026:47082: Important: pipewire security update
- RLSA-2026:47084: Important: libXfont2 security update
- RLSA-2026:47178: Important: yelp security update
- RLSA-2026:47179: Important: gstreamer1-plugins-bad-free security update
- RLSA-2026:47184: Important: libtiff security update
- RLSA-2026:47183: Important: compat-libtiff3 security update
- RLSA-2026:47177: Important: yelp security update
- RLSA-2023:2771: Moderate: unbound security and bug fix update
- RLSA-2026:49514: Important: perl-DBI security update
- RLSA-2026:49523: Important: perl-Archive-Tar security update
- RLSA-2026:49526: Important: osbuild-composer security update
- RLSA-2026:49668: Moderate: p11-kit security update
- RLSA-2026:49508: Important: gstreamer1-plugins-good security update
- RLSA-2026:49527: Important: frr security, bug fix, and enhancement update
- RLSA-2026:49612: Important: perl-DBI security update
- RLSA-2026:49667: Moderate: p11-kit security update
- RLSA-2026:49607: Important: frr10 security, bug fix, and enhancement update
- RLSA-2026:49525: Important: perl-Archive-Tar security update
- RLSA-2026:49512: Important: mingw-glib2 security update
- RLSA-2026:49213: Important: kernel-rt security update
- RLSA-2026:49520: Important: ldns security update
- RLSA-2026:49511: Important: frr security update
- RLSA-2026:49524: Important: perl-Archive-Tar security update
- RLSA-2026:49214: Important: kernel security update
- RXSA-2026:49857: Moderate: kernel security, bug fix, and enhancement update
- RXSA-2026:49870: Low: kernel security, bug fix, and enhancement update
- RLSA-2026:50142: Important: sg3_utils security, bug fix, and enhancement update
- RLSA-2026:50747: Important: freerdp security update
- RLSA-2026:50144: Moderate: libgcrypt security update
- RLSA-2026:49621: Important: thunderbird security update
- RLSA-2026:49836: Important: ldns security update
- RLSA-2026:49871: Moderate: kernel security, bug fix, and enhancement update
- RLSA-2026:50141: Important: sg3_utils security, bug fix, and enhancement update
- RLSA-2026:49838: Important: osbuild-composer security, bug fix, and enhancement update
- RLSA-2026:49870: Low: kernel security, bug fix, and enhancement update
- RLSA-2026:50317: Important: fence-agents security update
- RLSA-2026:50108: Important: ldns security update
- RLSA-2026:50147: Moderate: libgcrypt security update
- RLSA-2026:49921: Important: thunderbird security update
- RLSA-2026:49851: Moderate: kernel-rt security, bug fix, and enhancement update
- RLSA-2026:49927: Moderate: fence-agents security update
- RLSA-2026:49922: Important: thunderbird security update
- RLSA-2026:49857: Moderate: kernel security, bug fix, and enhancement update
- RXSA-2026:51035: Moderate: kernel security, bug fix, and enhancement update
- RXSA-2026:50978: Important: kernel security, bug fix, and enhancement update
- RLEA-2023:7117: Important:microcode_ctl bug fix and enhancement update
- RLSA-2026:51105: Important: LibRaw security update
- RLSA-2026:51075: Important: gpsd security update
- RLSA-2026:51153: Important: gpsd-minimal security update
- RLSA-2026:50979: Important: kernel-rt security, bug fix, and enhancement update
- RLSA-2026:50978: Important: kernel security, bug fix, and enhancement update
- RLSA-2026:51295: Moderate: kernel security, bug fix, and enhancement update
- RLSA-2026:51035: Moderate: kernel security, bug fix, and enhancement update
Slackware Linux
The Slackware Linux Security Team issued security updates for stunnel, p11-kit, libXfont2, and wpa_supplicant for Slackware 15.0 and the -current branch. Stunnel now ships as version 5.80 to correct an out-of-bounds memory access vulnerability that activates when logging protocol messages exceeding 1,024 bytes. Patches for p11-kit and libXfont2 appear under advisory SSA:2026-218 to fix critical flaws, and wpa_supplicant received version 2.12 builds to close multiple Wi-Fi authentication gaps.
- stunnel (SSA:2026-216-01)
- p11-kit (SSA:2026-218-02)
- libXfont2 (SSA:2026-218-01)
- wpa_supplicant (SSA:2026-220-01)
SUSE Linux
SUSE issued a series of security advisories covering critical, important, and moderate vulnerabilities across its repositories for SUSE Linux Enterprise Server 15 and openSUSE Leap 15. The patches prioritize a critical flaw in WebKit2GTK3 while delivering updates for OpenSSL 1.1, Nginx, BIND DNS, and the Xen hypervisor to harden infrastructure components. Application layer releases include Python 3.10 and 3.13, PHP 8.5, Node.js 22, and Django 4 to address issues in development environments and running services. Maintenance tools such as Wireshark, Vim, FFmpeg, and Azure AzCopy also received fixes for secure operations in production settings.
- openSUSE-SU-2026:21508-1: important: Security update for webkit2gtk3
- openSUSE-SU-2026:21509-1: moderate: Security update for warewulf4
- openSUSE-SU-2026:11419-1: moderate: python313-GitPython-3.1.56-1.1 on GA media
- openSUSE-SU-2026:11422-1: moderate: python313-huggingface-hub-1.26.0-1.1 on GA media
- openSUSE-SU-2026:11418-1: moderate: php8-8.5.9-1.1 on GA media
- openSUSE-SU-2026:11420-1: moderate: python313-asteval-1.0.9-1.1 on GA media
- openSUSE-SU-2026:11417-1: moderate: libntpc1-1.2.5-1.1 on GA media
- openSUSE-SU-2026:11421-1: moderate: python313-certifi-2026.7.22-1.1 on GA media
- openSUSE-SU-2026:11416-1: moderate: gdk-pixbuf-loader-libheif-1.23.1-1.1 on GA media
- openSUSE-SU-2026:11415-1: moderate: gio-branding-upstream-2.88.3-1.1 on GA media
- SUSE-SU-2026:3448-1: important: Security update for nginx
- SUSE-SU-2026:3452-1: important: Security update for bind
- SUSE-SU-2026:3457-1: important: Security update for openssl-1_1
- SUSE-SU-2026:3458-1: important: Security update for vim
- SUSE-SU-2026:3459-1: important: Security update for python3-dulwich
- openSUSE-SU-2026:11424-1: moderate: python313-pydantic-2.13.4-2.1 on GA media
- openSUSE-SU-2026:11433-1: moderate: ImageMagick-7.1.2.28-2.1 on GA media
- openSUSE-SU-2026:11428-1: moderate: python312-3.12.13-8.1 on GA media
- openSUSE-SU-2026:11425-1: moderate: python313-sentry-sdk-2.66.1-1.1 on GA media
- SUSE-SU-2026:3441-1: important: Security update for GraphicsMagick
- SUSE-SU-2026:3442-1: important: Security update for rsyslog
- SUSE-SU-2026:3462-1: important: Security update for xen
- SUSE-SU-2026:3463-1: moderate: Security update for libssh
- SUSE-SU-2026:3483-1: important: Security update for valkey
- SUSE-SU-2026:3485-1: important: Security update for spice-vdagent
- SUSE-SU-2026:3486-1: moderate: Security update for openssl-3
- SUSE-SU-2026:3488-1: important: Security update for openssl-1_1
- SUSE-SU-2026:3489-1: moderate: Security update for multipath-tools
- SUSE-SU-2026:3490-1: low: Security update for wpa_supplicant
- SUSE-SU-2026:3491-1: moderate: Security update for libgcrypt
- SUSE-SU-2026:3492-1: moderate: Security update for alsa
- SUSE-SU-2026:3493-1: important: Security update for libpng16
- openSUSE-SU-2026:21518-1: important: Security update for python-ujson
- openSUSE-SU-2026:21516-1: important: Security update for python-sh
- openSUSE-SU-2026:21522-1: important: Security update for ffmpeg-4
- openSUSE-SU-2026:11436-1: moderate: golang-github-prometheus-prometheus-3.13.2-1.1 on GA media
- openSUSE-SU-2026:11438-1: moderate: alloy-1.18.0-1.1 on GA media
- openSUSE-SU-2026:11437-1: moderate: podman-6.0.2-1.1 on GA media
- openSUSE-SU-2026:11434-1: moderate: chromedriver-151.0.7922.71-1.1 on GA media
- openSUSE-SU-2026:11440-1: moderate: nodejs26-26.5.1-1.1 on GA media
- openSUSE-SU-2026:11439-1: moderate: corepack24-24.18.1-1.1 on GA media
- openSUSE-SU-2026:11441-1: moderate: xen-4.22.0_02-1.1 on GA media
- SUSE-SU-2026:3468-1: important: Security update for rrdtool
- SUSE-SU-2026:3469-1: important: Security update for nginx
- SUSE-SU-2026:3470-1: important: Security update for spice-vdagent
- SUSE-SU-2026:3474-1: moderate: Security update for s390-tools
- SUSE-SU-2026:3475-1: moderate: Security update for s390-tools
- SUSE-SU-2026:3476-1: important: Security update for bind
- SUSE-SU-2026:3477-1: important: Security update for bind
- openSUSE-SU-2026:0275-1: important: Security update for thrift
- openSUSE-SU-2026:0274-1: important: Security update for perl-HTTP-Tiny
- openSUSE-SU-2026:0273-1: important: Security update for perl-YAML-Syck
- openSUSE-SU-2026:21524-1: important: Security update for nginx
- openSUSE-SU-2026:21526-1: important: Security update for python-httplib2
- openSUSE-SU-2026:21525-1: important: Security update for rrdtool
- openSUSE-SU-2026:0277-1: important: Security update for python-nltk
- openSUSE-SU-2026:0276-1: important: Security update for vifm
- SUSE-SU-2026:3502-1: important: Security update for openssl-3
- SUSE-SU-2026:3503-1: critical: Security update for python-Django
- SUSE-SU-2026:3505-1: critical: Security update for pcp
- SUSE-SU-2026:3506-1: critical: Security update for pcp
- SUSE-SU-2026:3507-1: critical: Security update for pcp
- SUSE-SU-2026:3510-1: critical: Security update for php7
- SUSE-SU-2026:3512-1: moderate: Security update for evince
- SUSE-SU-2026:3513-1: critical: Security update for php8
- SUSE-SU-2026:3514-1: critical: Security update for php8
- openSUSE-SU-2026:21535-1: important: Security update for rsyslog
- openSUSE-SU-2026:21534-1: important: Security update for wireshark
- openSUSE-SU-2026:21533-1: important: Security update for dnsdist
- openSUSE-SU-2026:21532-1: critical: Security update for php8
- openSUSE-SU-2026:11445-1: moderate: bouncycastle-1.85-1.1 on GA media
- openSUSE-SU-2026:11450-1: moderate: perl-Mojo-JWT-1.20.0-2.1 on GA media
- openSUSE-SU-2026:11448-1: moderate: ffmpeg-4-4.4.8-3.1 on GA media
- openSUSE-SU-2026:11446-1: moderate: cockpit-repos-4.9-1.1 on GA media
- openSUSE-SU-2026:11447-1: moderate: cockpit-subscriptions-16.3-1.1 on GA media
- openSUSE-SU-2026:11442-1: moderate: OpenImageIO-3.1.16.0-1.1 on GA media
- openSUSE-SU-2026:11444-1: moderate: azure-storage-azcopy-10.32.6-1.1 on GA media
- openSUSE-SU-2026:11443-1: moderate: amazon-ecs-init-1.106.0-1.1 on GA media
- SUSE-SU-2026:3515-1: important: Security update for openssl-1_1
- SUSE-SU-2026:3516-1: important: Security update for openssl-3
- SUSE-SU-2026:3518-1: important: Security update for rsyslog
- SUSE-SU-2026:3521-1: important: Security update for nodejs22
- openSUSE-SU-2026:0278-1: moderate: Security update for perl-Mojolicious
- openSUSE-SU-2026:11460-1: moderate: libwireshark19-4.6.7-3.1 on GA media
- openSUSE-SU-2026:11461-1: moderate: fuse-overlayfs-1.17-1.1 on GA media
- openSUSE-SU-2026:11454-1: moderate: libssh2-1-1.11.1-4.1 on GA media
- SUSE-SU-2026:3527-1: moderate: Security update for gstreamer-plugins-bad
- SUSE-SU-2026:3528-1: important: Security update for azure-storage-azcopy
- SUSE-SU-2026:3529-1: important: Security update for ffmpeg-4
- SUSE-SU-2026:3530-1: important: Security update for python310
- openSUSE-SU-2026:0279-1: moderate: Security update for perl-Mojo-JWT
- openSUSE-SU-2026:11471-1: moderate: tekton-cli-0.46.0-1.1 on GA media
- openSUSE-SU-2026:11463-1: moderate: libXfont2-2-2.0.7-3.1 on GA media
- openSUSE-SU-2026:11465-1: moderate: python313-Django4-4.2.30-5.1 on GA media
- openSUSE-SU-2026:11462-1: moderate: gleam-1.18.1-1.1 on GA media
How to apply these Linux security updates
Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.
Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.
Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.
Debian/Ubuntu (apt)
The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.
sudo apt update sudo apt upgrade -y
Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)
On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.
sudo dnf check-update sudo dnf upgrade -y
or on older releases
sudo yum check-update sudo yum update
SUSE (zypper)
SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.
sudo zypper refresh sudo zypper update -y
Slackware (slackpkg and pkgtool)
Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.
sudo slackpkg update sudo slackpkg upgrade-all
It's a heavy week, but the redundancy across AlmaLinux, Oracle, Rocky, and RHEL means a single maintenance window handles most of it. Debian and Slackware operators will need to work through their own trees first, and ELTS distributions demand their usual attention. Bottom line: schedule the update, run the regression tests, and move on. The overlap actually works in your favor here.
