Major distributions delivered a synchronized wave of security errata this past week, with the EL derivatives moving in lockstep to patch the kernel, .NET stack, and BIND DNS server across versions seven through ten. The sheer volume is exhausting, as identical .NET and BIND bumps hit four major distributions while Ubuntu shipped twelve separate advisories just for its kernel variants. Privilege escalation dominated the higher severity ratings, with critical patches targeting local trust boundaries in bubblewrap, systemd, haveged, and a lingering ProFTPD use-after-free on Slackware. The patch window is tight and the queue is long, so apply the kernel and network-stack updates first, verify your version numbers after reboot, and stagger your rollouts if you are running a multi-node cluster.
Weekly Linux Security Roundup: Kernel, .NET, and BIND Take the Hit Across Nearly Every Major Distro
The major Linux distributions delivered a synchronized wave of security errata this past week, targeting everything from privilege escalation flaws in systemd to memory corruption bugs in ProFTPD. If you are running anything from RHEL 7 to Ubuntu 26.04, your update queue just grew significantly.
AlmaLinux, Oracle Linux, Rocky Linux, and Red Hat itself moved in lockstep again, which is becoming the standard pattern for the EL family. The patches span versions seven through ten and hit the kernel, PostgreSQL, Python, PHP, and BIND hard. You will see the same advisory IDs bouncing across Alma, Oracle, Rocky, and RHEL, just with different package prefixes. It is the same underlying upstream code getting the same treatment across four different flavors.
.NET on Linux is clearly no longer an afterthought. .NET 8.0, 9.0, and 10.0 all received Important ratings across the RHEL-derivatives, SUSE, and Debian. Six years ago, treating .NET as a first-class security citizen on Linux felt ambitious. Now it is just Tuesday. BIND DNS server patches are everywhere too, with bind9.16, bind, and bind security updates hitting AlmaLinux, Rocky, RHEL, SUSE, and Debian. FreeRDP follows a similar pattern, with updates rolling out across Alma, Oracle, Rocky, RHEL, and SUSE. The recurring trio of .NET, BIND, and FreeRDP suggests upstream maintainers have been quietly knocking out fixes that distro security teams finally caught up to this cycle.
Memory corruption and privilege escalation dominated the higher severity ratings. Gentoo's GLSA batch specifically calls out root privilege escalation in Bubblewrap, privilege escalation in haveged, and improper header handling in HTTP-Daemon. Ubuntu's USN-8626-1 blocks three systemd vulnerabilities that could let local attackers terminate protected processes or crash core system services. Slackware's SSA:2026-227-01 fixes a use-after-free in ProFTPD triggered by the FTP STAT command. That is a notoriously nasty class of bug in legacy FTP servers, and the 1.3.9d release corrects how the daemon handles AllowForeignAddress during passive transfers. You probably do not run ProFTPD in 2026, but if you do, apply the patch before breakfast.
Ubuntu, SUSE, and the Fedora Family
Ubuntu also closed a massive hole in the Axios HTTP client library. The update targets Node.js applications that rely on axios, and the CVE list is long enough to make library maintainers nervous. That said, the Linux kernel got the bulk of the attention, with separate advisories for default, Azure, OEM, Oracle, NVIDIA Tegra IGX, and HWE variants. If you are on cloud or edge hardware, your kernel update is probably mandatory.
SUSE Linux Enterprise 15 SP6 and SP7, along with openSUSE Leap and Tumbleweed, patched chromium, the Linux kernel, python311/312/313, ffmpeg-4, podman, bind, erlang26, openvpn, dracut, and rpm. The chromium patches alone carry critical and important ratings across multiple SUSE-SU and openSUSE-SU advisory numbers. Fedora 43 and 44 stayed quieter but still rolled out updates for suricata, clamav, domoticz, vaultwarden, sqlite, cri-o, stunnel, and a batch of Rust libraries. Debian and Freexian LTS covered Thunderbird, openjdk-25, wordpress, caddy, flatpak, python-django, spip, and util-linux.
Latest Security Updates by Distribution
Here’s a complete breakdown of the security updates for AlmaLinux, Debian GNU/Linux, Fedora Linux, Gentoo Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux.
AlmaLinux
AlmaLinux deployed multiple security update batches across operating system versions eight, nine, and ten. The initial rollout fixed command injection risks in GPSD, a double-free memory error in libarchive, and XFS data corruption, while also addressing flaws in Go, Tomcat, and Perl DBI. A second wave of advisories patched the Linux kernel, PostgreSQL, Firefox, iSCSI utilities, and the automatic bug reporting tool, followed by another series that covered vim, FreeRDP, Grafana, and the Xwayland display server, these errata resolve important and moderate vulnerabilities across .NET, BIND, and core system utilities to keep AlmaLinux installations secure.
- ALSA-2026:52674: libarchive security update (Moderate)
- ALSA-2026:51153: gpsd-minimal security update (Important)
- ALSA-2026:51075: gpsd security update (Important)
- ALSA-2026:39494: kernel security, bug fix, and enhancement update (Important)
- ALSA-2026:45114: kernel security update (Important)
- ALSA-2026:38513: perl-DBI security update (Important)
- ALSA-2026:37436: golang security, bug fix, and enhancement update (Important)
- ALSA-2026:36790: tomcat9 security, bug fix, and enhancement update (Important)
- ALSA-2026:53365: fence-agents security update (Important)
- ALSA-2026:49607: frr10 security, bug fix, and enhancement update (Important)
- ALSA-2026:53844: iscsi-initiator-utils security, bug fix, and enhancement update (Important)
- ALSA-2026:53847: isns-utils security update (Important)
- ALSA-2026:47104: firefox security update (Important)
- ALSA-2026:52395: postgresql security update (Important)
- ALSA-2026:52772: perl-DBI:1.641 security update (Important)
- ALSA-2026:53848: isns-utils security update (Important)
- ALSA-2026:53452: gstreamer1-plugins-good security update (Moderate)
- ALSA-2026:53363: fence-agents security update (Important)
- ALSA-2026:53364: resource-agents security update (Important)
- ALSA-2026:52396: postgresql:12 security update (Important)
- ALSA-2026:52765: kernel security update (Moderate)
- ALSA-2026:52761: kernel-rt security update (Moderate)
- ALSA-2026:53845: iscsi-initiator-utils security, bug fix, and enhancement update (Important)
- ALSA-2026:53846: isns-utils security update (Important)
- ALSA-2026:27742: postgresql18 security update (Important)
- ALSA-2026:24348: postgresql-jdbc security update (Important)
- ALSA-2026:51295: kernel security, bug fix, and enhancement update (Moderate)
- ALSA-2026:52841: nodejs-nodemon security update (Important)
- ALSA-2026:52675: libarchive security update (Moderate)
- ALSA-2026:38490: xorg-x11-server-Xwayland security update (Important)
- ALSA-2026:38497: gegl04 security update (Important)
- ALSA-2026:49838: osbuild-composer security, bug fix, and enhancement update (Important)
- ALSA-2026:54272: abrt security update (Important)
- ALSA-2026:54246: kernel security update (Moderate)
- ALSA-2026:54290: python-idna security update (Moderate)
- ALSA-2026:54481: python-idna security update (Moderate)
- ALSA-2026:28231: opencryptoki security update (Moderate)
- ALSA-2026:53330: kernel security, bug fix, and enhancement update (Important)
- ALSA-2026:25216: valkey security update (Important)
- ALSA-2026:40833: pacemaker security update (Important)
- ALSA-2026:28582: keylime security update (Moderate)
- ALSA-2026:25999: yggdrasil-worker-package-manager security update (Moderate)
- ALSA-2026:26566: xorg-x11-server-Xwayland security, bug fix, and enhancement update (Important)
- ALSA-2026:53451: gstreamer1-plugins-good security update (Moderate)
- ALSA-2026:49526: osbuild-composer security update (Important)
- ALSA-2026:54178: grafana security, bug fix, and enhancement update (Moderate)
- ALSA-2026:39297: edk2 security, bug fix, and enhancement update (Moderate)
- ALSA-2026:38489: xorg-x11-server-Xwayland security update (Important)
- ALSA-2026:54210: dhcpcd security update (Moderate)
- ALSA-2026:38509: vim security update (Important)
- ALSA-2026:53435: udisks2 security update (Important)
- ALSA-2026:54268: python3.9 security update (Important)
- ALSA-2026:54484: python-idna security update (Moderate)
- ALSA-2026:53329: kernel security, bug fix, and enhancement update (Important)
- ALSA-2026:38511: vim security update (Important)
- ALSA-2026:25051: libyang security update (Important)
- ALSA-2026:38510: vim security update (Important)
- ALSA-2026:54485: freerdp security update (Important)
- ALSA-2026:54247: kernel-rt security update (Moderate)
- ALSA-2026:54538: .NET 8.0 security, bug fix, and enhancement update (Important)
- ALSA-2026:54542: .NET 10.0 security, bug fix, and enhancement update (Important)
- ALSA-2026:54654: bind security update (Important)
- ALSA-2026:54550: .NET 9.0 security, bug fix, and enhancement update (Important)
- ALSA-2026:54509: bind9.16 security update (Important)
- ALSA-2026:54575: dracut security update (Important)
- ALSA-2026:54487: freerdp security update (Important)
- ALSA-2026:54510: bind security update (Important)
- ALSA-2026:54571: dracut security update (Important)
- ALSA-2026:54662: nghttp2 security update (Moderate)
- ALSA-2026:54343: kernel security, bug fix, and enhancement update (Important)
- ALSA-2026:54486: freerdp security update (Important)
- ALSA-2026:54512: gnome-remote-desktop security update (Moderate)
- ALSA-2026:54576: dracut security update (Important)
- ALSA-2026:54650: nghttp2 security update (Moderate)
- ALSA-2026:54541: .NET 8.0 security, bug fix, and enhancement update (Important)
- ALSA-2026:54590: .NET 9.0 security, bug fix, and enhancement update (Important)
Debian GNU/Linux
Debian and Freexian LTS released multiple security advisory batches across Bookworm and Trixie. The patches address dozens of CVEs across widely used software including Chromium, PostgreSQL, PHP, BIND9, Xorg, Kitty, and Xen. Attackers could exploit unresolved flaws to execute arbitrary code, bypass authentication, trigger stack buffer overflows, or perform SQL injection through malformed input. These advisories directly target race conditions, use-after-free memory errors, and certificate validation failures that previously allowed attackers to escalate privileges or crash mail and database services.
- [DSA 6423-1] kitty security update
- [DSA 6424-1] xen security update
- [DLA 4726-1] ca-certificates CA certificate update
- [DLA 4728-1] chromium security update
- [DLA 4727-1] thunderbird security update
- [DSA 6426-1] icinga2 security update
- [DSA 6425-1] openjdk-21 security update
- [DLA 4729-1] nss security update
- [DSA 6427-1] wordpress security update
- [DSA 6429-1] caddy security update
- [DLA 4730-1] libyaml-syck-perl security update
- [DSA 6428-1] libyaml-syck-perl security update
- ELA-1799-1 libinput security update (by )
- ELA-1798-1 libinput security update (by )
- ELA-1800-1 nss security update (by )
- [DSA 6430-1] postfix security update
- [DLA 4733-1] php7.4 security update
- [DLA 4732-1] php8.2 security update
- [DSA 6431-1] openjdk-25 security update
- [DLA 4731-1] libgd2 security update
- ELA-1802-1 bind9 security update (by )
- ELA-1801-1 jq security update (by )
- ELA-1803-1 ca-certificates CA certificates update (by )
- ELA-1802-1 bind9 security update (by )
- ELA-1807-1 php7.0 security update (by )
- ELA-1806-1 php7.3 security update (by )
- ELA-1805-1 libgd2 security update (by )
- ELA-1804-1 libconfig-inifiles-perl security update (by )
- [DLA 4735-1] neutron security update
- [DSA 6434-1] lemonldap-ng security update
- [DSA 6432-1] flatpak security update
- [DLA 4736-1] python-django security update
- [DSA 6435-1] spip security update
- [DLA 4738-1] xorg-server security update
- [DLA 4737-1] xorg-server security update
- [DSA 6433-1] xdg-dbus-proxy security update
- ELA-1808-1 python-django security update (by )
- [DSA 6437-1] apr-util security update
- [DSA 6436-1] chromium security update
- [DLA 4739-1] chromium security update
- [DSA 6438-1] postgresql-17 security update
- [DSA 6441-1] python-httplib2 security update
- [DSA 6440-1] unzip security update
- [DSA 6439-1] zip security update
- ELA-1809-1 ca-certificates-java bugfix update (by )
- [DSA 6442-1] util-linux security update
- [DLA 4740-1] postgresql-15 security update
Fedora Linux
Fedora distributed coordinated security patches across Fedora 43 and Fedora 44. The release refreshes widely used software like the Linux kernel, Chromium browser, stunnel, and the Erlang web frameworks to close active exploits. Developers also received fixed versions of vaultwarden, sqlite, cri-o, and multiple Rust and Perl libraries to resolve memory corruption and denial of service flaws. The distribution spans antivirus scanners, home automation controllers, and multiple networking libraries, ensuring every flagged component receives an official fix.
- Fedora 43 Update: python-wsgidav-4.3.5-1.fc43
- Fedora 44 Update: python-wsgidav-4.3.5-1.fc44
- Fedora 43 Update: chromium-151.0.7922.108-1.fc43
- Fedora 43 Update: kernel-7.1.8-100.fc43
- Fedora 43 Update: nghttp2-1.66.0-3.fc43
- Fedora 43 Update: p11-kit-0.26.5-1.fc43
- Fedora 43 Update: libcupsfilters-2.1.1-9.fc43
- Fedora 43 Update: python-webob-1.8.11-1.fc43
- Fedora 43 Update: mingw-gstreamer1-plugins-good-1.26.11-2.fc43
- Fedora 43 Update: mingw-python-pip-26.2-1.fc43
- Fedora 43 Update: mingw-libidn-1.44-1.fc43
- Fedora 43 Update: suricata-7.0.17-1.fc43
- Fedora 43 Update: xen-4.20.4-1.fc43
- Fedora 44 Update: kernel-7.1.8-200.fc44
- Fedora 44 Update: emacs-30.2-27.fc44
- Fedora 44 Update: chromium-151.0.7922.108-1.fc44
- Fedora 44 Update: chezmoi-2.72.0-1.fc44
- Fedora 44 Update: python-webob-1.8.11-1.fc44
- Fedora 44 Update: mingw-python-pip-26.2-1.fc44
- Fedora 44 Update: knot-3.5.6-1.fc44
- Fedora 44 Update: suricata-8.0.6-1.fc44
- Fedora 43 Update: clamav-1.4.6-1.fc43
- Fedora 43 Update: libidn-1.44-1.fc43
- Fedora 44 Update: clamav-1.4.6-1.fc44
- Fedora 44 Update: libidn-1.44-1.fc44
- Fedora 44 Update: domoticz-2026.3-1.fc44
- Fedora 43 Update: cri-o1.34-1.34.11-1.fc43
- Fedora 43 Update: vaultwarden-1.37.1-1.fc43
- Fedora 44 Update: sqlite-3.51.2-2.fc44
- Fedora 44 Update: linux-firmware-20260810-1.fc44
- Fedora 44 Update: apr-util-1.6.5-1.fc44
- Fedora 44 Update: libcupsfilters-2.1.1-9.fc44
- Fedora 44 Update: cri-o1.34-1.34.11-1.fc44
- Fedora 44 Update: vaultwarden-1.37.1-1.fc44
- Fedora 43 Update: erlang-cowlib-2.19.0-1.fc43
- Fedora 43 Update: erlang-cowboy-2.18.0-1.fc43
- Fedora 44 Update: flatpak-1.18.1-1.fc44
- Fedora 44 Update: libnfs-6.0.2-9.fc44
- Fedora 44 Update: erlang-cowlib-2.19.0-1.fc44
- Fedora 44 Update: erlang-cowboy-2.18.0-1.fc44
- Fedora 43 Update: chromium-151.0.7922.137-1.fc43
- Fedora 43 Update: pdns-5.0.7-1.fc43
- Fedora 43 Update: php-pear-PHP-CodeSniffer-4.0.4-1.fc43
- Fedora 43 Update: perl-Archive-Tar-3.12-1.fc43
- Fedora 44 Update: libsoup3-3.6.6-9.fc44
- Fedora 44 Update: chromium-151.0.7922.137-1.fc44
- Fedora 44 Update: pdns-5.0.7-1.fc44
- Fedora 44 Update: php-pear-PHP-CodeSniffer-4.0.4-1.fc44
- Fedora 44 Update: rust-pretty-git-prompt-0.2.2-11.fc44
- Fedora 44 Update: rust-lsd-1.2.0-8.fc44
- Fedora 44 Update: rust-tokei-14.0.0-7.fc44
- Fedora 44 Update: rust-git-interactive-rebase-tool-2.4.1-17.fc44
- Fedora 44 Update: rust-git-delta-0.19.1-7.fc44
- Fedora 44 Update: rust-bat-0.26.1-3.fc44
- Fedora 44 Update: jrnl-4.6-1.fc44
- Fedora 44 Update: libgsasl-1.10.0-17.fc44
- Fedora 44 Update: stunnel-5.80-1.fc44
- Fedora 43 Update: jrnl-4.6-1.fc43
- Fedora 43 Update: libgsasl-1.10.0-17.fc43
- Fedora 43 Update: stunnel-5.80-1.fc43
Gentoo Linux
Gentoo Linux issued GLSA 202608-02 to patch nine CVEs in FreeType versions under 2.14.3, addressing out-of-bounds reads and information disclosure risks. Mid-month advisories also target seven widely used services including Bubblewrap, Apache HTTPD, Exim, Flatpak, Dnsmasq, libinput, and rsync, closing attack vectors like remote code execution and root privilege escalation. Separate notices fix a high-severity privilege escalation flaw in haveged that could grant local attackers root access, alongside an update for httpd. The distribution further resolved sandbox bypass vulnerabilities in the Portage package manager and patched multiple flaws in the NTFS-3G filesystem driver.
- [ GLSA 202608-02 ] FreeType: Multiple Vulnerabilities
- [ GLSA 202608-09 ] Bubblewrap: Root privilege escalation
- [ GLSA 202608-08 ] libinput: Multiple Vulnerabilities
- [ GLSA 202608-06 ] Flatpak: Multiple Vulnerabilities
- [ GLSA 202608-07 ] Exim: Multiple Vulnerabilities
- [ GLSA 202608-05 ] Apache HTTPD: Multiple Vulnerabilities
- [ GLSA 202608-04 ] Dnsmasq: Multiple Vulnerabilities
- [ GLSA 202608-03 ] rsync: Multiple Vulnerabilities
- [ GLSA 202608-11 ] haveged: Privilege escalation
- [ GLSA 202608-10 ] HTTP-Daemon: Improper header handling
- [ GLSA 202608-12 ] Portage: Multiple Vulnerabilities
- [ GLSA 202608-13 ] NTFS-3G: Multiple Vulnerabilities
Oracle Linux
Oracle Linux distributed multiple security and maintenance update batches for operating system versions 7 through 10. Each advisory addresses critical vulnerabilities and resolves software bugs across core infrastructure and developer libraries. System administrators should apply the patches immediately to secure widely used components like the Unbreakable Enterprise Kernel, OpenJDK, BIND, Node.js, and FreeRDP.
- ELBA-2026-47011-1 Oracle Linux 8 kernel bug fix update
- ELSA-2026-43702 Moderate: Oracle Linux 7 libpng12 security update
- ELBA-2026-51070 Oracle Linux 7 tzdata bug fix and enhancement update
- ELSA-2026-33685 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
- ELSA-2026-52841 Important: Oracle Linux 10 nodejs-nodemon security update
- ELBA-2026-50154-0 Oracle Linux 10 linux-firmware bug fix and enhancement update
- ELBA-2026-50146-0 Oracle Linux 10 selinux-policy bug fix and enhancement update
- ELSA-2026-51295 Moderate: Oracle Linux 10 kernel security, bug fix, and enhancement update
- ELBA-2026-500139 Oracle Linux 10 nodejs22 bug fix update
- ELSA-2026-52675 Moderate: Oracle Linux 10 libarchive security update
- ELBA-2026-500144 Oracle Linux 10 nodejs24 bug fix update
- ELSA-2026-500150 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
- ELBA-2026-500147 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-50828 Important: Oracle Linux 9 ruby:3.3 security, bug fix, and enhancement update
- ELBA-2026-500147 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-50827 Important: Oracle Linux 9 ruby:4.0 security, bug fix, and enhancement update
- ELSA-2026-48197 Low: Oracle Linux 9 php:8.3 security, bug fix, and enhancement update
- ELSA-2026-51153 Important: Oracle Linux 9 gpsd-minimal security update
- ELBA-2026-500152 Oracle Linux 9 xfsprogs bug fix update
- ELBA-2026-500120 Oracle Linux 9 leapp-repository bug fix update
- ELBA-2026-49214-1 Oracle Linux 8 kernel bug fix update
- ELBA-2026-47121 Oracle Linux 8 linux-firmware bug fix and enhancement update
- ELSA-2026-500150 Important: Unbreakable Enterprise kernel security update
- ELSA-2026-53451 Moderate: Oracle Linux 10 gstreamer1-plugins-good security update
- ELSA-2026-53435 Important: Oracle Linux 10 udisks2 security update
- ELSA-2026-53846 Important: Oracle Linux 10 isns-utils security update
- ELSA-2026-53330 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
- ELSA-2026-49526 Important: Oracle Linux 10 osbuild-composer security update
- ELSA-2026-34911 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
- ELBA-2026-50139-0 Oracle Linux 10 tuned bug fix and enhancement update
- ELBA-2026-39299 Oracle Linux 10 microcode_ctl bug fix and enhancement update
- ELSA-2026-500162 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
- ELSA-2026-53847 Important: Oracle Linux 9 isns-utils security update
- ELSA-2026-53452 Moderate: Oracle Linux 9 gstreamer1-plugins-good security update
- ELSA-2026-53365 Important: Oracle Linux 9 fence-agents security update
- ELSA-2026-53329 Important: Oracle Linux 9 kernel security, bug fix, and enhancement update
- ELSA-2026-52395 Important: Oracle Linux 9 postgresql security update
- ELSA-2026-52674 Moderate: Oracle Linux 9 libarchive security update
- ELSA-2026-47082 Important: Oracle Linux 9 pipewire security update
- ELSA-2026-42877 Important: Oracle Linux 9 java-1.8.0-openjdk security update
- ELBA-2026-39314 Oracle Linux 9 microcode_ctl bug fix and enhancement update
- ELSA-2026-500162 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
- ELBA-2026-500146 Oracle Linux 9 libguestfs bug fix update
- ELSA-2026-500162 Important: Oracle Linux 8 Unbreakable Enterprise kernel security update
- ELBA-2026-500147 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-53363 Important: Oracle Linux 8 fence-agents security update
- ELSA-2026-50728 Important: Oracle Linux 8 ruby:3.3 security, bug fix, and enhancement update
- ELBA-2026-47114 Oracle Linux 8 microcode_ctl bug fix and enhancement update
- ELSA-2026-42877 Important: Oracle Linux 8 java-1.8.0-openjdk security update
- ELBA-2026-500165 Oracle Linux 8 leapp-repository bug fix update
- ELSA-2026-49513 Important: Oracle Linux 7 dovecot security update
- ELSA-2026-8517 Important: Oracle Linux 7 libarchive security update
- ELSA-2026-47176 Important: Oracle Linux 7 gstreamer1-plugins-bad-free security update
- ELSA-2026-43575 Moderate: Oracle Linux 7 gnutls security update
- ELSA-2026-41904 Important: Oracle Linux 7 evince security update
- ELSA-2026-37397 Important: Oracle Linux 7 ruby security update
- ELSA-2026-26564 Important: Oracle Linux 7 dovecot security update
- ELSA-2026-13895 Important: Oracle Linux 7 sudo security update
- ELSA-2026-54486 Important: Oracle Linux 10 freerdp security update
- ELSA-2026-54481 Moderate: Oracle Linux 10 python-idna security update
- ELSA-2026-54178 Moderate: Oracle Linux 10 grafana security, bug fix, and enhancement update
- ELSA-2026-36541 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
- ELBA-2026-500170 Oracle Linux 10 makedumpfile bug fix update
- ELBA-2026-500168 Oracle Linux 10 crash bug fix update
- ELSA-2026-54268 Important: Oracle Linux 9 python3.9 security update
- ELSA-2026-42887 Important: Oracle Linux 9 java-17-openjdk security update
- ELBA-2026-500163 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
- ELBA-2026-500169 Oracle Linux 9 kexec-tools bug fix update
- ELBA-2026-500167 Oracle Linux 9 crash bug fix update
- ELBA-2026-500163 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
- ELBA-2026-500164 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-54290 Moderate: Oracle Linux 8 python-idna security update
- ELSA-2026-54243 Important: Oracle Linux 8 grafana security update
- ELSA-2026-53848 Important: Oracle Linux 8 isns-utils security update
- ELSA-2026-52772 Important: Oracle Linux 8 perl-DBI:1.641 security update
- ELSA-2026-52765 Moderate: Oracle Linux 8 kernel security update
- ELBA-2026-500164 Oracle Linux 8 Unbreakable Enterprise kernel bug fix update
- ELBA-2026-500148 Oracle Linux 8 systemd bug fix update
- ELBA-2026-500164 Oracle Linux 7 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-51183 Important: Oracle Linux 7 glib2 security update
- ELSA-2026-51063 Important: Oracle Linux 7 libXfont2 security update
- ELSA-2026-50808 Moderate: Oracle Linux 7 libpng security update
- ELSA-2026-49603 Important: Oracle Linux 7 gstreamer1-plugins-good security update
- ELSA-2026-54574 Important: Oracle Linux 9 .NET 8.0 security, bug fix, and enhancement update
- ELSA-2026-54512 Moderate: Oracle Linux 10 gnome-remote-desktop security update
- ELSA-2026-42887 Important: Oracle Linux 8 java-17-openjdk security update
- ELSA-2026-54485 Important: Oracle Linux 8 freerdp security update
- ELSA-2026-54650 Moderate: Oracle Linux 10 nghttp2 security update
- ELSA-2026-54590 Important: Oracle Linux 10 .NET 9.0 security, bug fix, and enhancement update
- ELSA-2026-54541 Important: Oracle Linux 10 .NET 8.0 security, bug fix, and enhancement update
- ELBA-2026-500173 Oracle Linux 10 image-builder bug fix update
- ELBA-2026-500163 Oracle Linux 9 Unbreakable Enterprise kernel bug fix update
- ELSA-2026-54662 Moderate: Oracle Linux 9 nghttp2 security update
- ELSA-2026-54510 Important: Oracle Linux 9 bind security update
- ELSA-2026-54487 Important: Oracle Linux 9 freerdp security update
- ELSA-2026-54509 Important: Oracle Linux 8 bind9.16 security update
- ELSA-2026-36083 Important: Oracle Linux 7 xorg-x11-server security update
- New Ksplice updates for UEKR6 5.4.17 on OL7 and OL8
- ELSA-2026-54542 Important: Oracle Linux 8 .NET 10.0 security, bug fix, and enhancement update
- ELSA-2026-54538 Important: Oracle Linux 8 .NET 8.0 security, bug fix, and enhancement update
- ELSA-2026-54484 Moderate: Oracle Linux 9 python-idna security update
- ELSA-2026-54443 Important: Oracle Linux 9 kernel security, bug fix, and enhancement update
- ELSA-2026-54571 Important: Oracle Linux 9 dracut security update
- ELSA-2026-54184 Important: Oracle Linux 9 grafana security update
- ELSA-2026-53844 Important: Oracle Linux 9 iscsi-initiator-utils security, bug fix, and enhancement update
- ELSA-2026-47756 Important: Oracle Linux 9 openssh security update
- ELBA-2026-500143 Oracle Linux 9 oracle-ovirt-release-45-el9 bug fix update
- ELSA-2026-54654 Important: Oracle Linux 8 bind security update
- ELSA-2026-54576 Important: Oracle Linux 10 dracut security update
- ELSA-2026-54343 Important: Oracle Linux 10 kernel security, bug fix, and enhancement update
- ELSA-2026-54210 Moderate: Oracle Linux 10 dhcpcd security update
- ELSA-2026-53845 Important: Oracle Linux 10 iscsi-initiator-utils security, bug fix, and enhancement update
- ELSA-2026-50778 Important: Oracle Linux 10 ruby security, bug fix, and enhancement update
- ELSA-2026-50773 Important: Oracle Linux 10 ruby4.0 security, bug fix, and enhancement update
- ELSA-2026-36956 Important: Oracle Linux 10 kernel security update
- ELSA-2026-22450 Important: Oracle Linux 10 osbuild-composer security update
- ELBA-2026-500142 Oracle Linux 9 oVirt 4.5 OLVM Engine Release for OL9
- ELBA-2026-500141 Oracle Linux 9 oVirt 4.5 OLVM Engine Release for OL9
- ELSA-2026-54575 Important: Oracle Linux 8 dracut security update
- ELSA-2026-54550 Important: Oracle Linux 8 .NET 9.0 security, bug fix, and enhancement update
- ELSA-2026-54371 Important: Oracle Linux 8 nodejs:24 security update
Red Hat Enterprise Linux
Red Hat Product Security released a series of errata for Red Hat Enterprise Linux versions 7 through 10, patching security flaws across numerous widely used components. The advisories cover the Linux kernel, Python, Node.js, PostgreSQL, Firefox, Thunderbird, BIND, .NET, GStreamer, libgcrypt, and mod_md. Other critical updates target OpenShift Container Platform, JBoss Enterprise Application Platform, OpenStack Platform 16.2, and osbuild-composer, alongside fixes for Xwayland and various supporting packages. Red Hat assigned an Important impact rating to the majority of these patches, while moderate severity updates address python-idna, nghttp2, and gnome-remote-desktop within extended support streams.
- RHSA-2026:52399: Important: nodejs:22 security update
- RHSA-2026:52400: Important: python3 security update
- RHSA-2026:52389: Important: osbuild-composer security update
- RHSA-2026:52397: Important: xorg-x11-server-Xwayland security update
- RHSA-2026:52392: Important: xorg-x11-server-Xwayland security update
- RHSA-2026:52390: Important: osbuild-composer security update
- RHSA-2026:52393: Moderate: mod_md security update
- RHSA-2026:52649: Important: kernel security update
- RHSA-2026:52551: Important: python-pillow security update
- RHSA-2026:52395: Important: postgresql security update
- RHSA-2026:52396: Important: postgresql:12 security update
- RHSA-2026:52398: Important: xorg-x11-server-Xwayland security update
- RHSA-2026:52391: Important: osbuild-composer security update
- RHSA-2026:52394: Important: nodejs-nodemon security update
- RHSA-2026:52772: Important: perl-DBI:1.641 security update
- RHSA-2026:52765: Moderate: kernel security update
- RHSA-2026:52674: Moderate: libarchive security update
- RHSA-2026:52761: Moderate: kernel-rt security update
- RHSA-2026:52675: Moderate: libarchive security update
- RHSA-2026:52667: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:52764: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:52832: Important: RHELAI 3.0 Backport fixes for CVE-2026-64835 and CVE-2026-58049
- RHSA-2026:52833: Important: RHELAI 3.2 Backport fixes for CVE-2026-64835 and CVE-2026-58049
- RHSA-2026:52848: Important: mariadb:10.11 security update
- RHSA-2026:52930: Important: postgresql-jdbc security update
- RHSA-2026:52929: Important: postgresql-jdbc security update
- RHSA-2026:52928: Important: postgresql-jdbc security update
- RHSA-2026:52950: Moderate: libgcrypt security update
- RHSA-2026:52953: Moderate: libgcrypt security update
- RHSA-2026:52952: Moderate: libgcrypt security update
- RHSA-2026:52978: Important: postgresql-jdbc security update
- RHSA-2026:52951: Moderate: libgcrypt security update
- RHSA-2026:52948: Important: java-21-ibm-semeru-certified-jdk security update
- RHSA-2026:52949: Important: java-1.8.0-ibm security update
- RHSA-2026:52841: Important: nodejs-nodemon security update
- RHSA-2026:52826: Important: ignition security update
- RHSA-2026:53455: Important: thunderbird security update
- RHSA-2026:53446: Important: thunderbird security update
- RHSA-2026:53444: Important: thunderbird security update
- RHSA-2026:53475: Important: thunderbird security update
- RHSA-2026:53452: Moderate: gstreamer1-plugins-good security update
- RHSA-2026:53435: Important: udisks2 security update
- RHSA-2026:53445: Important: thunderbird security update
- RHSA-2026:53412: Important: opentelemetry-collector security update
- RHSA-2026:53413: Important: opentelemetry-collector security update
- RHSA-2026:53365: Important: fence-agents security update
- RHSA-2026:51036: Important: OpenShift Container Platform 4.22.9 packages and security update
- RHSA-2026:53330: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:53806: Important: Red Hat JBoss Enterprise Application Platform 7.4.25 security update
- RHSA-2026:53644: Important: Red Hat JBoss Enterprise Application Platform 7.4.25 security pdate
- RHSA-2026:53454: Important: thunderbird security update
- RHSA-2026:53453: Important: thunderbird security update
- RHSA-2026:53451: Moderate: gstreamer1-plugins-good security update
- RHSA-2026:53329: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:53363: Important: fence-agents security update
- RHSA-2026:53374: Important: rhc security update
- RHSA-2026:53364: Important: resource-agents security update
- RHSA-2026:53298: Important: nodejs22 security update
- RHSA-2026:53416: Important: host-metering security update
- RHSA-2026:53402: Important: ldns security update
- RHSA-2026:53990: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:53989: Important: kernel security update
- RHSA-2026:51422: Important: Red Hat build of MicroShift 4.19.42 security update
- RHSA-2026:53844: Important: iscsi-initiator-utils security, bug fix, and enhancement update
- RHSA-2026:53845: Important: iscsi-initiator-utils security, bug fix, and enhancement update
- RHSA-2026:53848: Important: isns-utils security update
- RHSA-2026:53847: Important: isns-utils security update
- RHSA-2026:53450: Important: xorg-x11-server-Xwayland security update
- RHSA-2026:53415: Important: opentelemetry-collector security update
- RHSA-2026:53846: Important: isns-utils security update
- RHSA-2026:54168: Important: rhc-worker-playbook security update
- RHSA-2026:54142: Important: mariadb:10.11 security update
- RHSA-2026:54254: Important: ldns security update
- RHSA-2026:54246: Moderate: kernel security update
- RHSA-2026:54244: Important: ldns security update
- RHSA-2026:54247: Moderate: kernel-rt security update
- RHSA-2026:54191: Important: rhc-worker-script security update
- RHSA-2026:54182: Important: firefox security update
- RHSA-2026:54181: Important: firefox security update
- RHSA-2026:54178: Moderate: grafana security, bug fix, and enhancement update
- RHSA-2026:54185: Important: firefox security update
- RHSA-2026:54180: Important: firefox security update
- RHSA-2026:54343: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:47117: Moderate: libgcrypt security update
- RHSA-2026:47126: Moderate: resource-agents security update
- RHSA-2026:47129: Moderate: resource-agents security update
- RHSA-2026:54339: Important: firefox security update
- RHSA-2026:54268: Important: python3.9 security update
- RHSA-2026:54272: Important: abrt security update
- RHSA-2026:54290: Moderate: python-idna security update
- RHSA-2026:54248: Important: firefox security update
- RHSA-2026:54249: Important: firefox security update
- RHSA-2026:54259: Important: firefox security update
- RHSA-2026:54210: Moderate: dhcpcd security update
- RHSA-2026:54435: Important: Streams for Apache Kafka 3.2.1 release and security update
- RHSA-2026:54417: Important: python-pillow security update
- RHSA-2026:54443: Important: kernel security, bug fix, and enhancement update
- RHSA-2026:54401: Important: rhc security update
- RHSA-2026:54377: Important: ldns security update
- RHSA-2026:54509: Important: bind9.16 security update
- RHSA-2026:54512: Moderate: gnome-remote-desktop security update
- RHSA-2026:54485: Important: freerdp security update
- RHSA-2026:54484: Moderate: python-idna security update
- RHSA-2026:54482: Important: kernel security update
- RHSA-2026:54481: Moderate: python-idna security update
- RHSA-2026:54510: Important: bind security update
- RHSA-2026:54528: Important: python-pillow security update
- RHSA-2026:54538: Important: .NET 8.0 security, bug fix, and enhancement update
- RHSA-2026:54539: Important: yelp security update
- RHSA-2026:54540: Important: yelp security update
- RHSA-2026:51653: Important: Red Hat build of Quarkus 3.33.3 release and security update
- RHSA-2026:54541: Important: .NET 8.0 security, bug fix, and enhancement update
- RHSA-2026:54532: Important: postgresql-jdbc security update
- RHSA-2026:54487: Important: freerdp security update
- RHSA-2026:54486: Important: freerdp security update
- RHSA-2026:54637: Important: yelp security update
- RHSA-2026:54624: Important: yelp security update
- RHSA-2026:54550: Important: .NET 9.0 security, bug fix, and enhancement update
- RHSA-2026:54638: Important: compat-libtiff3 security update
- RHSA-2026:54650: Moderate: nghttp2 security update
- RHSA-2026:54667: Important: freerdp security update
- RHSA-2026:54654: Important: bind security update
- RHSA-2026:54660: Important: gstreamer1-plugins-bad-free security update
- RHSA-2026:54658: Important: gstreamer1-plugins-bad-free security update
- RHSA-2026:54752: Important: gstreamer1-plugins-bad-free security update
- RHSA-2026:54776: Important: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 update is now available (RHBQ 3.33.3.GA)
- RHSA-2026:54662: Moderate: nghttp2 security update
- RHSA-2026:54664: Important: gstreamer1-plugins-bad-free security update
- RHSA-2026:54666: Important: yelp security update
- RHSA-2026:54665: Important: gstreamer1-plugins-bad-free security update
- RHSA-2026:54634: Important: webkit2gtk3 security update
- RHSA-2026:54590: Important: .NET 9.0 security, bug fix, and enhancement update
- RHSA-2026:54659: Important: gstreamer1-plugins-bad-free security update
- RHSA-2026:54642: Important: compat-libtiff3 security update
- RHSA-2026:54640: Important: compat-libtiff3 security update
- RHSA-2026:54574: Important: .NET 8.0 security, bug fix, and enhancement update
- RHSA-2026:54576: Important: dracut security update
- RHSA-2026:54572: Important: webkit2gtk3 security update
- RHSA-2026:54571: Important: dracut security update
- RHSA-2026:54605: Important: yelp security update
- RHSA-2026:54575: Important: dracut security update
- RHSA-2026:54542: Important: .NET 10.0 security, bug fix, and enhancement update
- RHSA-2026:53643: Important: Red Hat build of Quarkus 3.27.5 release and security update
- RHSA-2026:54622: Important: Red Hat Build of Apache Camel 4.18.3 for Spring Boot release.
- RHSA-2026:54757: Important: Red Hat OpenStack Platform 16.2 security advisory
Rocky Linux
Rocky Linux published a series of security advisories across versions 8, 9, and 10, addressing vulnerabilities in core system components and development tools. The updates include patches for the Linux kernel, vim, Python, PHP, .NET 8, .NET 9, and .NET 10, alongside fixes for BIND DNS, dracut, libarchive, and FreeRDP. High-availability cluster tools like fence-agents and resource-agents received updates, and the .NET 8.0 patch targets Rocky Linux 9 while .NET 9.0, .NET 10.0, bind, and dracut update Rocky Linux 8 systems. The errata also include updates for nodejs-nodemon on Rocky Linux 10, perl-DBI on Rocky Linux 8, and enhancements for Grafana, nghttp2, and GNOME Remote Desktop.
- RLSA-2026:52674: Moderate: libarchive security update
- RLBA-2022:3897: new packages: libarchive
- RLSA-2026:52761: Moderate: kernel-rt security update
- RLSA-2026:52772: Important: perl-DBI:1.641 security update
- RLSA-2026:52765: Moderate: kernel security update
- RLSA-2026:52841: Important: nodejs-nodemon security update
- RLSA-2026:38509: Important: vim security update
- RLSA-2026:52675: Moderate: libarchive security update
- RLSA-2026:38511: Important: vim security update
- RLSA-2026:38510: Important: vim security update
- RLSA-2026:53847: Important: isns-utils security update
- RLSA-2026:53365: Important: fence-agents security update
- RLSA-2026:53844: Important: iscsi-initiator-utils security, bug fix, and enhancement update
- RLSA-2026:53452: Moderate: gstreamer1-plugins-good security update
- RLSA-2026:53329: Important: kernel security, bug fix, and enhancement update
- RLSA-2026:53364: Important: resource-agents security update
- RLSA-2026:53363: Important: fence-agents security update
- RLSA-2026:53848: Important: isns-utils security update
- RLSA-2026:53846: Important: isns-utils security update
- RLSA-2026:53435: Important: udisks2 security update
- RLSA-2026:53330: Important: kernel security, bug fix, and enhancement update
- RLSA-2026:53845: Important: iscsi-initiator-utils security, bug fix, and enhancement update
- RLSA-2026:53451: Moderate: gstreamer1-plugins-good security update
- RLSA-2026:47126: Moderate: resource-agents security update
- RLSA-2026:47117: Moderate: libgcrypt security update
- RLSA-2026:54268: Important: python3.9 security update
- RLSA-2026:54247: Moderate: kernel-rt security update
- RLSA-2026:54272: Important: abrt security update
- RLSA-2026:54290: Moderate: python-idna security update
- RLSA-2026:54246: Moderate: kernel security update
- RLSA-2026:54481: Moderate: python-idna security update
- RLSA-2026:54210: Moderate: dhcpcd security update
- RLSA-2026:54343: Important: kernel security, bug fix, and enhancement update
- RLSA-2026:54178: Moderate: grafana security, bug fix, and enhancement update
- RLSA-2026:54484: Moderate: python-idna security update
- RLSA-2026:54486: Important: freerdp security update
- RLSA-2026:48170: Low: php security, bug fix, and enhancement update
- RLSA-2026:49914: Low: php8.4 security, bug fix, and enhancement update
- RLSA-2026:48197: Low: php:8.3 security, bug fix, and enhancement update
- RLSA-2026:40416: Low: php:8.2 security, bug fix, and enhancement update
- RLSA-2026:47749: Low: php:8.2 security, bug fix, and enhancement update
- RLSA-2026:47750: Low: php:7.4 security, bug fix, and enhancement update
- RLSA-2026:54485: Important: freerdp security update
- RLSA-2026:54509: Important: bind9.16 security update
- RLSA-2026:54538: Important: .NET 8.0 security, bug fix, and enhancement update
- RLSA-2026:54590: Important: .NET 9.0 security, bug fix, and enhancement update
- RLSA-2026:54650: Moderate: nghttp2 security update
- RLSA-2026:54541: Important: .NET 8.0 security, bug fix, and enhancement update
- RLSA-2026:54576: Important: dracut security update
- RLSA-2026:54512: Moderate: gnome-remote-desktop security update
- RLSA-2026:54662: Moderate: nghttp2 security update
- RLSA-2026:54510: Important: bind security update
- RLSA-2026:54443: Important: kernel security, bug fix, and enhancement update
- RLSA-2026:54487: Important: freerdp security update
- RLSA-2026:54571: Important: dracut security update
- RLSA-2026:54574: Important: .NET 8.0 security, bug fix, and enhancement update
- RLSA-2026:54550: Important: .NET 9.0 security, bug fix, and enhancement update
- RLSA-2026:54542: Important: .NET 10.0 security, bug fix, and enhancement update
- RLSA-2026:54654: Important: bind security update
- RLSA-2026:54575: Important: dracut security update
Slackware Linux
The Slackware Linux Security Team distributed new security packages for Slackware 15.0 and the -current branch to address multiple known vulnerabilities. Administrators should install the updated Expat XML parser and OpenSSH 10.5p1 builds to close reported security gaps. The rsync 3.5.0 update patches known vulnerabilities and resolves operational bugs for Slackware 15.0 systems. The ProFTPD 1.3.9d release fixes a critical use-after-free flaw triggered by the FTP STAT command and corrects how the server handles AllowForeignAddress settings during passive transfers.
SUSE Linux
SUSE has released multiple batches of security advisories addressing dozens of vulnerabilities across SUSE Linux Enterprise 15 SP6, SLES 15 SP7, openSUSE Leap, and openSUSE Tumbleweed. These patches target high-risk components including the Linux kernel, Python 3, Chromium, OpenSSH, Bind, Erlang26, FFmpeg, Podman, Node.js, RPM, OpenVPN, and Dracut. The updates prioritize fixes for active CVEs affecting core system packages and services to defend against known exploits. Administrators running SUSE platforms should apply these updates immediately to close security gaps associated with the disclosed flaws.
- SUSE-SU-2026:3533-1: important: Security update for openssl-1_1-livepatches
- SUSE-SU-2026:3536-1: important: Security update for podman
- openSUSE-SU-2026:11477-1: moderate: librest-1_0-0-0.10.2-2.1 on GA media
- openSUSE-SU-2026:11480-1: moderate: vlang-0.5.2-2.1 on GA media
- openSUSE-SU-2026:11476-1: moderate: kernel-devel-7.1.7-1.1 on GA media
- openSUSE-SU-2026:11478-1: moderate: python313-pymongo-4.17.0-1.1 on GA media
- openSUSE-SU-2026:11479-1: moderate: libsdb2_5_0-6.2.0-1.1 on GA media
- openSUSE-SU-2026:11473-1: moderate: dhcpcd-10.5.0-1.1 on GA media
- openSUSE-SU-2026:11481-1: moderate: weechat-4.10.0-1.1 on GA media
- openSUSE-SU-2026:11472-1: moderate: agama-web-ui-23+75.1a877fb50-50.1 on GA media
- openSUSE-SU-2026:11474-1: moderate: gitoxide-0.56.0-1.1 on GA media
- openSUSE-SU-2026:11475-1: moderate: kak-lsp-21.0.2-1.1 on GA media
- SUSE-SU-2026:3541-1: important: Security update for libssh2_org
- SUSE-SU-2026:3542-1: important: Security update for ffmpeg-4
- SUSE-SU-2026:3547-1: moderate: Security update for suseconnect-ng
- SUSE-SU-2026:3548-1: important: Security update for python311
- SUSE-SU-2026:3549-1: moderate: Security update for python3-sqlparse
- SUSE-SU-2026:3554-1: important: Security update for bind
- SUSE-SU-2026:3558-1: important: Security update for perl
- SUSE-SU-2026:3560-1: important: Security update for python311
- SUSE-SU-2026:3561-1: moderate: Security update for PackageKit
- SUSE-SU-2026:3569-1: important: Security update for python312
- openSUSE-SU-2026:11487-1: moderate: java-1_8_0-openj9-1.8.0.502-1.1 on GA media
- openSUSE-SU-2026:11490-1: moderate: libpcp-devel-6.3.8-3.1 on GA media
- openSUSE-SU-2026:11482-1: moderate: wild-0.10.0-2.1 on GA media
- openSUSE-SU-2026:11488-1: moderate: java-21-openj9-21.0.12.0-1.1 on GA media
- openSUSE-SU-2026:11491-1: moderate: python313-Django5-5.2.17-1.1 on GA media
- openSUSE-SU-2026:11489-1: moderate: java-25-openj9-25.0.4.0-1.1 on GA media
- openSUSE-SU-2026:11486-1: moderate: java-17-openj9-17.0.20.0-1.1 on GA media
- openSUSE-SU-2026:11485-1: moderate: java-11-openj9-11.0.32.0-1.1 on GA media
- openSUSE-SU-2026:11484-1: moderate: chromedriver-151.0.7922.108-1.1 on GA media
- openSUSE-SU-2026:11483-1: moderate: zpaqfranz-64.8-1.1 on GA media
- SUSE-SU-2026:3571-1: moderate: Security update for ImageMagick
- SUSE-SU-2026:3572-1: moderate: Security update for xmlrpc-c
- SUSE-SU-2026:3573-1: moderate: Security update for gstreamer-plugins-bad
- SUSE-SU-2026:3575-1: moderate: Security update for libarchive
- SUSE-SU-2026:3576-1: important: Security update for himmelblau, himmelblau.SUSE_SLE-15-SP5_Update
- SUSE-SU-2026:3577-1: important: Security update for snpguest
- openSUSE-SU-2026:0280-1: important: Security update for go-sendxmpp
- SUSE-SU-2026:3579-1: important: Security update for erlang26
- SUSE-SU-2026:3588-1: moderate: Security update for python3-pip
- SUSE-SU-2026:3589-1: moderate: Security update for python-pip
- openSUSE-SU-2026:11500-1: moderate: stunnel-5.80-1.1 on GA media
- openSUSE-SU-2026:11495-1: moderate: git-cliff-2.13.1-1.1 on GA media
- openSUSE-SU-2026:11498-1: moderate: python313-scikit-learn-1.9.0-1.1 on GA media
- openSUSE-SU-2026:11494-1: moderate: clusterctl-1.14.0-1.1 on GA media
- SUSE-SU-2026:3596-1: important: Security update for openvpn
- SUSE-SU-2026:3599-1: important: Security update for dracut
- SUSE-SU-2026:3600-1: important: Security update for rpm
- openSUSE-SU-2026:21561-1: critical: Security update for chromium
- openSUSE-SU-2026:21563-1: important: Security update for librest0_7
- openSUSE-SU-2026:21567-1: moderate: Security update for zk
- openSUSE-SU-2026:21557-1: moderate: Security update for gleam
- openSUSE-SU-2026:21553-1: important: Security update for GraphicsMagick
- openSUSE-SU-2026:21551-1: important: Security update for govulncheck-vulndb
- openSUSE-SU-2026:21548-1: important: Security update for gd
- openSUSE-SU-2026:21546-1: important: Security update for nodejs24
- openSUSE-SU-2026:21545-1: important: Security update for nodejs22
- SUSE-SU-2026:3593-1: important: Security update for the Linux Kernel
- SUSE-SU-2026:3595-1: important: Security update for the Linux Kernel
- openSUSE-SU-2026:0281-1: critical: Security update for chromium
- SUSE-SU-2026:3602-1: important: Security update for the Linux Kernel
- SUSE-SU-2026:3605-1: important: Security update for openssh
- openSUSE-SU-2026:0284-1: important: Security update for chromium
- SUSE-SU-2026:3611-1: important: Security update for dracut
- SUSE-SU-2026:3612-1: important: Security update for dracut
- SUSE-SU-2026:3617-1: important: Security update for the Linux Kernel
- openSUSE-SU-2026:21573-1: important: Security update for himmelblau
- openSUSE-SU-2026:11506-1: moderate: kernel-devel-7.1.8-1.1 on GA media
- openSUSE-SU-2026:11509-1: moderate: python3-ansible-compat-26.8.0-1.1 on GA media
- openSUSE-SU-2026:11502-1: moderate: 7zip-26.02-2.1 on GA media
- openSUSE-SU-2026:11510-1: moderate: python313-nltk-3.10.2-1.1 on GA media
- openSUSE-SU-2026:11503-1: moderate: ansible-lint-26.8.0-1.1 on GA media
- openSUSE-SU-2026:11508-1: moderate: pgadmin4-9.17-1.1 on GA media
- openSUSE-SU-2026:11507-1: moderate: molecule-26.8.0-1.1 on GA media
- openSUSE-SU-2026:11504-1: moderate: dracut-112+suse.29.gc0c5e1d-1.1 on GA media
Ubuntu Linux
Ubuntu released a coordinated wave of security notices to patch critical flaws across systemd, ImageMagick, the Linux kernel, and several developer libraries. The systemd fixes block three vulnerabilities that could let local attackers escalate privileges, terminate protected processes, or crash core system services. Parallel updates resolve security gaps in the Yelp help browser, the node-follow-redirects module, the libgit2 library, and kernel versions spanning Ubuntu 16.04 onward. The same release also closes dozens of Axios HTTP client vulnerabilities to keep Node.js applications secure.
- [USN-8626-1] systemd vulnerabilities
- [USN-8592-1] ImageMagick vulnerabilities
- [USN-8627-1] Yelp vulnerability
- [USN-8632-1] follow-redirects vulnerability
- [USN-8628-1] libgit2 vulnerabilities
- [USN-8631-1] Linux kernel vulnerabilities
- [USN-8635-1] Linux kernel (Azure) vulnerabilities
- [USN-8629-1] Linux kernel vulnerabilities
- [USN-8633-1] Linux kernel vulnerabilities
- [USN-8636-1] Linux kernel vulnerabilities
- [USN-8630-1] Linux kernel vulnerabilities
- [USN-8634-1] Linux kernel vulnerabilities
- [USN-8631-2] Linux kernel (Oracle) vulnerabilities
- [USN-8637-1] Linux kernel (OEM) vulnerabilities
- [USN-8630-2] Linux kernel vulnerabilities
- [USN-8633-2] Linux kernel vulnerabilities
- [USN-8631-3] Linux kernel (NVIDIA Tegra IGX) vulnerabilities
- [USN-8529-2] Linux kernel vulnerabilities
- [USN-8530-2] Linux kernel (HWE) vulnerabilities
- [USN-8548-2] Linux kernel vulnerabilities
- [USN-8638-1] Axios vulnerabilities
How to apply these Linux security updates
Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.
Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.
Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.
Debian/Ubuntu (apt)
The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.
sudo apt update sudo apt upgrade -y
Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)
On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.
sudo dnf check-update sudo dnf upgrade -y
or on older releases
sudo yum check-update sudo yum update
SUSE (zypper)
SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.
sudo zypper refresh sudo zypper update -y
Slackware (slackpkg and pkgtool)
Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.
sudo slackpkg update sudo slackpkg upgrade-all
Gentoo Linux
Updating Gentoo Linux is more involved than binary distributions because it's a source-based system with highly customizable packages.
sudo emerge --sync sudo emerge -avuDN @world
