Security 10978 Published by

Major distributions delivered a synchronized wave of security errata this past week, with the EL derivatives moving in lockstep to patch the kernel, .NET stack, and BIND DNS server across versions seven through ten. The sheer volume is exhausting, as identical .NET and BIND bumps hit four major distributions while Ubuntu shipped twelve separate advisories just for its kernel variants. Privilege escalation dominated the higher severity ratings, with critical patches targeting local trust boundaries in bubblewrap, systemd, haveged, and a lingering ProFTPD use-after-free on Slackware. The patch window is tight and the queue is long, so apply the kernel and network-stack updates first, verify your version numbers after reboot, and stagger your rollouts if you are running a multi-node cluster.





Weekly Linux Security Roundup: Kernel, .NET, and BIND Take the Hit Across Nearly Every Major Distro

The major Linux distributions delivered a synchronized wave of security errata this past week, targeting everything from privilege escalation flaws in systemd to memory corruption bugs in ProFTPD. If you are running anything from RHEL 7 to Ubuntu 26.04, your update queue just grew significantly.

AlmaLinux, Oracle Linux, Rocky Linux, and Red Hat itself moved in lockstep again, which is becoming the standard pattern for the EL family. The patches span versions seven through ten and hit the kernel, PostgreSQL, Python, PHP, and BIND hard. You will see the same advisory IDs bouncing across Alma, Oracle, Rocky, and RHEL, just with different package prefixes. It is the same underlying upstream code getting the same treatment across four different flavors.

.NET on Linux is clearly no longer an afterthought. .NET 8.0, 9.0, and 10.0 all received Important ratings across the RHEL-derivatives, SUSE, and Debian. Six years ago, treating .NET as a first-class security citizen on Linux felt ambitious. Now it is just Tuesday. BIND DNS server patches are everywhere too, with bind9.16, bind, and bind security updates hitting AlmaLinux, Rocky, RHEL, SUSE, and Debian. FreeRDP follows a similar pattern, with updates rolling out across Alma, Oracle, Rocky, RHEL, and SUSE. The recurring trio of .NET, BIND, and FreeRDP suggests upstream maintainers have been quietly knocking out fixes that distro security teams finally caught up to this cycle.

Memory corruption and privilege escalation dominated the higher severity ratings. Gentoo's GLSA batch specifically calls out root privilege escalation in Bubblewrap, privilege escalation in haveged, and improper header handling in HTTP-Daemon. Ubuntu's USN-8626-1 blocks three systemd vulnerabilities that could let local attackers terminate protected processes or crash core system services. Slackware's SSA:2026-227-01 fixes a use-after-free in ProFTPD triggered by the FTP STAT command. That is a notoriously nasty class of bug in legacy FTP servers, and the 1.3.9d release corrects how the daemon handles AllowForeignAddress during passive transfers. You probably do not run ProFTPD in 2026, but if you do, apply the patch before breakfast.

Secpin

Ubuntu, SUSE, and the Fedora Family

Ubuntu also closed a massive hole in the Axios HTTP client library. The update targets Node.js applications that rely on axios, and the CVE list is long enough to make library maintainers nervous. That said, the Linux kernel got the bulk of the attention, with separate advisories for default, Azure, OEM, Oracle, NVIDIA Tegra IGX, and HWE variants. If you are on cloud or edge hardware, your kernel update is probably mandatory.

SUSE Linux Enterprise 15 SP6 and SP7, along with openSUSE Leap and Tumbleweed, patched chromium, the Linux kernel, python311/312/313, ffmpeg-4, podman, bind, erlang26, openvpn, dracut, and rpm. The chromium patches alone carry critical and important ratings across multiple SUSE-SU and openSUSE-SU advisory numbers. Fedora 43 and 44 stayed quieter but still rolled out updates for suricata, clamav, domoticz, vaultwarden, sqlite, cri-o, stunnel, and a batch of Rust libraries. Debian and Freexian LTS covered Thunderbird, openjdk-25, wordpress, caddy, flatpak, python-django, spip, and util-linux.

Latest Security Updates by Distribution

Here’s a complete breakdown of the security updates for AlmaLinux, Debian GNU/Linux, Fedora Linux, Gentoo Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux.

AlmaLinux

AlmaLinux deployed multiple security update batches across operating system versions eight, nine, and ten. The initial rollout fixed command injection risks in GPSD, a double-free memory error in libarchive, and XFS data corruption, while also addressing flaws in Go, Tomcat, and Perl DBI. A second wave of advisories patched the Linux kernel, PostgreSQL, Firefox, iSCSI utilities, and the automatic bug reporting tool, followed by another series that covered vim, FreeRDP, Grafana, and the Xwayland display server, these errata resolve important and moderate vulnerabilities across .NET, BIND, and core system utilities to keep AlmaLinux installations secure.

Debian GNU/Linux

Debian and Freexian LTS released multiple security advisory batches across Bookworm and Trixie. The patches address dozens of CVEs across widely used software including Chromium, PostgreSQL, PHP, BIND9, Xorg, Kitty, and Xen. Attackers could exploit unresolved flaws to execute arbitrary code, bypass authentication, trigger stack buffer overflows, or perform SQL injection through malformed input. These advisories directly target race conditions, use-after-free memory errors, and certificate validation failures that previously allowed attackers to escalate privileges or crash mail and database services.

Fedora Linux

Fedora distributed coordinated security patches across Fedora 43 and Fedora 44. The release refreshes widely used software like the Linux kernel, Chromium browser, stunnel, and the Erlang web frameworks to close active exploits. Developers also received fixed versions of vaultwarden, sqlite, cri-o, and multiple Rust and Perl libraries to resolve memory corruption and denial of service flaws. The distribution spans antivirus scanners, home automation controllers, and multiple networking libraries, ensuring every flagged component receives an official fix.

Gentoo Linux

Gentoo Linux issued GLSA 202608-02 to patch nine CVEs in FreeType versions under 2.14.3, addressing out-of-bounds reads and information disclosure risks. Mid-month advisories also target seven widely used services including Bubblewrap, Apache HTTPD, Exim, Flatpak, Dnsmasq, libinput, and rsync, closing attack vectors like remote code execution and root privilege escalation. Separate notices fix a high-severity privilege escalation flaw in haveged that could grant local attackers root access, alongside an update for httpd. The distribution further resolved sandbox bypass vulnerabilities in the Portage package manager and patched multiple flaws in the NTFS-3G filesystem driver.

Oracle Linux

Oracle Linux distributed multiple security and maintenance update batches for operating system versions 7 through 10. Each advisory addresses critical vulnerabilities and resolves software bugs across core infrastructure and developer libraries. System administrators should apply the patches immediately to secure widely used components like the Unbreakable Enterprise Kernel, OpenJDK, BIND, Node.js, and FreeRDP.

Red Hat Enterprise Linux

Red Hat Product Security released a series of errata for Red Hat Enterprise Linux versions 7 through 10, patching security flaws across numerous widely used components. The advisories cover the Linux kernel, Python, Node.js, PostgreSQL, Firefox, Thunderbird, BIND, .NET, GStreamer, libgcrypt, and mod_md. Other critical updates target OpenShift Container Platform, JBoss Enterprise Application Platform, OpenStack Platform 16.2, and osbuild-composer, alongside fixes for Xwayland and various supporting packages. Red Hat assigned an Important impact rating to the majority of these patches, while moderate severity updates address python-idna, nghttp2, and gnome-remote-desktop within extended support streams.

Rocky Linux

Rocky Linux published a series of security advisories across versions 8, 9, and 10, addressing vulnerabilities in core system components and development tools. The updates include patches for the Linux kernel, vim, Python, PHP, .NET 8, .NET 9, and .NET 10, alongside fixes for BIND DNS, dracut, libarchive, and FreeRDP. High-availability cluster tools like fence-agents and resource-agents received updates, and the .NET 8.0 patch targets Rocky Linux 9 while .NET 9.0, .NET 10.0, bind, and dracut update Rocky Linux 8 systems. The errata also include updates for nodejs-nodemon on Rocky Linux 10, perl-DBI on Rocky Linux 8, and enhancements for Grafana, nghttp2, and GNOME Remote Desktop.

Slackware Linux

The Slackware Linux Security Team distributed new security packages for Slackware 15.0 and the -current branch to address multiple known vulnerabilities. Administrators should install the updated Expat XML parser and OpenSSH 10.5p1 builds to close reported security gaps. The rsync 3.5.0 update patches known vulnerabilities and resolves operational bugs for Slackware 15.0 systems. The ProFTPD 1.3.9d release fixes a critical use-after-free flaw triggered by the FTP STAT command and corrects how the server handles AllowForeignAddress settings during passive transfers.

SUSE Linux

SUSE has released multiple batches of security advisories addressing dozens of vulnerabilities across SUSE Linux Enterprise 15 SP6, SLES 15 SP7, openSUSE Leap, and openSUSE Tumbleweed. These patches target high-risk components including the Linux kernel, Python 3, Chromium, OpenSSH, Bind, Erlang26, FFmpeg, Podman, Node.js, RPM, OpenVPN, and Dracut. The updates prioritize fixes for active CVEs affecting core system packages and services to defend against known exploits. Administrators running SUSE platforms should apply these updates immediately to close security gaps associated with the disclosed flaws.

Ubuntu Linux

Ubuntu released a coordinated wave of security notices to patch critical flaws across systemd, ImageMagick, the Linux kernel, and several developer libraries. The systemd fixes block three vulnerabilities that could let local attackers escalate privileges, terminate protected processes, or crash core system services. Parallel updates resolve security gaps in the Yelp help browser, the node-follow-redirects module, the libgit2 library, and kernel versions spanning Ubuntu 16.04 onward. The same release also closes dozens of Axios HTTP client vulnerabilities to keep Node.js applications secure.

How to apply these Linux security updates

Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.

Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.

Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.

Debian/Ubuntu (apt)

The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.

sudo apt update
sudo apt upgrade -y

Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)

On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.

sudo dnf check-update
sudo dnf upgrade -y

or on older releases

sudo yum check-update
sudo yum update

SUSE (zypper)

SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.

sudo zypper refresh
sudo zypper update -y

Slackware (slackpkg and pkgtool)

Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.

sudo slackpkg update
sudo slackpkg upgrade-all

Gentoo Linux

Updating Gentoo Linux is more involved than binary distributions because it's a source-based system with highly customizable packages.

sudo emerge --sync
sudo emerge -avuDN @world