Nine major Linux distributions, AlmaLinux, Debian, Fedora, Oracle Linux, Red Hat, Rocky Linux, Slackware, SUSE, and Ubuntu, shipped security updates today. The headline stories are kernel roll-ups that close more than 1,100 CVEs in Oracle's Unbreakable Enterprise kernel and roughly 950 in Ubuntu's NVIDIA kernel. A set of recurring flaws forces attention too, including a Python certificate verification bypass, an OpenSSL DTLS stale-buffer fix, and glibc updates landing across AlmaLinux, Oracle, and Rocky. SUSE's pair of Chromium fixes at 246 CVEs each and a 9.2-rated fetchmail NTLM buffer overflow top the list, and the practical takeaway is the same everywhere: run your normal update and reboot, since kernel patches don't take effect until you restart.
Nine major Linux distros ship security updates today, led by kernel patches with more than a thousand CVEs
If you run anything from AlmaLinux to Ubuntu, you probably have some updating to do. Nine distributions rolled out security updates this week, and the biggest stories are kernel roll-ups that close more than a thousand vulnerabilities in a single advisory.
That's AlmaLinux, Debian, Fedora, Oracle Linux, Red Hat, Rocky Linux, Slackware, SUSE, and Ubuntu, in case you lost count somewhere along the way.
The kernel CVE counts that will make you blink
The standout in the whole batch is Oracle Linux 10. Its Unbreakable Enterprise kernel advisory (ELSA-2026-500374) is tagged Important and claims more than 1,100 CVEs, spanning CVE-2025-21817 to CVE-2026-98159. Don't do a double-take at that number. It's the normal RHEL upstream pattern, where a single kernel gets a decade's worth of backported fixes in a single day. Most of that volume is driver work, mostly the GVE network driver getting hammered at once, plus two genuine security issues in dm-integrity and the mana driver. There's also a pile of module-signing certificate rework you'll only appreciate if you boot with Secure Boot actually on.
Ubuntu's NVIDIA kernel is right behind it. USN-8875-2, aimed at NVIDIA 5.15 kernels on 22.04 LTS, patches roughly 950 vulnerabilities. USN-8887-3 comes in just under it at over 700. The batch covering GKE, IBM, NVIDIA, Oracle, and low-latency kernels (USN-8903-2) and the 6.8 GCP kernel (USN-8905-2) each sit around 230. The OEM kernel is a tidy 29, and BlueZ tops out at a manageable five.
For what it's worth, the counting is where the whole thing gets absurd. You want to reboot after any kernel change regardless, since the running kernel stays unpatched until you restart, but seeing half a kernel's worth of CVEs in one notice is a good reminder of how much the upstream tree has aged.
USN-8887-3 is the one notice that explains itself instead of burying you in numbers. Certain AMD processors skip a Reverse Map Table check when the IOMMU touches specific host buffers, which a local attacker with hypervisor access could use to break the integrity of AMD SEV-SNP guest memory (CVE-2023-20585). That's meaningful only if you run confidential-computing guests on AMD. The rest lean on the familiar "an attacker could compromise the system" line and move on.
The recurring flaws and the ones that actually bite
SUSE is the other place to look. Two critical updates push Chromium 155.0.8059.39 to stable, one for Backports SLE-15-SP7 (openSUSE-SU-2026:0347-1) and another for Leap 16.0 (openSUSE-SU-2026:22041-1). Each plugs 246 vulnerabilities, which is a long list even for a browser. The bugs are the expected kind: use-after-frees, memory corruption in ANGLE and V8, authorization gaps across a dozen subsystems, and a couple of integer overflows. Across all fifteen SUSE updates you're looking at roughly 531 CVEs, with the Chromium pair accounting for just over half of them on their own.
On the important tier, fetchmail is the scariest. SUSE-SU-2026:4604-1 fixes a 9.2-rated buffer overflow in NTLM authentication (CVE-2026-94184) that can hand an attacker remote code execution. php8 carries its own strangeness: a TLS check that falls back to Common Name when subjectAltName is missing, plus a partial IPv6 comparison that slips past access control.
AlmaLinux issued 20 security updates on October 9 across versions 8, 9, and 10. Fifteen are Important, five Moderate, and most of them will want a reboot if you run them in production. The one to read for is Dovecot. The AL10 errata (ALSA-2026:79371) packs eight CVEs, two of which are the real ones: an authentication bypass through faulty OAuth2 token validation and arbitrary code execution via a Sieve editheader use-after-free. Six reasons or eight, you don't need many to patch a mail server.
The kbd update on AL8 bites closer to home. It closes a local privilege escalation in openvt (CVE-2026-72693) that lets someone log in as root without a password, which matters more than most of the remote Denial-of-Service tweaks on the list. FreeRDP also came through hard, with five issues including two remote code executions. Grab that one if you connect to RDP servers at all.
Keep in mind that several flaws recur across the batch, which is standard for a coordinated refresh. The Python certificate verification bypass (CVE-2026-19553) and use-after-free (CVE-2026-19445) turn up in python3.12 and python3.14 across AlmaLinux, Oracle, and Rocky. The OpenSSL DTLS stale-buffer fix (CVE-2026-84782) lands on those same three, and glibc shows up on AL9 and AL10 with an added strfmon buffer overflow on AL10.
Debian shipped just three updates this week, and you'd be wise to apply the first and last before doing much else. The xz-version advisory is the one worth a second glance. An invalid write could trigger memory corruption, and there's no CVE attached, just a GHSA reference. Given the trouble xz-utils had last year, the missing number is a little suspicious, but it's still an Extended LTS fix on bullseye, so treat it as worth doing anyway.
The smaller players moved quietly. Fedora rolled out four updates within the same hour on October 10, and php-getid3 is the one worth noticing since it shuts down an XML external injection vector hiding behind a silent failure in libxml. Slackware shipped only mutt 2.4.3, closing an out-of-bounds write (CVE-2026-107570) in convert_file_from_to() that only really bites if you run mutt in template mode and open a dodgy message. Not the kind of thing you hit by merely reading mail.
Red Hat pushed five kernel advisories, all rated Important, but aimed squarely at older LTS flavors: 8.8 SAP, 8.6 Advanced Mission Critical, 8.4 AMC, 9.6 EUS, and 9.4 SAP. That's the crowd still sitting on a slightly dated kernel. Rocky's 17 advisories split 13 Important, with kernel and Python recurring across RL8 through RL10. Only httpd is filed as a bugfix and rated Low, so that one can wait for a maintenance window rather than waking you at 3 a.m.
Here's the odd one out that made me pause mid-write. Oracle Linux 10's tzdata advisory (ELBA-2026-77613) moves Manitoba to a permanent -05 offset starting October 31. It's arguably the most surprising headline on the whole batch, and you'll never find it in a vulnerability tracker.
What you should do is fairly routine. Pull the latest packages from your distro's errata portal and run your normal update, then reboot for any kernel change since the running kernel stays unpatched until you restart. Ubuntu's notice also flags an ABI change, meaning third-party DKMS modules have to be recompiled and reinstalled. A normal upgrade handles the metapackages for you unless you manually stripped them out. And the older BlueZ releases on 16.04, 18.04, and 20.04 only exist under Ubuntu Pro, so patching those needs the paid support tier.
A Detailed Breakdown of the Updates
AlmaLinux
AlmaLinux issued 20 security updates on October 9 across versions 8, 9, and 10. Fifteen carry an "Important" rating and five are "Moderate," and if you run any of this in production, most of them deserve the reboot.
Dovecot is the one that stands out. The AL10 errata (ALSA-2026:79371) packs eight CVEs, and two are the ones you actually read for: an authentication bypass through faulty OAuth2 token validation, and an arbitrary code execution via a Sieve editheader use-after-free. The other six are denial-of-service tweaks, but you do not need eight reasons to patch an email server.
The kernel update (ALSA-2026:77690) is nearly as busy with sixteen CVEs spanning vsock, NFSD, NFS, igc, and a pair of AMD SEV/KVM issues, plus a driver bump and some NVIDIA firmware interface work. It is doing more than patching holes.
A few things recur across the batch, which is standard for a coordinated refresh. The Python SSL hole (CVE-2026-19553, a certificate verification bypass in wrap_bio, and a use-after-free on CVE-2026-19445) turns up in both python3.12 and python3.14 on AL9 and AL10, and the openssl DTLS fix (CVE-2026-84782) shows up on both AL9 and AL10. glibc lands on AL9 and AL10, with the AL10 note (ALSA-2026:76781) adding a strfmon buffer overflow on top of the wordexp and tilde-expansion fixes.
The kbd update on AL8 is the one that bites close to home. It closes a local privilege escalation in openvt that lets someone log in as root without a password, which matters more than any remote DoS on the list. FreeRDP (ALSA-2026:76755) came through hard too, with five issues including two remote code executions, so if you connect to RDP servers at all, grab that one.
| Errata | Package | OS Version | Severity | Key Fixes |
|---|---|---|---|---|
| ALSA-2026:79281 | glibc | 9 | Moderate | 6 CVEs: tilde-expansion DoS, wordexp abort, tdelete out-of-bounds, two SHIFT_JISX0213 non-progress DoS, fopen mode heap overflow; stops shipping glibc32-debuginfo |
| ALSA-2026:76755 | FreeRDP | 9 | Important | 6 CVEs: DoS via Surface Bits, RCE via Server Redirection PDU, DoS via URBDRC read, RCE uninitialized heap, DoS RPC gateway over-read, heap overflow LB_LOAD_BALANCE_INFO |
| ALSA-2026:77396 | openssl | 9 | Important | DTLS retransmits handshake messages from a stale buffer offset (CVE-2026-84782) |
| ALSA-2026:77017 | python3.12 | 9 | Important | Cert verification bypass in wrap_bio (CVE-2026-19553); use-after-free SSLContext via sni_callback (CVE-2026-19445) |
| ALSA-2026:79177 | mod_auth_openidc | 9 | Important | DoS via malformed state cookie parsing (CVE-2026-54789) |
| ALSA-2026:76760 | perl-DBI | 9 | Important | DoS via invalid memory read during numeric type casting (CVE-2026-88815) |
| ALSA-2026:77021 | python3.14 | 9 | Important | Same two CVEs as python3.12 (cert bypass, use-after-free) |
| ALSA-2026:78952 | tftp | 8 | Moderate | DoS via out-of-bounds read/write in remap engine (CVE-2026-85234) |
| ALSA-2026:79113 | bind9.16 | 8 | Important | 3 CVEs: DoS via 16-bit length truncation, crafted DNSSEC reply, malformed DNS64; plus SIGSEGV crash fix |
| ALSA-2026:79162 | bind | 8 | Important | Same three CVEs as bind9.16 (no extra bug fix) |
| ALSA-2026:78951 | kbd | 8 | Moderate | Local privilege escalation in openvt allowing passwordless root login (CVE-2026-72693) |
| ALSA-2026:77648 | dogtag-pki | 10 | Important | CPU DoS via unbounded numeric parsing in jackson-databind (CVE-2026-68497) |
| ALSA-2026:76781 | glibc | 10 | Moderate | 4 CVEs: wordexp abort, tilde-expansion DoS, strfmon buffer overflow, tdelete out-of-bounds; plus iconv exit-status, counter-overflow, and fcntl.h conflict fixes |
| ALSA-2026:79122 | cjose | 10 | Important | Heap buffer overflow in AES Key Wrap decryption (CVE-2026-53938) |
| ALSA-2026:79371 | dovecot | 10 | Important | 8 CVEs: auth bypass via OAuth2, RCE via Sieve editheader use-after-free, five DoS variants, and wrong MySQL multi-byte escaping |
| ALSA-2026:77020 | python3.12 | 10 | Important | Same two CVEs as python3.12 (cert bypass, use-after-free) |
| ALSA-2026:77690 | kernel | 10 | Important | 16 CVEs across vsock, NFSD, NFS, igc, ipvlan, udp, and KVM SEV; plus mlxbf_bootctl driver bump and NVIDIA GNR interface fixes |
| ALSA-2026:77018 | python3.14 | 10 | Important | Same two CVEs as python3.12 (cert bypass, use-after-free) |
| ALSA-2026:77534 | sssd | 10 | Moderate | IdP authentication prefix comparison allows cross-user impersonation (CVE-2026-87853) |
| ALSA-2026:76918 | openssl | 10 | Important | Same DTLS fix as AL9 (CVE-2026-84782) |
Debian GNU/Linux
Three Debian security updates went out this week, and you'd be wise to apply the first and last before doing much else on your machine.
The bootstrap fix is the most mundane of the group. twitter-bootstrap3, which somehow still hangs around despite being well past its shelf life, had an XSS hole in its Popover and Tooltip components where unsanitized HTML could slip through. That's CVE-2025-1647, and the patched build for Debian 12 bookworm is 3.4.1+dfsg-3+deb12u2. One practical wrinkle: if you pull bootstrap in through a module bundler, expect to rebuild your application after upgrading.
The xz-utils advisory is the one worth a second glance. An invalid write could trigger memory corruption in certain situations, and there's no CVE attached, just a GHSA reference. The absence of a number is a little suspicious given the trouble xz-utils had last year, but it's still an Extended LTS fix on bullseye (5.2.5-2.1~deb11u3), so treat it as worth doing anyway.
Ghostscript closes out the batch with the least pleasant combination: two CVEs that open the door to denial of service and possibly arbitrary code execution if you happen to process a malformed document. Trixie gets the fix at 10.05.1~dfsg-1+deb13u3.
| Package | Fixed version | Distribution | CVE(s) | Vulnerability |
|---|---|---|---|---|
| twitter-bootstrap3 | 3.4.1+dfsg-3+deb12u2 | Debian 12 (bookworm) | CVE-2025-1647 | XSS in Popover and Tooltip |
| xz-utils | 5.2.5-2.1~deb11u3 | Debian 11 (bullseye, Extended LTS) | None (GHSA-5qpq-xqfv-j9pg) | Memory corruption from an invalid write |
| ghostscript | 10.05.1~dfsg-1+deb13u3 | Debian stable (trixie) | CVE-2026-101258, CVE-2026-103226 | Denial of service and possible arbitrary code execution |
Fedora Linux
Fedora pushed four security-flavored package updates to Fedora 43 and 44, and they all rolled out within the same hour on October 10th. Two of them, openbao and php-getid3, actually carry GHSA security advisories, which is the part worth paying attention to. The php-getid3 patch is the more interesting one: one of its fixes shuts down an XML external injection vector that was hiding behind a silent failure in libxml, so a crafted media file could otherwise play games with you. OpenVPN's 2.7.8 bump looks more like a routine version update than an emergency patch. And openbao just sweeps up a pile of security notices into a single release. Nothing here needs you to lose sleep, but the php-getid3 issue is the kind of thing you'd want squashed before feeding it an unknown file.
| Package | Version | Fedora | Advisory ID | What changed |
|---|---|---|---|---|
| openbao | 2.6.4-1.fc43 | 43 | FEDORA-2026-12caf78d6a | Upstream 2.6.4; multiple GHSA security notices |
| php-getid3 | 1.9.27-1.fc43 | 43 | FEDORA-2026-b9ef1180ce | Upstream 1.9.27; GHSA fixes for compressed ID3v2 frame length, corrupt embedded WMA pictures, and XXE via libxml |
| openvpn | 2.7.8-1.fc44 | 44 | FEDORA-2026-eed9c789d3 | Upstream 2.7.8 release (routine version bump) |
| php-getid3 | 1.9.27-1.fc44 | 44 | FEDORA-2026-71df118e18 | Same 1.9.27 security fixes shipped for Fedora 43 |
Oracle Linux
Oracle Linux 10 just got a wide stack of errata, and if you run that release you have some updating to do. The advisory worth opening first is OpenSSL 3.5.8, which closes a DTLS handshake bug where retransmitted handshake messages get read from a stale buffer offset (CVE-2026-84782). You probably don't call openssl by hand much, but your package manager takes care of this. The same fix ships on OpenSSL for Oracle Linux 9.
The two kernel rollups are the ones that will make you block off time. The Unbreakable Enterprise kernel advisory (ELSA-2026-500374) is tagged Important and resolves a wall of more than 1,100 CVEs, ranging from CVE-2025-21817 to CVE-2026-98159. Don't do a double-take at the count, since it's the normal RHEL upstream pattern. Most of that volume is driver work, mostly the GVE network driver getting hammered with fixes at once, plus two genuine security issues in dm-integrity and the mana driver. That advisory also bundles a pile of module-signing certificate rework, which you'll only appreciate if you boot with Secure Boot actually on.
Python had its quarterly patch day. Oracle shipped Python 3.12.15 for OL9 and OL10, and Python 3.14.8 for OL8, OL9, and OL10, all taking the same batch of upstream security fixes. If you're developing on 3.14, that lands you at 3.14.8.
Dovecot is the OL10 item that bites people running a mail server. The advisory stacks up seven fixes, including a use-after-free and information leak in the sieve editheader extension, alongside denial-of-service and memory-exhaustion problems across ManageSieve and pre-login commands.
The rest of the OL10 advisory is lighter: SSSD with an IDP prefix-match bypass worth patching promptly, cjose with a heap buffer overflow in AES key unwrap, dogtag-pki, sequoia-sq (which now aliases ML-DSA keys during key generation), and tzdata moving Manitoba to a permanent offset. The timezone change is arguably the most surprising headline on this whole release.
Oracle Linux 8 and 9 weren't spared either. OL8 picked up Firefox 140.17.0 ESR, Node.js 24.21.0, bind 9.11.36, tftp, Ruby 2.5.9, and a pki-core rebase, while OL9 got its OpenSSL and both Python versions. tzdata updated on both OL8 and OL10 under a shared advisory id, so Manitoba gets its time zone fixed in one place.
| Advisory | Release | Package | Severity | Latest version | What's fixed |
|---|---|---|---|---|---|
| ELSA-2026-76918 | OL10 | openssl | Important | 3.5.8-2.0.1 | CVE-2026-84782 DTLS retransmit stale-buffer fix |
| ELSA-2026-500374 | OL10 | UEK kernel 6.12 | Important | 6.12.0-207.111.5.1 | 1,100+ CVEs (2025-21817 to 2026-98159); GVE driver churn, dm-integrity and mana security fixes, signing cert work |
| ELSA-2026-79371 | OL10 | dovecot | Important | 2.3.21-19.8 | CVE-2026-27852, 33263, 33605, 40018, 40019, 42007, 42391, 73208 |
| ELSA-2026-79122 | OL10 | cjose | Important | 0.6.2.2-7.1 | CVE-2026-53938 heap buffer overflow in AES key unwrap |
| ELSA-2026-77534 | OL10 | sssd | Moderate | 2.12.0-3.0.1 | CVE-2026-87853 IDP prefix-match bypass; sudo and GPO kerberos bypass fixes |
| ELSA-2026-77020 | OL10 | python3.12 | Important | 3.12.15-1.0.1 | CVE-2026-15310, 15806, 17084, 19445, 19553, 19672, 82049, 87910 |
| ELSA-2026-77648 | OL10 | dogtag-pki | Important | 11.9.0-6.0.1 | CVE-2026-68497; jackson bumped to 2.21.6; OL treated like RHEL for Tomcat |
| ELSA-2026-76737 | OL10 | rust-sequoia-sq | Important | 1.4.0.1-2.0.1 | CVE-2026-42784; ML-DSA key-generation alias; hard openssl-libs dependency |
| ELSA-2026-77018 | OL10 | python3.14 | Important | 3.14.8-1 | CVE-2026-15310, 15806, 17084, 19445, 19553, 19672, 82049 |
| ELSA-2026-75576 | OL10 | kernel 6.12 | Important | 6.12.0-211.62.1 | CVE-2026-64034 (mana) and 72099 (dm-integrity); large GVE driver update |
| ELBA-2026-77613 | OL10 | tzdata | Bug fix | 2026e-1 | Manitoba moves to permanent -05 on 2026-10-31 |
| ELSA-2026-77021 | OL9 | python3.14 | Important | 3.14.8-1 | CVE-2026-15310, 15806, 17084, 19445, 19553, 19672, 82049 |
| ELSA-2026-77017 | OL9 | python3.12 | Important | 3.12.15-1.0.1 | CVE-2026-15310, 15806, 17084, 19445, 19553, 19672, 82049, 87910 |
| ELSA-2026-77396 | OL9 | openssl | Important | 3.5.8-2.0.1 | CVE-2026-84782 DTLS retransmit fix |
| ELSA-2026-79162 | OL8 | bind | Important | 9.11.36-16 | CVE-2026-19666, 19667, 80274 (dns64 assertion, wildcard crash, oversized negative cache) |
| ELSA-2026-78952 | OL8 | tftp | Moderate | 5.2-28 | CVE-2026-85234 buffer overflow in remap genmatchstring with inverse rules |
| ELSA-2026-76850 | OL8 | firefox | Important | 140.17.0-1 | Long CVE list (92035, 96869, 100756-100832); ESR update with OpenELA debranding |
| ELSA-2026-75573 | OL8 | pki-core:10.6 | Important | 10.15.1-3 | CVE-2026-76561 executable allow-list; JSS/LDAP SDK/TomcatJSS rebase |
| ELSA-2026-74085 | OL8 | nodejs:24 | Important | 24.21.0-1 | CVE-2026-19534, 84961, 85152; also sqlite and nghttp2 backports |
| ELBA-2026-77613 | OL8 | tzdata | Bug fix | 2026e-1.0.1 | Manitoba permanent -05; obsolescent TZ settings conformed to POSIX |
| ELSA-2026-73519 | OL8 | ruby:2.5 | Important | 2.5.9-114 | CVE-2026-80212, 88030 (mongo query-operator injection); regexec integer-overflow fix |
Red Hat Enterprise Linux
Red Hat just pushed a batch of kernel security patches, and if you're running anything near these versions, it's worth your attention. Five separate advisories went out, all rated "Important" severity by Red Hat's Product Security team—meaning real vulnerabilities were closed off, not just routine housekeeping. CVSS scores sit behind the CVE links in each advisory's references if you want to eyebow the specifics.
The interesting thing here is how these span both the 8.x and 9.x lines, and they're aimed at the older, long-term support flavors more than the current mainstream releases. That's the crowd most likely to still be sitting on a slightly dated kernel.
| Advisory | Affected platforms | Severity |
|---|---|---|
| RHSA-2026:79782 | RHEL 8.8 Update Services for SAP Solutions; RHEL 8.8 Telecommunications Update Service | Important |
| RHSA-2026:79783 | RHEL 8.6 Advanced Mission Critical Update Support; RHEL 8.6 Extended Update Support Long-Life Add-On | Important |
| RHSA-2026:79778 | RHEL 8.4 Advanced Mission Critical Update Support; RHEL 8.4 Extended Update Support Long-Life Add-On | Important |
| RHSA-2026:79784 | RHEL 9.6 Extended Update Support | Important |
| RHSA-2026:79786 | RHEL 9.4 Update Services for SAP Solutions | Important |
Rocky Linux
Rocky Linux just pushed another batch of errata, and if you're running anything from RL8 through RL10, there's a decent chance you owe a reboot. The bulk of it is security work, though a couple of entries are the less exciting "bug fix and enhancement" variety.
Thirteen of the seventeen advisories land at the "Important" severity tier, which for Rocky's scale usually means remotely exploitable flaws rather than the kind of thing that only bites you if you've locked yourself in a room with root access. The kernel keeps showing up across all three releases, so if you haven't rebooted recently, this is the reminder. Python is also a recurring theme, with python3.12 and python3.14 each getting updates on multiple versions.
The one entry worth a raised eyebrow: the httpd advisory is filed as an RLBA, not an RLSA, and rated just "Low." That's the bugfix-and-enhancement batch, so unless your web server is acting up, this is the item you can schedule for a maintenance window rather than the one that wakes you at 3 a.m.
| Advisory | Package | Severity | Release | Type |
|---|---|---|---|---|
| RLSA-2026:77500 | kernel-rt | Important | RL8 | Security |
| RLSA-2026:79113 | bind9.16 | Important | RL8 | Security, bug fix, enhancement |
| RLSA-2026:78952 | tftp | Moderate | RL8 | Security |
| RLSA-2026:77498 | kernel | Important | RL8 | Security |
| RLSA-2026:78951 | kbd | Moderate | RL8 | Security |
| RLSA-2026:79162 | bind | Important | RL8 | Security |
| RLSA-2026:77648 | dogtag-pki | Important | RL10 | Security |
| RLSA-2026:77020 | python3.12 | Important | RL10 | Security |
| RLBA-2026:50158 | httpd | Low | RL10 | Bug fix, enhancement |
| RLSA-2026:77690 | kernel | Important | RL10 | Security, bug fix, enhancement |
| RLSA-2026:77534 | sssd | Moderate | RL10 | Security |
| RLSA-2026:77018 | python3.14 | Important | RL10 | Security |
| RLSA-2026:77021 | python3.14 | Important | RL9 | Security |
| RLSA-2026:77396 | openssl | Important | RL9 | Security |
| RLSA-2026:77017 | python3.12 | Important | RL9 | Security |
| RLSA-2026:77689 | kernel | Important | RL9 | Security, bug fix, enhancement |
| RLSA-2026:79177 | mod_auth_openidc | Important | RL9 | Security |
Slackware Linux
Slackware shipped a security update for mutt, targeting 15.0 and -current. The fix is in version 2.4.3, and it closes an out-of-bounds write that only really bites if you do something a little unusual: run mutt in template mode and open a dodgy message.
The flaw lives in the convert_file_from_to() function, and it's tripped by a specially crafted Content-Type header. Push someone a message that looks fine but gets pulled in as a template, and you can trigger memory corruption and application instability. It's not the kind of thing you hit by merely reading mail normally, but you're still told to patch it anyway, which is fair when the fix is a one-liner upgrade.
Installation is the usual Slackware ritual: grab the .txz, run upgradepkg as root, and call it a day.
| Package | Version | Advisory | CVE | Affected platforms | Type | Vulnerability |
|---|---|---|---|---|---|---|
| mutt | 2.4.3 | SSA:2026-282-01 | CVE-2026-107570 | Slackware 15.0 and -current | Security fix | Out-of-bounds write in convert_file_from_to() triggered by a malicious Content-Type header when an email is used as a template; can lead to memory corruption and app instability |
SUSE Linux
Fifteen security updates landed across SUSE Linux Enterprise, openSUSE Leap, and openSUSE Tumbleweed, and two of them are dominated almost entirely by how many CVEs they cram into a single release.
Two critical updates both point at the same Chromium, and both push 155.0.8059.39 to stable. openSUSE-SU-2026:0347-1 hits Backports SLE-15-SP7 and openSUSE-SU-2026:22041-1 hits Leap 16.0. Each one plugs 246 vulnerabilities, which is a long list even for a browser. The bugs themselves are the expected kind: use-after-frees, memory corruption in ANGLE and V8, authorization gaps spread across a dozen subsystems, a couple of integer overflows. You want this on any Chromium you run.
On the important side, three server packages get patched. The bind update (SUSE-SU-2026:4608-1) climbs to 9.18.50 and closes 10 resolver holes, several use-after-frees and amplification vectors that mostly amount to denial of service. php8 (SUSE-SU-2026:4603-1) reaches 8.2.34 with 10 fixes, including some stranger ones: a TLS check that falls back to Common Name when subjectAltName is missing, and a partial IPv6 comparison that lets you slip past access control. The fetchmail fix (SUSE-SU-2026:4604-1) is the scariest on paper, a 9.2-rated buffer overflow in NTLM auth that can hand an attacker remote code execution.
The remaining dozen are moderate, all Tumbleweed packages shipped on general availability media, and mostly the kind of single- or double-digit-CVE fixes you'd expect from routine maintenance. yast2-users (SUSE-SU-2026:11978-1) at 8.0 and shadowsocks-rust (SUSE-SU-2026:11976-1) at 8.7 are the loudest of the group. dash, trivy, expat, ccache, and a few Python libraries round out the list with quieter numbers.
Across all fifteen, that's roughly 531 CVEs being addressed, and the chromium pair alone account for just over half of them.
| Announcement ID | Software | Rating | # CVEs | Notable CVEs / notes | Affected product | Version |
|---|---|---|---|---|---|---|
| openSUSE-SU-2026:0347-1 | chromium | critical | 246 | Use-after-free, memory corruption, auth gaps (CVE-2026-106179 through 106427) | Backports SLE-15-SP7 | 155.0.8059.39 |
| openSUSE-SU-2026:22041-1 | chromium | critical | 246 (+1 bugfix) | Same Chromium fix as above | Leap 16.0 | 155.0.8059.39 |
| openSUSE-SU-2026:11980-1 | dash | moderate | 1 | CVE-2026-102474 (4.0) | Tumbleweed | 0.5.13.5 |
| openSUSE-SU-2026:11977-1 | trivy | moderate | 1 | CVE-2026-53495 (5.5) | Tumbleweed | 0.75.0 |
| openSUSE-SU-2026:11975-1 | python312 | moderate | 4 | CVE-2026-15310, 15806, 17084, 19672 | Tumbleweed | 3.12.14 |
| openSUSE-SU-2026:11979-1 | ccache | moderate | 2 | CVE-2026-77341 (5.3), CVE-2026-77358 (5.0) | Tumbleweed | 4.14.1 |
| openSUSE-SU-2026:11976-1 | shadowsocks-rust | moderate | 1 | CVE-2026-93599 (7.5) | Tumbleweed | 1.25.0 |
| openSUSE-SU-2026:11981-1 | expat | moderate | 2 | CVE-2026-102633 (5.9), CVE-2026-93990 (5.3) | Tumbleweed | 2.8.5 |
| openSUSE-SU-2026:11978-1 | yast2-users | moderate | 1 | CVE-2026-59680 (8.0, local privilege escalation) | Tumbleweed | 5.0.9 |
| openSUSE-SU-2026:11974-1 | python313-virtualenv | moderate | 4 | CVE-2024-9287, 102925, 102930, 102938 | Tumbleweed | 21.14.2 |
| openSUSE-SU-2026:11973-1 | python313-oauthlib | moderate | 1 | CVE-2026-49264 (4.7) | Tumbleweed | 4.0.0 |
| openSUSE-SU-2026:11972-1 | python313-jwcrypto | moderate | 1 | CVE-2026-92091 (5.3) | Tumbleweed | 1.6.1 |
| SUSE-SU-2026:4603-1 | php8 | important | 10 | TLS cert impersonation (CVE-2026-91769), IPv6 access-control bypass (CVE-2026-91768), TAR injection (CVE-2026-6103) | Leap 15.6, SLES 15 SP6 | 8.2.34 |
| SUSE-SU-2026:4604-1 | fetchmail | important | 1 | CVE-2026-94184 (9.2, NTLM buffer overflow, RCE) | Leap 15.6, SLES 15 SP6/SP7, others | 6.4.22 |
| SUSE-SU-2026:4608-1 | bind | important | 10 | Use-after-frees, amplification, DoS (CVE-2026-19033, 19662, 19666, 19667, 19941, 75029, 78301, 80274, 81563, 81736) | Leap 15.6, SLES 15 SP6 | 9.18.50 |
Ubuntu Linux
Ubuntu pushed a pile of security notices out the door, and if any of your machines run a cloud kernel, the low-latency build, or NVIDIA's kernel, this is a reboot you'll want to schedule this week.
Six Ubuntu Security Notices went out. Five touch the Linux kernel and one takes aim at BlueZ, the software behind Bluetooth. Four of the kernel notices target 24.04 LTS, two also reach back to 22.04 LTS, and the BlueZ notice casts the widest net, covering everything from 16.04 to 26.04.
The notices don't exactly gloat. USN-8887-3 actually describes a problem: certain AMD processors skip a Reverse Map Table check when the IOMMU touches specific host buffers, which a local attacker with hypervisor access could abuse to break the integrity of AMD SEV-SNP guest memory (CVE-2023-20585). That's meaningful if you run confidential-computing guests on AMD. The rest lean on the familiar "an attacker could use these to compromise the system" line and then bury you in CVE numbers.
The counting is where it gets absurd. USN-8875-2, aimed at NVIDIA kernels on 22.04, patches roughly 950 vulnerabilities. USN-8887-3 comes in just under it at more than 700. The batch covering GKE, IBM, NVIDIA, Oracle, and low-latency kernels (USN-8903-2) and the 6.8 GCP kernel (USN-8905-2) each sit around 230. The OEM kernel (USN-8911-1) is a tidy 29, and BlueZ tops out at a manageable five.
BlueZ is the one notice that explains itself, and it's worth a closer look since the issues are concrete. One flaw in A2DP codec handling overflows the stack and can run arbitrary code (CVE-2026-19774). Another misjudges packet length and leaks memory (CVE-2026-75032). There's also crafted XML that crashes the daemon, a malformed extended inquiry name that overflows the stack again, and a sloppy AVRCP parse that reads past its buffers. All five hit six Ubuntu releases.
The practical side is fairly routine. You'll need to reboot after the standard update for any kernel change, since the running kernel stays unpatched until it restarts. The notices also flag an ABI change, which means third-party modules like DKMS drivers have to be recompiled and reinstalled. A normal upgrade handles the metapackages for you unless you manually stripped them out. The older BlueZ releases on 20.04, 18.04, and 16.04 only exist under Ubuntu Pro, so patching those requires the paid support tier.
| Notice | Package(s) | Ubuntu versions | Scope |
|---|---|---|---|
| USN-8887-3 | linux-gcp-7.0, linux-hwe-7.0, linux-oracle-7.0 | 24.04 | AMD SEV-SNP RMP check (CVE-2023-20585) plus 700+ more |
| USN-8903-2 | linux-gke, linux-gkeop, linux-ibm, linux-lowlatency, linux-nvidia, linux-oracle | 24.04, 22.04 | ~230 CVEs |
| USN-8875-2 | linux-nvidia (5.15) | 22.04 | i.MX clock deref (CVE-2022-3114) plus ~950 total |
| USN-8905-2 | linux-gcp (6.8) | 24.04 | ~230 CVEs |
| USN-8911-1 | linux-oem-6.17 | 24.04 | 29 CVEs |
| USN-8908-1 | bluez | 26.04, 24.04, 22.04, 20.04, 18.04, 16.04 | 5 CVEs (buffer overflows, memory leaks, crashes) |
How to apply these Linux security updates
Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.
Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.
Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.
Debian/Ubuntu (apt)
The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.
sudo apt update sudo apt upgrade -y
Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)
On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.
sudo dnf check-update sudo dnf upgrade -y
or on older releases
sudo yum check-update sudo yum update
SUSE (zypper)
SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.
sudo zypper refresh sudo zypper update -y
