Ubuntu, Red Hat, SUSE and other major Linux distros shipped another wave of security patches dominated by kernel and browser fixes. Oracle Linux leads the chaos with a Critical webkit2gtk3 update carrying 323 CVEs, while SUSE announced twenty advisories wrapping roughly 182 vulnerabilities. Chromium recurs across the board with a 32-CVE patch, and several fixes including libvirt, ghostscript and libpcap echo across multiple distros. You should patch first if you're on Oracle's webkit engine or SUSE's pcre2 build, and take SUSE's cumulative kernel live patches as newest-of-family updates.
Linux distros ship another week of security fixes, with webkit carrying 323 CVEs
Ubuntu, Red Hat, SUSE, and a dozen others all shipped patches. The counts are climbing, and this week pulls ahead. Somewhere in the shuffle sits a browser engine with 323 vulnerabilities, a Chromium build with 32, and a SUSE batch that claims 182 individual problems.
Oracle Linux is where you'll find the standouter. Its webkit2gtk3 advisory (ELSA-2026-74084) jumps to 2.54.0 and carries 323 CVEs tagged Critical. That's a browser engine most people never think about unless their box is on fire, and 323 outclasses just about everything else on the board. Fix it before you fix much else.
SUSE went the other way, chasing volume instead of severity. Its October 5th batch of twenty announcements wraps roughly 182 vulnerabilities across openSUSE Tumbleweed, Leap, and SUSE Linux Enterprise. Only one reaches Critical, and it's the usual monthly Chromium fix at 154.0.8037.92.
Keep in mind that a good chunk of those 182 SUSE numbers overlap, so the real distinct problem count sits well under that figure. Still, it's a wall you have to walk through.
The Chrome problem keeps recurring across every distro this week. Fedora 43 shipped three updates in one batch, and the chromium one is the long. Google bundles upstream issues into a handful of advisories, but Fedora spells out each of the 32. Type confusion in V8 leads with five hits, use-after-free bugs fill half a dozen components, and authorization failures round things out across Payments, CORS, WebView and SiteIsolation. On Chrome's upstream build you're already covered. On open-source Chromium, it's time to move.
That same 154.0.8037.92 browser shows up again in SUSE's Critical slot, so you're not imagining it. Chrome collects front-page exploits every month and this month is no exception.
The kernel keeps doing all the work
Kernel updates are the honest reason most of these tallies exist. AlmaLinux rolled out a batch split between versions 10 and 9, and more than three-quarters of its roughly 75 CVEs are kernel fixes. The biggest single advisory, ALSA-2026:71602, alone packs 22 fixes spanning amdgpu out-of-bounds reads, a PPPoE memory-corruption bug, and an nvme-tcp disclosure that would leak host RAM on a read command. Grab that one first.
Several of those dates are stamped 2026, meaning some advisories are riding forward-looking identifiers while the release dates all sit in early October 2026. Not much to do about it beyond apply the patch, but if your pipeline ever chokes on unknown CVE years you now know where the noise comes from.
Ubuntu leans on kernels too. Its Raspberry Pi update (USN-8871-1) plugs an ARM64 flaw where broadcast TLB invalidation could finish before memory writes were globally observed. A local attacker could then write to memory after permissions were pulled back. That's the quiet kind of bug that hands over elevated access without much fanfare.
The Azure kernel update (USN-8851-3) is smaller, three issues in the NFS server, IPv6 and Netfilter. Note the ABI change, though, since any third-party modules you built yourself will need recompiling after you upgrade.
Things past the browser worth chasing
SUSE's batch has a few real standouts beyond Chrome. pcre2 carries the top scores, two 9.2-rated out-of-bounds writes under CVE-2026-89157 and CVE-2026-89158. If your build chain compiles against PCRE2, run this one now. The lone valkey entry, CVE-2026-92925, is a 7.1 out-of-bounds read in the cluster bus parser, which bites if you run a Redis-compatible store in a cluster.
Then there's the kernel live-patch pileup. SLE 15 SP5 alone gets four separate announcements, Live Patches 39, 41, 43 and 44. SP7 gets two, SP6 gets one. They're cumulative, so the newest patch in each family already covers the earlier CVEs. Apply the latest of each family and don't treat them as separate fixes. SUSE does like to slip in an extra fix now and then too, and rpm quietly closed a leaked libelf handle that breaks NFS buildroots along with its security patch.
Red Hat kept everything at Important rather than Critical, 22 advisories across RHEL. A few touch the stuff that actually bites: sudo, bind, kernel, libvirt. Most of the attention lands on RHEL 10, and there's a lone Single Sign-On entry still targeting OpenShift Container Platform 3.10 and 3.11, old enough that you may want to check whether you're actually running something that far behind.
Debian brought the biggest single advisory with perl (DLA-4821-1), 13 CVEs including heap overflows, code execution, and some oddly sneaky problems like silently wrong regular-expression matches. If you parse archives or compile regexes on 32-bit systems, that batch wants your attention. One wrinkle worth flagging: the Archive::Tar fix broke libmodule-cpants-analyse-perl's test suite, so Debian published a follow-up (DLA-4821-2) the very next day.
The rest is smaller housekeeping. Slackware issued a 13-issue CUPS bump (SSA:2026-278-01) for its print server, Rocky Linux shipped two Important errata for version 8 covering pki-core and nodejs:22, and the libvirt, ghostscript JPEG 2000, and libpcap BPF fixes all echo across multiple distros, which is just the sane way to do this.
A Detailed Breakdown of the Updates
AlmaLinux
AlmaLinux rolled out a batch of errata this week split between AlmaLinux 10 and 9, and the kernel is doing most of the work. Six advisories hit version 10, four landed on 9, and between them they carry about 75 CVEs. More than three-quarters of those are kernel fixes, a tally that should tell you exactly where the security work actually landed. Kernel updates have a habit of showing up in just about every round, and this week is no exception.
Those kernel hauls are spread across four separate releases, so you won't get one clean update if you're watching this closely. The biggest, ALSA-2026:71602, alone packs 22 fixes spanning amdgpu out-of-bounds reads, a PPPoE memory-corruption bug, and a memory disclosure in nvme-tcp that would have leaked host RAM on a read command. You probably want to grab that one first.
The rest of the round is quieter but not uninteresting. On AlmaLinux 9, the libvirt update closes a swtpm symlink-following privilege escalation plus a heap overflow in the page-handling RPC, which matters if you run virtualized guests. osbuild-composer on both versions eats a batch of Go dependencies, where the headline issues are an arbitrary-code-execution XSS in the HTML parser and a privilege-escalation bug in Punycode handling. Git-lfs gets three Go-related denial-of-service fixes, and Ruby's single change stops a memory-growth DoS from crafted DNS responses. Ghostscript is the only Moderate severity in the whole round, a JPEG 2000 heap overflow that probably won't wake you up at night unless you render suspicious PDFs for a living.
The CVE dates are worth a glance. Several are stamped 2026, meaning they're riding some unusually forward-looking identifiers, while the advisory release dates all sit in early October 2026. Nothing to act on beyond the usual "apply the update," but if your patching pipeline ever chokes on unknown CVE years, you now know where the noise comes from.
| Errata | Component | Platform | Severity | Release date | CVEs | Notable fixes |
|---|---|---|---|---|---|---|
| ALSA-2026:71602 | kernel | 10 | Important | 2026-10-05 | 22 | amdgpu OOB reads, PPPoE memory corruption, nvme-tcp host RAM disclosure |
| ALSA-2026:72785 | ruby | 10 | Important | 2026-10-02 | 1 | resolv gem DoS from crafted DNS responses |
| ALSA-2026:72624 | kernel | 10 | Important | 2026-10-05 | 10 | KVM nSVM #UD, ext4 bitmap inconsistency, nvme-tcp read rejection |
| ALSA-2026:66432 | osbuild-composer | 10 | Important | 2026-10-05 | 6 | Go HTML XSS, idna Punycode privilege escalation |
| ALSA-2026:70498 | kernel | 10 | Important | 2026-10-05 | 12 | libceph OOB/DoS, mlx5 MCIA buffer overflow, Bluetooth RFCOMM UAF |
| ALSA-2026:71233 | kernel | 10 | Important | 2026-10-05 | 13 | SMB2 double-free, ebtables shared-memory write, sctp transport handling |
| ALSA-2026:74424 | libvirt | 9 | Important | 2026-10-05 | 2 | swtpm symlink privilege escalation, NodeGetFreePages heap overflow |
| ALSA-2026:74457 | ghostscript | 9 | Moderate | 2026-10-05 | 1 | JPEG 2000 output adapter heap buffer overflow |
| ALSA-2026:66364 | git-lfs | 9 | Important | 2026-10-02 | 3 | Go asn1, crypto-tls, and net/url denial-of-service fixes |
| ALSA-2026:69293 | osbuild-composer | 9 | Important | 2026-10-05 | 5 | Same Go HTML XSS and Punycode issues as the v10 osbuild update |
Debian GNU/Linux
Debian's security and LTS teams rolled out a pile of patches, and perl is the one to look at first. The perl advisory (DLA-4821-1) carries 13 CVEs, spanning heap buffer overflows, code execution, and some oddly sneaky problems like silently wrong regular-expression matches. If you parse archives or compile regexes on 32-bit systems, this batch is worth your time. The standout issues are a glob in IO-Compress that runs arbitrary Perl when handed a hostile output string, plus an Archive::Tar symlink escape that lets attacker-chosen targets point outside your extraction directory.
The rest of the batch is smaller. ruby-oauth2 closes a redirect flaw that leaks bearer tokens to whatever host a redirect names. Roundcube is on the receiving end of a long list of browser-land problems: XSS, SSRF, email header injection, and privilege escalation. Sabnzbd's web UI could run arbitrary code or skip authorization entirely. LibreOffice picks up six CVEs for crashing or executing code on malformed documents, the usual "don't open that attachment" story.
There are also two housekeeping items. One is a genuine annoyance: the Archive::Tar fix shipped in the perl update broke the test suite for libmodule-cpants-analyse-perl, so Debian had to publish a follow-up (DLA-4821-2) the very next day. The other is a use-after-free in libpng1.6 that would mostly show up as a crash rather than anything flashier.
All the perl, ruby-oauth2, Roundcube, and libpng fixes land in Debian 12 bookworm, while sabnzbd and LibreOffice shipped for the stable trixie release. Upgrade if you haven't already.
| Advisory | Package | Fixed Version | CVEs / Details | Impact |
|---|---|---|---|---|
| DLA-4821-1 | perl | 5.36.0-7+deb12u4 | 13 CVEs including CVE-2025-15649, CVE-2026-8376, CVE-2026-57432 | Buffer overflows, code execution, out-of-bounds reads, broken regex matches |
| DLA-4822-1 | ruby-oauth2 | 1.4.4-1+deb12u1 | CVE-2026-54603 | Bearer token forwarded to redirect target |
| DSA-6544-1 | sabnzbdplus | 4.5.0+dfsg-1+deb13u2 | Not yet available | Arbitrary code execution or auth bypass in web UI |
| DSA-6543-1 | libreoffice | 4:25.2.3-2+deb13u8 | CVE-2026-63266 through 63270 (6 total) | DoS, info disclosure, code execution on bad documents |
| DLA-4823-1 | roundcube | 1.6.5+dfsg-1+deb12u12 | Not yet available | XSS, SSRF, header injection, privilege escalation, cross-user access |
| DLA-4821-2 | libmodule-cpants-analyse-perl | 1.01-1+deb12u1 | Regression (CVE-2026-42496 fix) | Test suite broke after perl Archive::Tar patch |
| DLA-4824-1 | libpng1.6 | 1.6.39-2+deb12u6 | CVE-2026-46675 | Use-after-free, denial of service |
Fedora Linux
Fedora shipped three updates to its Fedora 43 release in a single batch, and two of them are the kind you install without reading the fine print.
The browser is the headline, and it is a long one. The chromium update to 154.0.8037.92 closes 32 distinct flaws, which is a lot even for a point release. Google's own Chromium builds bundle these into a handful of advisories, but Fedora's notification spells out each one. Type confusion in the V8 JavaScript engine leads the way with five separate hits, and use-after-free bugs turn up in half a dozen components, from Bluetooth and Passwords to FullScreen and Views. Uninitialized-memory reads, buffer overflows, a cross-site scripting hole in the WebUI, and a cluster of authorization failures across Payments, CORS, WebView and SiteIsolation round things out. If you're on Chrome's upstream build, these are already covered. If you're actually using the open-source Chromium, it's time to update.
The kernel got 7.2.9 as a stable point release, which pulls in a pile of tree-wide fixes from upstream. Two changes are specific to Fedora though: a revert of the af_alg_restrict sysctl for the 43 and 44 tracks, and a new allowance for unprivileged users to call hmac(sha512). The rest is just 7.2.9 doing its normal job.
Python had its turn as well. Version 3.12.15 packages eight security fixes, including a use-after-free on the server-side SSLContext that the advisory specifically calls out (CVE-2026-19445). The remaining seven are standard patches for the 3.12 line.
Three updates, none a lone reason to panic, but a browser with 32 holes alongside a kernel and a Python interpreter in one shot is about as much housekeeping as you can ask for.
| Package | Version | Release | Type | Fixes | Highlights |
|---|---|---|---|---|---|
| chromium | 154.0.8037.92 | 1.fc43 | Security | 32 CVEs | 5 V8 type-confusion bugs, multiple use-after-free (Bluetooth, Passwords, Views, FullScreen), WebUI XSS, authorization gaps in Payments/CORS/WebView, buffer overflows in V8 and ANGLE |
| kernel | 7.2.9 | 100.fc43 | Stable | N/A | Revert of af_alg_restrict sysctl for F43/44, hmac(sha512) allowed for unprivileged users, pulls in Linux 7.2.9 tree-wide fixes |
| python3.12 | 3.12.15 | 1.fc43 | Security | 8 CVEs | Use-after-free in server-side SSLContext (CVE-2026-19445) plus seven other security patches for the 3.12 line |
Oracle Linux
Oracle Linux shipped a broad batch of updates across OL8, OL9, and OL10, mixing security advisories with a bug-fix notice. The list runs long, so some of it is unavoidable housekeeping. The kernel appears three times on OL8 for the same 553.168.1 build, which feels like more errata than the job strictly requires.
The entry that actually earns attention is webkit2gtk3 for OL8, tagged Critical with 323 CVEs and a jump to version 2.54.0. That is a browser engine most people never think about, and it carries a far bigger vulnerability count than anything else in the batch. bind for OL10 is next loudest at five CVEs.
Several fixes recur across distros, which is the sane way to do it. The libvirt integer-overflow patch (CVE-2026-18917) and the libpcap BPF change (CVE-2026-0799) both hit OL9 and OL10, as does ghostscript's JPEG 2000 heap overflow (CVE-2026-39919). gvfs takes the same two CVEs on OL9 and OL10 but only one on OL8.
The rest is mostly routine. mailx gets a UTC offset fix for its Date headers, and a pile of kernel entries absorb whatever landed upstream. Nothing spectacular, but that webkit number alone makes this batch worth installing quickly.
| Advisory | Package | Distro | Severity | Key CVEs | What changed |
|---|---|---|---|---|---|
| ELSA-2026-75583 | libvirt | OL10 | Important | 18917, 63622 | Integer overflow in virNodeGetFreePages RPC; stop following symlinks in virFileChownFiles |
| ELSA-2026-75581 | mod_auth_openidc | OL10 | Important | 54789 | Out-of-bounds read/write on state cookies |
| ELSA-2026-75577 | bind | OL10 | Important | 19666, 19667, 80274, 81563, 81736 | dns64 assertion failure, HTTPS/SVCB leaks, wildcard crashes |
| ELSA-2026-74464 | ghostscript | OL10 | Moderate | 39919 | Heap overflow in JPEG 2000 output adapter |
| ELSA-2026-74442 | libpcap | OL10 | Important | 0799 | Bounds-check BPF scratch register indices |
| ELSA-2026-73954 | openssh | OL10 | Moderate | 60001 | Enforce minimum per-attempt delay in GSSAPI/keyboard-interactive auth |
| ELSA-2026-74001 | expat | OL10 | Important | 66046, 93990 | DoS via attribute complexity; XML injection from malformed UTF-16 |
| ELSA-2026-73998 | gvfs | OL10 | Important | 84268, 88924 | Several backported CVE fixes |
| ELSA-2026-73427 | gdb | OL10 | Important | 13732 | Oracle patches for ol10-u2 |
| ELSA-2026-72624 | kernel (6.12.0-211.61.1) | OL10 | Important | 10 CVEs | perf, KVM arm64, nvme-tcp, ext4, crypto fixes |
| ELSA-2026-71233 | kernel (6.12.0-211.60.1) | OL10 | Important | 13 CVEs | Same upstream batch, one build down |
| ELSA-2026-75575 | gimp | OL9 | Important | 90947, 90948, 92248, 97185 | Four CVE fixes |
| ELSA-2026-74457 | ghostscript | OL9 | Moderate | 39919 | Same JPEG 2000 heap overflow |
| ELSA-2026-74441 | libpcap | OL9 | Important | 0799 | Same BPF bounds check |
| ELSA-2026-74438 | kernel (5.14.0-687.54.1) | OL9 | Moderate | 45856, 63794, 80775 (+ futex UAFs) | futex race fixes; RDMA and KVM sev bounds |
| ELSA-2026-74424 | libvirt | OL9 | Important | 18917, 63622 | Same as OL10 libvirt |
| ELSA-2026-74370 | gvfs | OL9 | Important | 84268, 88924 | Same backports as OL10 |
| ELSA-2026-73955 | openssh | OL9 | Moderate | 60001 | Same auth delay fix |
| ELSA-2026-73426 | gdb | OL9 | Important | 13732 | Oracle patches for ol9-u8 |
| ELSA-2026-74095 | rsync | OL8 | Important | 17 CVEs | Latest rsync CVEs; fixes a patch regression |
| ELSA-2026-74084 | webkit2gtk3 | OL8 | Critical | 323 CVEs | Update to 2.54.0 |
| ELSA-2026-73511 | gawk | OL8 | Moderate | 40467, 40468 | Use-after-free in getline redirect; integer overflow |
| ELSA-2026-74133 | kernel (4.18.0-553.170.1) | OL8 | Important | 64102, 68299, 72099, 72329 | keys, tracing, dm-integrity, liquidio, vmxnet3, siw |
| ELSA-2026-73997 | gvfs | OL8 | Important | 84268 | SFTP backend heap overflow |
| ELSA-2026-73971 | thunderbird | OL8 | Important | 44 CVEs | Update to 140.16.0 ESR |
| ELSA-2026-71329 | kernel (4.18.0-553.168.1) | OL8 | Important | 5 CVEs | pppoe, nvme-tcp, ipvs, nf_queue, amdgpu |
| ELSA-2026-70402 | kernel (4.18.0-553.168.1) | OL8 | Important | 18 CVEs | Overlaps ELSA-2026-71329, same build |
| ELBA-2026-73449 | mailx | OL8 | Bug Fix | none | UTC offset in Date headers |
| ELSA-2026-71213 | kernel (4.18.0-553.168.1) | OL8 | Important | 7 CVEs | Overlaps 71329 and 70402, same build |
Red Hat Enterprise Linux
Red Hat pushed another round of "Important"-rated advisories across RHEL, and if you're responsible for keeping a fleet patched, this is the part you care about. All 22 are tagged Important rather than Critical, which mostly means the flaws here land somewhere in the middle of the severity ladder, worth fixing promptly, but not the "shutdown and reboot at midnight" kind. A handful touch the stuff that actually bites people: sudo, bind, kernel, and libvirt.
What stands out is how many are going to RHEL 10, which tells you where Red Hat's pushing its attention. You'll also spot two separate Single Sign-On entries, one of which is an OpenShift image still supporting Container Platform 3.10 and 3.11, old enough that you may want to check whether you're actually running something that far behind. There's a lone entry for RHEL 7 Extended Lifecycle Support, which is the paid extension track, so don't act surprised if you're not on it.
| RHSA ID | Component | Platform(s) | Type |
|---|---|---|---|
| 75746 | kernel-rt | RHEL 8 | Security, bug fix, enhancement |
| 75673 | mariadb-connector-c | RHEL 9 | Security |
| 75680 | gd | RHEL 8 | Security |
| 75674 | mariadb-connector-c | RHEL 8 | Security |
| 75576 | kernel | RHEL 10 | Security, bug fix, enhancement |
| 75689 | rhc-worker-script | RHEL 7 ELS | Security |
| 75583 | libvirt | RHEL 10 | Security, bug fix, enhancement |
| 75571 | sudo | RHEL 9 | Security |
| 75577 | bind | RHEL 10 | Security |
| 75579 | sudo | RHEL 10 | Security |
| 75570 | freerdp | RHEL 10 | Security |
| 75581 | mod_auth_openidc | RHEL 10 | Security |
| 75575 | gimp | RHEL 9 | Security |
| 75769 | vim | RHEL 10 | Security |
| 75870 | nodejs:22 (module) | RHEL 8 | Security |
| 75747 | kernel | RHEL 8 | Security, bug fix, enhancement |
| 75578 | bind9.18 | RHEL 9 | Security |
| 76045 | libpcap | RHEL 8 | Security |
| 75767 | bind | RHEL 9 | Security |
| 76134 | Red Hat Single Sign-On 7.6.13 (OpenShift image) | OCP 3.10, 3.11, 4.3 | Security |
| 76132 | Red Hat Single Sign-On 7.6.13 | Customer Portal | Security |
| 75864 | nodejs22 | RHEL 10 | Security |
Rocky Linux
Rocky Linux rolled out two more security errata for version 8, both tagged "Important" rather than the scarier "Critical." You won't need to cancel dinner, but both are worth applying before someone reminds you you didn't.
The first (RLSA-2026:75573) is a pki-core:10.6 update that reaches into the surrounding Java toolchain, touching the tomcatjss, resteasy, ldapjdk, and jss modules along with their versioned siblings. The second (RLSA-2026:75870) bumps nodejs:22 and the packaging and nodemon modules. Each entry links a full CVE list with CVSS base scores, so you can check exactly how bad each hole is before touching a live box.
| Errata ID | Severity | Component | Packages/modules updated | OS |
|---|---|---|---|---|
| RLSA-2026:75573 | Important | pki-core:10.6 | module.tomcatjss, module.resteasy, ldapjdk, tomcatjss, jss, module.ldapjdk, resteasy, module.jss | Rocky Linux 8 |
| RLSA-2026:75870 | Important | nodejs:22 | module.nodejs-packaging, nodejs-packaging, nodejs-nodemon, module.nodejs-nodemon | Rocky Linux 8 |
Slackware Linux
Slackware just issued a security bump for CUPS, the print server that quietly sits on most Linux boxes handling everything from a single PDF to an entire office's paper hunger. This one, SSA:2026-278-01, is a fairly generous haul. Slackware lists 13 separate issues, which is a lot of vulnerabilities to cram into what was, to most users, an unchanged print queue. New builds ship for Slackware 15.0 and -current.
The fixes themselves are a grab bag of scheduler and validation bugs: the scheduler didn't open temporary PPD files exclusively, forgot to strip job-status attributes, and left request languages unvalidated. One UTF-32 converter mistook 32-bit values for 64-bit, held jobs crashed the scheduler, and startup permission checks fell prey to time-of-use attacks. A few of these are the "someone could crash your print server" variety rather than the "your data is gone" variety, though with 13 entries it pays to patch anyway.
| Identifier | Component / Platforms | Version | MD5 |
|---|---|---|---|
| SSA:2026-278-01 | 15.0 i586: cups-2.4.20-i586-1_slack15.0.txz · 15.0 x86_64: cups-2.4.20-x86_64-1_slack15.0.txz · -current i686: cups-2.4.19-i686-2.txz · -current x86_64: cups-2.4.20-x86_64-1.txz | 2.4.20 (i686 -current still on 2.4.19) | e7ea3beb82b30e86732d3d74f9475ee5 · ec0565e851bb8598d7da77776d4ced3c · 9136bc3148f67a2f40a3b723a41e7e6a · dd6664efacd6ea30a4a23a2f39cb102f |
SUSE Linux
SUSE shipped a proper wall of security updates on October 5th: twenty announcements across openSUSE Tumbleweed, openSUSE Leap, and SUSE Linux Enterprise, wrapping in roughly 182 individual vulnerabilities. Only one of them earns a critical rating, and that's the standard monthly Chrome fix, so if you're skimming for something to lose sleep over, that's it. The rest is either local-only, routine maintenance, or a browser that picks up front-page exploits every month and this month is no exception.
The chromium update is the sole critical entry, landing on openSUSE Backports SLE-15-SP7 at version 154.0.8037.92. Thirty-two CVEs is normal for a browser getting its monthly treatment, and this batch reads like the usual roster: type confusions and use-after-frees in V8, GPU, Blink, and WebGPU, plus a scatter of cross-site scripting and authorization holes. You patch it because leaving Chrome unpatched in 2026 is its own form of bravery.
Three things actually stand out past the browser. First, pcre2 carries the highest scores in the set, with two 9.2-rated vulnerabilities (CVE-2026-89157 and CVE-2026-89158, both out-of-bounds writes). If your build chain compiles against PCRE2, run this one. Second, SUSE handed out a pile of overlapping kernel live patches. SLE 15 SP5 alone gets four separate announcements (Live Patch 39, 41, 43, and 44), SP7 gets two (7 and 15), and SP6 gets one (29). They're cumulative, so the newest patch in each series already covers the earlier CVEs. Apply the latest of each family rather than treating them as distinct fixes. Third, the lone valkey entry is worth a look: CVE-2026-92925 is a 7.1-rated out-of-bounds read in the cluster bus packet parser, which bites if you run a Redis-compatible store in a cluster.
The remainder is mostly moderate or the "important" tier that just doesn't reach critical. binutils tops the line-item count with 16 CVEs, but nearly all sit at 5.5 or below and require local access, so they only matter if you trust unprivileged code on a machine shipping them. Two do climb to 7.8 (CVE-2026-18220 and CVE-2026-6846), though they stay AV:L. Tumbleweed's moderate group includes squid's CVE-2026-50012 at 8.1, the one to flag if you run a proxy. The single-hitters are scattered but genuine: a use-after-free in wpa_supplicant (CVE-2026-78807, 8.4), a heap buffer overflow in libX11's keyboard map handler (CVE-2026-88806, 8.9), and an out-of-bounds read in the SSSD PAM responder. rpm also tacks a non-security bugfix onto its security patch, closing a leaked libelf handle that breaks NFS buildroots, since SUSE apparently likes to slip in an extra fix now and then. Keep in mind a good chunk of those 182 numbers overlap, so the actual count of distinct problems sits well under that.
| Announcement | Component | Rating | CVEs | Platform(s) | Version | Standout CVE(s) |
|---|---|---|---|---|---|---|
| openSUSE-SU-2026:11940-1 | apache-sshd | Moderate | 8 | Tumbleweed | 2.20.0-1.1 | CVE-2026-93994 (8.1), CVE-2026-94053 (8.1) |
| openSUSE-SU-2026:11933-1 | libraw-devel | Moderate | 1 | Tumbleweed | 0.22.2-2.1 | CVE-2026-88387 (6.5) |
| openSUSE-SU-2026:11937-1 | squid | Moderate | 3 | Tumbleweed | 7.7-2.1 | CVE-2026-50012 (8.1) |
| openSUSE-SU-2026:11936-1 | python313/314-tokenizers | Moderate | 4 | Tumbleweed | 0.23.2-1.1 | CVE-2026-93599 (7.5) |
| openSUSE-SU-2026:11932-1 | binutils | Moderate | 16 | Tumbleweed | 2.47-1.1 | CVE-2026-18220 (7.8), CVE-2026-6846 (7.8) |
| openSUSE-SU-2026:0344-1 | chromium | Critical | 32 | openSUSE Backports SLE-15-SP7 | 154.0.8037.92 | Many V8/GPU UAF + type confusion |
| SUSE-SU-2026:4443-1 | python-msgpack | Important | 1 | Leap 15.6, SLE 15 SP6/SP7 (+SAP/LTSS) | 1.0.7-... | CVE-2026-57585 (7.5) |
| SUSE-SU-2026:4456-1 | sssd | Moderate | 2 | Leap 15.5, SUSE Micro 5.5 | 2.5.2-... | CVE-2026-12610 (6.4), CVE-2026-68743 (5.5) |
| SUSE-SU-2026:4457-1 | rpm | Important | 1 (+1 bugfix) | Leap 15.3, Micro 5.3 | 4.14.3-... | CVE-2026-44605 (7.8) |
| SUSE-SU-2026:4458-1 | pcre2 | Important | 6 | Leap 15.4, SLE HPC/Micro/Server/SAP 15 SP4/SP5 | 10.39-... | CVE-2026-89157 (9.2), CVE-2026-89158 (9.2) |
| SUSE-SU-2026:4450-1 | Linux kernel (Live Patch 39, SP5) | Important | 13 | SP4/SP5 family | 5.14.21-150500.55.163 | CVE-2026-63921 (9.3) |
| SUSE-SU-2026:4471-1 | Linux kernel (Live Patch 7, SP7) | Important | 19 | SP6/SP7, Leap 15.6 | 6.4.0-150700.53.25 | CVE-2026-74612 (10.0 NVD) |
| SUSE-SU-2026:4491-1 | valkey | Important | 1 | Leap 15.6, SLE 15 SP6 (+SAP/LTSS) | 8.0.10-... | CVE-2026-92925 (7.1) |
| SUSE-SU-2026:4492-1 | wpa_supplicant | Important | 2 | Leap 15.6, SLE 15 SP6 (+SAP/LTSS) | 2.10-... | CVE-2026-78807 (8.4) |
| SUSE-SU-2026:4501-1 | libX11 | Important | 4 | Leap 15.6, SLE 15 SP6 (+SAP/LTSS) | 1.8.7-... | CVE-2026-88806 (8.9) |
| SUSE-SU-2026:4507-1 | Linux kernel (Live Patch 41, SP5) | Important | 13 | SP4/SP5 family | 5.14.21-150500.55.169 | CVE-2026-63921 (9.3) |
| SUSE-SU-2026:4489-1 | Linux kernel (Live Patch 15, SP7) | Important | 19 | SP6/SP7, Leap 15.6 | 6.4.0-150700.53.55 | CVE-2026-74612 (10.0 NVD) |
| SUSE-SU-2026:4495-1 | Linux kernel (Live Patch 43, SP5) | Important | 12 | SP5 family | 5.14.21-150500.55.177 | CVE-2026-63921 (9.3) |
| SUSE-SU-2026:4497-1 | Linux kernel (Live Patch 44, SP5) | Important | 7 | SP5 family | 5.14.21-150500.55.182 | CVE-2026-64114 (8.5) |
| SUSE-SU-2026:4498-1 | Linux kernel (Live Patch 29, SP6) | Important | 18 | Leap 15.6, SLE 15 SP6 (+SAP) | 6.4.0-150600.23.125 | CVE-2026-74612 (10.0 NVD) |
Ubuntu Linux
Ubuntu shipped another round of security fixes on October 5th, and this week's batch leans on kernel work. There are seven updates total, spanning Microsoft Azure's custom kernel down to LibreOffice throwing a fit over a bad PDF.
The Raspberry Pi kernel (USN-8871-1) carries the most interesting fix. It plugs an ARM64 flaw where broadcast TLB invalidation could finish before memory writes were globally observed, letting a local attacker write to memory after permissions had been pulled back. That is the sort of bug that quietly hands over elevated access, and it ships alongside nineteen more kernel fixes across InfiniBand, NFS, IPv6, and friends.
The Azure kernel (USN-8851-3) is smaller, three issues in the NFS server, IPv6, and Netfilter. Take note of the ABI change, though, since any third-party kernel modules you built yourself will need recompiling after you upgrade.
LibreOffice (USN-8868-1) gets a fresh upstream release to close eight gaps. Dodgy WMF, PDF, and PICT imports, plus CFF and Graphite fonts, can crash the app or run arbitrary code, and a couple of URL-handling and validation shortfalls leak data. On 26.04, 24.04, or 22.04? Grab it.
The remaining fixes live mostly in backend territory. EDK II (USN-8865-1) patches four OpenSSL-in-UEFI issues affecting everything from 16.04 to 26.04, including a forged-message acceptance hole on the newer releases. Ceph's object gateway (USN-8867-1) let presigned-URL holders slip unsigned headers through to grab more privileges than the signer intended. OpenStack's Aodh and Watcher (USN-8870-1) let you read alarm metadata or fire action plans without proper checks, so restart both after updating. The libxmltok/Expat update (USN-8872-1) could crash on a crafted XML file, but it's largely Ubuntu Pro and ESM ground.
| USN | Package | Ubuntu versions | CVEs | What got patched |
|---|---|---|---|---|
| USN-8851-3 | linux-azure-5.4 (Azure kernel) | 18.04 LTS | CVE-2025-38724, CVE-2026-53131, CVE-2026-53221 | NFS server daemon, IPv6 networking, Netfilter. Requires reboot and recompile of third-party kernel modules. |
| USN-8871-1 | linux-raspi (Raspberry Pi kernel) | 22.04 LTS | 21 total: CVE-2025-10263 plus CVE-2026-53131, 53186, 53216, 53221, 53354, 53355, 53398, 63800, 63808, 63887, 63888, 63912, 63922, 63924, 63984, 63992, 63993, 63994, 64007, 64091 | ARM64 TLB invalidation privilege escalation, InfiniBand, network drivers, TCM, exFAT, NFS client/server, BATMAN, IPv4/IPv6, Netfilter, RDS. Requires reboot. |
| USN-8868-1 | libreoffice | 26.04, 24.04, 22.04 LTS | CVE-2026-50593, 63272, 63273, 63274, 63275, 63276, 63278, 63279 | WMF/PDF/PICT image imports, CFF font handling, package URL validation, Graphite font out-of-bounds writes. Ships new upstream release. |
| USN-8865-1 | edk2 (UEFI firmware) | 16.04–26.04 LTS | CVE-2026-54874, 63072, 63076, 75803 | Embedded OpenSSL heap overflow (DoS), CMP protection DoS, DTLS record buffering, forged AEAD message acceptance. |
| USN-8867-1 | ceph (RGW) | 26.04, 22.04, 20.04, 18.04 LTS | CVE-2026-54330 | SigV4 handler accepting unsigned x-amz-* headers to escalate privileges beyond a presigned URL's intent. |
| USN-8870-1 | aodh, watcher | 26.04, 24.04, 22.04, 20.04 LTS | CVE-2026-76878 | Aodh alarm API not enforcing project scoping; Watcher webhook trigger missing authorization. Restart both after update. |
| USN-8872-1 | libxmltok (Expat) | 24.04, 22.04, 20.04, 18.04, 16.04 LTS | CVE-2026-56404, CVE-2026-56405 | Integer arithmetic mishandling causing denial of service. Mostly ESM/Ubuntu Pro packages. |
How to apply these Linux security updates
Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.
Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.
Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.
Debian/Ubuntu (apt)
The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.
sudo apt update sudo apt upgrade -y
Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)
On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.
sudo dnf check-update sudo dnf upgrade -y
or on older releases
sudo yum check-update sudo yum update
SUSE (zypper)
SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.
sudo zypper refresh sudo zypper update -y
Slackware (slackpkg and pkgtool)
Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.
sudo slackpkg update sudo slackpkg upgrade-all
