Debian, Fedora, Red Hat, Rocky Linux, SUSE, and Ubuntu all pushed fresh security updates this week. Red Hat flagged three Critical advisories led by the unbound DNS resolver, while Ubuntu's PyJWT notice adds a signature-bypass that lets attackers forge valid tokens. Debian's libheif update carries seven CVEs plus eleven non-numbered advisories, and Fedora's Chromium build quietly closes more than 100 CVEs in one release. The takeaway is simple: patch the DNS resolver and token forgery first, then clear the rest when convenient.
Linux security roundup: Red Hat flags three Critical advisories, Ubuntu ships PyJWT signature-bypass fix
Debian, Fedora, Red Hat, Rocky Linux, SUSE, and Ubuntu all pushed security updates this week. Most of it is the usual quarterly churn. Two things deserve your attention before you close the tab, though.
Red Hat handed out 26 advisories spanning RHEL 7 through 10, and the story is mostly "Important" with three Critical calls. The loud one is unbound, the DNS resolver. Red Hat rates it Critical twice, once for RHEL 7 Extended Lifecycle Support and once for the RHEL 8.8 SAP and Telecommunications channels. If you run either, treat it as front-of-line work. A third Critical lands on Red Hat Identity Management (ipa) in RHEL 10, bundled alongside bug fixes and enhancements.
On the softer end, two rrdtool updates are only Moderate. That is a relief of sorts, given rrdtool quietly lives in monitoring stacks that nobody ever inspects. Everything else sits in the Important bucket, including postgresql in various forms, qt5 and qt6, ruby, pcp, tesseract, git-lfs, libreswan, gstreamer, and an OpenShift 4.15.69 release that mixes bug fixes with security work.
Ubuntu's PyJWT notice is the other one to chase. USN-8823-1 brings five CVEs, and the standout is a signature bypass that fires when both HMAC and asymmetric algorithms are enabled, letting attackers forge valid tokens. There is also a PyJWKClient problem that opens the door to server-side request forgery and local file exposure, plus two denial-of-service paths and a forgery route for tokens decoded with PyJWK keys. It reaches six releases, down to 16.04 LTS.
Fix versions run from 2.10.1 on 26.04 down to 1.3.0 on 16.04, with older tracks served through Ubuntu Pro.
The rest of the batch
Debian cycled through a fresh set of advisories across four days in late September, and nearly all target the trixie stable release. None reads like an "exploit your box today" emergency, but several of these packages run on far more servers than you would expect, so a glance is worth it.
Two things pull the eye. Debian's own LTS window for buster and bullseye is largely gone, so FreeXian filed separate nginx patches for those releases, meaning you will need the extra steps if you are still on something older than trixie. libheif is the one to actually worry about if you feed it untrusted files, carrying seven CVEs plus eleven upstream-only GitHub Security Advisories that slipped through without a number. exim4's SMTP smuggling is the flavor of flaw most quietly abused in the wild.
The Debian list also carries Swift (DSA-6519-1), ruby-oj (DSA-6521-1), lemonldap-ng (DSA-6520-1), and two nginx bundles (ELA-1832-1 and ELA-1833-1).
If you tinker with AI tooling, the Fedora entry worth a second look is goose. Its on-machine agent client picked up a fix for arbitrary command execution through goose review, which is a polite way of saying a crafted Git configuration could hand an attacker a shell. It also carries the full 1.45.0 feature set, adding providers like Together AI, Perplexity, and Alibaba's Qwen. The developer-agent market is crowded, but goose is at least trying to be useful instead of just another code-suggestion box.
If you sit behind a Postgres dashboard, pgAdmin 9.18 is the bigger story. It folds in an authentication bypass driven by a client-controlled identity header, string injection through the Backup, Restore, and Maintenance tools, and an arbitrary file write through a symlink in the File Manager. That is enough attack surface to make the update count.
Chromium is the loud entry on the Fedora 44 side. The build jumps to 154.0.8037.57 and quietly closes more than 100 CVEs in a single release, spanning use-after-free, buffer overflows, type confusion, and missing authorization checks. You probably already update your browser without thinking about it, but a hundred-entry list for one build is a good reason to stop shrugging.
The rest is steadier, unglamorous work. PostGIS gets a backported fix for memory disclosure and DoS triggered by malformed FlatGeobuf buffers. The MongoDB C driver moves to 1.30.11 for SCRAM authentication and GridFS validation. mingw-gstreamer plugs a NULL-pointer crash that shows up when parsing crafted RTSP auth headers. Nextcloud 34.0.4 rounds out the batch, and Suricata and C-Kermit take their respective upstream releases.
Rocky Linux dropped five advisories tagged Important, and three of them are really the same Firefox fix served to three different major releases. You would think patching a browser means one update, but since Firefox ships under Rocky Linux 8, 9, and 10, Mozilla's latest hole-closing shows up in triplicate. The other two land on narrower targets: a Tomcat fix for Linux 10 and a Ruby 3.3 update that reaches into three gems. Nothing here asks you to upgrade, just apply the patch.
SUSE sent just three updates to openSUSE Tumbleweed, and they happen to all be Python. Everything sits at moderate severity, so none of these will make headlines, but they cover ground you might actually use. The vllm fix is the one worth a glance if you serve LLMs locally. The Python 3.14 update is the most substantial of the group. Note that SUSE only assigned CVSS scores to two of vllm's four CVEs, both in the low single digits, which is a little odd for something labeled moderate.
Ubuntu's libwebsockets notice took two hits: an SSH handler that choked on certain protocol messages, letting an attacker starve the process, plus a second flaw where malformed CBOR data could crash the library or hand a remote attacker arbitrary code execution. Only 24.04 and 26.04 LTS carry the CBOR hole, though. LXC is a quieter pair, but there is one wrinkle: you have to restart the containers after updating, whereas the others fold in cleanly with a normal system update. Requests closes out Ubuntu's batch with a single issue, generating temporary file paths unsafely so a crafted file lets an attacker run code as your login account.
These roundups roll through every quarter without much fuss, and most of this is business as usual. The pattern holds: patch the DNS resolver and the token forgery first, then clear the rest when you get to it. Head to your distro's security announcement page for the exact advisories and update channels, and check the CVE list to confirm anything you actually run is covered.
A Detailed Overview of the Updates
Debian GNU/Linux
Debian's security team cycled through a fresh batch of advisories across four days in late September, and nearly all of them target the trixie stable release. None of it reads like an "exploit your box today" emergency, but several of these packages run on far more servers than you'd expect, so a quick glance is worth it.
The updates touch web infrastructure (nginx), mail handling (exim4), JSON processing (ruby-oj), single sign-on (lemonldap-ng), image decoding (libheif), and Swift object storage. Most advisories arrive as bundles rather than a single tidy flaw, which is normal autumn fare.
Two things pull the eye. FreeXian filed separate LTS patches for buster and bullseye on nginx since Debian's own extended-LTS window for those older releases is largely gone, so you'll need those extra steps if you're on anything older than trixie. libheif is the one to actually worry about if you feed it untrusted files, carrying seven CVEs plus eleven upstream-only GitHub Security Advisories that slipped through without a CVE number. exim4's SMTP smuggling is the flavor of vulnerability most quietly abused in the wild.
| Advisory ID | Package | CVE(s) | Impact | Fixed version |
|---|---|---|---|---|
| DSA-6519-1 | swift | CVE-2026-97149 | Information disclosure in Swift tempurl middleware | 2.35.1-0+deb13u4 (trixie) |
| ELA-1833-1 | nginx | CVE-2026-42533, CVE-2026-56434 | DoS or arbitrary code execution (heap overflow, use-after-free) | 1.14.2-2+deb10u9 (buster) |
| ELA-1832-1 | nginx | CVE-2026-42533, CVE-2026-56434, CVE-2026-60005 | DoS, memory disclosure, or arbitrary code execution | 1.18.0-6.1+deb11u9 (bullseye) |
| DSA-6521-1 | ruby-oj | CVE-2026-54500, 54502, 54592, 54896, 54897, 54898, 54899, 54900, 54901, 54902, 54903 | DoS or memory disclosure in Ruby JSON parser/serializer | 3.16.3-1+deb13u1 (trixie) |
| DSA-6520-1 | lemonldap-ng | CVE-2026-92288, 92289, 95811 | Access-control bypass, PKCE authorisation bypass, info disclosure | 2.21.2+ds-1+deb13u4 (trixie) |
| DSA-6522-1 | exim4 | CVE-2026-94054, 94056, 94057 (Debian Bug 1148506) | SMTP smuggling, info disclosure, DoS, or arbitrary code | 4.98.2-1+deb13u5 (trixie) |
| DSA-6523-1 | libheif | CVE-2026-84384, 84444, 84446, 84447, 84448, 84450, 84451 (+ 11 non-CVE GHSA issues) | DoS, memory disclosure, or arbitrary code from malformed HEIF/AVIF images | 1.23.4-1~deb13u1 (trixie) |
Fedora Linux
Fedora shipped a fresh round of security patches across Fedora 43 and 44 this week, and most of it is the usual business: close the hole, bump the version, move on. A handful actually earn a second look.
The one worth your attention if you tinker with AI tooling is goose. The extensible on-machine agent client picked up a fix for arbitrary command execution through goose review, which is a polite way of saying a crafted Git configuration could hand an attacker a shell. It also carries the full 1.45.0 feature set: a pile of new providers (Together AI, Perplexity, Alibaba's Qwen, several more) and a hooks system for people who like their agents extensible. The developer-agent market is thoroughly crowded, but goose is at least trying to be useful instead of just another code-suggestion box.
If you sit behind a Postgres dashboard, pgAdmin 9.18 is the bigger story. It folds in a spread of separate problems: an authentication bypass driven by a client-controlled identity header, string injection through the Restore, Maintenance, and Backup tools, and an arbitrary file write that sneaks in through a symlink in the File Manager. That's enough distinct attack surfaces to make the update count.
Chromium is the loud entry. The Fedora 44 build jumps to 154.0.8037.57 and quietly closes more than 100 CVEs in a single release, spanning use-after-free, buffer overflows, type confusion, and missing authorization checks. You probably already update your browser without thinking about it, but seeing a hundred-entry list for one build is a good reason to stop shrugging.
The rest is steadier, unglamorous work. PostGIS gets a backported fix for memory disclosure and denial of service triggered by malformed FlatGeobuf buffers, landing on the PostgreSQL 16, 17, and 18 builds. The MongoDB C driver moves to 1.30.11 for SCRAM authentication and GridFS file-ID validation. mingw-python3 absorbs the tarfile arbitrary-file-write issue. mingw-gstreamer 1.28.7 plugs a NULL-pointer crash that shows up when parsing crafted RTSP auth headers. Nextcloud 34.0.4 rounds out the batch with denial-of-service and cross-site-scripting fixes, while Suricata and C-Kermit take their respective upstream releases.
| Package | Fedora | Version | What's fixed |
|---|---|---|---|
| goose | 43 | 1.45.0-1.fc43 | Arbitrary command execution via goose review (GHSA-r5pp-p5r8-466r); new providers, hooks system |
| pgAdmin | 43 | 9.18-1.fc43 | Auth bypass via identity header; injection in Backup/Restore/Maintenance; symlink file write (CVE-2026-86861 through CVE-2026-86864) |
| mingw-python3 | 43 | 3.11.16-1.fc43 | tarfile arbitrary file write via crafted links (CVE-2026-7774) |
| postgresql18-postgis | 43 | 3.6.4-5.fc43 | Memory disclosure and DoS from malformed FlatGeobuf (CVE-2026-73515) |
| postgresql16-postgis | 43 | 3.6.4-5.fc43 | Memory disclosure and DoS from malformed FlatGeobuf (CVE-2026-73515) |
| ckermit | 43 | 11.0.509-2.fc43 | Update to 11.0.509 addressing CVE-2025-68920 |
| postgresql17-postgis | 43 | 3.6.4-5.fc43 | Memory disclosure and DoS from malformed FlatGeobuf (CVE-2026-73515) |
| mongo-c-driver | 43 | 1.30.11-1.fc43 | SCRAM auth and GridFS file-ID fixes; CVE-2026-88035, CVE-2026-88036 |
| nextcloud | 43 | 34.0.4-1.fc43 | DoS via smartquotes, query-string parsing, stringify; XSS via DOMPurify (CVE-2026-48988, CVE-2026-75838, CVE-2026-82417, CVE-2026-82562) |
| chromium | 44 | 154.0.8037.57-1.fc44 | 100+ CVEs: use-after-free, buffer overflow, type confusion, missing authorization |
| mingw-gstreamer1-plugins-good | 44 | 1.28.7-1.fc44 | gstreamer 1.28.7; NULL-pointer parse crash in RTSP auth (CVE-2026-85150) |
| mingw-gstreamer1-plugins-bad-free | 44 | 1.28.7-1.fc44 | gstreamer 1.28.7; NULL-pointer parse crash in RTSP auth (CVE-2026-85150) |
| goose | 44 | 1.45.0-1.fc44 | Arbitrary command execution via goose review (GHSA-r5pp-p5r8-466r); new providers, hooks system |
| mingw-gstreamer1 | 44 | 1.28.7-1.fc44 | gstreamer 1.28.7; NULL-pointer parse crash in RTSP auth (CVE-2026-85150) |
| mingw-gstreamer1-plugins-base | 44 | 1.28.7-1.fc44 | gstreamer 1.28.7; NULL-pointer parse crash in RTSP auth (CVE-2026-85150) |
| pgAdmin | 44 | 9.18-1.fc44 | Auth bypass via identity header; injection in Backup/Restore/Maintenance; symlink file write (CVE-2026-86861 through CVE-2026-86864) |
| mingw-python3 | 44 | 3.11.16-1.fc44 | tarfile arbitrary file write via crafted links (CVE-2026-7774) |
| ckermit | 44 | 11.0.509-2.fc44 | Update to 11.0.509 addressing CVE-2025-68920 |
| postgresql18-postgis | 44 | 3.6.4-5.fc44 | Memory disclosure and DoS from malformed FlatGeobuf (CVE-2026-73515) |
| postgresql16-postgis | 44 | 3.6.4-5.fc44 | Memory disclosure and DoS from malformed FlatGeobuf (CVE-2026-73515) |
| postgresql17-postgis | 44 | 3.6.4-5.fc44 | Memory disclosure and DoS from malformed FlatGeobuf (CVE-2026-73515) |
| mongo-c-driver | 44 | 1.30.11-1.fc44 | SCRAM auth and GridFS file-ID fixes; CVE-2026-88035, CVE-2026-88036 |
| suricata | 44 | 8.0.7-1.fc44 | Upstream security and bugfix release |
| nextcloud | 44 | 34.0.4-1.fc44 | DoS via smartquotes, query-string parsing, stringify; XSS via DOMPurify (CVE-2026-48988, CVE-2026-75838, CVE-2026-82417, CVE-2026-82562) |
Red Hat Enterprise Linux
Red Hat pushed out a batch of security advisories this week, and the story is mostly "Important," with three Critical calls that should make you pause before you finish patching.
The biggest worry is unbound, the DNS resolver, which appears twice as Critical: once for RHEL 7 Extended Lifecycle Support and once for the RHEL 8.8 SAP and Telecommunications channels. If you run either of those, treat it as a front-of-line job. The third Critical lands on Red Hat Identity Management (ipa) in RHEL 10, and it bundles the security fixes together with bug fixes and enhancements.
The rest is the usual distribution. Two rrdtool updates for the SAP Solutions channel are rated only Moderate, which is a welcome relief since rrdtool quietly lives in monitoring stacks nobody inspects. Everything else sits in the Important bucket: postgresql in its many forms, the qt5 and qt6 libraries, ruby, pcp, tesseract, git-lfs, libreswan, rhc, gstreamer, and an OpenShift 4.15.69 release that mixes bug fixes with security work.
Altogether that's 26 advisories spanning RHEL 7 through 10, including several Extended Update Support and SAP Solutions tracks, so it may pay to check whether more than one applies to you.
| RHSA ID | Package | Severity | Target Channel |
|---|---|---|---|
| RHSA-2026:72199 | unbound | Critical | RHEL 7 ELS |
| RHSA-2026:72264 | unbound | Critical | RHEL 8.8 SAP + Telecom |
| RHSA-2026:72279 | ipa | Critical | RHEL 10 |
| RHSA-2026:72277 | rrdtool | Moderate | RHEL 9.2 SAP Solutions |
| RHSA-2026:72278 | rrdtool | Moderate | RHEL 9.4 SAP Solutions |
| RHSA-2026:72280 | tesseract | Important | RHEL 9.2 SAP Solutions |
| RHSA-2026:72287 | libreswan | Important | RHEL 8.8 SAP + Telecom |
| RHSA-2026:72276 | git-lfs | Important | RHEL 9.4 SAP Solutions |
| RHSA-2026:67857 | OpenShift Container Platform 4.15.69 | Important | OCP 4.15 |
| RHSA-2026:72383 | qt6-qt5compat | Important | RHEL 10.0 EUS |
| RHSA-2026:72367 | gstreamer1-plugins-good | Important | RHEL 7 ELS |
| RHSA-2026:72378 | qt5-qtbase | Important | RHEL 8.8 SAP + Telecom |
| RHSA-2026:72377 | qt5-qtbase | Important | RHEL 8.6 AMCU + EUS LL |
| RHSA-2026:72376 | qt5-qtbase | Important | RHEL 8.4 AMCU + EUS LL |
| RHSA-2026:72286 | ruby | Important | RHEL 9 |
| RHSA-2026:72361 | postgresql | Important | RHEL 9.2 SAP Solutions |
| RHSA-2026:72363 | postgresql:12 | Important | RHEL 8.6 AMCU + EUS LL |
| RHSA-2026:72362 | postgresql:12 | Important | RHEL 8.8 SAP + Telecom |
| RHSA-2026:72272 | pcp | Important | RHEL 9.6 EUS |
| RHSA-2026:72275 | rhc | Important | RHEL 9 |
| RHSA-2026:72285 | ruby:3.3 | Important | RHEL 8 |
| RHSA-2026:72273 | pcp | Important | RHEL 10.0 EUS |
| RHSA-2026:72274 | postgresql:12 | Important | RHEL 8 |
| RHSA-2026:72281 | postgresql | Important | RHEL 9.6 EUS |
| RHSA-2026:72282 | postgresql16 | Important | RHEL 10.0 EUS |
| RHSA-2026:72283 | postgresql | Important | RHEL 9.4 SAP Solutions |
Rocky Linux
Rocky Linux just dropped five security advisories tagged "Important," and three of them are really just the same Firefox fix served to three different major releases. You'd think patching a browser would mean one update, but since Firefox ships under Rocky Linux 8, 9, and 10, Mozilla's latest hole-closing gets patched in triplicate. The other two land on narrower targets: a Tomcat fix for Linux 10 and a Ruby 3.3 update that reaches into three gems. Nothing here asks you to upgrade, just apply the patch.
| Advisory ID | Package | Affected OS | Details |
|---|---|---|---|
| RLSA-2026:67129 | Firefox | Rocky Linux 10 | Browser security update |
| RLSA-2026:67133 | Firefox | Rocky Linux 9 | Browser security update |
| RLSA-2026:68549 | Firefox | Rocky Linux 8 | Browser security update |
| RLSA-2026:25341 | tomcat9 | Rocky Linux 10 | Server security update |
| RLSA-2026:72285 | ruby:3.3 (rubygem-mysql2, rubygem-abrt, rubygem-pg) | Rocky Linux 8 | Multiple gems patched |
SUSE Linux
Three security updates landed on openSUSE Tumbleweed's general availability media, and they happen to all be Python. Everything sits at moderate severity, so none of these are going to make headlines, but they cover ground you might actually use. The vllm fix is the one worth a glance if you serve LLMs locally, since that package is the framework people lean on for it. The Python 3.14 update is the most substantial of the group, mending three separate issues across the interpreter and its bundled libraries. The WebOb patch is the low-key one, shutting a single hole across three package variants.
Note that SUSE only assigned CVSS scores to two of vllm's four CVEs, and both sit in the low single digits. That's a little odd for something labeled moderate, but the numbers don't argue with the rating. All three updates target Tumbleweed only.
| Announcement ID | Package(s) | CVE(s) | Highest CVSS | Severity |
|---|---|---|---|---|
| openSUSE-SU-2026:11864-1 | python-WebOb-doc 1.8.11-1.1, python313-WebOb 1.8.11-1.1, python314-WebOb 1.8.11-1.1 | CVE-2026-54770 | 6.1 | moderate |
| openSUSE-SU-2026:11868-1 | python314 3.14.7-2.1, python314-32bit, python314-curses, python314-dbm, python314-idle, python314-tk, python314-x86-64-v3 (all 3.14.7-2.1) | CVE-2026-15310, CVE-2026-17084, CVE-2026-19672 | 6.3 | moderate |
| openSUSE-SU-2026:11867-1 | python313-vllm 0.30.0-1.1 | CVE-2026-90713, CVE-2026-92365, CVE-2026-93841, CVE-2026-93989 | 4.3 | moderate |
Ubuntu Linux
Ubuntu shipped four security notices. The range spans the genuinely bad to the mildly annoying, so here is the breakdown.
libwebsockets (USN-8822-1) took two hits. Its SSH handler choked on certain SSH protocol messages, letting an attacker starve the process for a denial of service (CVE-2026-10650). A second flaw means malformed CBOR data could either crash the library or, worse, hand a remote attacker a way to run arbitrary code (CVE-2026-78161). Only 24.04 and 26.04 LTS carry the CBOR hole. The 26.04 track lands on 4.3.5, while the older releases get patched through Ubuntu Pro.
PyJWT (USN-8823-1) got the most CVEs of the bunch, at five. The standout is a signature-bypass that triggers when both HMAC and asymmetric algorithms are enabled, letting attackers forge valid tokens (CVE-2026-48526). There is also a PyJWKClient problem that opens the door to server-side request forgery and leaking local files (CVE-2026-48522), alongside two denial-of-service paths from untrusted key requests and detached JWS payloads, plus a forgery path for tokens decoded with PyJWK keys (CVE-2026-48523). This one reaches six releases, down to 16.04 LTS.
LXC (USN-8826-1) is a quieter pair. One flaw leaks sensitive information when failure messages get logged (CVE-2022-47952), and another trips over user authorization handling to cause a denial of service (CVE-2026-39402). The one wrinkle: you have to restart the containers after updating, whereas the others fold in cleanly with a normal system update.
Requests (USN-8825-1) closes out the batch with a single issue. It generated temporary file paths unsafely, so opening a specially crafted file let an attacker run code as your login account (CVE-2026-25645).
| Security Notice | Package | CVEs | Impact | Fixed version | Notes |
|---|---|---|---|---|---|
| USN-8822-1 | libwebsockets | CVE-2026-10650, CVE-2026-78161 | SSH message mishandling (DoS); malformed CBOR data (DoS or code execution) | 4.3.5 (26.04); 4.3.3 (24.04); 4.0.20 (22.04); 3.2.1 (20.04) | CBOR bug only on 24.04 and 26.04; older fixes via Ubuntu Pro |
| USN-8823-1 | pyjwt | CVE-2026-48522, CVE-2026-48523, CVE-2026-48524, CVE-2026-48525, CVE-2026-48526 | SSRF and local file exposure; signature bypass and token forgery; two DoS paths | 2.10.1 (26.04); 2.7.0 (24.04); 2.3.0 (22.04); 1.7.1 (20.04); 1.5.3 (18.04); 1.3.0 (16.04) | Six releases affected; older tracks via Ubuntu Pro |
| USN-8826-1 | lxc | CVE-2022-47952, CVE-2026-39402 | Info leak via logging; DoS via authorization handling | 1:6.0.6 (26.04); 1:5.0.3 (24.04); 1:5.0.0 (22.04); 1:4.0.12 (20.04); 1:3.0.3 (18.04); 1:2.0.11 (16.04) | Restart containers after update; all via Ubuntu Pro |
| USN-8825-1 | requests | CVE-2026-25645 | Unsafe temp file path creation runs code as login user | 2.32.5 (26.04); 2.31.0 (24.04); 2.25.1 (22.04); 2.22.0 (20.04) | 20.04 fix via Ubuntu Pro |
How to apply these Linux security updates
Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.
Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.
Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.
Debian/Ubuntu (apt)
The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.
sudo apt update sudo apt upgrade -y
Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)
On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.
sudo dnf check-update sudo dnf upgrade -y
or on older releases
sudo yum check-update sudo yum update
SUSE (zypper)
SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.
sudo zypper refresh sudo zypper update -y
