Security 11022 Published by

Debian, Fedora, Red Hat, Rocky Linux, SUSE, and Ubuntu all pushed fresh security updates this week. Red Hat flagged three Critical advisories led by the unbound DNS resolver, while Ubuntu's PyJWT notice adds a signature-bypass that lets attackers forge valid tokens. Debian's libheif update carries seven CVEs plus eleven non-numbered advisories, and Fedora's Chromium build quietly closes more than 100 CVEs in one release. The takeaway is simple: patch the DNS resolver and token forgery first, then clear the rest when convenient.





Linux security roundup: Red Hat flags three Critical advisories, Ubuntu ships PyJWT signature-bypass fix

Debian, Fedora, Red Hat, Rocky Linux, SUSE, and Ubuntu all pushed security updates this week. Most of it is the usual quarterly churn. Two things deserve your attention before you close the tab, though.

Red Hat handed out 26 advisories spanning RHEL 7 through 10, and the story is mostly "Important" with three Critical calls. The loud one is unbound, the DNS resolver. Red Hat rates it Critical twice, once for RHEL 7 Extended Lifecycle Support and once for the RHEL 8.8 SAP and Telecommunications channels. If you run either, treat it as front-of-line work. A third Critical lands on Red Hat Identity Management (ipa) in RHEL 10, bundled alongside bug fixes and enhancements.

Linux Security

On the softer end, two rrdtool updates are only Moderate. That is a relief of sorts, given rrdtool quietly lives in monitoring stacks that nobody ever inspects. Everything else sits in the Important bucket, including postgresql in various forms, qt5 and qt6, ruby, pcp, tesseract, git-lfs, libreswan, gstreamer, and an OpenShift 4.15.69 release that mixes bug fixes with security work.

Ubuntu's PyJWT notice is the other one to chase. USN-8823-1 brings five CVEs, and the standout is a signature bypass that fires when both HMAC and asymmetric algorithms are enabled, letting attackers forge valid tokens. There is also a PyJWKClient problem that opens the door to server-side request forgery and local file exposure, plus two denial-of-service paths and a forgery route for tokens decoded with PyJWK keys. It reaches six releases, down to 16.04 LTS.

Fix versions run from 2.10.1 on 26.04 down to 1.3.0 on 16.04, with older tracks served through Ubuntu Pro.

The rest of the batch

Debian cycled through a fresh set of advisories across four days in late September, and nearly all target the trixie stable release. None reads like an "exploit your box today" emergency, but several of these packages run on far more servers than you would expect, so a glance is worth it.

Two things pull the eye. Debian's own LTS window for buster and bullseye is largely gone, so FreeXian filed separate nginx patches for those releases, meaning you will need the extra steps if you are still on something older than trixie. libheif is the one to actually worry about if you feed it untrusted files, carrying seven CVEs plus eleven upstream-only GitHub Security Advisories that slipped through without a number. exim4's SMTP smuggling is the flavor of flaw most quietly abused in the wild.

The Debian list also carries Swift (DSA-6519-1), ruby-oj (DSA-6521-1), lemonldap-ng (DSA-6520-1), and two nginx bundles (ELA-1832-1 and ELA-1833-1).

If you tinker with AI tooling, the Fedora entry worth a second look is goose. Its on-machine agent client picked up a fix for arbitrary command execution through goose review, which is a polite way of saying a crafted Git configuration could hand an attacker a shell. It also carries the full 1.45.0 feature set, adding providers like Together AI, Perplexity, and Alibaba's Qwen. The developer-agent market is crowded, but goose is at least trying to be useful instead of just another code-suggestion box.

If you sit behind a Postgres dashboard, pgAdmin 9.18 is the bigger story. It folds in an authentication bypass driven by a client-controlled identity header, string injection through the Backup, Restore, and Maintenance tools, and an arbitrary file write through a symlink in the File Manager. That is enough attack surface to make the update count.

Chromium is the loud entry on the Fedora 44 side. The build jumps to 154.0.8037.57 and quietly closes more than 100 CVEs in a single release, spanning use-after-free, buffer overflows, type confusion, and missing authorization checks. You probably already update your browser without thinking about it, but a hundred-entry list for one build is a good reason to stop shrugging.

The rest is steadier, unglamorous work. PostGIS gets a backported fix for memory disclosure and DoS triggered by malformed FlatGeobuf buffers. The MongoDB C driver moves to 1.30.11 for SCRAM authentication and GridFS validation. mingw-gstreamer plugs a NULL-pointer crash that shows up when parsing crafted RTSP auth headers. Nextcloud 34.0.4 rounds out the batch, and Suricata and C-Kermit take their respective upstream releases.

Rocky Linux dropped five advisories tagged Important, and three of them are really the same Firefox fix served to three different major releases. You would think patching a browser means one update, but since Firefox ships under Rocky Linux 8, 9, and 10, Mozilla's latest hole-closing shows up in triplicate. The other two land on narrower targets: a Tomcat fix for Linux 10 and a Ruby 3.3 update that reaches into three gems. Nothing here asks you to upgrade, just apply the patch.

SUSE sent just three updates to openSUSE Tumbleweed, and they happen to all be Python. Everything sits at moderate severity, so none of these will make headlines, but they cover ground you might actually use. The vllm fix is the one worth a glance if you serve LLMs locally. The Python 3.14 update is the most substantial of the group. Note that SUSE only assigned CVSS scores to two of vllm's four CVEs, both in the low single digits, which is a little odd for something labeled moderate.

Ubuntu's libwebsockets notice took two hits: an SSH handler that choked on certain protocol messages, letting an attacker starve the process, plus a second flaw where malformed CBOR data could crash the library or hand a remote attacker arbitrary code execution. Only 24.04 and 26.04 LTS carry the CBOR hole, though. LXC is a quieter pair, but there is one wrinkle: you have to restart the containers after updating, whereas the others fold in cleanly with a normal system update. Requests closes out Ubuntu's batch with a single issue, generating temporary file paths unsafely so a crafted file lets an attacker run code as your login account.

These roundups roll through every quarter without much fuss, and most of this is business as usual. The pattern holds: patch the DNS resolver and the token forgery first, then clear the rest when you get to it. Head to your distro's security announcement page for the exact advisories and update channels, and check the CVE list to confirm anything you actually run is covered.

A Detailed Overview of the Updates

Debian GNU/Linux

Debian's security team cycled through a fresh batch of advisories across four days in late September, and nearly all of them target the trixie stable release. None of it reads like an "exploit your box today" emergency, but several of these packages run on far more servers than you'd expect, so a quick glance is worth it.

The updates touch web infrastructure (nginx), mail handling (exim4), JSON processing (ruby-oj), single sign-on (lemonldap-ng), image decoding (libheif), and Swift object storage. Most advisories arrive as bundles rather than a single tidy flaw, which is normal autumn fare.

Two things pull the eye. FreeXian filed separate LTS patches for buster and bullseye on nginx since Debian's own extended-LTS window for those older releases is largely gone, so you'll need those extra steps if you're on anything older than trixie. libheif is the one to actually worry about if you feed it untrusted files, carrying seven CVEs plus eleven upstream-only GitHub Security Advisories that slipped through without a CVE number. exim4's SMTP smuggling is the flavor of vulnerability most quietly abused in the wild.

Advisory IDPackageCVE(s)ImpactFixed version
DSA-6519-1swiftCVE-2026-97149Information disclosure in Swift tempurl middleware2.35.1-0+deb13u4 (trixie)
ELA-1833-1nginxCVE-2026-42533, CVE-2026-56434DoS or arbitrary code execution (heap overflow, use-after-free)1.14.2-2+deb10u9 (buster)
ELA-1832-1nginxCVE-2026-42533, CVE-2026-56434, CVE-2026-60005DoS, memory disclosure, or arbitrary code execution1.18.0-6.1+deb11u9 (bullseye)
DSA-6521-1ruby-ojCVE-2026-54500, 54502, 54592, 54896, 54897, 54898, 54899, 54900, 54901, 54902, 54903DoS or memory disclosure in Ruby JSON parser/serializer3.16.3-1+deb13u1 (trixie)
DSA-6520-1lemonldap-ngCVE-2026-92288, 92289, 95811Access-control bypass, PKCE authorisation bypass, info disclosure2.21.2+ds-1+deb13u4 (trixie)
DSA-6522-1exim4CVE-2026-94054, 94056, 94057 (Debian Bug 1148506)SMTP smuggling, info disclosure, DoS, or arbitrary code4.98.2-1+deb13u5 (trixie)
DSA-6523-1libheifCVE-2026-84384, 84444, 84446, 84447, 84448, 84450, 84451 (+ 11 non-CVE GHSA issues)DoS, memory disclosure, or arbitrary code from malformed HEIF/AVIF images1.23.4-1~deb13u1 (trixie)

Fedora Linux

Fedora shipped a fresh round of security patches across Fedora 43 and 44 this week, and most of it is the usual business: close the hole, bump the version, move on. A handful actually earn a second look.

The one worth your attention if you tinker with AI tooling is goose. The extensible on-machine agent client picked up a fix for arbitrary command execution through goose review, which is a polite way of saying a crafted Git configuration could hand an attacker a shell. It also carries the full 1.45.0 feature set: a pile of new providers (Together AI, Perplexity, Alibaba's Qwen, several more) and a hooks system for people who like their agents extensible. The developer-agent market is thoroughly crowded, but goose is at least trying to be useful instead of just another code-suggestion box.

If you sit behind a Postgres dashboard, pgAdmin 9.18 is the bigger story. It folds in a spread of separate problems: an authentication bypass driven by a client-controlled identity header, string injection through the Restore, Maintenance, and Backup tools, and an arbitrary file write that sneaks in through a symlink in the File Manager. That's enough distinct attack surfaces to make the update count.

Chromium is the loud entry. The Fedora 44 build jumps to 154.0.8037.57 and quietly closes more than 100 CVEs in a single release, spanning use-after-free, buffer overflows, type confusion, and missing authorization checks. You probably already update your browser without thinking about it, but seeing a hundred-entry list for one build is a good reason to stop shrugging.

The rest is steadier, unglamorous work. PostGIS gets a backported fix for memory disclosure and denial of service triggered by malformed FlatGeobuf buffers, landing on the PostgreSQL 16, 17, and 18 builds. The MongoDB C driver moves to 1.30.11 for SCRAM authentication and GridFS file-ID validation. mingw-python3 absorbs the tarfile arbitrary-file-write issue. mingw-gstreamer 1.28.7 plugs a NULL-pointer crash that shows up when parsing crafted RTSP auth headers. Nextcloud 34.0.4 rounds out the batch with denial-of-service and cross-site-scripting fixes, while Suricata and C-Kermit take their respective upstream releases.

PackageFedoraVersionWhat's fixed
goose431.45.0-1.fc43Arbitrary command execution via goose review (GHSA-r5pp-p5r8-466r); new providers, hooks system
pgAdmin439.18-1.fc43Auth bypass via identity header; injection in Backup/Restore/Maintenance; symlink file write (CVE-2026-86861 through CVE-2026-86864)
mingw-python3433.11.16-1.fc43tarfile arbitrary file write via crafted links (CVE-2026-7774)
postgresql18-postgis433.6.4-5.fc43Memory disclosure and DoS from malformed FlatGeobuf (CVE-2026-73515)
postgresql16-postgis433.6.4-5.fc43Memory disclosure and DoS from malformed FlatGeobuf (CVE-2026-73515)
ckermit4311.0.509-2.fc43Update to 11.0.509 addressing CVE-2025-68920
postgresql17-postgis433.6.4-5.fc43Memory disclosure and DoS from malformed FlatGeobuf (CVE-2026-73515)
mongo-c-driver431.30.11-1.fc43SCRAM auth and GridFS file-ID fixes; CVE-2026-88035, CVE-2026-88036
nextcloud4334.0.4-1.fc43DoS via smartquotes, query-string parsing, stringify; XSS via DOMPurify (CVE-2026-48988, CVE-2026-75838, CVE-2026-82417, CVE-2026-82562)
chromium44154.0.8037.57-1.fc44100+ CVEs: use-after-free, buffer overflow, type confusion, missing authorization
mingw-gstreamer1-plugins-good441.28.7-1.fc44gstreamer 1.28.7; NULL-pointer parse crash in RTSP auth (CVE-2026-85150)
mingw-gstreamer1-plugins-bad-free441.28.7-1.fc44gstreamer 1.28.7; NULL-pointer parse crash in RTSP auth (CVE-2026-85150)
goose441.45.0-1.fc44Arbitrary command execution via goose review (GHSA-r5pp-p5r8-466r); new providers, hooks system
mingw-gstreamer1441.28.7-1.fc44gstreamer 1.28.7; NULL-pointer parse crash in RTSP auth (CVE-2026-85150)
mingw-gstreamer1-plugins-base441.28.7-1.fc44gstreamer 1.28.7; NULL-pointer parse crash in RTSP auth (CVE-2026-85150)
pgAdmin449.18-1.fc44Auth bypass via identity header; injection in Backup/Restore/Maintenance; symlink file write (CVE-2026-86861 through CVE-2026-86864)
mingw-python3443.11.16-1.fc44tarfile arbitrary file write via crafted links (CVE-2026-7774)
ckermit4411.0.509-2.fc44Update to 11.0.509 addressing CVE-2025-68920
postgresql18-postgis443.6.4-5.fc44Memory disclosure and DoS from malformed FlatGeobuf (CVE-2026-73515)
postgresql16-postgis443.6.4-5.fc44Memory disclosure and DoS from malformed FlatGeobuf (CVE-2026-73515)
postgresql17-postgis443.6.4-5.fc44Memory disclosure and DoS from malformed FlatGeobuf (CVE-2026-73515)
mongo-c-driver441.30.11-1.fc44SCRAM auth and GridFS file-ID fixes; CVE-2026-88035, CVE-2026-88036
suricata448.0.7-1.fc44Upstream security and bugfix release
nextcloud4434.0.4-1.fc44DoS via smartquotes, query-string parsing, stringify; XSS via DOMPurify (CVE-2026-48988, CVE-2026-75838, CVE-2026-82417, CVE-2026-82562)

Red Hat Enterprise Linux

Red Hat pushed out a batch of security advisories this week, and the story is mostly "Important," with three Critical calls that should make you pause before you finish patching.

The biggest worry is unbound, the DNS resolver, which appears twice as Critical: once for RHEL 7 Extended Lifecycle Support and once for the RHEL 8.8 SAP and Telecommunications channels. If you run either of those, treat it as a front-of-line job. The third Critical lands on Red Hat Identity Management (ipa) in RHEL 10, and it bundles the security fixes together with bug fixes and enhancements.

The rest is the usual distribution. Two rrdtool updates for the SAP Solutions channel are rated only Moderate, which is a welcome relief since rrdtool quietly lives in monitoring stacks nobody inspects. Everything else sits in the Important bucket: postgresql in its many forms, the qt5 and qt6 libraries, ruby, pcp, tesseract, git-lfs, libreswan, rhc, gstreamer, and an OpenShift 4.15.69 release that mixes bug fixes with security work.

Altogether that's 26 advisories spanning RHEL 7 through 10, including several Extended Update Support and SAP Solutions tracks, so it may pay to check whether more than one applies to you.

RHSA IDPackageSeverityTarget Channel
RHSA-2026:72199unboundCriticalRHEL 7 ELS
RHSA-2026:72264unboundCriticalRHEL 8.8 SAP + Telecom
RHSA-2026:72279ipaCriticalRHEL 10
RHSA-2026:72277rrdtoolModerateRHEL 9.2 SAP Solutions
RHSA-2026:72278rrdtoolModerateRHEL 9.4 SAP Solutions
RHSA-2026:72280tesseractImportantRHEL 9.2 SAP Solutions
RHSA-2026:72287libreswanImportantRHEL 8.8 SAP + Telecom
RHSA-2026:72276git-lfsImportantRHEL 9.4 SAP Solutions
RHSA-2026:67857OpenShift Container Platform 4.15.69ImportantOCP 4.15
RHSA-2026:72383qt6-qt5compatImportantRHEL 10.0 EUS
RHSA-2026:72367gstreamer1-plugins-goodImportantRHEL 7 ELS
RHSA-2026:72378qt5-qtbaseImportantRHEL 8.8 SAP + Telecom
RHSA-2026:72377qt5-qtbaseImportantRHEL 8.6 AMCU + EUS LL
RHSA-2026:72376qt5-qtbaseImportantRHEL 8.4 AMCU + EUS LL
RHSA-2026:72286rubyImportantRHEL 9
RHSA-2026:72361postgresqlImportantRHEL 9.2 SAP Solutions
RHSA-2026:72363postgresql:12ImportantRHEL 8.6 AMCU + EUS LL
RHSA-2026:72362postgresql:12ImportantRHEL 8.8 SAP + Telecom
RHSA-2026:72272pcpImportantRHEL 9.6 EUS
RHSA-2026:72275rhcImportantRHEL 9
RHSA-2026:72285ruby:3.3ImportantRHEL 8
RHSA-2026:72273pcpImportantRHEL 10.0 EUS
RHSA-2026:72274postgresql:12ImportantRHEL 8
RHSA-2026:72281postgresqlImportantRHEL 9.6 EUS
RHSA-2026:72282postgresql16ImportantRHEL 10.0 EUS
RHSA-2026:72283postgresqlImportantRHEL 9.4 SAP Solutions

Rocky Linux

Rocky Linux just dropped five security advisories tagged "Important," and three of them are really just the same Firefox fix served to three different major releases. You'd think patching a browser would mean one update, but since Firefox ships under Rocky Linux 8, 9, and 10, Mozilla's latest hole-closing gets patched in triplicate. The other two land on narrower targets: a Tomcat fix for Linux 10 and a Ruby 3.3 update that reaches into three gems. Nothing here asks you to upgrade, just apply the patch.

Advisory IDPackageAffected OSDetails
RLSA-2026:67129FirefoxRocky Linux 10Browser security update
RLSA-2026:67133FirefoxRocky Linux 9Browser security update
RLSA-2026:68549FirefoxRocky Linux 8Browser security update
RLSA-2026:25341tomcat9Rocky Linux 10Server security update
RLSA-2026:72285ruby:3.3 (rubygem-mysql2, rubygem-abrt, rubygem-pg)Rocky Linux 8Multiple gems patched

SUSE Linux

Three security updates landed on openSUSE Tumbleweed's general availability media, and they happen to all be Python. Everything sits at moderate severity, so none of these are going to make headlines, but they cover ground you might actually use. The vllm fix is the one worth a glance if you serve LLMs locally, since that package is the framework people lean on for it. The Python 3.14 update is the most substantial of the group, mending three separate issues across the interpreter and its bundled libraries. The WebOb patch is the low-key one, shutting a single hole across three package variants.

Note that SUSE only assigned CVSS scores to two of vllm's four CVEs, and both sit in the low single digits. That's a little odd for something labeled moderate, but the numbers don't argue with the rating. All three updates target Tumbleweed only.

Announcement IDPackage(s)CVE(s)Highest CVSSSeverity
openSUSE-SU-2026:11864-1python-WebOb-doc 1.8.11-1.1, python313-WebOb 1.8.11-1.1, python314-WebOb 1.8.11-1.1CVE-2026-547706.1moderate
openSUSE-SU-2026:11868-1python314 3.14.7-2.1, python314-32bit, python314-curses, python314-dbm, python314-idle, python314-tk, python314-x86-64-v3 (all 3.14.7-2.1)CVE-2026-15310, CVE-2026-17084, CVE-2026-196726.3moderate
openSUSE-SU-2026:11867-1python313-vllm 0.30.0-1.1CVE-2026-90713, CVE-2026-92365, CVE-2026-93841, CVE-2026-939894.3moderate

Ubuntu Linux

Ubuntu shipped four security notices. The range spans the genuinely bad to the mildly annoying, so here is the breakdown.

libwebsockets (USN-8822-1) took two hits. Its SSH handler choked on certain SSH protocol messages, letting an attacker starve the process for a denial of service (CVE-2026-10650). A second flaw means malformed CBOR data could either crash the library or, worse, hand a remote attacker a way to run arbitrary code (CVE-2026-78161). Only 24.04 and 26.04 LTS carry the CBOR hole. The 26.04 track lands on 4.3.5, while the older releases get patched through Ubuntu Pro.

PyJWT (USN-8823-1) got the most CVEs of the bunch, at five. The standout is a signature-bypass that triggers when both HMAC and asymmetric algorithms are enabled, letting attackers forge valid tokens (CVE-2026-48526). There is also a PyJWKClient problem that opens the door to server-side request forgery and leaking local files (CVE-2026-48522), alongside two denial-of-service paths from untrusted key requests and detached JWS payloads, plus a forgery path for tokens decoded with PyJWK keys (CVE-2026-48523). This one reaches six releases, down to 16.04 LTS.

LXC (USN-8826-1) is a quieter pair. One flaw leaks sensitive information when failure messages get logged (CVE-2022-47952), and another trips over user authorization handling to cause a denial of service (CVE-2026-39402). The one wrinkle: you have to restart the containers after updating, whereas the others fold in cleanly with a normal system update.

Requests (USN-8825-1) closes out the batch with a single issue. It generated temporary file paths unsafely, so opening a specially crafted file let an attacker run code as your login account (CVE-2026-25645).

Security NoticePackageCVEsImpactFixed versionNotes
USN-8822-1libwebsocketsCVE-2026-10650, CVE-2026-78161SSH message mishandling (DoS); malformed CBOR data (DoS or code execution)4.3.5 (26.04); 4.3.3 (24.04); 4.0.20 (22.04); 3.2.1 (20.04)CBOR bug only on 24.04 and 26.04; older fixes via Ubuntu Pro
USN-8823-1pyjwtCVE-2026-48522, CVE-2026-48523, CVE-2026-48524, CVE-2026-48525, CVE-2026-48526SSRF and local file exposure; signature bypass and token forgery; two DoS paths2.10.1 (26.04); 2.7.0 (24.04); 2.3.0 (22.04); 1.7.1 (20.04); 1.5.3 (18.04); 1.3.0 (16.04)Six releases affected; older tracks via Ubuntu Pro
USN-8826-1lxcCVE-2022-47952, CVE-2026-39402Info leak via logging; DoS via authorization handling1:6.0.6 (26.04); 1:5.0.3 (24.04); 1:5.0.0 (22.04); 1:4.0.12 (20.04); 1:3.0.3 (18.04); 1:2.0.11 (16.04)Restart containers after update; all via Ubuntu Pro
USN-8825-1requestsCVE-2026-25645Unsafe temp file path creation runs code as login user2.32.5 (26.04); 2.31.0 (24.04); 2.25.1 (22.04); 2.22.0 (20.04)20.04 fix via Ubuntu Pro

How to apply these Linux security updates

Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.

Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.

Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.

Debian/Ubuntu (apt)

The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.

sudo apt update
sudo apt upgrade -y

Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)

On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.

sudo dnf check-update
sudo dnf upgrade -y

or on older releases

sudo yum check-update
sudo yum update

SUSE (zypper)

SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.

sudo zypper refresh
sudo zypper update -y