Eight major Linux vendors shipped a large round of security updates, led by Red Hat's 48 errata and its lone Critical rating on the Red Hat Directory Server redhat-ds:11 module. Kernel rollups dominated across the board, with SUSE logging 153 CVEs (84 in the kernel alone) and Oracle's UEK 5.15 and 6.12 builds each carrying several hundred. Notable non-kernel hits include Fedora Xwayland's 12 CVEs, Ubuntu's Erlang fix for 30 issues, and a glibc TOCTOU privilege-escalation flaw in SLE 15. Patch priority starts with the directory server, then the kernel reboots, then the Important and Moderate fixes.
Linux vendors ship a heavy security round; RHEL Directory Server earns the lone Critical
Eight major Linux vendors pushed security updates this cycle, and the total is unusually large. Red Hat alone handed out 48 errata, exactly one of which is a genuine Critical. Fedora, Ubuntu, SUSE, Oracle, AlmaLinux, Rocky, and Debian filled out the rest with mostly Important and Moderate fixes.
Red Hat's lone Critical lands on Red Hat Directory Server's redhat-ds:11 module. It's advisory RHSA-2026:79217, shipped for the Extended 4-year Support track on RHEL 8. If you still run directory services on that track, this is the patch you should chase down first.
Everything else on the Red Hat side clusters around Important. Kernels took the biggest hit this round, with five Important updates plus a Moderate real-time variant spread across RHEL 9, RHEL 10, two EUS tracks, and a RHEL 7 ELS holdout. OpenSSL and Python each picked up two Important advisories split between RHEL 9 and RHEL 10. PostgreSQL scattered across the 8.4, 8.6, and 8.8 Advanced Mission Critical, SAP, and Telecommunications tracks. If you're still running postgresql:12 anywhere in there, line up several updates.
There's also a quiet corner. Four Low-rated libxml2 advisories sit across the SAP and Extended Support lines. Low isn't nothing. It's just the kind of thing you put on a calendar instead of racing to fix it.
Keep in mind that the kernel volume tells a familiar story. These updates matter, yes. But a few hundred CVEs jammed into a single kernel advisory usually says more about upstream bundling than about the patch itself.
Holes elsewhere
On Fedora, Xwayland on Fedora 44 is the one worth upgrading before your next reboot. Version 24.1.14 takes in 12 separate CVEs in a single jump. Run X clients under Wayland? This is the important one. Sudo picked up a single fix, CVE-2026-96512, but only on Fedora 44. A tool whose entire reason for existing is deciding who may become root, it's a little odd it skipped Fedora 43. The patch is out. Apply it.
SUSE's wave is the biggest by raw CVE count, at 153 across 22 advisories. The Linux Kernel (SUSE-SU-2026:4595-1) accounts for 84 of them on its own, spanning networking, RDMA, BPF, KVM, and iSCSI. SUSE asks for a reboot. Most of those are use-after-free and memory-corruption bugs, so delaying only buys you a bigger headache later.
For SLE 15 users the glibc patch (SUSE-SU-2026:4591-1) is the one that'll keep you up. Of its ten fixes sits a TOCTOU race in the dynamic loader that lets local attackers escalate privileges. There's also an nscd stack overflow that quietly degrades DNS.
Ubuntu's batch is fifteen notices, and the kernels dominate again. Six separate USNs cover the generic build plus the AWS, Azure, GCP, and IBM cloud variants, together patching well over a hundred CVEs. Two things before you run the update. You have to reboot. The kernel builds also carry a deliberate ABI change, so third-party modules like NVIDIA drivers or zfs need recompiling. A normal apt upgrade handles the metapackage but leaves the modules to you.
Erlang is the standout non-kernel story here, fixing 30 issues clustered around the TLS/SSL stack and the built-in servers. A couple are genuinely useful for attackers: the SSH server enabling zlib compression by default without bounding the decompressed size, and the DNS resolver using predictable transaction IDs.
Oracle Linux pushed a wide batch across OL7 through OL10, and the UEK kernels carry the real volume. The OL9 UEK 5.15 and UEK 6.12 kernels each show up with several hundred CVEs between them. If you're on one of those OL9 builds, the reboot is the main event.
AlmaLinux threw out six "Important" advisories on October 7 and 8. The sharpest edge is on vim, where CVE-2026-73073 lets a crafted tags file trigger arbitrary command execution through omni-completion. Opening the wrong file in the editor can hand an attacker a shell. Vim has been the perennial problem child of this story for years, and this is just the most blatant version yet. BIND carries the most CVEs overall, though they're all denial-of-service flavor.
Debian's LTS advisories are smaller fare, hitting a media framework and the Rails web framework. Rails gets eight CVEs in one release, including path traversal and one entry that would let crafted images run code through libvips. Nothing that rewrites the rulebook. The one you might trip over by accident is feeding number_to_delimited a really long digit string and watching CPU spike.
Rocky Linux kept it sparse, as those notes often do. Five updates, mostly version 9, with openssl as the lone jump to version 10. Each names a package and points you at a CVE list, leaving the actual details for you to dig up. If you run any of these on production, the advisory link is where the homework happens.
A Detailed Overview of the Updates
AlmaLinux
AlmaLinux pushed out six security advisories within a couple of days, and every single one is stamped "Important." That severity tier sits just under "Critical," which tends to mean "get to this before you get comfortable." All six landed on October 7 and 8, 2026, spanning Linux 8, 9, and 10.
The sharpest edge is on vim. CVE-2026-73073 lets a crafted tags file trigger arbitrary command execution through C omni-completion, so opening the wrong file in the editor can hand an attacker a shell. You probably hadn't fully appreciated how much of your workflow leans on a text editor, but this one earns the attention.
BIND comes with the most CVEs, and they're all denial-of-service flavor. Three separate paths, a 16-bit length truncation in DNS negative cache handling, a crafted DNSSEC reply, and malformed DNS64 responses, can each take a nameserver offline. If you run your own DNS, that is the batch to prioritize.
The kernel situation is a little redundant. The same trio of fixes appears in both a plain kernel advisory and a kernel-rt advisory for Linux 8. Those cover a vsock/vmci use-after-free during a peer reset, the packet hard_header_len consistency fixes, and the svcrdma inline-reply buffer overflow. A single apply satisfies both advisories, so you can skip the second one.
The rest is smaller. perl-DBI can crash on a bad numeric type cast, the Sequoia command-line frontend has a key-flag confusion bug that undermines cryptographic integrity, and a bundled capnproto gets unbundled as a bit of housekeeping.
| Advisory ID | Package | AlmaLinux release | Released | What's fixed |
|---|---|---|---|---|
| ALSA-2026:77359 | vim | 8 | 2026-10-08 | CVE-2026-73073: arbitrary command execution via crafted tags file in C omni-completion |
| ALSA-2026:77500 | kernel-rt | 8 | 2026-10-08 | CVE-2026-64115, CVE-2026-74582, CVE-2026-89530 |
| ALSA-2026:77498 | kernel | 8 | 2026-10-08 | CVE-2026-64115, CVE-2026-74582, CVE-2026-89530 (same fixes as kernel-rt) |
| ALSA-2026:77576 | perl-DBI | 8 | 2026-10-08 | CVE-2026-88815: denial of service via invalid memory read during numeric type casting |
| ALSA-2026:76737 | rust-sequoia-sq | 10 | 2026-10-08 | CVE-2026-42784: crypto integrity compromise via key flag confusion; capnproto unbundled |
| ALSA-2026:75767 | bind | 9 | 2026-10-07 | CVE-2026-19667, CVE-2026-80274, CVE-2026-19666: three denial-of-service paths |
Debian GNU/Linux
Two Debian LTS advisories dropped for packages still getting security maintenance on Debian 12 bookworm. One hits a media framework, the other the Rails web framework. Both are the "please patch your stuff" flavor you probably already know by heart, but the details are worth a glance.
The gst-plugins-base1.0 update is the smaller of the two, tacking on fixes for a buffer overflow in the Opus decoder and a NULL pointer deref in the RTSP library. Either one can crash things; the Opus one is worse because a malformed audio file could in principle let arbitrary code run. The RTSP flaw is mostly a crash risk when digest auth is involved, either server or client side.
Rails gets the bulk of the attention here, with eight CVEs bundled into one release. The usual suspects show up: cross-site scripting here, denial of service there, path traversal sneaking in somewhere, and one entry that would let crafted images execute code through libvips. Nothing that rewrites the rulebook, but some of these are easy to trigger by accident—like feeding number_to_delimited a really long digit string and watching CPU spike.
| Advisory | Package | Fixed version | CVEs | What's fixed |
|---|---|---|---|---|
| DLA-4828-1 | gst-plugins-base1.0 | 1.22.0-3+deb12u7 | CVE-2026-18297 | Buffer overflow in Opus audio decoder; DoS or arbitrary code from a malformed audio file |
| DLA-4828-1 | gst-plugins-base1.0 | 1.22.0-3+deb12u7 | CVE-2026-85150 | NULL pointer deref in RTSP library parsing Digest auth headers; DoS via crafted request or response |
| DLA-4829-1 | rails | 2:6.1.7.10+dfsg-1~deb12u3 | CVE-2026-33168 | Action View tag helpers now escape blank HTML attribute names (fixes XSS) |
| DLA-4829-1 | rails | 2:6.1.7.10+dfsg-1~deb12u3 | CVE-2026-33169 | Active Support's number_to_delimited no longer takes quadratic time on long digit strings (DoS) |
| DLA-4829-1 | rails | 2:6.1.7.10+dfsg-1~deb12u3 | CVE-2026-33170 | Unsafe SafeBuffer formatted with % no longer marked html_safe (fixes XSS) |
| DLA-4829-1 | rails | 2:6.1.7.10+dfsg-1~deb12u3 | CVE-2026-33173 | Active Storage direct uploads can no longer set analyzed/identified metadata keys (fixes XSS) |
| DLA-4829-1 | rails | 2:6.1.7.10+dfsg-1~deb12u3 | CVE-2026-33176 | Number helpers no longer expand scientific notation like "1E1000" through BigDecimal (DoS) |
| DLA-4829-1 | rails | 2:6.1.7.10+dfsg-1~deb12u3 | CVE-2026-33176 | (Duplicate CVE number in source; see row above) |
| DLA-4829-1 | rails | 2:6.1.7.10+dfsg-1~deb12u3 | CVE-2026-33195 | Disk service now rejects "../" keys, raising InvalidKeyError (path traversal) |
| DLA-4829-1 | rails | 2:6.1.7.10+dfsg-1~deb12u3 | CVE-2026-33202 | delete_prefixed now escapes glob metacharacters before passing to Dir.glob |
| DLA-4829-1 | rails | 2:6.1.7.10+dfsg-1~deb12u3 | CVE-2026-66066 | :vips variant processor now blocks untrusted libvips loaders; MiniMagick unaffected |
Fedora Linux
Fedora pushed a round of security fixes across Fedora 43 and Fedora 44, and if you're on either release there's a package worth upgrading before the next reboot. Most of these are routine, but a few clear real holes.
The Xwayland server on Fedora 44 is the one to look at. Version 24.1.14 takes in 12 separate CVEs in a single jump. That's a big stack of holes to close at once, which says more about how much landed upstream than about the patch itself. Run X clients under Wayland? This is the important one.
Sudo picked up a single fix, CVE-2026-96512, and only on Fedora 44. A tool whose whole reason for existing is deciding who may become root, it's a little odd it skipped Fedora 43. The patch is out, so apply it.
Cockpit got the most complete treatment on Fedora 43. Three advisories landed together, including an unbounded connection thread spawning flaw (CVE-2026-91149) plus hardening against a trailing-slash issue and PackageKit URL handling. A web console is an obvious attack surface, so capping connection spawning is a fair move.
The Hetzner CLI (hcloud) closed out two SSH denial-of-service issues in golang.org/x/crypto/ssh (CVE-2026-56855 and CVE-2026-78662), on both releases. Perl's DBI module took a hit too, with two more DoS bugs around numeric type casting (CVE-2026-88815 and CVE-2026-88816), also on both.
ModSecurity users on Fedora 44 rebuilt libmodsecurity (3.0.17) and its nginx connector in lockstep to cover the September advisory fixes. No CVE numbers are spelled out, so read that as "we sorted things out" unless you want to dig through the upstream digest yourself.
Then there's barman, the PostgreSQL backup tool. Both releases rolled 3.20.1 with no security issue attached. Pure version bump, fine when you want newer features, just don't expect it to fight off an attacker.
Everything installs the same way, through dnf upgrade --advisory <FEDORA-ID>.
| Package | Version | Fedora release | What this update does |
|---|---|---|---|
| hcloud | 1.69.0 | 43, 44 | Closes two SSH DoS CVEs (CVE-2026-56855, CVE-2026-78662) |
| perl-DBI | 1.655 | 43, 44 | Fixes two numeric DoS CVEs (CVE-2026-88815, CVE-2026-88816) |
| barman | 3.20.1 | 43, 44 | Version bump, no security fix |
| cockpit | 368 | 43 | Bundles three CVE fixes, incl. DoS via unbounded connections (CVE-2026-91149) |
| sudo | 1.9.17-10.p2 | 44 only | Fixes CVE-2026-96512 |
| Xwayland | 24.1.14 | 44 only | Patches 12 CVEs |
| libmodsecurity | 3.0.17 | 44 only | Rebuilt for September advisory fixes |
| nginx-mod-modsecurity | 1.0.4-18 | 44 only | Rebuilt alongside libmodsecurity |
Oracle Linux
Oracle Linux just pushed a wide batch of advisories across OL7 through OL10, and the kernels are doing most of the work. The UEK rollups carry the real volume. The OL9 UEK 5.15 kernel and the OL9 UEK 6.12 kernel each show up with several hundred CVEs between them, which is normal for kernel packages but still a big patch to swallow.
The packages you might actually touch are more modest. Firefox climbed to 140.17.0 (ESR) to clear out a batch of bugs, most of them routine. Vim got its security pass on both OL8 and OL10, as did Python 3.12, Node 24, FreeRDP, BIND 9.18, and perl-DBI. Virtuoso, sg3_utils, and rpm-sequoia each take out a single backported fix. One entry is not security at all: the ELBA for fips-provider-next retightens RSA key import speed and fixes a pair of test-suite deadlocks.
The advisories name their CVEs but rarely spell out impact, so treat the kernel updates as apply-and-reboot and the app fixes as check-what-you-run. If you're on one of the OL9 UEK builds, that reboot is the main event.
| Advisory | OS version | Package | What changed |
|---|---|---|---|
| ELSA-2026-67157-0 | OL7 | sg3_utils 1.37-19.0.3 | Backported fix for CVE-2026-16313 |
| ELSA-2026-66026-0 | OL7 | virtuoso-opensource 6.1.6 | Fixes for CVE-2025-61021 and CVE-2024-57656 |
| ELSA-2026-77359 | OL8 | vim 8.0.1763-32.0.1 | Adds fixes for code injection, buffer overflows, out-of-bounds writes (CVE-2026-73073 and friends) |
| ELSA-2026-77028 | OL8 | python3.12 3.12.15 | Bumps to 3.12.15 with 8 security fixes |
| ELSA-2026-500375 | OL8 | UEK kernel 5.4.17-2136.360.3 | 13 CVEs across net, crypto, KVM, netfilter, tipc |
| ELSA-2026-500377 | OL8 | UEK kernel 5.15.0-325.220.5 | Security update (bpftool, containers, modules) |
| ELSA-2026-76755 | OL9 | freerdp 2.11.7 | Six backported CVE fixes |
| ELSA-2026-76733 | OL9 | rpm-sequoia 1.10.2.1 | Rebase with fix for CVE-2026-42784 |
| ELSA-2026-500377 | OL9 | UEK kernel 5.15.0-325.220.5 | Several hundred CVEs |
| ELBA-2026-76614 | OL10 | fips-provider-next 1.5.2 | Bugfix/enhancement: RSA key import perf, test deadlocks, self-test patch |
| ELSA-2026-500374 | OL9 | UEK kernel 6.12.0-207.111.5.1 | Several hundred CVEs across gpu, crypto, network, storage |
| ELSA-2026-76760 | OL9 | perl-DBI 1.643-9.7 | CVE-2026-88815, DoS via invalid memory read in numeric casting |
| ELSA-2026-75578 | OL9 | bind9.18 9.18.29-14.10 | Five CVEs (assertion failure, memory leak, crash) plus new root key |
| ELSA-2026-76761 | OL9 | firefox 140.17.0 ESR | Large batch of bug fixes; adds OpenELA/Oracle default prefs |
| ELSA-2026-73428 | OL10 | nodejs24 24.21.0 | Adds c-ares dependency; 3 CVEs |
| ELSA-2026-75769 | OL10 | vim 9.1.083-9.0.1.22 | Same vim fixes as the OL8 build |
| ELSA-2026-70498 | OL10 | kernel 6.12.0-211.60.1 | Bugfixes, signing changes (new driver signing key, UKI signing disabled) |
Red Hat Enterprise Linux
Red Hat handed out 48 security errata in this batch, and if you only patch one thing today, make it the directory server. Only one advisory here carries a Critical rating, and it lands on Red Hat Directory Server's redhat-ds:11 module (RHSA-2026:79217), shipped for the Extended 4-year Support track on RHEL 8. The rest cluster around Important, which is where the real volume sits.
Kernel is getting an inordinate amount of attention this round. Count them: five Important kernel updates alongside one Moderate real-time variant, spread across RHEL 9, RHEL 10, 9.6 EUS, 10.0 EUS, and a RHEL 7 ELS holdout. If you run anything on an Extended Update Support track, these updates are not going anywhere, and neither should you.
Several packages show up more than once, which is usually a sign you have legacy support tracks to sort through. OpenSSL gets two Important advisories, one each for RHEL 9 and RHEL 10. Python mirrors that split, with python3.12 and python3.14 each getting a pair. PostgreSQL is the real scattergun, scattered across the 8.4, 8.6, and 8.8 Advanced Mission Critical, SAP, and Telecommunications support tracks. If you are still running postgresql:12 anywhere in there, line up several updates.
The quiet corner of the release is the four Low-rated libxml2 advisories across the SAP and Extended Support lines. Low is not nothing, but it is the kind of thing you put on a calendar rather than race to fix. The full breakdown follows.
| Errata ID | Package | Severity | Release / Support track | Scope |
|---|---|---|---|---|
| RHSA-2026:79217 | redhat-ds:11 | Critical | RHEL Directory Server 11.5 E4S (RHEL 8) | Security, bug fix, enhancement |
| RHSA-2026:77396 | openssl | Important | RHEL 9 | Security |
| RHSA-2026:76918 | openssl | Important | RHEL 10 | Security |
| RHSA-2026:77017 | python3.12 | Important | RHEL 9 | Security |
| RHSA-2026:77020 | python3.12 | Important | RHEL 10 | Security |
| RHSA-2026:77018 | python3.14 | Important | RHEL 10 | Security |
| RHSA-2026:77021 | python3.14 | Important | RHEL 9 | Security |
| RHSA-2026:76739 | kernel | Important | RHEL 9 | Security, bug fix, enhancement |
| RHSA-2026:77689 | kernel | Important | RHEL 9 | Security, bug fix, enhancement |
| RHSA-2026:77690 | kernel | Important | RHEL 10 | Security, bug fix, enhancement |
| RHSA-2026:77219 | kernel | Important | RHEL 9.6 EUS | Security, bug fix, enhancement |
| RHSA-2026:77634 | kernel | Important | RHEL 10.0 EUS | Security, bug fix, enhancement |
| RHSA-2026:76750 | nodejs:22 | Important | RHEL 9 | Security |
| RHSA-2026:77297 | resteasy | Important | RHEL 9.6 EUS | Security |
| RHSA-2026:77632 | thunderbird | Important | RHEL 9.2 USFS | Security |
| RHSA-2026:79114 | dracut | Important | RHEL 6 ELSC Extension | Security, bug fix, enhancement |
| RHSA-2026:76744 | opentelemetry-collector | Important | RHEL 9 | Security |
| RHSA-2026:76755 | freerdp | Important | RHEL 9 | Security |
| RHSA-2026:76760 | perl-DBI | Important | RHEL 9 | Security |
| RHSA-2026:79113 | bind9.16 | Important | RHEL 8 | Security, bug fix, enhancement |
| RHSA-2026:79112 | rhc-worker-playbook | Important | RHEL 10.0 EUS | Security |
| RHSA-2026:79028 | postgresql:12 | Important | RHEL 8.6 AMCUS + EUS LL | Security |
| RHSA-2026:79027 | postgresql:12 | Important | RHEL 8.6 AMCUS + EUS LL | Security |
| RHSA-2026:79009 | postgresql:12 | Important | RHEL 8.8 USFS + TCU | Security |
| RHSA-2026:77648 | dogtag-pki | Important | RHEL 10 | Security |
| RHSA-2026:79011 | rhc | Important | RHEL 9.4 USFS | Security |
| RHSA-2026:79012 | rhc | Important | RHEL 9.2 USFS | Security |
| RHSA-2026:79010 | rhc | Important | RHEL 9.6 EUS | Security |
| RHSA-2026:73851 | OpenShift 4.16.72 | Important | OpenShift 4.16 | Security, bug fix |
| RHSA-2026:73864 | OpenShift 4.14.75 | Important | OpenShift 4.14 | Security, bug fix (packages) |
| RHSA-2026:73866 | OpenShift 4.14.75 | Important | OpenShift 4.14 | Security, bug fix |
| RHSA-2026:79162 | bind | Important | RHEL 8 | Security |
| RHSA-2026:79160 | bind9.16 | Important | RHEL 8.8 USFS + TCU | Security, bug fix, enhancement |
| RHSA-2026:74797 | MicroShift 4.20.41 | Important | MicroShift 4.20 | Security |
| RHSA-2026:79371 | dovecot | Important | RHEL 10 | Security |
| RHSA-2026:79122 | cjose | Important | RHEL 10 | Security |
| RHSA-2026:79177 | mod_auth_openidc | Important | RHEL 9 | Security |
| RHSA-2026:79101 | Ceph Storage 8.1 | Important | Ceph Storage 8.1 | Security, bug fix |
| RHSA-2026:78952 | tftp | Moderate | RHEL 8 | Security |
| RHSA-2026:78843 | kernel-rt | Moderate | RHEL 7 ELS | Security |
| RHSA-2026:79281 | glibc | Moderate | RHEL 9 | Security, bug fix, enhancement |
| RHSA-2026:76781 | glibc | Moderate | RHEL 10 | Security, bug fix, enhancement |
| RHSA-2026:77534 | sssd | Moderate | RHEL 10 | Security |
| RHSA-2026:78951 | kbd | Moderate | RHEL 8 | Security |
| RHSA-2026:79118 | libxml2 | Low | RHEL 9.2 USFS | Security |
| RHSA-2026:79120 | libxml2 | Low | RHEL 8.6 AMCUS + EUS LL | Security |
| RHSA-2026:79121 | libxml2 | Low | RHEL 9.4 USFS | Security |
| RHSA-2026:79119 | libxml2 | Low | RHEL 8.8 USFS + TCU | Security |
Rocky Linux
Rocky Linux is pushing out five security updates this cycle, mostly to version 9, with a single exception landing on version 10. The announcements are about as sparse as errata notes get: each one names a package, points you at a CVE list for severity scores, and leaves the actual details for you to go dig up. Nothing here tells you exactly what's being patched, so if you're running any of these on production, the link is where you'll do the homework.
The openssl jump is the only one touching Rocky Linux 10, and nodejs:22 lands on the 9 line. Freerdp, perl-DBI, and opentelemetry-collector round out the rest, all on 9. Worth checking these regardless of which distro version you're on, since openssl is the odd one out.
| Errata ID | Package | Rocky Linux Version |
|---|---|---|
| RLSA-2026:76750 | nodejs:22 | 9 |
| RLSA-2026:76918 | openssl | 10 |
| RLSA-2026:76755 | freerdp | 9 |
| RLSA-2026:76760 | perl-DBI | 9 |
| RLSA-2026:76744 | opentelemetry-collector | 9 |
SUSE Linux
SUSE put out another wide security update, and the sheer count makes it worth pausing to patch. This wave touches openSUSE Leap 16.0, openSUSE Tumbleweed, and a pile of SUSE Linux Enterprise 15 variants, so if any of those run in your shop you've got work to do. The total lands at 153 CVEs across 22 advisories, with the Linux Kernel single-handedly accounting for 84 of them.
The kernel update (SUSE-SU-2026:4595-1) is the one to treat as a priority. It closes a huge list of flaws spanning networking, RDMA, BPF, KVM, iSCSI, and a dozen more, plus ten non-security fixes. SUSE asks for a reboot after applying it, which you were probably going to do anyway. Most of those CVEs are use-after-free and memory-corruption bugs rated high enough that delaying only buys you a bigger headache later.
For SLE 15 users the glibc patch (SUSE-SU-2026:4591-1) is the scary one. Of its ten fixes is a TOCTOU race in the dynamic loader that lets local attackers escalate privileges, alongside an nscd stack overflow that quietly degrades DNS and a reachable assert that crashes processes over the network.
The emacs update (4594-1) closes an arbitrary-code-execution flaw from editing untrusted files in most modes. That's the incomplete-fix story, so if you frequently open random text in Emacs you already know the move. wpa_supplicant (4590-1) gets a fix for a missing check that could let someone skip local WiFi security, and php-composer2 (4589-1) handles path traversal, permission changes from package paths, and a token leak hiding in debug output.
On the openSUSE front, alloy (22032-1) is the heavyweight with 19 vulnerabilities folded into a bump to 1.19.2. The jackson trio (22034-1) takes ten fixes, and the AWS ECS agent (22035-1) ships three security patches next to a feature most people won't touch: MPS GPU sharing. It's there for those actually running NVIDIA MPS workloads and harmless for everyone else.
The rest of the openSUSE-SU entries are the quiet ones. Half a dozen target Tumbleweed on GA media - perl-DBI, helm, helm3, poppler, GitPython, logback, pvetui, portprotonqt, pi-coding-agent, and hauler - almost all rated moderate, and several of them chase the same klauspost/compress overflow (CVE-2026-63209) that also appears in the distribution package. Low stakes, but quick wins.
| Announcement | Package | Rating | # CVEs | What it actually fixes |
|---|---|---|---|---|
| openSUSE-SU-2026:22039-1 | distribution (distribution-registry) | important | 1 | klauspost/compress signed integer overflow (CVE-2026-63209) |
| openSUSE-SU-2026:22040-1 | busybox | moderate | 5 | awk heap overflow, crafted-script DoS, use-after-free |
| openSUSE-SU-2026:22035-1 | amazon-ecs-init | important | 3 | grpc xDS RBAC bypass + HTTP/2 heap exhaustion; to 1.107.0 |
| openSUSE-SU-2026:22032-1 | alloy | important | 19 | crypto/ssh auth bypass, go-git symlink read, mongo driver; to 1.19.2 |
| openSUSE-SU-2026:22034-1 | jackson (annotations/core/databind) | important | 10 | async parser bypass, Path URI deserialization, cache growth; to 2.18.11 |
| openSUSE-SU-2026:22031-1 | libXtst | important | 1 | out-of-bounds read in RECORD parser (CVE-2026-94286) |
| openSUSE-SU-2026:11966-1 | perl-DBI (Tumbleweed) | moderate | 2 | GA media release |
| openSUSE-SU-2026:11970-1 | pvetui (Tumbleweed) | moderate | 1 | CVE-2026-33186, CVSS 8.1 |
| openSUSE-SU-2026:11964-1 | helm3 (Tumbleweed) | moderate | 1 | CVE-2026-63209 |
| openSUSE-SU-2026:11968-1 | libpoppler-cpp3 (Tumbleweed) | moderate | 2 | GA media release |
| openSUSE-SU-2026:11963-1 | helm (Tumbleweed) | moderate | 2 | CVE-2026-63209 + CVE-2026-81870 |
| openSUSE-SU-2026:11965-1 | logback (Tumbleweed) | moderate | 1 | CVE-2026-19880 |
| openSUSE-SU-2026:11967-1 | pi-coding-agent (Tumbleweed) | moderate | 2 | CVE-2026-102277/102278 |
| openSUSE-SU-2026:11969-1 | portprotonqt (Tumbleweed) | moderate | 1 | CVE-2026-59678 |
| openSUSE-SU-2026:11971-1 | python313/314-GitPython (Tumbleweed) | moderate | 1 | CVE-2026-100689 |
| openSUSE-SU-2026:11962-1 | hauler (Tumbleweed) | moderate | 1 | CVE-2026-63209 |
| SUSE-SU-2026:4589-1 | php-composer2 | important | 3 | path traversal, permission mods, token disclosure; SLE 15 SP4/SP5 |
| SUSE-SU-2026:4591-1 | glibc | important | 10 | loader TOCTOU priv-esc, nscd DoS; SLE 15, Leap 15.3 |
| SUSE-SU-2026:4590-1 | wpa_supplicant | important | 1 | PMKSA local security bypass; SLE 15 SP5 |
| SUSE-SU-2026:4592-1 | GraphicsMagick | moderate | 1 | uncontrolled WPG recursion; Leap 15.6 |
| SUSE-SU-2026:4594-1 | emacs | important | 1 | arbitrary code editing untrusted files |
| SUSE-SU-2026:4595-1 | Linux Kernel | important | 84 (+ 10 non-sec) | broad memory-safety fixes; reboot required |
Ubuntu Linux
Ubuntu put out fifteen security notices. Most of them land on Ubuntu 24.04 and 22.04 LTS; the older releases (20.04 and below) mostly need a Ubuntu Pro subscription to get the patched packages at all. The kernels are the usual broad sweeps, and Erlang happened to draw a long list.
The kernel updates dominate this batch. Six separate USNs cover the generic build plus the AWS, Azure, GCP, and IBM cloud variants, together patching well over a hundred CVEs across nearly every subsystem worth naming: GPU drivers, USB, networking, filesystems, KVM, the works. Two things to know before you run the update. First, you have to reboot. Second, the kernel builds carry a deliberate ABI change, so any third-party kernel modules (NVIDIA drivers, VirtualBox, zfs, similar) need recompiling. A normal apt upgrade sorts out the metapackage side automatically but leaves the modules to you.
Erlang is the stand-out non-kernel story, fixing 30 issues that cluster around the TLS/SSL stack and the built-in servers (SFTP, SSH, HTTP, FTP, DNS). Some are genuinely useful for attackers: the SSH server enabling zlib compression by default without bounding the decompressed size, the DNS resolver using predictable transaction IDs, and the HTTP server not enforcing access controls on CGI scripts served through aliases.
libxml2 picked up six problems. A couple are heap buffer overflows from oversized qualified names and XPointer expressions that could run code, and one lets XML external entity injection through because parser options like blocking network access get ignored under XInclude.
The Apache fix (three CVEs) mixes two memory-handling bugs in mod_rewrite and mod_http2 that are mostly denial of service with a mod_ssl one that actually bypasses access restrictions. You need to restart apache2 afterward.
The remaining notices are single-CVE jobs or small hauls. GStreamer Ugly Plugins has four, all requiring a user to actually open a crafted media file, which trims the threat surface considerably. lxml has two, one of which lets a remote attacker read local files. libarchive has a signed integer overflow in the ZIP writer, libpng has a compression-chunk crash, libgit2 lets a machine-in-the-middle slip past TLS certificate checks, and libde265 just crashes on bad H.265 streams.
| USN | Component | Approx. CVEs | What breaks | Before you update |
|---|---|---|---|---|
| USN-8901-1 | Erlang | 30 | TLS/SSL stack; SFTP, SSH, HTTP, FTP, DNS servers | Reboot after install |
| USN-8903-1 | Linux kernel (generic/AWS/FIPS/realtime) | 100+ | Broad: GPU, USB, networking, filesystems, KVM | Reboot; ABI change needs module recompiling |
| USN-8904-1 | Linux kernel (Azure) | 100+ | Same broad sweep | Reboot; ABI change |
| USN-8905-1 | Linux kernel (GCP) | 100+ | Same broad sweep | Reboot; ABI change |
| USN-8906-1 | Linux kernel (IBM) | 100+ | Same sweep, plus ARM TLB privilege-escalation bug | Reboot; ABI change |
| USN-8887-2 | Linux kernel (AWS 7.0) | 100+ | Broad sweep | Reboot; ABI change |
| USN-8888-2 | Linux kernel (Azure 7.0) | 100+ | Broad sweep | Reboot; ABI change |
| USN-8910-1 | libxml2 | 6 | Heap overflows (possible RCE), XXE injection | Standard update |
| USN-8898-1 | Apache (apache2) | 3 | DoS plus mod_ssl access-restriction bypass | Restart apache2 |
| USN-8902-1 | libarchive | 1 | Crash or RCE via signed overflow in ZIP writer | Standard update |
| USN-8909-1 | libde265 | 1 | DoS (NULL pointer) on crafted H.265 streams | Standard update |
| USN-8899-1 | libpng | 1 | DoS from malformed compressed PNG chunks | Standard update |
| USN-8907-1 | libgit2 | 1 | MITM via weak TLS certificate SAN verification | Standard update |
| USN-8897-1 | lxml | 2 | XSS and local file read from untrusted input | Standard update |
| USN-8896-1 | GStreamer Ugly Plugins | 4 | Code execution from crafted media files | Requires user to open file |
How to apply these Linux security updates
Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.
Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.
Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.
Debian/Ubuntu (apt)
The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.
sudo apt update sudo apt upgrade -y
Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)
On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.
sudo dnf check-update sudo dnf upgrade -y
or on older releases
sudo yum check-update sudo yum update
SUSE (zypper)
SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.
sudo zypper refresh sudo zypper update -y
