Security 11023 Published by

SUSE led today's Linux patch wave with a 133-CVE kernel update that still needs a reboot, though the real standouts were the bugs you'd expect to be long fixed. Debian shipped rsync with 33 CVEs and dovecot with 25, while Debian's OpenStack and Slackware's 26-year-old groff command-injection holes made the week feel oddly retro. Ubuntu's Exim brought proxy-protocol code execution, but the most awkward moment went to its curl cleanup notice targeting the still-supported 14.04 LTS. If any of this software runs on boxes you manage, the advisory tables are worth a scroll and the reboot is unavoidable.





Linux security roundup: a 133-CVE SUSE kernel, a botched curl fix, and rsync with 33 flaws

A dozen or so distros shipped patches today. Here's what you should actually install and what you can leave on the desk for now.

SUSE just handed out a pile of advisories, and the kernel update is the one worth your attention. SUSE-SU-2026:4369-1 patches 133 vulnerabilities plus 19 non-security fixes in a single release. NVD grades one of them, CVE-2026-74612, a clean 10.0. You'll still need to reboot, so don't apply this on a Friday afternoon and stroll off.

Linux Security

The printer news deserves a second look. hplip picked up ten vulnerabilities split across two separate advisories, both rated critical. SUSE-SU-2026:4364-1 targets the newer platforms, while 4371-1 covers older SLE 15 SP4 and SP5 installs. Same ten CVEs either way, so a single install won't rescue you if you're on an older release. Check which SP level you're on first.

If you're keeping score on the rest, nodejs16 brings 31 vulnerabilities and erlang27 takes 20. Redis shows up three times this round, all chasing the same out-of-bounds read in the cluster bus parser, CVE-2026-92925. Three advisories for one bug is a bit much. It's also a single fix to apply, so that's fine.

Here's the one that made me do a double take. libsodium (4368-1) is tagged "moderate" but really reads like a feature release. Alongside two CVEs it ships post-quantum key encapsulation, ML-KEM768 and X-Wing, plus SHA-3 hashing and a pile of ARM and WebAssembly performance work. If you've been meaning to poke at quantum-resistant crypto, this is an easy vehicle to do it. The kernel live patch (4381-1) meanwhile fixes four vulnerabilities on the 15 SP5 kernel without a reboot, which is, of course, the entire point of live patching.

What actually needs patching

Keep in mind that the SUSE kernel isn't the only reason to crack open a terminal. Across the distros a couple of flaws are the kind you'd expect to have been cleaned up a long time ago.

Slackware's groff fix is the funniest one. Version 1.24.2 patches command injection flaws in mmroff, pdfmom, and pre-grohtml, the tools that escape groff's default "safer" mode when you feed them untrusted input and render to HTML. The kicker is that these vulnerabilities are somewhere between 14 and 26 years old. Arbitrary commands have been runnable at your privilege level for a very long time, and the dev team's advice is about as subtle as it gets: if you use those tools with untrusted input, update.

Debian was busy over the last couple of days. rsync picked up 33 CVEs and dovecot 25. rsync's fixes range from local privilege escalation to arbitrary code execution, so if you host files with it, skipping this one is on you. dovecot's list leans more toward plumbing headaches: SMTP smuggling, code injection through malformed Sieve scripts, and ACL bypasses on your mail server.

If you run OpenStack, swift and glance both got patched for issues that let users step past their own access controls. swift's S3API middleware stopped stripping native Swift control headers off client requests, so someone could slip through S3 ACL checks. glance tripped over several SSRF holes, letting an authenticated user point it at internal URLs including cloud metadata endpoints, and in one configuration turning a blind fetch into full data exfiltration.

AlmaLinux pushed a batch across 8, 9, and 10, and most of the volume sits in Ruby. The same resolv gem denial-of-service bug, CVE-2026-80212, shows up in four advisories on 9 and 10, driving uncontrolled memory growth from crafted DNS responses. The kernel gets the meaty one instead: 13 CVEs on both the regular kernel and kernel-rt, all matching across the two advisories on Linux 8, so one install covers whichever flavor you run. Tomcat rounds it out with a digest authentication bypass that should make any servlet admin double-check their configs.

Head here to remind yourself why Fedora is worth a glance. Chromium leads the charge with version 154.0.8037.57 carrying over a hundred CVEs, use-after-free and buffer overflows and type confusion. VLC got a more interesting set of changes, closing an integer overflow that runs arbitrary code and leaking info through an unterminated RTSP line, plus a Qt6 GUI that's been on the roadmap for a while. The funny bit is that the streamlink advisory description reads like it was copied straight from the urllib3 release notes, and the advisory ID is even identical, which points at a cloning mistake. The patch is legit, the announcement text is not.

Oracle Linux rounds out the field with its only "Critical" item being the unbound update for OL9, closing three DNSSEC issues including heap corruption during CNAME synthesis. libxml2 got hit three times with the same six-CVE set across OL8, OL9, and OL10, and the OL9 kernel update is sprawling at 13 CVEs stacked on a big non-security dump. libxml2 shows up in just about everything, so the fix matters more than the CVE count implies.

The awkward one

And Ubuntu. Exim is the headline there, four problems including an out-of-bounds write that hands an attacker arbitrary code when Proxy-Protocol meets an attacker-controlled proxy. Not an ideal feature set for a mail transport agent.

But the most awkward framing goes to curl. Its original advisory fixed a pile of curl bugs and botched one of them, leaving a partial fix for CVE-2026-8927. This notice is simply the cleanup. A regression fix on a 2014 release, no less. That's the story there, and it lands on Ubuntu 14.04 LTS patched through Ubuntu Pro, one of those older releases still limping along with paid support.

For what it's worth, the libvirt advisories in the Ubuntu batch both require a reboot, and if you're on 26.04 running the HWE stack the second notice is the one that covers you.

The Updates in Detail

AlmaLinux

AlmaLinux just pushed a batch of security advisories across AlmaLinux 8, 9, and 10. If you're running any of those, this is the patch cycle to clear off the desk. 

Ruby is where most of the volume sits. The same resolv gem denial-of-service bug (CVE-2026-80212) shows up in four advisories on AlmaLinux 9 and 10, hitting ruby 4.0, ruby 3.3, and the plain ruby package. The flaw is crafted DNS responses driving uncontrolled memory growth, which usually means "the box chokes on RAM and stops responding" rather than "someone walks out with your data." One of those Ruby advisories also sneaks in a Konflux test fix, because no release feels complete without a side quest.

The kernel gets the meaty one. Both the regular kernel and the real-time kernel-rt took identical treatment on AlmaLinux 8, with 13 CVEs spanning amdgpu out-of-bounds reads, a mana double-fetch, libceph stack writes, and a perf edge case. All thirteen match across the two advisories, so one install covers whichever flavor you're running. The amdgpu and libceph pieces are the ones that could plausibly be abused.

Tomcat gets the rougher treatment, though both land as moderate. Two advisories hit on AlmaLinux 10, one for tomcat9 and one for plain tomcat. tomcat9 alone packs eight CVEs: a digest authentication bypass, an HTTP/2 header gap, WebSocket information disclosure, an authorization bypass, and a security-constraint bypass through bad URL encoding. The plain tomcat advisory is a trimmed version of the same list. The digest authentication bypass (CVE-2026-43512) is the one that makes a servlet admin double-check their configs.

A handful of single-purpose fixes round out the batch. cockpit-image-builder absorbed four fast-uri vulnerabilities, all variations on server-side request forgery and authority injection. resteasy closed a remote unauthenticated file read, and expat picked up two hits, a quadratic-complexity DoS and an XML injection through malformed UTF-16 input.

That covers the field. Here's where each advisory lands:

AdvisoryPackageAlmaLinuxSeverityReleasedFixes
ALSA-2026:72427ruby4.010Important2026-09-28CVE-2026-80212 (resolv DoS via memory growth)
ALSA-2026:71543cockpit-image-builder10Important2026-09-26fast-uri SSRF/injection: CVE-2026-75899, 75975, 76172, 84292
ALSA-2026:68651tomcat910Moderate2026-09-258 CVEs: 32990, 43512, 41293, 42498, 43515, 43513, 59083, 59084
ALSA-2026:69259tomcat10Moderate2026-09-256 CVEs: 32990, 43512, 41293, 42498, 43513, 43515
ALSA-2026:72484ruby:4.09Important2026-09-28CVE-2026-80212 (resolv DoS)
ALSA-2026:72485ruby:3.39Important2026-09-28CVE-2026-80212 (resolv DoS)
ALSA-2026:72424resteasy9Important2026-09-28CVE-2026-17615 (remote unauthenticated file read)
ALSA-2026:72286ruby9Important2026-09-28CVE-2026-80212 (resolv DoS) + 1 Konflux test fix
ALSA-2026:72467kernel-rt8Important2026-09-2813 CVEs: 40323, 45942, 46230, 46204, 46199, 63875, 64034, 64556, 68159, 68156, 68155, 68273, 74753
ALSA-2026:72468kernel8Important2026-09-28Same 13 CVEs as kernel-rt
ALSA-2026:72448expat8Important2026-09-28CVE-2026-66046 (quadratic DoS), CVE-2026-93990 (XML injection)

Debian GNU/Linux

Debian has been working through its usual security backlog, and the last couple of days were no exception. Debian's LTS and main security teams shipped fixes for about a dozen packages spanning OpenStack tooling, email servers, a blogging platform, desktop app packaging, and a couple of libraries that quietly hold up much of the Python and Perl world.

swift and glance, the object- and image-storage services underpinning OpenStack, both got patched for issues that let users step past their own access controls. swift's S3API middleware stopped stripping native Swift control headers off client requests, so someone could slip through S3 ACL checks. glance tripped over several SSRF holes, letting an authenticated user point it at internal URLs, including cloud metadata endpoints, and in one configuration turning a blind fetch into full data exfiltration.

rsync and dovecot came out of this batch with by far the biggest CVE counts. rsync picked up 33, and dovecot 25. rsync's fixes reach from local privilege escalation to arbitrary code execution, so if you host files with it, skipping this one is on you. dovecot's list leans toward the plumbing headaches: SMTP smuggling, code injection through malformed Sieve scripts, and ACL bypasses on your mail server.

lxml brought four fixes worth knowing if you parse HTML or XML: a CSS @import filter that slipped through via unicode escapes, <base> tag injection, local external-entity reads, and a Cleaner that forgot to strip javascript: URLs from certain attributes. libdbi-perl shows up twice because both Debian LTS and Freexian's extended-LTS program backported the same three CVEs, covering an arbitrary module-load hole and a couple of numeric-type mishaps that crash the app.

PackageAdvisoryFixed versionCVEsWhat it fixes
swiftDLA 4801-12.30.1-0+deb12u32 (CVE-2026-71191, CVE-2026-97149)S3 ACL authorization bypass; cross-container copy via tempurl
glanceDLA 4800-12:25.1.0-2+deb12u54 (CVE-2026-71196/71197/71198, CVE-2026-77648)SSRF via web download/import APIs and the legacy /v2/tasks handler
lxmlDLA 4799-14.9.2-1+deb12u14 (CVE-2026-28348/28350/41066/49825)CSS @import bypass, <base> injection, local XXE, leaked javascript: URLs
libdbi-perlDLA 4798-11.643-4+deb12u33 (CVE-2026-78030/88815/88816)Arbitrary module load and app crashes from numeric-type mishaps
rsyncDSA 6527-13.5.0+ds1-0+deb13u133 (CVE-2026-53783-53803, CVE-2026-70452-70464)Privilege escalation, access-restriction bypass, info disclosure, DoS, RCE
dovecotDSA 6526-11:2.4.1+dfsg1-6+deb13u725 (CVE-2026-27852/33263/33604...73209)DoS, SMTP smuggling, Sieve code injection, ACL bypass
wordpressDSA 6525-16.8.10+dfsg1-0+deb13u13 (CVE-2026-65640/87902/93485)XSS, privilege escalation, RCE
flatpakDSA 6524-11.16.6-1~deb13u38 (CVE-2026-90616/92162/97023-97029)DoS via malicious apps, info disclosure
libdbi-perlELA-1834-1stretch/buster/bullseye3 (CVE-2026-78030/88815/88816)Same three CVEs, backported for older Debian releases

Fedora Linux

Fedora pushed another security sweep through Fedora 43 and 44 around Sept. 29, and anyone running these builds should apply it. Most of the batch is small package bumps, but the Chromium release alone is enough to make you open a terminal.

Chromium leads the charge. Version 154.0.8037.57 for Fedora 43 carries the usual wall of fixes, CVE-2026-95274 all the way through CVE-2026-95385. That is over a hundred CVEs in one update, covering the standard browser attack toolkit: use-after-free, buffer overflows, type confusion, missing authorization, information leaks. Chromium ships around this many at a time, but a changelog longer than most feature releases still deserves a glance. If you still run Chromium rather than a browser that updates itself, this is the nudge you were waiting for.

VLC got its own set of changes that look more interesting than the version number suggests. The 3.0.24 update in Fedora 44 closes CVE-2026-56711, which lets an integer overflow in picture allocation run arbitrary code, and CVE-2026-73324, which leaks information through an unterminated RTSP response line. You also get the Qt6 GUI that has been on the roadmap for a while, plus a few plugin swaps: AS-DCP comes back, while RDP and Real RTSP get cut.

The urllib3 family is worth a close look. python-urllib3 jumped to 2.8.0 and closes three problems, including an HTTPS proxy that would ignore its own TLS settings, a chunked body that could buffer without limit, and a deflate path that could spin forever. The streamlink advisory is the funny one here. Its description reads like it was copied straight from the urllib3 release notes, and the advisory ID is identical to urllib3's, which points at a cloning mistake rather than a real notice. The actual changelog is thinner: streamlink simply backports urllib3 2.8.0 compatibility. The patch is legitimate, even if the announcement text is not.

The Perl packages are all about input you did not control. perl-Dancer2 stops deserialize from handing raw request bodies to the YAML loader, which could previously instantiate arbitrary objects or trigger string evals. perl-HTML-FormFu now caps the repeat count that shows up in query strings, defaulting to 100, to keep a denial-of-service from piling up work. perl-Catalyst-Plugin-Static-Simple used to mark static assets as cacheable with "public," letting proxies and CDN edge caches serve responses meant to stay private, and this update lets you override that and sets Expires to 0. All three shipped across Fedora 43 and 44.

NetworkManager's VPN plugins rounded out the set. NetworkManager-iodine fixes a local privilege escalation that let nameserver option injection climb all the way to root, and NetworkManager-l2tp bundles two fixes in 1.52.6. Both moved to 43 and 44 alike.

FreeIPA closed the round with a 4.13.4 security release for Fedora 43, resolving two CVEs and rebuilding against a pre-release Samba 4.25.0-RC2.

PackageFedoraVersionCVE(s) / issueWhat changed
chromium43154.0.8037.57-1CVE-2026-95274 through CVE-2026-95385Upstream browser fixes: use-after-free, buffer overflows, type confusion, missing authorization
vlc443.0.24-1CVE-2026-56711, CVE-2026-73324RCE via integer overflow; info leak via unterminated RTSP. Also Qt6 GUI and plugin swaps
python-urllib3442.8.0-1GHSA-8988-9cw3-xx77, GHSA-vxq7-64xx-v4gw, GHSA-gh4c-6fx4-qh6gHTTPS proxy TLS override, unbounded chunk-size buffering, chunked-deflate infinite loop
python-streamlink448.4.0-2urllib3 2.8.0 compatibilityBackport for new urllib3; advisory text and ID copied from the urllib3 notice
NetworkManager-l2tp43, 441.52.6-1CVE-2026-75131, CVE-2026-93337VPN fixes bundled in 1.52.6
NetworkManager-iodine43, 441.2.0-29CVE-2026-91837Local privilege escalation via nameserver option injection
perl-Dancer2442.2.1-1YAML deserialization gadget chainsStops deserialize from feeding request bodies to the YAML loader
perl-HTML-FormFu43, 442.07-23 (44) / 2.07-22 (43)CVE-2026-19873Caps repeat count (default 100) to block DoS
perl-Catalyst-Plugin-Static-Simple43, 440.38-2CVE-2026-15743Allows Cache-Control override, sets Expires to 0
freeipa434.13.4-2CVE-2026-79678, CVE-2026-76578Security fixes; rebuilt against Samba 4.25.0-RC2

Oracle Linux

Oracle just rolled out a batch of bug-fix and security errata spanning Oracle Linux 7 through 10. The security releases are the ones worth flagging if these systems are yours.

The only "Critical" item here is the unbound update for Oracle Linux 9. It closes three DNSSEC-related issues: a heap corruption during CNAME synthesis and two heap buffer overflows while digesting DNSKEY and performing DNSSEC canonicalization. Heap bugs in a resolver aren't a category you want to skip, so this one earns the top severity.

libxml2 got hit three times. Oracle pushed the same six-CVE fix set to all three supported releases (OL8, OL9, OL10), with OL8 listing only five because one CVE didn't apply. Since this library shows up in just about everything, the fix matters more than the CVE count implies.

The OL9 kernel update is the sprawling one: 13 CVEs across crypto, Ceph, Bluetooth, IOMMU, DM cache, and keys, stacked on top of a large non-security code dump. Most of the visible changes cluster around the Intel ice network driver (E825/E825C/E830 NICs) and a broad DPLL framework rewrite, plus some reshuffling of kernel signing keys. If you run those NICs, grab it.

The bug-fix side is steadier work. Oracle Linux 9 and 8 get ovirt-engine updates that finally get Windows 11 OVA import/export working again, plus FIPS-mode backup restore hardening (the OL8 note also rebuilds a postgresql-16 database-script incompatibility). The vdsm updates on OL8 and OL9 switch to selecting v2v options based on advertised virt-v2v capabilities. Oracle Linux 10's iscsi-initiator-utils gets a long list of startup-reliability tweaks, and Oracle Linux 8's bind gains a new root signing key (38696) baked into the package so DNSSEC validation keeps resolving.

Errata IDSeverity / TypeTargetVersionChange
ELBA-2026-500346Bug fixOL9 oVirt 4.5 (ovirt-engine)4.5.5-1.74Fix Windows 11 OVA import/export OS ID compatibility
ELBA-2026-500347Bug fixOL8 oVirt 4.5 (vdsm)4.50.5.1-9Select v2v options using advertised virt-v2v capabilities
ELBA-2026-500348Bug fixOL9 oVirt 4.5 (vdsm)4.50.5.1-9Same v2v capability-selection fix
ELBA-2026-500345Bug fixOL8 oVirt 4.5 (ovirt-engine)4.5.5-1.74 (and -1.73)Windows 11 OVA fix; postgresql-16 DB-script + FIPS backup-restore hardening
ELBA-2026-500351Bug fixOL10 iscsi-initiator-utils6.2.1.11-0.git4b3e853.0.3Validate interface IP vs. target address family; delay reconnect until valid IP; service ordering/startup fixes
ELBA-2026-500349Bug fixOL9 oracle-ovirt-release-45-el91.0-9Lock libvirt/python3-libvirt at 9 and qemu at 7.2, independent of epoch
ELBA-2026-70265Bug fixOL8 bind9.11.36-16.el8_10.15Add new root key 38696; update built-in anchors in delv and named
ELSA-2026-71487Critical (security)OL9 unbound1.24.2-3.el9_8.83 CVEs: heap corruption in CNAME synthesis; 2 heap buffer overflows (DNSKEY, DNSSEC canonicalization)
ELSA-2026-71586Important (security)OL10 libxml22.12.5-10.el10_2.46 CVEs (86138, 86140, 86142, 86143, 86144, 74860)
ELSA-2026-70459Important (security)OL9 kernel5.14.0-687.50.1.el9_813 CVEs (crypto af_alg, hugetlb, Ceph, Bluetooth, IOMMU vt-d, dm cache, ccp, keys); large ice driver + DPLL work; signing-key changes
ELSA-2026-71585Important (security)OL9 libxml22.9.13-14.el9_8.56 CVEs (same set as OL10)
ELSA-2026-71641Important (security)OL8 libxml22.9.7-21.el8_10.95 CVEs (86142 did not apply)
ELSA-2026-48866Important (security)OL7 abrt2.1.11-60.0.5.el72 CVEs: TOCTOU in SetElement/DeleteElement; race in ChownProblemDir

Oracle Linux

Oracle just rolled out a batch of bug-fix and security errata spanning Oracle Linux 7 through 10. The security releases are the ones worth flagging if these systems are yours.

The only "Critical" item here is the unbound update for Oracle Linux 9. It closes three DNSSEC-related issues: a heap corruption during CNAME synthesis and two heap buffer overflows while digesting DNSKEY and performing DNSSEC canonicalization. Heap bugs in a resolver aren't a category you want to skip, so this one earns the top severity.

libxml2 got hit three times. Oracle pushed the same six-CVE fix set to all three supported releases (OL8, OL9, OL10), with OL8 listing only five because one CVE didn't apply. Since this library shows up in just about everything, the fix matters more than the CVE count implies.

The OL9 kernel update is the sprawling one: 13 CVEs across crypto, Ceph, Bluetooth, IOMMU, DM cache, and keys, stacked on top of a large non-security code dump. Most of the visible changes cluster around the Intel ice network driver (E825/E825C/E830 NICs) and a broad DPLL framework rewrite, plus some reshuffling of kernel signing keys. If you run those NICs, grab it.

The bug-fix side is steadier work. Oracle Linux 9 and 8 get ovirt-engine updates that finally get Windows 11 OVA import/export working again, plus FIPS-mode backup restore hardening (the OL8 note also rebuilds a postgresql-16 database-script incompatibility). The vdsm updates on OL8 and OL9 switch to selecting v2v options based on advertised virt-v2v capabilities. Oracle Linux 10's iscsi-initiator-utils gets a long list of startup-reliability tweaks, and Oracle Linux 8's bind gains a new root signing key (38696) baked into the package so DNSSEC validation keeps resolving.

Errata IDSeverity / TypeTargetVersionChange
ELBA-2026-500346Bug fixOL9 oVirt 4.5 (ovirt-engine)4.5.5-1.74Fix Windows 11 OVA import/export OS ID compatibility
ELBA-2026-500347Bug fixOL8 oVirt 4.5 (vdsm)4.50.5.1-9Select v2v options using advertised virt-v2v capabilities
ELBA-2026-500348Bug fixOL9 oVirt 4.5 (vdsm)4.50.5.1-9Same v2v capability-selection fix
ELBA-2026-500345Bug fixOL8 oVirt 4.5 (ovirt-engine)4.5.5-1.74 (and -1.73)Windows 11 OVA fix; postgresql-16 DB-script + FIPS backup-restore hardening
ELBA-2026-500351Bug fixOL10 iscsi-initiator-utils6.2.1.11-0.git4b3e853.0.3Validate interface IP vs. target address family; delay reconnect until valid IP; service ordering/startup fixes
ELBA-2026-500349Bug fixOL9 oracle-ovirt-release-45-el91.0-9Lock libvirt/python3-libvirt at 9 and qemu at 7.2, independent of epoch
ELBA-2026-70265Bug fixOL8 bind9.11.36-16.el8_10.15Add new root key 38696; update built-in anchors in delv and named
ELSA-2026-71487Critical (security)OL9 unbound1.24.2-3.el9_8.83 CVEs: heap corruption in CNAME synthesis; 2 heap buffer overflows (DNSKEY, DNSSEC canonicalization)
ELSA-2026-71586Important (security)OL10 libxml22.12.5-10.el10_2.46 CVEs (86138, 86140, 86142, 86143, 86144, 74860)
ELSA-2026-70459Important (security)OL9 kernel5.14.0-687.50.1.el9_813 CVEs (crypto af_alg, hugetlb, Ceph, Bluetooth, IOMMU vt-d, dm cache, ccp, keys); large ice driver + DPLL work; signing-key changes
ELSA-2026-71585Important (security)OL9 libxml22.9.13-14.el9_8.56 CVEs (same set as OL10)
ELSA-2026-71641Important (security)OL8 libxml22.9.7-21.el8_10.95 CVEs (86142 did not apply)
ELSA-2026-48866Important (security)OL7 abrt2.1.11-60.0.5.el72 CVEs: TOCTOU in SetElement/DeleteElement; race in ChownProblemDir

Rocky Linux

Rocky Linux shipped three security fixes, and the targets are exactly the things developers actually rely on: Postgres tooling and Ruby gems. All three sit in the "Important" severity tier, the second-highest they assign, and each one tells you to check the CVE list for a CVSS base score so you can figure out which one to bother with first.

The Postgres side (RLSA-2026:72274) lands on Rocky Linux 8 and covers pg_repack, postgres-decoderbufs, and pgaudit. Ruby gets two of them, both for Rocky Linux 9. A ruby:4.0 fix (72484) and a ruby:3.3 fix (72485) hit the same two gems—mysql2 and pg—so you're patching the same code, just across two release tracks. Nothing exotic here, but if any of these are in production you'll want to schedule the reinstall.

RLSA IDTopicSeverityOSAffected Packages
RLSA-2026:72274postgresql:12ImportantRocky Linux 8pg_repack, postgres-decoderbufs, pgaudit (+ modules of each)
RLSA-2026:72484ruby:4.0ImportantRocky Linux 9rubygem-mysql2, rubygem-pg (+ modules of each)
RLSA-2026:72485ruby:3.3ImportantRocky Linux 9rubygem-mysql2, rubygem-pg (+ modules of each)

Slackware Linux

Slackware shipped two security patches this round, and both come dressed in bugs you'd expect to have been cleaned up a while ago.

The pcre2 update nudges the regex library to 10.49. The headline issue is that an attacker-controlled pattern can trigger an out-of-bounds write, shoving arbitrary data into memory it has no business touching. Not a disaster if you never point a parser at untrusted input, but most of us do at some point.

The groff fix is the more amusing one. Version 1.24.2 patches command injection flaws (CWE-78) in mmroff, pdfmom, and pre-grohtml. These are the tools that escape groff's default "safer" mode when you feed them untrusted input and render to HTML. The kicker is that the vulnerabilities are somewhere between 14 and 26 years old, so arbitrary commands have been runnable at your privilege level for a very long time. The dev team's advice is as subtle as it gets: if you use those tools with untrusted input, update.

Both land on Slackware 15.0 and -current. Install as root with upgradepkg and check the MD5s against the table below before you trust a download.

PackageVersionAdvisoryIssueWho should care
pcre210.49SSA:2026-271-02 / GHSA-r9hj-j2rw-4q3mOut-of-bounds write via attacker-controlled regexAnyone running regex over untrusted input
groff1.24.2SSA:2026-271-01Command injection (CWE-78) escaping "safer" modeAnyone using mmroff, pdfmom, or pre-grohtml with untrusted input

SUSE Linux

SUSE handed out a pile of security and the kernel update is the one worth reading. SUSE-SU-2026:4369-1 patches 133 vulnerabilities plus 19 non-security fixes in a single release. NVD grades one of them (CVE-2026-74612) a clean 10.0. You'll still need to reboot.

The printer situation is worth a second look. hplip picked up ten vulnerabilities split across two separate advisories, both rated critical. SUSE-SU-2026:4364-1 targets the newer platforms while 4371-1 covers older SLE 15 SP4 and SP5 installs. Same ten CVEs either way, so a single install won't rescue you if you're running an older release. The update also rides along with the HPLIP 3.26.6 release and adds a fresh batch of printer support, which is the one genuinely pleasant detail.

nodejs16 (4355-1) isn't far behind with 31 vulnerabilities, and some of them are genuinely ugly. One lets leftover memory from earlier operations leak in-process secrets, another is a TLS wildcard-depth authentication bypass, and a third is a session-reuse hole that accepts connections without proper authorization. Worth patching.

The rest are smaller but not skippable. Redis shows up three times this round (4370-1, 4375-1, and 4377-1), all fixing the exact same out-of-bounds read in the cluster bus parser, CVE-2026-92925. That's three advisories for a single bug, though it is a single fix to apply. erlang27 (4358-1) collects 20 vulnerabilities, ImageMagick (4376-1) takes on 14, and exiv2 (4374-1) closes three out-of-bounds reads that a malicious server could trigger.

libsodium (4368-1) is the odd one out: tagged "moderate," it really reads like a feature release. Alongside two CVEs it ships post-quantum key encapsulation (ML-KEM768 and X-Wing), SHA-3 hashing, and a pile of ARM and WebAssembly performance work. If you've been meaning to look at quantum-resistant crypto, this is your vehicle. The kernel live patch (4381-1) fixes four vulnerabilities on the 15 SP5 kernel without a reboot, which is the entire point of live patching.

Announcement IDSoftwareSeverityFixesVersionKey platformsNotes
SUSE-SU-2026:4355-1nodejs16important31 vulns16.20.2SLE 15 SP4, SAP 15 SP4, Leap 15.4Memory-leak secret exposure, TLS bypass
SUSE-SU-2026:4358-1erlang27important20 vulns27.1.3Leap 15.3Buffer overflows, SSL handshake injection
SUSE-SU-2026:4363-1libtpmsmoderate10.9.6Leap 15.6, SLE 15 SP7Heap OOB read in TPM state unmarshalling
SUSE-SU-2026:4364-1hplipcritical10 vulns + 13.26.6Leap 15.6, SLE 15 SP6RCE/priv-esc; CVEs 91104/91106 hit 9.8 (NVD)
SUSE-SU-2026:4365-1python-soupsievemoderate22.5Leap 15.6, Py3 module 15-SP7Regex DoS (ReDoS) in whitespace/identifier patterns
SUSE-SU-2026:4368-1libsodiummoderate2 vulns + 1 feature1.0.22SLE 15 SP4-7, Leap 15.4-6, UEM 5.3-5.5Post-quantum KEM, SHA-3, Argon2/SHA3 perf
SUSE-SU-2026:4369-1Linux kernelimportant133 vulns + 196.4.0Leap 15.6, SLE 15 SP6Requires reboot; CVE-2026-74612 scores 10.0
SUSE-SU-2026:4370-1redis7important17.2.4Leap 15.6, SLE 15 SP6CVE-2026-92925 cluster-bus OOB read
SUSE-SU-2026:4371-1hplipcritical10 vulns + 13.26.6SLE 15 SP4/SP5, Leap 15.4Same CVEs as 4364, older platforms
SUSE-SU-2026:4374-1exiv2important30.27.5SLE 15 SP4-7, Leap 15.4Heap OOB read/write over remote CRW files
SUSE-SU-2026:4375-1redis7important17.0.8Leap 15.5, SLE 15 SP5Duplicate of 4370-1, same CVE-2026-92925
SUSE-SU-2026:4376-1ImageMagickimportant147.1.1.21Leap 15.6, SLE 15 SP6UAF, DoS, code injection via HTML encoder
SUSE-SU-2026:4377-1redis7important17.0.8Leap 15.6, SLE 15 SP6Duplicate of 4375-1, same CVE
SUSE-SU-2026:4381-1kernel live patchimportant45.14.21Leap 15.5, SLE 15 SP5No reboot needed

Ubuntu Linux

Ubuntu put out a batch of security notices, so if any of this software lives on a box you administer, it's patch time.

FreeRDP got the lightest treatment. A grab-bag of issues that could leak sensitive data, crash the client, or let an attacker run arbitrary code. Ubuntu also bundled in a fresh upstream release (3.32.0), so you pick up extra bug fixes alongside the security ones. Reasonable trade.

Exim is where today's headline sits. Four problems, including an out-of-bounds write that fires when Proxy-Protocol meets an attacker-controlled proxy and hands an attacker arbitrary code, plus SMTP smuggling that lets someone inject messages straight into your mail queue. Not an ideal feature set for a mail transport agent.

libvirt shows up twice, in two separate advisories. The standard package carries an integer overflow and a symlink-following flaw that could let a local attacker with the swtpm account take ownership of arbitrary files. The HWE package (26.04 only) is the uglier half: a DNS TXT/SRV newline-validation gap that lets a local user able to define virtual networks drop dnsmasq config directives and end up executing commands as root. There's also over-permissive permissions on cloned storage volumes, so guest disk contents can leak to anyone with local access.

curl finishes the batch, though the framing is awkward. Its original advisory (USN-8487-1) fixed a pile of curl bugs and botched one of them, leaving a partial fix for CVE-2026-8927. This notice is the cleanup. The affected box is Ubuntu 14.04 LTS, patched through Ubuntu Pro — one of the older releases still limping along with paid support.

Two things to keep straight when you apply these: both libvit advisories require a reboot to actually take effect, and if you're on 26.04 running the HWE stack, the second libvirt notice is the one that covers you.

NoticeSoftwareFixesAffected versionsNew versionReboot?
USN-8836-1freerdp3Info disclosure, crash/DoS, arbitrary code exec26.04, 24.043.32.0+dfsg-0ubuntu0.26.04.1 / .24.04.1No
USN-8834-1exim4OOB write (code exec), use-after-free (DoS), uninit read (info disclosure), SMTP smuggling (email injection)26.04, 24.04, 22.044.99.1-1ubuntu1.5 / 24.04: 4.97-4ubuntu4.8 / 22.04: 4.95-4ubuntu2.12No
USN-8831-1libvirtInteger overflow (DoS/code exec), symlink-following (privilege escalation)26.04, 24.04, 22.0412.0.0-1ubuntu5.5 / 24.04: 10.0.0-2ubuntu8.19 / 22.04: 8.0.0-1ubuntu7.21Yes
USN-8833-1libvirt-hwe6 CVEs incl. command exec as root, DoS, 2x privilege escalation, info disclosure26.04 (HWE only)12.0.0-1ubuntu5.5Yes
USN-8487-2curlRegression fix for CVE-2026-8927 (partial fix from USN-8487-1)14.04 (via Ubuntu Pro)7.35.0-1ubuntu2.20+esm23No

How to apply these Linux security updates

Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.

Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.

Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.

Debian/Ubuntu (apt)

The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.

sudo apt update
sudo apt upgrade -y

Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)

On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.

sudo dnf check-update
sudo dnf upgrade -y

or on older releases

sudo yum check-update
sudo yum update

SUSE (zypper)

SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.

sudo zypper refresh
sudo zypper update -y

Slackware (slackpkg and pkgtool)

Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.

sudo slackpkg update
sudo slackpkg upgrade-all