A broad wave of Linux security patches rolled out today across Debian, Fedora, Ubuntu, Red Hat, Rocky, Slackware, and SUSE, delivering a heavy multi-distro load rather than one standout critical. Mozilla's Thunderbird and Firefox-ESR dominate the CVE counts, with Debian shipping 62 flaws in Firefox-ESR and 44 in Thunderbird across most of the affected releases. The two fixes that could surprise admins are Debian's Python 3.7 parser, which now treats only ampersands as query separators, and Fedora's ruff and ty, which gained an arbitrary code execution risk when checking untrusted code. Big numbers like SUSE's 108 Chromium CVEs and Ubuntu's 101-CVE Oracle kernel are mostly about staying current, so prioritize the OpenSSL key-recovery and PHP TLS updates and fold the rest into normal maintenance.
This round of Linux security updates is a big one. And one Debian Python change might break something
Debian, Fedora, Ubuntu, Red Hat, Rocky, Slackware, and SUSE have all pushed security erratas today. Some distros are carrying double-digit and triple-digit CVE counts. There's no single critical bombshell today so much as a wide, heavy load across basically everything you run. If you're managing even one server between a web stack and a build machine, there's a meaningful chunk of patching to do.
Let's sort the urgent from the wait-and-see, and flag the couple of updates that might surprise you.
The Mozilla family is carrying the heaviest load again
Thunderbird and Firefox-ESR are the obvious headline, and they're showing up everywhere. Debian crammed 62 CVEs into a single Firefox-ESR advisory. Slackware's Thunderbird update shipped 44. RHEL, Rocky, and AlmaLinux all have their own Thunderbird entries. It's the same Mozilla codebase, same use-after-free pile, different advisory number each time. Same bug, new ticket.
Here's a detail only someone watching the release notes closely would catch. Two of Slackware's Thunderbird IDs break the usual pattern: CVE-2026-92035 and CVE-2026-96869. The rest ride the 100xxx numbering. Two IDs sticking out on their own is exactly the kind of thing that makes you raise an eyebrow, though Mozilla does toss out odd numbers now and then. Worth a quick sanity check before you trust the list.
Slackware's second update is the saner of the pair. libpng climbs to 1.6.59, closing a single use-after-free in png_read_end that trips on a truncated image stream. One CVE for an actual heap bug. Exactly the kind you'd rather not leave sitting around while your parser munches a suspicious image.
The builds you actually want are where it counts. Debian's Firefox-ESR now tracks 153.x, sitting at 153.4.0esr-1~deb13u1. Slackware ships 140.17.0esr on 15.0 and 153.4.0esr on -current, all filed under MFSA2026-102. You don't have to read all 44 to know that's the version you want running.
AlmaLinux separately put its weight behind databases and toolchains, with PostgreSQL 15 landing 16 CVEs. 389 Directory Server carried the distro's lone Critical, a SASL PLAIN flaw that climbs all the way to Directory Manager. If your stack is built in Go, check the go-toolset and container-tools entries before you move on.
Changes that bite before they fix
Most security patches are invisible once they land. Debian's Python 3.7 update isn't. It changes how the parser splits query strings. Only ampersands count as separators now. Semicolons don't. If your stack splits parameters at semicolons, this breaks it quietly, which is precisely the wrong way for a fix to bite. Freexian did bold the API change in its advisory, so it's not hiding.
Fedora has its own surprise tucked into a two-version sweep. One advisory pushed uv, ruff, and ty to both Fedora 43 and 44. There's a use-after-free in salsa, sure. But the one that should make you stop is the arbitrary code execution in ruff and ty when they typecheck untrusted code. Lint or typecheck other people's source on a Fedora box? That's your reason to patch today.
Then come the big numbers, real but mostly a matter of keeping up. SUSE quietly absorbed 108 CVEs in a single chromedriver/chromium update. Not surprising, so much as exhausting. Ubuntu's Oracle 7.0 FIPS kernel for 24.04 swept in 101, though that count isn't padded. It's one release catching up to everything fixed upstream since the last sync.
OpenSSL is the line item that makes ops teams lean in. Debian's version carries 13 CVEs including private key recovery, and that backs basically every TLS connection people actually bother setting up. Get onto 3.5.7-1~deb13u3. Fedora's PHP update hit 8.5.11 on Fedora 44 and 8.4.26 on Fedora 43, and one of its ten lets a TLS hostname check quietly fall back to the common name after a subject alternative name mismatch. That undercuts the whole point of the check. If anything server-side speaks PHP, treat this as urgent.
Red Hat's batch reads like a form letter, package name filled in each time. The lone Critical is webkit2gtk3 on RHEL 8, a component you know gets exploited for real. The kernel alone accounts for five separate advisories across the lot. The rest sit at Important, with two kernel updates and both OpenSSH fixes downgraded to Moderate.
Rocky pushed 14 errata across Linux 8, 9, and 10, mostly Important. The kernel shows up four times, which is about as expected as things get. Run anything mail-related on Linux 10? The Thunderbird patch is the one to prioritize, since email clients have always been a favorite attacker target.
SUSE kept most of its batch on the moderate end, threading 170-plus vulnerabilities across Chromium, Netty (30), and the Python stack. The important-rated fixes aren't dramatic. python-pymongo's worst is a BSON integer overflow that usually plays out as a local privilege problem rather than a remote meltdown. gdb's single CVE is an 8.4 out-of-bounds write in the STABS parser, triggered by a malformed ELF. If you don't drive Chromium headless, the biggest SUSE update can probably wait.
Ubuntu pushed its notice over the last two days of September 2026, and the kernel carries the bulk of the CVEs. CVE-2025-10263, a local privilege-escalation bug in Arm's TLB invalidation, keeps turning up across the AWS, Tegra, and Oracle kernels. The desktop-facing stuff is the gentler half: GVfs heap overflow, OpenStack Keystone token-scoping holes, OpenVPN's use-after-free in TLS handling. OpenVPN and Keystone are the ones to patch before you hand out credentials.
Installing all of it is the boring but good kind of work. Fedora wants the usual dnf upgrade --advisory line per advisory. Ubuntu's kernel notices all need a reboot, and the FIPS variants add an unavoidable ABI change, so self-compiled out-of-tree modules need rebuilding. Set aside real time if you run third-party drivers. OpenVPN just wants a service restart, and the simpler packages apply on the next update without fuss.
An Overview of the Updates
AlmaLinux
AlmaLinux rolled out fifteen security advisories, hitting databases, mail clients, web servers, and the Go and Node.js toolchains. Eleven land at Important severity, one is Critical, two are Moderate, and one is Low. The PostgreSQL updates and the Thunderbird entry do most of the heavy lifting.
postgresql:15 tops the list with sixteen separate CVEs. They span arbitrary code execution routes, from an integer wraparound in tsvector/tsquery functions to a heap overflow in regexp handling, a COPY FROM STDIN command injection, and a privilege escalation through EXTRACT() deparse. It's a list the size of a quarterly review for what is usually a routine maintenance bump. postgresql:12 absorbed essentially the same fixes, minus the pg_dump untrusted-data issue.
Thunderbird got the familiar release-day treatment. Because it shares Firefox's codebase, one Mozilla rollout arrives as a pile of use-after-free bugs plus a few IMAP and MIME parser flaws. You're looking at 44 CVEs here, with sandbox escapes and privilege escalations doing the interesting work while the mail client itself carries a handful of out-of-bounds reads on its own.
The rest is more surgical. 389 Directory Server carries the only Critical rating: a SASL PLAIN flaw that lets an attacker climb to Directory Manager, a heap buffer overflow, and a SELFDN ACI bypass worth patching promptly. go-toolset and container-tools both carry Go fixes for net/mail DoS, net/url quadratic-complexity parsing, and html/template XSS, so check those if your stack is built in Go. nodejs:22 covers an HTTP/2 memory-exhaustion issue and a filesystem access flaw, while nodejs24 also rebases to the latest Node.js 24 release. gawk and gdb show up twice each for the same CVEs, split between AlmaLinux 9 and 10.
| Advisory | Package | AlmaLinux | Severity | CVEs | What it covers |
|---|---|---|---|---|---|
| ALSA-2026:69923 | postgresql:15 | 8 | Important | 16 | Arbitrary code execution via integer wraparound, pg_dump, COPY FROM STDIN, logical decoding, regexp heap overflow, EXTRACT() privilege escalation |
| ALSA-2026:69924 | postgresql:12 | 8 | Important | 15 | Same fixes minus the pg_dump untrusted-data issue |
| ALSA-2026:22112 | go-toolset:rhel8 | 8 | Important | 11 | net/mail DoS, cmd/go integrity bypass, html/template XSS, go bug symlink file overwrite |
| ALSA-2026:63163 | container-tools:rhel8 | 8 | Important | 7 | Go net/url quadratic DoS, TLS KeyUpdate DoS, html/template XSS, asn1/xml recursion |
| ALSA-2026:54243 | grafana | 8 | Important | 2 | Privilege escalation via dashboard overwrite; DoS via large JSON payloads |
| ALSA-2026:62219 | nodejs:22 | 8 | Important | 3 | Filesystem access permission flaw; HTTP/2 memory exhaustion; HTTP/2 use-after-free |
| ALSA-2026:64794 | httpd:2.4 | 8 | Low | 1 | use-after-free in mod_ldap per-directory configuration |
| ALSA-2026:64791 | 389-ds:1.4 | 8 | Critical | 4 | SASL PLAIN escalation to Directory Manager, SASL heap overflow, SELFDN ACI bypass; plus 2 replication bug fixes |
| ALSA-2026:67872 | corosync | 10 | Important | 1 | heap buffer overflow in totempg during fragmented message reassembly |
| ALSA-2026:73428 | nodejs24 | 10 | Important | 3 | undici auth bypass, TLS validation bypass in BalancedPool, WebSocket DoS; plus a rebase to latest Node.js 24 |
| ALSA-2026:73427 | gdb | 10 | Important | 1 | out-of-bounds write in STABS parser via crafted ELF |
| ALSA-2026:73512 | gawk | 9 | Moderate | 3 | integer-overflow memory corruption, ftype() buffer overflow, use-after-free in io.c |
| ALSA-2026:73426 | gdb | 9 | Important | 1 | out-of-bounds write in STABS parser via crafted ELF |
| ALSA-2026:73429 | gawk | 10 | Moderate | 3 | integer-overflow memory corruption, ftype() buffer overflow, use-after-free in io.c |
| ALSA-2026:73130 | thunderbird | 10 | Important | 44 | Sandbox escapes, privilege escalations, use-after-free across DOM/Graphics/JS, plus IMAP and MIME parser overflows |
Debian GNU/Linux
Debian has been handing out security updates with the steady rhythm of a pay day. The stable release (trixie) and the long-term support track (bookworm) both show up, along with a pile of extended-LTS fixes from Freexian aimed at the older stretches, busters, and bullseyes.
Firefox-ESR is the one that makes you stop scrolling. Mozilla crammed 62 CVEs into a single advisory, touching arbitrary code execution, sandbox escapes, info disclosure and privilege escalation. Debian now tracks Firefox 153.x instead of the previous 140.x line, so you'll see the version bump ride along with the patch. The fixed version lands at 153.4.0esr-1~deb13u1.
OpenSSL isn't far behind, with 13 CVEs and the less-fun possibility of private keys slipping out the door. That's the line item that makes ops teams pay attention, since it backs basically every TLS connection people bother setting up. Get onto 3.5.7-1~deb13u3.
The interesting wrinkle comes from python3.7. This update changes how the parser splits query strings: only ampersands count as separators now, semicolons don't. If your stack relies on splitting parameters at semicolons, this could break it quietly, in exactly the way security patches shouldn't. Freexian does flag the API change in bold, which is fair. Expat ate roughly a dozen bugs spanning billion-laughs attacks, integer overflows, and some genuinely clumsy UTF-16 handling. And node-tar, with its hardlink and symlink path-traversal holes, is the classic "don't extract that archive" situation.
The rest are quieter. Tor picked up a denial-of-service hole with no CVE number yet, which is normal this early. mkvtoolnix has a heap overflow in its bundled avilib (poking at Matroska files was apparently a good enough exploit vector). pgextwlist now refuses schema and owner substitutions that tried to match a short set of characters. libsmpp34 has an out-of-bounds read when processing SMPP PDUs. And Django shows up twice over cache-poisoning bugs in its Vary-header and cookie handling.
| Package | Advisory | CVEs | What's broken | Fixed in |
|---|---|---|---|---|
| openssl | DSA 6531-1 | 13 CVEs (35189 through 84784) | DoS, info disclosure, private key recovery | 3.5.7-1~deb13u3 (trixie) |
| firefox-esr | DSA 6533-1 | 62 CVEs (96869, 100756-100832) | Code execution, sandbox escape, info disclosure, priv esc | 153.4.0esr-1~deb13u1 (trixie) |
| tor | DSA 6532-1 | none assigned yet | Denial of service | 0.4.9.13-0+deb13u1 (trixie) |
| mkvtoolnix | DLA 4805-1 | 90783 | Heap buffer overflow in bundled avilib | 74.0.0-1+deb12u1 (bookworm) |
| pgextwlist | DLA 4806-1 | 2023-39417 | Schema/owner substitution (now rejected) | 1.15-2+deb12u1 (bookworm) |
| libsmpp34 | DLA 4804-1 | 2026-75895 | Out-of-bounds read, memory corruption | 1.14.1-3+deb12u1 (bookworm) |
| python-django | DLA 4802-1 | 48587, 48588 | Cache poisoning via Vary header and cookies | 3:3.2.25-0+deb12u5 (bookworm) |
| ruby-oj | DLA 4803-1 | 11 CVEs (54500-54903) | DoS, memory disclosure | 3.14.2-1+deb12u1 (bookworm) |
| expat | DLA 4807-1 | 10 CVEs (28757, 59375, 24515-93990) | Billion laughs, overflow, NULL deref, bad UTF-16 | 2.5.0-1+deb12u4 (bookworm) |
| mkvtoolnix | ELA-1837-1 | 90783 | Heap overflow in avilib | 54.0.0+really52.0.0-3+deb11u1 (bullseye) |
| pyasn1 | ELA-1840-1 | 59884-59886 | DoS via unbounded/quadratic ASN.1 parsing | stretch/buster/bullseye |
| python3.7 | ELA-1839-1 | 12 CVEs (23336-6100) | Cache poisoning, header injection, UAF | 3.7.3-2+deb10u12 (buster) |
| node-tar | ELA-1838-1 | 28863, 23745, 26960, 29786 | Path traversal via hardlinks/symlinks | 4.4.6+ds1-3+deb10u3 (buster) |
| lxml | ELA-1836-1 | 2309, 28348, 28350, 41066, 49825 | XEE, tag injection, javascript: URLs | stretch/buster/bullseye |
| python-django | ELA-1835-1 | 48587, 48588, 53877 | Cache poisoning, GDALRaster over-read | 1:1.10.7-2+deb9u32 (buster/stretch) |
Fedora Linux
Fedora's security queue carried a heavy load this round, with both Fedora 44 and Fedora 43 getting patched and several of the affected packages coming with holes you actually want to know about. You get two versions in one sweep, plus a shared Rust-Python cluster that rolls out under a single advisory for both.
The two that matter most are the ones you probably already run. PHP landed version 8.5.11 on Fedora 44 and 8.4.26 on Fedora 43, and as you'd expect from a PHP point release, the changelog is long enough to read like a novella. Ten vulnerabilities made the cut for each, and not all of them are theoretical. One lets a TLS hostname check quietly give up and fall back to the common name after a subject alternative name mismatch, which undercuts the whole point of the check. There's also a heap buffer overflow a crafted wildcard on a server certificate can poke, along with the usual grab bag of memory-safety bugs spread across DOM, SOAP, Phar, and the HTTP stream wrapper. If anything server-side speaks PHP, treat this as install-now rather than install-when-you-feel-like-it.
ffmpeg is another quiet winner. Fedora 44's 8.1.3 update closes 22 CVEs across formats and demuxers, from RASC and ADX/AAX to RIST and the CIFF family. Some let an attacker run code from a crafted image or video file, others leak uninitialized memory or just chew through your resources. It's the kind of update you don't fully appreciate until someone mails you a strangely sized attachment.
Then comes the Rust-Python cluster. One advisory (FEDORA-2026-407b957a3b) pushed uv, ty, ruff, python-uv-build, and the libcst and salsa families to both Fedora versions. Two things are worth your attention: a use-after-free in salsa (GHSA-xc3w-55vh-cw3w), and more interestingly, an arbitrary code execution in ruff and ty when they typecheck untrusted code (GHSA-vxvm-j4xq-q7m4). If you lint or typecheck other people's source, the second is your reason.
A handful of smaller fixes round out the batch. xdg-dbus-proxy gets a stopgap for a message-filtering bypass that let sandboxes be escaped, which is exactly the kind of thing flatpak users should care about. apptainer moved to 1.5.4 on both Fedora versions, plugging a denial of service tied to oversized OpenTelemetry baggage headers. librabbitmq is up to 0.18.0 and stops a client-side memory-exhaustion stall. openbao reached 2.6.3 on Fedora 43, bringing its usual set of security advisories along with some cleanup to its own service file. And if you render HTML to PDF through WeasyPrint, a 70.0 update on Fedora 43 closes a server-side request forgery (CVE-2026-55073), alongside python-cssselect2.
Installing all of it is the boring, good kind of work. Run the usual dnf upgrade --advisory line for each, and every package carries the Fedora GPG signature.
| Package | Fedora | Version | Advisory ID | What it fixes |
|---|---|---|---|---|
| xdg-dbus-proxy | 44 | 0.1.9 | FEDORA-2026-93f562a43f | CVE-2026-94422 message-filtering bypass that allowed sandbox escape |
| ffmpeg | 44 | 8.1.3 | FEDORA-2026-3e109a0c85 | 22 CVEs across demuxers/decoders (RASC, ADX/AAX, RTP/ASF, zlib, vf_hqdn3d, PGS/SUP, CAF, PNG, IAMF, TIFF, Screenpresso, RSCC, VobSub, CFHD, WTV, NVDEC, AV1, DASH, Dirac, MPEG-PS, integer narrowing, RIST) |
| uv | 44 | 0.12.19 | FEDORA-2026-407b957a3b | salsa use-after-free (GHSA-xc3w-55vh-cw3w), ruff/ty arbitrary code exec (GHSA-vxvm-j4xq-q7m4) |
| ty | 44 | 0.0.84 | FEDORA-2026-407b957a3b | Same Rust/Python cluster fixes |
| rust-salsa-macro-rules | 44 | 0.28.5 | FEDORA-2026-407b957a3b | Same cluster fixes |
| rust-libcst_derive | 44 | 1.9.0 | FEDORA-2026-407b957a3b | Same cluster fixes |
| rust-salsa-macros | 44 | 0.28.5 | FEDORA-2026-407b957a3b | Same cluster fixes |
| rust-salsa | 44 | 0.28.5 | FEDORA-2026-407b957a3b | Same cluster fixes |
| rust-libcst | 44 | 1.9.0 | FEDORA-2026-407b957a3b | Same cluster fixes |
| python-uv-build | 44 | 0.12.19 | FEDORA-2026-407b957a3b | Same cluster fixes |
| ruff | 44 | 0.16.9 | FEDORA-2026-407b957a3b | Same cluster fixes |
| apptainer | 44 | 1.5.4 | FEDORA-2026-e84de41d80 | CVE-2026-41178 DoS via OpenTelemetry baggage headers, plus GHSA-cr2j-534f-mf3g |
| php | 44 | 8.5.11 | FEDORA-2026-5f0023de35 | 10 CVEs: OpenSSL TLS/SAN fallback and wildcard heap overflow, Phar TAR injection, SOAP recursion/overflow, HTTP stream wrapper leak and OOB read, mysqlnd overread |
| librabbitmq | 44 | 0.18.0 | FEDORA-2026-981119a846 | GHSA-5fp7-wg2f-hhgp client-side memory-exhaustion DoS |
| rust-salsa-macros | 43 | 0.28.5 | FEDORA-2026-056196047a | Same Rust/Python cluster fixes |
| openbao | 43 | 2.6.3 | FEDORA-2026-ccc419650a | Multiple security GHSAs, plus service-file and config cleanup |
| rust-libcst_derive | 43 | 1.9.0 | FEDORA-2026-056196047a | Same cluster fixes |
| uv | 43 | 0.12.19 | FEDORA-2026-056196047a | Same cluster fixes |
| ty | 43 | 0.0.84 | FEDORA-2026-056196047a | Same cluster fixes |
| rust-libcst | 43 | 1.9.0 | FEDORA-2026-056196047a | Same cluster fixes |
| rust-salsa-macro-rules | 43 | 0.28.5 | FEDORA-2026-056196047a | Same cluster fixes |
| rust-salsa | 43 | 0.28.5 | FEDORA-2026-056196047a | Same cluster fixes |
| ruff | 43 | 0.16.9 | FEDORA-2026-056196047a | Same cluster fixes |
| python-uv-build | 43 | 0.12.19 | FEDORA-2026-056196047a | Same cluster fixes |
| python-cssselect2 | 43 | 0.10.1 | FEDORA-2026-05e36e4865 | CVE-2026-55073 SSRF |
| weasyprint | 43 | 70.0 | FEDORA-2026-05e36e4865 | CVE-2026-55073 SSRF |
| apptainer | 43 | 1.5.4 | FEDORA-2026-b38ba933a5 | CVE-2026-41178 DoS via OpenTelemetry baggage headers, plus GHSA-cr2j-534f-mf3g |
| php | 43 | 8.4.26 | FEDORA-2026-d5e4829deb | 10 CVEs: same OpenSSL, Phar, SOAP, HTTP stream wrapper, and mysqlnd set as the 8.5 branch |
| librabbitmq | 43 | 0.18.0 | FEDORA-2026-3c05c90d12 | GHSA-5fp7-wg2f-hhgp client-side memory-exhaustion DoS |
Red Hat Enterprise Linux
Red Hat just pushed another batch of security errata, and if you read through the list you'll find nearly every entry built from the same template with the package name filled in. That's how these advisories work, and the repetition is harmless as long as you still do the patching.
The advisory that actually earns your attention is RHSA-2026:74084, the lone Critical in this lot, for webkit2gtk3 on RHEL 8. You know what that component is, so this is the kind of flaw that gets exploited for real. The rest of the batch sits at Important, with a handful downgraded to Moderate. That Moderate cluster includes two kernel updates on RHEL 8 (the regular kernel and the real-time kernel-rt), plus both OpenSsh fixes, one for RHEL 9 and one for RHEL 10.
A few patterns stand out beyond the severity tags. The kernel alone accounts for five separate advisories here, spanning NVIDIA's RHEL build, the RHEL 6 Extended Lifecycle Support extension, the RHEL 8 Moderate update, the kernel-rt Moderate update, and the SAP Solutions track for RHEL 9.4. You also get two OpenShift Container Platform releases (4.19.49 and 4.22.16) and two JBoss EAP updates (7.1.16 and 7.3.19), so if you run either stack you have two errata to chase down. Node and Python get the same treatment across RHEL 8, 9, and the extended tracks, and there's a lone RHEL AI 3.0 ffmpeg fix sitting at Moderate too.
| RHSA ID | Component | Severity | Scope | Platform / notes |
|---|---|---|---|---|
| 73915 | rhc | Important | Security | RHEL 8 |
| 71440 | OpenShift Container Platform 4.19.49 | Important | Bug fix + security | OSCP 4.19 |
| 73838 | nodejs:24 | Important | Security, bug fix, enhancement | RHEL 9 |
| 73765 | dogtag-pki | Important | Security | RHEL 10 |
| 73788 | kernel | Important | Security, bug fix, enhancement | RHEL for NVIDIA |
| 73732 | kernel | Important | Security | RHEL 6 ELS EXTENSION |
| 73766 | pki-core | Important | Security | RHEL 9 |
| 73768 | gimp | Important | Security | RHEL 9.6 EUS |
| 73976 | JBoss EAP 7.1.16 | Important | Security | RHEL 7 |
| 74088 | python3.9 | Important | Security | RHEL 9.6 EUS |
| 74133 | kernel | Moderate | Security, bug fix, enhancement | RHEL 8 |
| 74087 | python3.9 | Important | Security | RHEL 9.4 SAP |
| 74095 | rsync | Important | Security, bug fix, enhancement | RHEL 8 |
| 74085 | nodejs:24 | Important | Security, bug fix, enhancement | RHEL 8 |
| 74132 | kernel-rt | Moderate | Security, bug fix, enhancement | RHEL 8 |
| 74084 | webkit2gtk3 | Critical | Security | RHEL 8 |
| 74081 | python3.12-lxml | Important | Security | RHEL 9.6 EUS |
| 74082 | python3.12-lxml | Important | Security | RHEL 9.4 SAP |
| 74089 | RHEL AI 3.0 runtime (ffmpeg) | Moderate | CVE fix | RHEL AI |
| 73955 | openssh | Moderate | Security | RHEL 9 |
| 73997 | gvfs | Important | Security | RHEL 8 |
| 73971 | thunderbird | Important | Security | RHEL 8 |
| 73954 | openssh | Moderate | Security | RHEL 10 |
| 73767 | pcp | Important | Security | RHEL 8.8 (SAP + Telecom) |
| 73519 | ruby:2.5 | Important | Security | RHEL 8 |
| 73912 | postgresql:12 | Important | Security | RHEL 8.4 (AMC + ESL Long-Life) |
| 73645 | kernel | Important | Security, bug fix, enhancement | RHEL 9.4 SAP |
| 73644 | JBoss EAP 7.3.19 | Important | Security | RHEL 7 |
| 71446 | OpenShift Container Platform 4.22.16 | Important | Bug fix + security | OSCP 4.22 |
| 73998 | gvfs | Important | Security | RHEL 10 |
| 74001 | expat | Important | Security | RHEL 10 |
Rocky Linux
Rocky Linux just pushed a batch of 14 security errata across its three supported releases, with the load spread fairly evenly between Linux 8, 9, and 10. You'll want to sort through these before they start piling up.
Most land at "Important," which sits just below Critical on the severity ladder, so this isn't a drop-everything-and-reboot moment but it's also not a "read it someday" situation. Only gawk on Linux 9 and 10 comes in at "Moderate." If you happen to run anything mail-related, the Thunderbird patch on Linux 10 is the one to prioritize, since email clients have always been a favorite target for attackers.
The kernel family shows up four times, which is about as expected as things get. Linux 8 gets straight security fixes for kernel and kernel-rt, while Linux 9 and 10 get the fuller "security, bug fix, and enhancement" treatment. Those larger ones are probably best folded into your next planned maintenance window rather than triggering an emergency reboot.
The Node.js 24 and Ruby 2.5 updates carry the longest package lists, since they drag in a pile of related gems and modules. gdb alone appears on all three release versions.
| RLSA ID | Package | Severity | Rocky Linux | What it covers |
|---|---|---|---|---|
| RLSA-2026:72467 | kernel-rt | Important | 8 | Security |
| RLSA-2026:72468 | kernel | Important | 8 | Security |
| RLSA-2026:73425 | gdb | Important | 8 | Security |
| RLSA-2026:73519 | ruby:2.5 | Important | 8 | Security (several gems/modules) |
| RLSA-2026:74085 | nodejs:24 | Important | 8 | Security, bug fix, enhancement |
| RLSA-2026:72663 | expat | Important | 9 | Security |
| RLSA-2026:72623 | kernel | Important | 9 | Security, bug fix, enhancement |
| RLSA-2026:73426 | gdb | Important | 9 | Security |
| RLSA-2026:73512 | gawk | Moderate | 9 | Security |
| RLSA-2026:73838 | nodejs:24 | Important | 9 | Security, bug fix, enhancement |
| RLSA-2026:73427 | gdb | Important | 10 | Security |
| RLSA-2026:72624 | kernel | Important | 10 | Security, bug fix, enhancement |
| RLSA-2026:73429 | gawk | Moderate | 10 | Security |
| RLSA-2026:73130 | thunderbird | Important | 10 | Security |
Slackware Linux
Slackware's security team pushed two updates this round, and they aren't evenly matched.
Thunderbird got the heavy one. Slackware 15.0 lands on 140.17.0esr while -current leaps ahead to 153.4.0esr, and Mozilla packed a staggering 44 CVEs into the release. That is an odd amount of surface area for an ESR jump, and two of the IDs (CVE-2026-92035 and CVE-2026-96869) break the otherwise relentless 100xxx numbering, which is at least a little suspicious on its face. You do not have to sort through all of them to understand the takeaway: this is the patched build, and it is the one you want running. Everything is filed under MFSA2026-102.
The second update is the saner of the pair. libpng climbs to 1.6.59 to close a single use-after-free bug in png_read_end, which trips when a zTXt, iTXt, or iCCP stream gets cut off mid-decompression. That is one CVE (2026-46675) for an actual heap bug, and it is exactly the kind of thing you would rather not leave sitting around while your parser munches on a suspicious image.
Both reached 15.0 and -current, so if you are still on an older build of either, the fix is already sitting in the FTP tree.
| Package | Slackware 15.0 | -current | CVEs | What is actually fixed |
|---|---|---|---|---|
| mozilla-thunderbird | 140.17.0esr | 153.4.0esr | 44 (MFSA2026-102) | Broad set of security fixes; two IDs break the usual pattern, so bring your skepticism |
| libpng | 1.6.59 | 1.6.59 | CVE-2026-46675 | Use-after-free in png_read_end after truncated zTXt/iTXt/iCCP decompression |
SUSE Linux
SUSE's latest advisory batch lands almost entirely on the moderate end of the scale, with one exception worth your attention: a single update quietly absorbed 108 CVEs. Across 14 separate announcements you're looking at well over 170 individual vulnerabilities, mostly threading their way into the usual suspects like Chromium, Netty, and the Python stack. The important-rated fixes are worth your time even if none of them is going to keep you up at night.
The chromedriver headline is the obvious one. Chromium tends to release a half-dozen fixes in a single breath and expects you to keep up, so 108 isn't surprising so much as tedious. Netty isn't far behind with 30, and libtesseract5 carries 9 more. The rest are smaller.
On the important fixes, the honest read is that they aren't dramatic. The python-pymongo update covers three issues, and while the worst of them is an integer overflow in BSON encoding (CVE-2026-96749, rated 9.2 by SUSE), that kind of bug usually plays out as a local privilege problem rather than a remote meltdown. The tornado release folds in four bugs, including a reworked fix for a cookie attribute injection that they already tried to close once. gdb's one CVE is an out-of-bounds write in the STABS parser triggered by a malformed ELF file, and it scores a respectable 8.4.
Two things you'll want to know before you start patching. The openSUSE Tumbleweed entries use a different announcement format and don't publish CVSS scores for every CVE, so some numbers simply aren't there. The wicked2nm bulletin is also odd: it carries no CVE at all and is really a bug-fix release where a serialization panic and a VLAN flag default got lumped into a security notice. If you don't drive Chromium headless, the biggest update can probably wait.
| Announcement ID | Package(s) | Rating | CVEs | Notable issue |
|---|---|---|---|---|
| SUSE-SU-2026:4398-1 | python-pymongo | important | 3 | CVE-2026-96749 integer overflow in BSON encoding (9.2) |
| SUSE-SU-2026:4400-1 | gdb | important | 1 | CVE-2026-13732 out-of-bounds write via crafted ELF (8.4) |
| SUSE-SU-2026:4403-1 | python-tornado6 | important | 4 | HTTP smuggling, CRLF injection, cookie bypass |
| SUSE-SU-2026:4405-1 | wicked2nm | important | 0 | serde_with serialization panic; agama VLAN fix |
| openSUSE-SU-2026:11882-1 | netty | moderate | 30 | Multiple resource exhaustion / DoS paths |
| openSUSE-SU-2026:11883-1 | pcapplusplus-devel | moderate | 4 | Buffer handling in packet parsing |
| openSUSE-SU-2026:11884-1 | pi-coding-agent | moderate | 3 | CVE-2026-84961 (9.1) |
| openSUSE-SU-2026:11885-1 | libpoppler-cpp3 | moderate | 2 | Low-severity memory issues |
| openSUSE-SU-2026:11886-1 | python311 | moderate | 4 | CVE-2026-17084 / CVE-2026-19672 |
| openSUSE-SU-2026:11887-1 | libtesseract5 | moderate | 9 | Multiple tesseract parsing bugs |
| openSUSE-SU-2026:11888-1 | chromedriver / chromium | moderate | 108 | Chromium batch security fixes |
| openSUSE-SU-2026:11889-1 | emacs | moderate | 1 | Malformed input handling |
| openSUSE-SU-2026:11890-1 | gimp | moderate | 6 | Parsing/memory bugs |
| openSUSE-SU-2026:11891-1 | gpsd | moderate | 1 | Memory safety in GPS daemon |
Ubuntu Linux
Ubuntu pushed a batch of security notices across the last two days of September 2026, and the pile reads like the usual mix of the genuinely alarming and the mildly annoying. The OpenSSL update (USN-8847-2) arrives as a follow-up to last week's USN-8847-1 and plugs four problems: a memory-exhausting bug in cert-revocation handling, a DTLS handshake glitch, and two timing side-channel attacks in elliptic-curve and SM2 signature code. The side-channel fixes only land on 18.04 and 20.04, so if your box is still on 14.04 or 16.04 you get the memory-blowup but not the data leak. Everything older than 18.04 also reaches subscribers through Ubuntu Pro now, which means the free update path for those systems closed a while ago.
The kernel updates carry the bulk of the CVEs, and one flaw keeps turning up. CVE-2025-10263 is a local privilege-escalation bug in Arm's TLB invalidation that lets a process write to memory it has already lost access to. It rides along in the AWS, AWS FIPS, Oracle, and Tegra kernels, usually tagged onto lists of network and filesystem fixes. The outlier is USN-8816-3, the Oracle 7.0 FIPS kernel for 24.04, which sweeps in 101 CVEs across dozens of subsystems. That count isn't inflated, it is a single release catching up to everything fixed upstream since the previous sync.
The rest reaches people who actually run desktops. GVfs takes a heap buffer overflow from bad SFTP server data, OpenStack Keystone picks up three token-scoping holes, and OpenVPN's use-after-free in TLS handling can either crash the daemon or run arbitrary code. ImageMagick rounds things out with a half-dozen malformed-image handlers, its notice reading a little like a checklist of "did not correctly handle certain images." The Kdenlive proxy-parameter trap and the denial-of-service nits in OpenSBI and a Perl SASL library are the sort you patch when you remember, though the OpenVPN and Keystone issues are the ones worth patching before you hand out credentials.
Every kernel notice needs a reboot, and the FIPS variants add a wrinkle: an unavoidable ABI change means self-compiled third-party kernel modules need rebuilding, so set aside real time if you run out-of-tree drivers. The non-kernel packages are gentler. OpenVPN just wants a service restart, and OpenSBI plus the Perl library apply on the next update without fuss.
| USN | Software | Affected Ubuntu releases | CVEs |
|---|---|---|---|
| USN-8847-2 | OpenSSL (openssl1.0) | 20.04, 18.04, 16.04, 14.04 LTS | 4 |
| USN-8817-2 | Linux kernel (AWS FIPS) | 24.04 LTS | 20 (incl. CVE-2025-10263) |
| USN-8850-1 | Linux kernel (BlueField) | 20.04 LTS | 8 |
| USN-8849-1 | Linux kernel (NVIDIA Tegra) | 20.04 LTS | 18 (incl. CVE-2025-10263) |
| USN-8851-1 | Linux kernel (wide range) | 20.04, 18.04 LTS | 3 |
| USN-8818-4 | Linux kernel | 22.04 LTS | 20 (incl. CVE-2025-10263) |
| USN-8730-7 | Linux kernel (FIPS) | 22.04 LTS | 1 |
| USN-8819-4 | Linux kernel (FIPS) | 18.04 LTS | 3 |
| USN-8818-5 | Linux kernel (NVIDIA Tegra/IGX) | 22.04 LTS | 20 (incl. CVE-2025-10263) |
| USN-8816-3 | Linux kernel (Oracle) | 24.04 LTS | 101 |
| USN-8817-3 | Linux kernel (AWS) | 24.04, 22.04 LTS | 20 (incl. CVE-2025-10263) |
| USN-8852-1 | OpenVPN | 26.04, 24.04, 22.04 LTS | 2 |
| USN-8853-1 | OpenSBI | 22.04 LTS | 1 |
| USN-8858-1 | Authen::SASL (Perl) | 26.04, 24.04, 22.04, 20.04, 18.04, 16.04, 14.04 LTS | 1 |
| USN-8856-1 | Kdenlive, MLT | 26.04 LTS | 1 |
| USN-8854-1 | OpenStack Keystone | 26.04, 24.04, 22.04, 20.04, 18.04, 16.04 LTS | 3 |
| USN-8845-1 | GVfs | 26.04, 24.04, 22.04, 20.04, 18.04, 16.04 LTS | 2 |
| USN-8859-1 | ImageMagick | 26.04, 24.04, 22.04, 20.04, 18.04, 16.04, 14.04 LTS | 6 |
How to apply these Linux security updates
Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.
Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.
Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.
Debian/Ubuntu (apt)
The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.
sudo apt update sudo apt upgrade -y
Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)
On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.
sudo dnf check-update sudo dnf upgrade -y
or on older releases
sudo yum check-update sudo yum update
SUSE (zypper)
SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.
sudo zypper refresh sudo zypper update -y
Slackware (slackpkg and pkgtool)
Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.
sudo slackpkg update sudo slackpkg upgrade-all
