Ubuntu shipped today's most striking update, a kernel livepatch packing 150 CVEs that installs without a reboot. SUSE led the browser front with two simultaneous Chromium builds, while Red Hat delivered a JBoss Web Server patch and its lone Moderate rating for an RHEL 7 kernel update. Debian handed Python 3.11 thirteen CVEs and Qubes kept QSB 120 narrow, affecting only CTAP proxy users. Most of the remaining distro patches can safely ride to your next scheduled maintenance window.
Ubuntu ships 150 CVEs in a single kernel livepatch; Linux distros push a wave of security updates
Most of today's updates are routine. A handful, starting with Ubuntu's kernel notice, are worth acting on now.
The most noticeable thing in today's Linux security releases is a kernel update carrying 150 CVEs. Ubuntu filed that advisory as a livepatch, so you get the fixes without rebooting. It's a number that would have looked insane a few years ago.
The rest of today's updates are more ordinary. Red Hat, SUSE, Debian, Fedora, AlmaLinux, and a few other distros all shipped patches this round. A lot of the same packages show up in multiple places: Firefox, Sequoia, FreeRDP. The bugs are upstream bugs, so they ripple wherever the code runs. But a few stand on their own, and a couple are genuinely notable.
Here's a quick aside. Kernel CVE counts keep climbing while livepatches get more ambitious. Canonical clearly likes shoving a year's worth of fixes into one advisory, which is great for anyone who hates restarting servers.
Patch this first
Ubuntu's kernel notice is the heavyweight of today's roundup. Livepatch 122 packs 150 CVEs into a single bulletin, and most of them don't need a restart. The range runs from a use-after-free in the DLM filesystem to a NULL pointer dereference in the Broadcom brc43mac Wi-Fi driver, plus a logic flaw in the XFRM ESP-in-TCP stack that developers nicknamed Fragnesia. That one lets a local attacker escalate privileges or escape a container. Most of the CVEs trace back to 2025 and 2026, though a 2023 and a 2024 crept in at the front of the list. It's arguably the most ambitious single kernel patch I've seen in a long while.
Ubuntu's web stack deserves a look too. Poppler took integer overflows, a NULL dereference, and an oversized read, with four of five CVEs letting code run as you. The sudo fix is the one worth pausing over: sudo mishandled time-based rules when NOTBEFORE or NOTAFTER timestamps dropped their timezone indicator, so a local attacker could flip the TZ variable and run commands outside the window you thought was locked. It quietly undoes the time limits. Go networking rounds out the batch with HTTP/2 hangs, quadratic parsing, and a Punycode slip that lets some domain checks fail.
If you track SUSE, Chromium is where the news is, and this is one of those rare weeks the distro shipped two browser builds at once. The Leap 16.0 build closes 11 holes. The Tumbleweed version is messier, landing at 32 CVEs. A big number usually just means you're tallying every medium-severity nit the Chromium team reported, but a browser patch is genuinely one of the few things you should install immediately. SUSE flags the Tumbleweed list as "GA media," which reads like a placeholder, so treat the exact breakdown as provisional.
Fedora kept it simple. Both Fedora 43 and 44 landed on Chromium build 154.0.8037.97 with 11 fixes: type confusions in V8, out-of-bounds WebGL writes, and use-after-frees in MediaStream and FedCM. If you browse with Chromium, that's the one to prioritize.
Firefox shows up nearly everywhere this week. Oracle Linux crammed 43 vulnerabilities into one ESR release, which looks scary until you remember how normal that is when Mozilla ships a feature-heavy ESR. You're mostly catching up to stock Firefox ESR 140.17.0. Red Hat went a step stranger and slotted a Firefox patch straight from Oracle Linux 10 into its own tracker. It's a bit odd for Red Hat to cite another vendor's bulletin, though it does mean one less thing to hunt down.
Red Hat's lone Moderate rating deserves a wry look. It's a kernel update for RHEL 7's Extended Lifecycle Support. Mostly it just reminds you how many shops are still running a release deep into its twilight. There's also a JBoss Web Server 7.0.2 patch arriving twice: a normal package plus a separate zip build that covers Windows Server, so Windows users don't get skipped.
The smaller fish
Debian shipped just two advisories. Python 3.11 grabbed most of the trouble with 13 CVEs across Debian 12's LTS line. The usual suspects are here: crashable parsers, a cookie that escapes its own script tag, a bzip2 decompressor you can reuse to write past the end of a stack buffer. One of them lets hostname verification slip by silently, the sort of thing you'd rather not be doing while you're pretending to be behind a secure connection. The second advisory covers xz-utils, a single flaw in the LZMA1 decoder with no CVE assigned yet. It doesn't touch the 2024 supply-chain backdoor either, so the lingering wariness around that name is mostly historical.
Qubes issued QSB 120, but this one is narrow and easy to skip. It hits only Qubes 4.3 users running the CTAP proxy, the feature that shares a USB security key across qubes. Two flaws live in the qubes-ctap package, fixed in version 2.0.8. If you've never wired a hardware key this way, it isn't yours. The bulletin credits two contributors, one internal and one from the Freedom of the Press Foundation.
Slackware rebuilt xorg-server for both 15.0 and -current, plugging nine memory bugs: double frees, use-after-frees, heap overflows, out-of-bounds reads. They're all local. A client already talking to your X session has to be doing something mischievous to trigger them, so there's no clean remote route for a stranger. That trims the panic nicely. It does give you nine concrete reasons to stop letting random programs paint on your display anyway.
AlmaLinux led with sixteen errata and the longest Firefox list at 28 CVEs shared with Thunderbird, many escalating through the CanvasWebGL graphics stack. If you connect to Windows machines from a Linux desktop, FreeRDP is the closest to the metal item, with RCE routes through heap overflows. Oracle and Rocky each ran their own versions of the same Sequoia and perl-DBI fixes, which is fine. It's just upstream bugs rippling through the EL clones. And SUSE's govulncheck-vulndb update reads like a scary list of roughly 54 Go identifiers, but it's rated moderate and is basically a refreshed database snapshot. Don't let the number spook you.
A Detailed Breakdown
AlmaLinux
AlmaLinux shipped sixteen security errata over a single stretch. A good portion of them warrant an actual install rather than a lingering "maybe later," so here is what landed and who should actually move.
Most advisories carry an "Important" severity. Only two fall to "Moderate": glibc and ghostscript, both on AlmaLinux 8. The updates scatter across versions 8, 9, and 10, so the correct move partly depends on which release you actually run.
Firefox takes the longest list by a wide margin. The AL 9 advisory bundles 28 CVEs shared with Thunderbird, since the two products eat from the same codebase. The dominant flavor is use-after-free and privilege escalation, and a noticeable fraction of those escalate through the CanvasWebGL graphics stack. You likely patch your browser regardless, but this is a week where the bulletin is long enough to earn a skim.
FreeRDP is the other item that sits closer to the metal. The AL 10 fix alone covers 11 problems, including several remote code execution routes through heap overflows, and there is a separate 6-CVE pass for AL 8. If you connect to Windows machines from a Linux desktop, this bites harder than a browser bug.
Dovecot rounds out the mail-side trouble with an authentication bypass on top of a pile of denial-of-service states, plus a crash fix for a mailbox panic. The usual suspects fill the remainder: Node.js 22, python3.12, perl-DBI, vim (an RCE through a forged tags file), and kernel updates spread across all three OS versions.
The Sequoia cluster is the one you can most likely ignore. rust-rpm-sequoia (on both AL 9 and AL 10), sequoia-openpgp, and rust-sequoia-sqv all clear the same flaw, CVE-2026-42784, a key flag confusion that weakens signature verification. Unless you build RPMs signed through Sequoia, this is background noise, though the AL 10 rust-rpm-sequoia pass does add a little housekeeping, like clearer import error messages and a bindgen bump for LLVM 22.
| Package | AlmaLinux | Severity | Released | What's fixed |
|---|---|---|---|---|
| rust-rpm-sequoia (ALSA-2026:76733) | 9 | Important | Oct 6 | CVE-2026-42784, Sequoia key flag confusion |
| perl-DBI (ALSA-2026:76762) | 10 | Important | Oct 7 | CVE-2026-88815, DoS during numeric type casting |
| rust-sequoia-sqv (ALSA-2026:76735) | 10 | Important | Oct 7 | CVE-2026-42784, same Sequoia flag issue |
| freerdp (ALSA-2026:75570) | 10 | Important | Oct 6 | 11 CVEs including two RCEs, plus info disclosure and DoS |
| rust-rpm-sequoia (ALSA-2026:76734) | 10 | Important | Oct 6 | CVE-2026-42784, plus import errors, NotTrusted handling, bindgen/LLVM 22 |
| kernel (ALSA-2026:71233) | 10 | Important | Oct 6 | 13 CVEs (UAF, double-free, OOB reads), plus bug fixes |
| python3.12 (ALSA-2026:77028) | 8 | Important | Oct 7 | CVE-2026-19553 (SSL cert bypass), CVE-2026-19445 (UAF in SSLContext) |
| glibc (ALSA-2026:76777) | 8 | Moderate | Oct 7 | CVE-2026-6368, CVE-2026-6791, abort/DoS in wordexp and tilde expansion |
| ghostscript (ALSA-2026:76877) | 8 | Moderate | Oct 7 | CVE-2026-39919, heap overflow via JPEG 2000 output |
| freerdp (ALSA-2026:76747) | 8 | Important | Oct 7 | 6 CVEs including two RCEs and DoS |
| dovecot (ALSA-2026:76763) | 8 | Important | Oct 7 | 8 CVEs including OAuth2 auth bypass, plus a mailbox panic fix |
| nodejs:22 (ALSA-2026:75870) | 8 | Important | Oct 6 | CVE-2026-9496, CVE-2026-19534, both DoS |
| kernel (ALSA-2026:71213) | 8 | Important | Oct 6 | 7 CVEs, plus an sctp transport-count fix |
| kernel (ALSA-2026:71232) | 9 | Important | Oct 6 | 13 CVEs, plus nftables and memory-safety backports |
| vim (ALSA-2026:75768) | 9 | Important | Oct 7 | CVE-2026-73073, RCE via crafted tags file in omni-completion |
| firefox (ALSA-2026:69462) | 9 | Important | Oct 6 | 28 CVEs (Firefox/Thunderbird): UAF, privilege escalation, sandbox escape |
Debian GNU/Linux
Debian shipped two security advisories, and Python 3.11 grabbed most of the trouble this round.
The xz-utils advisory covers a single flaw in the LZMA1 decoder, where an invalid memory write could crash a process or let someone run code on their behalf. Debian patched it in the stable branch (trixie) at version 5.8.1-1+deb13u2. xz-utils carries some baggage these days, though: the library was the vehicle for a supply-chain backdoor that slipped into Debian's repos in early 2024, so a little wariness about anything wearing that name isn't unreasonable. This fix doesn't relate to that incident, and no CVE number has been assigned yet, which means the details stay thin until upstream fills them in.
The Python 3.11 advisory is where the surface area actually is. Thirteen CVEs landed across Debian 12's LTS line, fixed in 3.11.2-6+deb12u9. The spread covers the familiar categories: crashable parsers, credential leaks over plain HTTP, a cookie value that escapes its own script tag, and a bzip2 decompressor you could reuse in a way that writes past the end of a stack buffer. One of them lets hostname verification slip by silently, the sort of thing you'd rather not have happening while you think you're behind a secure connection. Beyond the CVEs, the build also folds in a few upstream fixes covering slow Sniffer detection, misbehaving regex possessive quantifiers, and tags parsed differently than HTML5 expects.
Upgrade whichever package you have installed and call it a day.
| Package | CVE | What broke | Impact | Fixed in |
|---|---|---|---|---|
| xz-utils | none assigned yet | invalid memory write in the LZMA1 decoder | DoS or arbitrary code execution | 5.8.1-1+deb13u2 (stable/trixie) |
| python3.11 | CVE-2025-69534 | html.parser raises AssertionError on malformed markup | DoS | 3.11.2-6+deb12u9 |
| python3.11 | CVE-2026-1502 | http.client doesn't reject CR/LF in proxy tunnel host or headers | HTTP header injection | 3.11.2-6+deb12u9 |
| python3.11 | CVE-2026-3276 | unicodedata.normalize() burns excessive CPU on crafted Unicode | DoS (CPU) | 3.11.2-6+deb12u9 |
| python3.11 | CVE-2026-6019 | cookies.Morsel.js_output() doesn't neutralize the </script> sequence | script/markup injection | 3.11.2-6+deb12u9 |
| python3.11 | CVE-2026-8328 | ftplib.ftpcp() still forwards the server-supplied PASV address | redirected data connection | 3.11.2-6+deb12u9 |
| python3.11 | CVE-2026-9669 | bz2 decompressor reusable after an error | out-of-bounds stack write | 3.11.2-6+deb12u9 |
| python3.11 | CVE-2026-15308 | incremental html.parser with long unterminated constructs | quadratic-time DoS | 3.11.2-6+deb12u9 |
| python3.11 | CVE-2026-15310 | zipfile pre-allocates memory with an attacker-controlled size | memory exhaustion | 3.11.2-6+deb12u9 |
| python3.11 | CVE-2026-15806 | urllib credential matcher ignores the URL scheme | credentials leaked in cleartext over HTTP | 3.11.2-6+deb12u9 |
| python3.11 | CVE-2026-17084 | stringprep uses the wrong Unicode version for IDNA tables | IDNA domain-name mismatches | 3.11.2-6+deb12u9 |
| python3.11 | CVE-2026-18503 | csv.Sniffer.sniff() runs super-linear regex on crafted samples | CPU exhaustion | 3.11.2-6+deb12u9 |
| python3.11 | CVE-2026-19445 | unauthenticated TLS client triggers a crash or freed-pointer call in sni_callback | DoS / pointer bug | 3.11.2-6+deb12u9 |
| python3.11 | CVE-2026-19553 | wrap_bio doesn't require server_hostname when check_hostname is on | hostname verification silently skipped | 3.11.2-6+deb12u9 |
| python3.11 | Upstream (gh-109638) | csv.Sniffer.sniff() still runs exponential time on quote-heavy samples | CPU exhaustion | 3.11.2-6+deb12u9 |
| python3.11 | Upstream (gh-100061, gh-106052) | regex possessive quantifiers match wrong when sub-pattern backtracks | incorrect matches | 3.11.2-6+deb12u9 |
| python3.11 | Upstream (gh-135661, gh-86155) | html.parser doesn't parse tags per HTML5, can lose data after unclosed tags | changed markup parsing | 3.11.2-6+deb12u9 |
Fedora Linux
Fedora has another pile of security patches to wade through, this one split between Fedora 43 and Fedora 44. Most of it is routine version bumps, but a handful are worth knowing before you run dnf upgrade.
The biggest is Chromium, which picked up 11 security fixes across the board. Both releases landed on the same build (154.0.8037.97), and the flaws span type confusions in V8, out-of-bounds writes in WebGL, and use-after-free bugs in MediaStream and FedCM. If you happen to browse with Chromium, this is the one to prioritize.
curl is close behind. The update closes a secure-cookie attribute bypass that a stray tab could exploit for information disclosure, along with two use-after-free issues, one in HTTP/2 server push and another tied to an OpenSSL provider. Two of those patched back to back, so curl has been getting its share of attention lately.
Then there's sos, which picked up a path-traversal hole in its tar cleaner. Unchecked symlinks and hardlinks could let a malicious archive write files outside its intended tree. docker-buildx gets two denial-of-service fixes aimed at a Go SSH library, and Lmod shows up in both Fedora releases to patch CVE-2026-85013.
The 7zip update, by contrast, is a masterclass in vagueness: "Some bugs and vulnerabilities were fixed." If you actually want to know what changed, head to the upstream changelog yourself.
The kernel is a standard 7.2.9 stable release, but note the retraction: Fedora pulled back an attempt to restrict the alg subsystem sysctl, and hmac(sha512) is now available again for unprivileged users.
| Package | Version | Release | Notable fixes |
|---|---|---|---|
| 7zip | 26.04-1.fc43 | Fedora 43 | Bug/vuln fixes, unspecified |
| chromium | 154.0.8037.97-1.fc43 | Fedora 43 | 11 security fixes (see changelog) |
| Lmod | 9.4.2-1.fc43 | Fedora 43 | CVE-2026-85013 |
| sos | 4.12.0-2.fc43 | Fedora 43 | CVE-2026-79655, path traversal in tar cleaner |
| 7zip | 26.04-1.fc44 | Fedora 44 | Bug/vuln fixes, unspecified |
| curl | 8.18.0-12.fc44 | Fedora 44 | CVE-2026-80255, CVE-2026-80229, CVE-2026-18924 |
| chromium | 154.0.8037.97-1.fc44 | Fedora 44 | 11 security fixes (see changelog) |
| kernel | 7.2.9-200.fc44 | Fedora 44 | Stable update; al_alg_restrict reversion |
| docker-buildx | 0.37.2-1.fc44 | Fedora 44 | CVE-2026-56855, CVE-2026-78662 (both DoS) |
| Lmod | 9.4.2-1.fc44 | Fedora 44 | CVE-2026-85013 |
Oracle Linux
Oracle Linux has published another round of security updates that spans three releases, from Linux 7 all the way to Linux 10. You get two kernel advisories, a Firefox ESR catch-up, and a handful of smaller packages patched for whatever flaw happened to warrant it.
The Firefox advisory is the one that looks scary if you glance at the CVE list. Oracle packed 43 vulnerabilities into a single ESR release, which is normal when Mozilla ships a feature-heavy ESR. In practice you are just catching up to stock Firefox ESR 140.17.0, plus a small Oracle tweak to its default prefs file for the newer NSS. You only need to act if you actually run this browser on these systems.
The two kernel updates carry the most CVEs and the most churn, but the substance stays in the usual driver and networking weeds: memory-safe fixes in the DRM stack, Ceph, and the net layer, on top of the regular queue of use-after-free and buffer overflow repairs. Oracle keeps its kernel lines split between the standard Unbreakable Linux kernel (the 6.12 build on OL10, the 4.18 build on OL8) and the Unbreakable Enterprise Kernel. If you run UEK, advisory 500375 is the one that applies. The OL7 and OL8 UEK entries list the same CVE set, which is just Oracle backporting the same fixes across two trees.
The smaller packages are more pointed. Dovecot picked up eight CVEs spanning a ManageSieve deadlock, a SQL escaping bug, and a heap use-after-free in pigeonhole. FreeRDP took six fixes, Ghostscript picked up one moderate-rated heap overflow around JPEG 2000 output, and GD plus librabbitmq each closed a single memory-safety hole. The two Rust sequoia packages on Linux 10 both chase the same OpenPGP flaw, CVE-2026-42784, which is enough to make you wonder why Oracle splits one fix across two packages.
The table below lays out every advisory, with package, release, severity, and the headline CVEs.
| Advisory | Package | Release | Severity | CVEs |
|---|---|---|---|---|
| ELSA-2026-76762 | perl-DBI | Linux 10 | Important | 1 (CVE-2026-88815) |
| ELSA-2026-76764 | firefox | Linux 10 | Important | 43 (CVE-2026-92035, CVE-2026-100832) |
| ELSA-2026-76735 | rust-sequoia-sqv | Linux 10 | Important | 1 (CVE-2026-42784) |
| ELSA-2026-71602 | kernel 6.12 | Linux 10 | Important | 22 (CVE-2026-89481, CVE-2026-68480) |
| ELSA-2026-76734 | rust-rpm-sequoia | Linux 10 | Important | 1 (CVE-2026-42784) |
| ELSA-2026-76763 | dovecot | Linux 8 | Important | 8 (CVE-2026-27852, CVE-2026-73208) |
| ELSA-2026-76877 | ghostscript | Linux 8 | Moderate | 1 (CVE-2026-39919) |
| ELSA-2026-76747 | freerdp | Linux 8 | Important | 6 (CVE-2026-91953, CVE-2026-91964) |
| ELSA-2026-72468 | kernel 4.18 | Linux 8 | Important | 13 (CVE-2026-68155, CVE-2026-74753) |
| ELSA-2026-75680 | gd | Linux 8 | Important | 1 (CVE-2026-9672) |
| ELSA-2026-75582 | librabbitmq | Linux 8 | Important | 1 (CVE-2026-44236) |
| ELSA-2026-500375 | kernel-uek | Linux 8 (aarch64) | Important | 13 (CVE-2026-23455, CVE-2026-81000) |
| ELSA-2026-500375 | kernel-uek | Linux 7 (x86_64) | Important | 13 (CVE-2026-23455, CVE-2026-81000) |
Qubes OS
Qubes OS released QSB 120, but before you go reconfiguring your entire workspace, note that this bulletin is narrow. It affects only Qubes 4.3 users who actually run the CTAP proxy, the feature that lets a USB security key be shared across qubes without exposing the full USB stack. If you have never wired a hardware key this way, this one is not yours.
The two flaws live in the qubes-ctap package, version 2.0.0 and newer (formerly called qubes-u2f). The first is a filtering gap: the proxy does not force CTAP requests to match their declared service types, so a qube granted just ctap.GetInfo can also sneak an authentication request out through one of its other allowed services. The second is more specific. When you lock a qube to particular credentials via service arguments, the u2f.Authenticate service still hands out multiple assertions as long as any single one matches the allowed argument. That bites CTAP2 only, not CTAP1.
| Bulletin | Date | Component | Fix | Affected | Who is affected | Vulnerabilities | Credits | User action |
|---|---|---|---|---|---|---|---|---|
| QSB 120 | 2026-10-08 | qubes-ctap 2.0.0+ (formerly qubes-u2f) | qubes-ctap 2.0.8 | Qubes 4.3 only | Anyone running the CTAP proxy with credential-restricted RPC policies | Vuln 1: proxy skips request-to-service-type matching (any version) / Vuln 2: u2f.Authenticate over-issues CTAP2 assertions (CTAP2 only) | Vuln 2: Giulio Berra (Freedom of the Press Foundation); Vuln 1: Piotr Bartman-Szwarc (internal) | Install 2.0.8 in the USB qube template once it reaches stable (~2 weeks), then restart each USB qube after shutdown |
Red Hat Enterprise Linux
Red Hat delivered another busy round of security errata, this time with a Firefox patch from Oracle slotted in alongside. Nearly everything carries an Important rating, meaning you probably should schedule the restart. The lone Moderate is a kernel update for RHEL 7's Extended Lifecycle Support, which mostly reminds you how many shops still run a release that's well into its twilight.
The real headline is JBoss Web Server 7.0.2, and it arrived twice: a normal package plus a separate zip build that also covers Windows Server, so you don't get skipped just because you're on Windows. The rest is the usual maintenance lineup, with RHEL 8 picking up the heaviest haul of the bunch.
| Advisory | Component | Severity | Affected platforms |
|---|---|---|---|
| RHSA-2026:76952 | JBoss Web Server 7.0.2 | Important | RHEL 8, 9, 10 |
| RHSA-2026:76956 | JBoss Web Server 7.0.2 (zip) | Important | RHEL 8, 9, 10, Windows Server |
| RHSA-2026:77359 | vim | Important | RHEL 8 |
| RHSA-2026:77500 | kernel-rt | Important | RHEL 8 |
| RHSA-2026:77610 | Firefox | Important | RHEL 10.0 EUS |
| RHSA-2026:77576 | perl-DBI | Important | RHEL 8 |
| RHSA-2026:77369 | mod_auth_openidc 2.3 | Important | RHEL 8 |
| RHSA-2026:76737 | rust-sequoia-sq | Important | RHEL 10 |
| ELSA-2026-76764 | Firefox 140.17.0 | Important | Oracle Linux 10 |
| RHSA-2026:77498 | kernel | Important | RHEL 8 |
| RHSA-2026:77627 | Thunderbird | Important | RHEL 9.4 US4S |
| RHSA-2026:77631 | Thunderbird | Important | RHEL 10.0 EUS |
| RHSA-2026:78844 | kernel | Moderate | RHEL 7 ELS |
Rocky Linux
Rocky Linux rolled out a fresh batch of errata this week, giving you ten updates to dig through if you run Rocky Linux 8 or 10. Nine of them arrive at "Important" severity, with a single glibc patch rounding things out at "Moderate."
Two patterns jump out. The Rust sequoia family takes most of the attention, with four packages patched, and two of those also bundle bug fixes and enhancements on top of the security work. Then there's perl-DBI showing up twice, which simply means the same fix rolled out across both major OS versions rather than anything more dramatic.
Every advisory carries a CVSS base score you can pull from the CVE list if you want the exact severity figures. None of this warrants a 3 a.m. reboot, but the sequoia and perl-DBI changes are the ones worth your attention since they land on stuff people actually run.
| Advisory ID | Package(s) | Severity | Platform | Scope |
|---|---|---|---|---|
| RSA-2026:76734 | rust-rpm-sequoia | Important | Rocky Linux 10 | Security + bug fixes + enhancements |
| RSA-2026:76735 | rust-sequoia-sqv | Important | Rocky Linux 10 | Security |
| RSA-2026:76737 | rust-sequoia-sq | Important | Rocky Linux 10 | Security + bug fixes + enhancements |
| RSA-2026:76743 | opentelemetry-collector | Important | Rocky Linux 10 | Security |
| RSA-2026:76762 | perl-DBI | Important | Rocky Linux 10 | Security |
| RSA-2026:76777 | glibc | Moderate | Rocky Linux 8 | Security |
| RSA-2026:77028 | python3.12 | Important | Rocky Linux 8 | Security |
| RSA-2026:77369 | cjose, mod_auth_openidc | Important | Rocky Linux 8 | Security |
| RSA-2026:77576 | perl-DBI | Important | Rocky Linux 8 | Security |
| RSA-2026:77369 | vim | Important | Rocky Linux 8 | Security |
Slackware Linux
Slackware pushed a security rebuild of xorg-server for both Slackware 15.0 and -current, and this batch carries more CVEs than most. The update plugs nine memory bugs in the X server, mostly the fun variety: double frees, use-after-frees, heap overflows, and out-of-bounds reads and writes. Local exploits are the shape of these. A client already talking to your X session has to be doing something mischievous to trigger them, so there's no clean remote route for a stranger to reach in over the network. That trims the panic reasonably. It also means you still shouldn't let random programs paint on your display, and now you have nine concrete reasons to keep that rule.
The rebuild covers five binaries: the server itself, plus the Xephyr, Xnest, and Xvfb variants, and then xwayland. xwayland runs on its own version track, so while xorg-server climbed to 21.1.25, xwayland jumped to 24.1.14. Every package ships in both 32- and 64-bit builds for each branch, so a box still on 15.0 is covered too.
Apply the upgrade as root with upgradepkg xorg-server-*.txz. Nothing exotic, but with nine holes being patched, this is one you might want to get on with before the reminder stops arriving.
| Package | Slackware 15.0 | Slackware -current |
|---|---|---|
| xorg-server | 1.20.14 | 21.1.25 |
| xorg-server-xephyr | 1.20.14 | 21.1.25 |
| xorg-server-xnest | 1.20.14 | 21.1.25 |
| xorg-server-xvfb | 1.20.14 | 21.1.25 |
| xorg-server-xwayland | 21.1.4 | 24.1.14 |
SUSE Linux
SUSE pushed a large batch of security updates in the same window, and if you only act on one thing, make it Chromium. There are actually two separate browser releases here, which normally doesn't happen at once, but the split is practical: the openSUSE Leap 16.0 build closes 11 holes and the Tumbleweed build is far messier at 32. A high CVE count usually just means you're counting every medium-severity quirk the Chromium team reported, but a browser patch is one of the few things you genuinely want to install.
A couple of other items deserve your attention. The python-fsspec update is the one worth pausing over, since it plugs an RCE through server-side template injection in ReferenceFileSystem. That is a code-execution headline, not a slow-request footnote. wpa_supplicant got a local security bypass fixed, something that lets a user on the machine slip past validation in PMKSA selection. The Prometheus side got hit too, with both alertmanager and blackbox_exporter taking fixes for validation bypass and privilege escalation tied to golang.org/x/net, alongside a couple of memory issues.
One thing to notice across the Tumbleweed batch: CVE-2026-63209 rides along through five unrelated packages, including google-osconfig-agent, aliyun-cli, cadvisor, crane, and distribution-registry. That usually means a shared dependency, even if the announcement doesn't spell it out. The govulncheck-vulndb entry looks alarming with its list of roughly 54 GO/GHSA identifiers, but it is rated moderate and is basically a refreshed vulnerability database snapshot. The two libsoup advisories cover the same six vulnerabilities for different lifecycles, so 4557 is the one for the older 15 SP4/SP5 track and 4558 is for SP6/SP7. Everything installs the usual way, zypper patch or YaST online_update.
| Announcement ID | Package(s) | Affected product(s) | Severity | Vulnerabilities / key CVEs |
|---|---|---|---|---|
| openSUSE-SU-2026:22027-1 | golang-github-prometheus-alertmanager | Leap 16.0 | Important | 2. CVE-2026-39821 (7.4), CVE-2026-2303 (5.4). Updates to 0.33.1 |
| openSUSE-SU-2026:22023-1 | chromium | Leap 16.0 | Important | 11. CVE-2026-103621 through 103631. Chromium 154.0.8037.97 |
| openSUSE-SU-2026:22022-1 | wpa_supplicant | Leap 16.0 | Important | 1. CVE-2026-78807 (8.4). Local PMKSA selection bypass |
| openSUSE-SU-2026:22020-1 | govulncheck-vulndb | Leap 16.0 | Moderate | ~54 GO/GHSA entries. Database snapshot refresh to 0.0.20261001 |
| openSUSE-SU-2026:22028-1 | python-fsspec | Leap 16.0 | Important | 1. CVE-2026-104851. RCE via SSTI in ReferenceFileSystem |
| openSUSE-SU-2026:22026-1 | prometheus-blackbox_exporter | Leap 16.0 | Important | 4. CVE-2026-84304 (8.7), CVE-2026-39821 (9.1), CVE-2025-22870, CVE-2023-45288. Updates to 0.26.0 |
| openSUSE-SU-2026:11961-1 | google-osconfig-agent | Tumbleweed | Moderate | 1. CVE-2026-63209 (8.7). GA media |
| openSUSE-SU-2026:11954-1 | busybox | Tumbleweed | Moderate | 7. CVE-2026-88830 through 88841. GA media |
| openSUSE-SU-2026:11956-1 | chromedriver, chromium | Tumbleweed | Moderate | 32. CVE-2026-102299 through 102331. GA media |
| openSUSE-SU-2026:11953-1 | aliyun-cli | Tumbleweed | Moderate | 1. CVE-2026-63209 (8.7). GA media |
| openSUSE-SU-2026:11958-1 | fio | Tumbleweed | Moderate | 1. CVE-2026-30656 (6.7). GA media |
| openSUSE-SU-2026:11959-1 | ghostscript | Tumbleweed | Moderate | 1. CVE-2026-39919 (8.5). GA media |
| openSUSE-SU-2026:11955-1 | cadvisor | Tumbleweed | Moderate | 1. CVE-2026-63209 (8.7). GA media |
| openSUSE-SU-2026:11960-1 | crane | Tumbleweed | Moderate | 1. CVE-2026-63209 (8.7). GA media |
| openSUSE-SU-2026:11952-1 | zcode | Tumbleweed | Moderate | 1. CVE-2026-45736 (4.4). GA media |
| openSUSE-SU-2026:11957-1 | distribution-registry | Tumbleweed | Moderate | 1. CVE-2026-63209 (8.7). GA media |
| SUSE-SU-2026:4558-1 | libsoup | SLE 15 SP6/SP7, Leap 15.6 | Important | 6. CVE-2026-12478, 12547, 15711, 15712, 15714, 66339 |
| SUSE-SU-2026:4557-1 | libsoup | SLE 15 SP4/SP5, Leap 15.4 | Important | 6. Same CVEs as 4558, older lifecycle packages |
Ubuntu Linux
Ubuntu released five security notices this week, spanning everything from a mild nudge to a kernel-scale pile-on. Apply them before you start poking at files you don't trust.
The kernel notice (LSN-0122-1) is the heavyweight. One hundred and fifty CVEs fit into a single livepatch, which is a lot of fixes to stuff into one release. The range runs from a use-after-free in the DLM filesystem to a NULL pointer dereference in the Broadcom brcfmac wifi driver, and there is a logic flaw in the XFRM ESP-in-TCP subsystem that developers nicknamed Fragnesia. That one lets a local attacker escalate privileges or escape a container. The thing that keeps this one from wrecking your weekend is that it ships as a livepatch, so you get the fixes without a reboot. Most of the CVEs trace back to 2025 and 2026, with a 2023 and a 2024 sneaking in up front.
Poppler (USN-8894-1) is the standard PDF headache. The rendering library took integer overflows here, a null pointer dereference there, and an oversized read, and bolted them together. Four of the five let code run as you, with one CVE-2026-93312 limited to crashing you.
The sudo fix (USN-8895-1) is the one worth pausing over. Sudo mishandled time-based access rules whenever NOTBEFORE or NOTAFTER timestamps dropped the timezone indicator. A local attacker could tweak the TZ environment variable and run commands outside the window you thought was locked. If you've ever relied on sudo time limits, this is exactly the thing that quietly undoes them.
Then there is Go networking (USN-8900-1), aimed at anyone still running golang-golang-x-net on 22.04. The fixes cover HTTP/2 connection hangs, quadratic HPACK and HTML parsing, an HTML parser that forgot to escape text, and a domain-name check that let Punycode slip past. Several are remote denials of service, and two set you up for cross-site scripting.
| Notice | Package(s) | Affected releases | CVEs | Fix version(s) |
|---|---|---|---|---|
| USN-8891-1 (librsvg) | librsvg2-2 | 26.04 LTS, 24.04 LTS | 1 (CVE-2026-96889) | 2.61.3+dfsg-3ubuntu0.1 (26.04); 2.58.0+dfsg-1ubuntu0.1 (24.04) |
| LSN-0122-1 (kernel) | linux, linux-aws/azure/gcp/gke/ibm/oracle | 20.04, 18.04, 24.04, 16.04, 22.04 LTS | 150 | Livepatch 122.1, 122.2, or 122.4 (varies by kernel) |
| USN-8894-1 (poppler) | libpoppler156 / 134 / 118 | 26.04, 24.04, 22.04 LTS | 5 | 26.01.0-2ubuntu0.2 (26.04); 24.02.0-1ubuntu9.10 (24.04); 22.02.0-2ubuntu0.14 (22.04) |
| USN-8895-1 (sudo) | sudo, sudo-ldap | 26.04, 24.04, 22.04 LTS | 1 (CVE-2026-96512) | 1.9.17p2-1ubuntu3.2 (26.04); 1.9.15p5-3ubuntu5.24.04.4 (24.04); 1.9.9-1ubuntu2.7 (22.04) |
| USN-8900-1 (Go net) | golang-golang-x-net-dev | 22.04 LTS | 8 | 1:0.0+git20211209.491a49a+dfsg-1ubuntu0.1 |
How to apply these Linux security updates
Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.
Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.
Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.
Debian/Ubuntu (apt)
The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.
sudo apt update sudo apt upgrade -y
Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)
On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.
sudo dnf check-update sudo dnf upgrade -y
or on older releases
sudo yum check-update sudo yum update
SUSE (zypper)
SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.
sudo zypper refresh sudo zypper update -y
Slackware (slackpkg and pkgtool)
Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.
sudo slackpkg update sudo slackpkg upgrade-all
