Ubuntu shipped 101 CVEs in a single kernel update for its Google Container Engine image on 26.04 LTS, hitting 38 subsystems and pointing more to a cleared backlog than a fresh emergency. Red Hat and Rocky Linux both tagged freerdp Critical for version 10, making it the top fix for anyone running remote desktop protocols. Debian leads with a sprawling 62-CVE Firefox ESR patch alongside a redis advisory and a "fix for the fix" for webkit2gtk, while Fedora, SUSE, and the rest close out the day with notable items including Fedora's WordPress RCE and SUSE's high-rated python-anyio flaw. Patch the Critical and high-severity fixes first, then work through the Important and Moderate updates at your next maintenance window.
Ubuntu ships 101 CVEs in a single kernel, Red Hat and Rocky both tag freerdp Critical
Red Hat and Rocky Linux both mark freerdp Critical today. Ubuntu delivers a 101-CVE GKE kernel patch. Debian's Firefox ESR update is a 62-CVE affair.
The daily Linux security digest normally has a couple of items worth your time, but today it lands a monster. Ubuntu pushed 101 CVEs through a single kernel update for its Google Container Engine image, and Red Hat flagged a Critical freerdp fix that Rocky Linux picked up at the exact same severity. Patch those first. Read the rest afterward.
The ones to patch today
USN-8816-4 is the headline act, and the number is the story. It lands 101 CVEs on the GKE kernel for Ubuntu 26.04 LTS, hitting 38 subsystems across most of your driver and networking stack. InfiniBand, NVME, SMB, the whole IPv6 apparatus. Most of those CVEs already lived upstream, so this reads less like an emergency and more like Ubuntu clearing a backlog. Not a bad thing, and it doesn't deserve the panic the digit invites.
The rest of the batch is quieter, meaning the same three flaws show up in three different places. USN-8851-2 (Raspberry Pi, 18.04) and USN-8864-1 (16.04 and 14.04 mainline) patch the NFS server daemon, IPv6, and Netfilter together under CVE-2025-38724, 53131, and 53221. That last one resurfaces in the FIPS notice, USN-8818-6 (22.04), which layers about a dozen more on top.
The single bug that earns your attention is CVE-2025-10263. Certain ARM chips can finish a broadcast TLB invalidation before memory writes through the mapping are globally seen, letting a local attacker write to memory after permission was revoked. Small window, privilege escalation on the other side.
Keep in mind that every notice closes the same way: update, reboot, and recompile any third-party kernel modules because of an unavoidable ABI change. The metapackages usually do it for you, but not always. Several of these also sit behind Ubuntu Pro, so if that checkbox is still unchecked on a box, sort it before anything else.
Red Hat's RHSA-2026:73979 rates freerdp Critical for RHEL 10, and the identical-looking RSA-2026:73979 does the same for Rocky Linux 10. If remote desktop protocols touch anything near production, this goes on before the rest.
The remainder of Red Hat's batch is a calendar entry. Two land at Important: ruby (RHEL 10) and a paired kpatch set for the 6.12.0-211 kernel, plus a kernel update NVIDIA-tagged for RHEL 10. On RHEL 8, gawk gets a Moderate, and ghostscript is Moderate for RHEL 9. Head to the Satellite advisory before trusting its rating, since the 6.17.12 title says Critical while the body says Important.
Debian's batch runs from database servers to web browsers, and two packages break from the crowd. Firefox ESR is where the numbers get absurd. Debian's LTS team and Freexian's extended program each pushed the same pile of patches, jumping from 140.x up to 153.x with 62 CVEs attached. The worst outcomes are arbitrary code execution, sandbox escape, and privilege escalation, which is exactly why you want it applied promptly. Debian 12 bookworm ships 153.4.0esr-1deb12u1, and the Freexian track for Debian 11 bullseye arrives as 153.4.0esr-1deb11u1.
redis is the other one that could bite. DSA 6538-1 bundles four CVEs plus a grab bag of non-CVE bugs: ACL checks skippable across SORT, GEORADIUS, and XREAD, an out-of-bounds read, a use-after-free, and an integer overflow in HyperLogLog. It ships for trixie stable at 5:8.0.2-3+deb13u3.
There's a touch of dark comedy in the webkit2gtk advisory. The prior fix (DSA-6534-1) introduced regressions that crashed Evolution and Eclipse on startup. The follow-up (DSA-6534-2) fixes the fix. Not the smoothest cycle they've had, but they caught it before it fully set.
Fedora, SUSE, and the lighter end
Fedora's advisories hit both 43 and 44, and hplip is the one to chase if you run any HP hardware. It carries eight CVEs spanning remote and local code execution plus privilege escalation. WordPress lands at 6.9.9, capped by an unauthenticated path traversal in page-template resolution that becomes conditional RCE (CVE-2026-87902). Blog operators should treat that as urgent.
unbound collects the most CVEs here, nine of them, from heap overflows while digesting DNSKEY records through to DNSSEC bypasses. Xen picks up four XSA fixes, and the openssl rebase to 3.5.9 will rebuild whatever links against it. firefox 157.0 and openvpn 2.6.23 arrive as clean upstream bumps with nothing attached, so you can glance past those.
SUSE delivered eight announcements, and three of them are the same OpenSSL fixes. You'll probably run zypper patch three times for basically the same six CVEs across different service packs. The worst is CVE-2026-84782, a DTLS issue where retransmitted handshake messages come from a stale buffer offset. NVD scores it 8.2, SUSE lists 8.3 under CVSS 4.0 and 7.4 under 3.1, so pick a scoreboard and expect the numbers to wander.
The one SUSE thing worth actually worrying about is python-anyio. CVE-2026-63374 lets a bad hostname slip past TLS certificate checks, and NVD rates it 9.3 against SUSE's own 7.6. It reaches most SLE service packs plus the Python 3 and Public Cloud modules, so patch that before the OpenSSL pileup.
AlmaLinux kept it short with three errata landing the same afternoon. libpcap is the only one worth a wince, an Important out-of-bounds read and write on AlmaLinux 9. ghostscript fixes a JPEG 2000 heap overflow for 10, and OpenSSH plugs a hole where weak authentication delays made brute-forcing a little easier.
Rocky Linux rounds out the day, and its only real alarm is the Critical freerdp for version 10, the same as Red Hat. libpcap and ghostscript each appear twice across versions, so you might apply two advisories if you run more than one release.
A Detailed Breakdown of the Updates
AlmaLinux
AlmaLinux shipped three security errata, all landing the same afternoon on packages almost everyone runs. None of these are the kind that makes you drop your coffee, but they're exactly the sort you patch quietly and move on with.
Ghostscript (AlmaLinux 10, Moderate) fixes a heap buffer overflow in the JPEG 2000 output adapter. If you render untrusted PDFs or PostScript regularly, that's the one to pay attention to. libpcap (AlmaLinux 9, Important) closes an out-of-bounds read and write that opens room for arbitrary memory access. That's the only entry here that should make you wince, since packet-sniffing tools tend to sit in some uncomfortable places. OpenSSH (AlmaLinux 9, Moderate) plugs a hole where brute-force attacks got easier because the authentication delay wasn't stiff enough. SSH is often the actual door people use to get onto a box, so this one carries more weight than its Moderate rating lets on.
| Package | Errata ID | AlmaLinux Version | Severity | CVE | Vulnerability |
|---|---|---|---|---|---|
| Ghostscript | ALSA-2026:74464 | 10 | Moderate | CVE-2026-39919 | Heap buffer overflow via JPEG 2000 output adapter |
| libpcap | ALSA-2026:74441 | 9 | Important | CVE-2026-0799 | Out-of-bounds read and write allowing arbitrary memory access |
| OpenSSH | ALSA-2026:73955 | 9 | Moderate | CVE-2026-60001 | Insufficient authentication delay enabling brute-force attacks |
Debian GNU/Linux
Debian issued another round of security patches, and this batch reaches from database servers to web browsers. Most of the packages here only matter to the people who actually run them, but two stand out.
The redis advisory is the one most likely to hurt someone. It bundles four CVEs plus a grab bag of un-CVE'd bugs: ACL permission checks that could be skipped across SORT, GEORADIUS, XREAD and related commands, an out-of-bounds read, a use-after-free, and an integer overflow in the HyperLogLog function. It also wraps up an incomplete fix for one of the earlier CVEs that never got its own standalone release in Debian stable. This ships for the trixie stable release at version 5:8.0.2-3+deb13u3.
Firefox ESR is where the numbers get absurd. Debian's long-term support team and Freexian's extended LTS program each shipped the same pile of patches, covering a jump from 140.x up to 153.x, and the CVE list runs to 62 entries. The worst-case outcomes are arbitrary code execution, sandbox escape and privilege escalation, which is exactly why you want to apply it promptly. Debian 12 bookworm gets 153.4.0esr-1deb12u1, and the Freexian track for Debian 11 bullseye arrives as 153.4.0esr-1deb11u1.
There's also a little dark comedy in the webkit2gtk advisory. The previous security fix (DSA-6534-1) introduced regressions that made Evolution and Eclipse crash on startup. The follow-up (DSA-6534-2) is the fix for the fix. Not the smoothest release cycle, but at least they caught it before it fully settled in.
A smaller set of packages closes out the day: radsecproxy has an incomplete packet-validation hole, php-mongodb deals with object injection and information disclosure, and open-iscsi (an LTS advisory) patches buffer overflows and integer underflows across its iSCSI stack.
| Package | Advisory | CVEs | What's broken | Fixed version | Debian release |
|---|---|---|---|---|---|
| redis | DSA 6538-1 | CVE-2026-23479, 23631, 25243, 81934 (+6 non-CVE issues incl. CVE-2026-66373) | DoS, arbitrary code, ACL bypasses, OOB reads, use-after-free, HyperLogLog overflow | 5:8.0.2-3+deb13u3 | trixie (stable) |
| firefox-esr | DLA 4814-1 | 62 CVEs (96869, 100756 through 100832) | Arbitrary code, sandbox escape, info disclosure, privilege escalation | 153.4.0esr-1~deb12u1 | bookworm (Debian 12) |
| open-iscsi | DLA 4813-1 | CVE-2026-18724 through 18728, 44943, 44944 | Stack buffer overflow, OOB access, ICMPv6/IPv6 parsing holes, DHCP underflows, control-socket abuse | 2.1.8-1+deb12u1 | bookworm (Debian 12) |
| firefox-esr | ELA 1841-1 (Freexian) | Same 62 CVEs as above | Same as Firefox advisory | 153.4.0esr-1~deb11u1 | bullseye (Debian 11) |
| radsecproxy | DSA 6540-1 | CVE-2026-104201 | DoS, arbitrary code from invalid MS-PPPE packets | 1.11.2-1+deb13u1 | trixie (stable) |
| php-mongodb | DSA 6539-1 | CVE-2026-6811, 84968, 96745 | Info disclosure, object injection, DoS | 2.0.0-1+deb13u1 | trixie (stable) |
| webkit2gtk | DSA 6534-2 | None (regression) | DoS/crashes in Evolution and Eclipse after prior update | 2.54.0-1~deb13u2 | trixie (stable) |
Fedora Linux
Fedora rolled out a batch of security advisories, and if you're on Fedora 43 or 44 a solid chunk of what runs on this box likely needs updating. Most of these are the patch-you-run-without-reading-the-changelog kind, since they close holes remote attackers would happily walk through. A few are plain upstream version bumps, but most carry real CVEs.
The ones worth your actual attention: hplip ships eight fixes for vulnerabilities spanning remote and local code execution, privilege escalation, and denial of service. Run any HP hardware on this machine and that's the one to chase. WordPress arrives at 6.9.9 with a long laundry list of fixes, capped by an unauthenticated path traversal in page-template resolution that turns into conditional RCE (CVE-2026-87902). Blog operators should treat this as urgent.
unbound collects the most CVEs of anything here, nine of them, from heap overflows while digesting DNSKEY records through to DNSSEC verification bypasses. If you run a resolver, that's a big pile. Xen took on four XSA fixes covering a memory leak tied to IRQ binding, stale TLB entries letting PV guests reach scrubbed memory, and unbounded watch accumulation in oxenstored. The openvpn jump to 2.6.23 and the firefox bump to 157.0 come through as clean upstream updates with no CVEs attached, so you can glance at those.
The rest are lesser-known packages. fetchmail closes a stack buffer overflow in NTLM handling. buildstream picks up a tarball symlink-escape hole, and the advisory is honest about it: Fedora's system Python is new enough that the packaged binary was already safe, so this mostly shields people running older parallel Python installs. libX11 gets a heap overflow fix aimed at a malicious X server, while the weasyprint, python-cssselect2, and python-httpx2 trio rounds out the Fedora 44 side with SSRF and request-smuggling flaws. The openssl rebase to 3.5.9 is its own beast, folding in a long list of CVEs, and expect it to rebuild whatever links against it.
| Package | Fedora | Version | Fixes |
|---|---|---|---|
| firefox | 43 | 157.0 | Upstream bump, no CVEs listed |
| docker-distribution | 43 | 3.1.2 | CVE-2026-41178 (DoS via oversized baggage headers), CVE-2026-85747 |
| erlang | 43 | 26.2.5.21-8 | Backported fixes for CVE-2026-65634, CVE-2026-68956, CVE-2026-89422 |
| cockpit-machines | 43 | 357 | Local info/sensitive-data exposure: CVE-2026-92768, CVE-2026-92747, CVE-2026-92745 |
| openvpn | 43 | 2.6.23 | Upstream bump, no CVEs listed |
| cockpit-files | 43 | 45 | Symlink-race file-ownership holes: CVE-2026-91202, CVE-2026-91203, CVE-2026-91205 |
| hplip | 43 | 3.26.6 | Eight CVEs (91097 through 91105), RCE and privilege escalation |
| fetchmail | 43 | 6.6.8 | Stack buffer overflow in NTLM (CVE-2026-94184) |
| wordpress | 43 | 6.9.9 | 6.9.9 + 6.9.8 security releases, incl. path traversal to conditional RCE (CVE-2026-87902) |
| buildstream | 43 | 2.8.1 | Tarball symlink escape (CVE-2026-82331); mostly covers older parallel Python |
| xen | 43 | 4.20.4-2 | Four XSA fixes (509-512): memory leak, TLB scrubbing, watch accumulation |
| unbound | 43 | 1.26.1 | Nine CVEs incl. heap overflows during DNSKEY parsing and DNSSEC bypasses |
| firefox | 44 | 157.0 | Upstream bump, no CVEs listed |
| libX11 | 44 | 1.8.13-3 | Heap overflow via malicious X server (CVE-2026-88806) |
| openssl | 44 | 3.5.9 | Rebase to 3.5.9, folds in CVEs 35189, 35191, 42772, 54872-54875, 72897, 75804-75806, 77696, 84782-84784 |
| docker-distribution | 44 | 3.1.2 | Same as Fedora 43 |
| erlang | 44 | 26.2.5.21-8 | Same as Fedora 43 |
| cockpit-machines | 44 | 357 | Same as Fedora 43 |
| cockpit-files | 44 | 45 | Same as Fedora 43 |
| hplip | 44 | 3.26.6 | Same as Fedora 43 |
| fetchmail | 44 | 6.6.8 | Same as Fedora 43 |
| wordpress | 44 | 6.9.9 | Same as Fedora 43 |
| buildstream | 44 | 2.8.1 | Same as Fedora 43 |
| weasyprint | 44 | 70.0 | SSRF fix (CVE-2026-55073), shipped alongside python-cssselect2 |
| python-cssselect2 | 44 | 0.10.1 | Same advisory as weasyprint (CVE-2026-55073) |
| python-httpx2 | 44 | 2.13.1 | Three CVEs (84378-84380): request smuggling, DoS, header injection |
| xen | 44 | 4.21.2-2 | Same XSA fixes as Fedora 43 (4.21 is the F44 line) |
Red Hat Enterprise Linux
Red Hat rolled out another batch of security updates for RHEL customers, and one of them deserves your attention before anything else. RHSA-2026:73979 hits freerdp at a Critical rating for RHEL 10. If you run remote desktop protocols anywhere near production, that's the one to apply first.
The remaining six are quieter but still belong on your patch calendar. Two land at Important: ruby (RHEL 10) and a paired set of kpatch patches for the 6.12.0-211 kernel (RHEL 10). There's also a kernel update tagged NVIDIA for RHEL 10, sharing the Important bucket. If you're still on RHEL 8, gawk gets a Moderate rating, and ghostscript picks up a Moderate bump for RHEL 9.
Satellite 6.17.12 for RHEL 9 is worth a second look on its own. The advisory is titled Critical, but the body rates it Important. Read it yourself before assuming the worst.
You don't have to chase all seven at once. Focus on the Critical and Important ones, and the rest can wait for your next scheduled maintenance window.
| Errata ID | Package / Component | Severity | Target |
|---|---|---|---|
| RHSA-2026:73979 | freerdp | Critical | RHEL 10 |
| RHSA-2026:74505 | Satellite 6.17.12 Async Update | Critical (body says Important) | RHEL 9 |
| RHSA-2026:72785 | ruby | Important | RHEL 10 |
| RHSA-2026:72831 | kpatch-patch-6_12_0-211_16_1 & kpatch-patch-6_12_0-211_49_1 | Important | RHEL 10 |
| RHSA-2026:74974 | kernel (NVIDIA) | Important | RHEL 10 |
| RHSA-2026:73511 | gawk | Moderate | RHEL 8 |
| RHSA-2026:74457 | ghostscript | Moderate | RHEL 9 |
Rocky Linux
Rocky Linux has pushed a fresh batch of errata, and if your machines run anything from version 8 up through 10, at least one advisory is going to touch your box. The only one worth losing sleep over is the Critical rating on freerdp for Rocky Linux 10. A few packages show up twice: libpcap and ghostscript each earned separate advisories split across OS versions, so you might actually be applying two of them if you run more than one release. The rest are a routine mix of Important and Moderate fixes, a couple of which bundle plain bug fixes alongside the security holes.
| Advisory ID | Package | Severity | Affected OS | Scope |
|---|---|---|---|---|
| RLSA-2026:73979 | freerdp | Critical | Rocky Linux 10 | Security |
| RLSA-2026:74442 | libpcap | Important | Rocky Linux 10 | Security |
| RLSA-2026:74464 | ghostscript | Moderate | Rocky Linux 10 | Security |
| RLSA-2026:72785 | ruby | Important | Rocky Linux 10 | Security |
| RLSA-2026:74370 | gvfs | Important | Rocky Linux 9 | Security |
| RLSA-2026:74441 | libpcap | Important | Rocky Linux 9 | Security |
| RLSA-2026:74438 | kernel | Moderate | Rocky Linux 9 | Security, bug fix, enhancement |
| RLSA-2026:74424 | libvirt | Important | Rocky Linux 9 | Security, bug fix, enhancement |
| RLSA-2026:74457 | ghostscript | Moderate | Rocky Linux 9 | Security |
| RLSA-2026:73511 | gawk | Moderate | Rocky Linux 8 | Security |
SUSE Linux
SUSE shipped eight security announcements, and three of them are the same OpenSSL fixes. If you run SUSE servers, you will probably run zypper patch three times for what is basically the same six CVEs, just spread across different service packs. Not the most economical use of a patch window, but the fix is the fix either way.
The OpenSSL bugs are worth a glance. The worst of the six is CVE-2026-84782, a DTLS issue where retransmitted handshake messages come from a stale buffer offset. NVD scores it 8.2. SUSE lists 8.3 under CVSS 4.0 and 7.4 under CVSS 3.1, so pick a scoreboard and expect the numbers to shift depending on which one you trust.
The other five are routine cryptography housekeeping. There is a memory-hog in CRLDP processing, two timing side-channels (one on non-NIST EC curves, one on SM2 signatures), a null-pointer crash in CMP revocation responses, and an undersized DTLS record that lets someone pin your server in a denial of service. None will make headlines, but they stack up.
The Tumbleweed updates are your standard moderate bumps. VLC picks up one CVE, django-allauth picks up one, and binaryen, the WebAssembly compiler, takes three. The moderate stamp usually means low severity and a local trigger, so you probably won't lose much sleep.
The one to actually worry about is python-anyio. It bundles two CVEs and reaches pretty much every SLE service pack from SP4 to SP7, plus the Python 3 and Public Cloud modules. CVE-2026-63374 lets a bad host name slip past TLS certificate checks, and NVD rated it 9.3 against SUSE's own 7.6. If you have anyio on anything Python, patch that first.
| Announcement ID | Package | Rating | CVE count | Key CVEs | Where it lands |
|---|---|---|---|---|---|
| SUSE-SU-2026:4412-1 | openssl-3 (3.0.8) | important | 6 | CVE-2026-84782 (8.2) | Leap 15.5, SLE HPC/Server/SAP 15 SP5 |
| SUSE-SU-2026:4413-1 | openssl-3 (3.0.8) | important | 6 | CVE-2026-84782 (8.2) | Leap 15.4, SLE HPC/Micro/Server/SAP 15 SP4 |
| SUSE-SU-2026:4416-1 | python-anyio | important | 2 | CVE-2026-63374 (9.3) | SLE SP4-SP7, Python3 & Public Cloud modules |
| SUSE-SU-2026:4418-1 | openssl-3-livepatches | important | 1 | CVE-2026-84782 (8.2) | Leap 15.6, SLE Live Patching/Real Time/Server/SAP 15 SP6 |
| SUSE-SU-2026:4419-1 | openssl-3 (3.1.4) | important | 6 | CVE-2026-84782 (8.2) | Leap 15.6, SLE Server/SAP 15 SP6 |
| openSUSE-SU-2026:11910-1 | libvlc5 | moderate | 1 | CVE-2026-56711 | Tumbleweed |
| openSUSE-SU-2026:11903-1 | python313-django-allauth | moderate | 1 | CVE-2026-97764 | Tumbleweed |
| openSUSE-SU-2026:11915-1 | binaryen | moderate | 3 | CVE-2025-14956/14957 & CVE-2026-8257 | Tumbleweed |
Ubuntu Linux
Ubuntu rolled out a pile of kernel security updates, and the headline act is an alarming batch of fixes for the Google Container Engine kernel. Most of the volume comes from USN-8816-4, which ships 101 CVEs to the GKE kernel on Ubuntu 26.04 LTS. That number usually means back-to-back maintenance windows, and the affected subsystems are about as broad as it gets: some 38 of them, spanning nearly every major driver and networking stack, from InfiniBand and NVME to SMB and the IPv6 machinery. Most of those CVEs landed upstream, so this reads more like Ubuntu catching up on a backlog than responding to a fresh emergency.
The rest of the batch is far quieter. USN-8851-2 (Raspberry Pi, Ubuntu 18.04 LTS) and USN-8864-1 (mainline kernel, Ubuntu 16.04 and 14.04 LTS) patch the identical trio of flaws across the NFS server daemon, IPv6, and Netfilter, filed under CVE-2025-38724, CVE-2026-53131, and CVE-2026-53221. You'll spot CVE-2026-53221 again in the FIPS notice, USN-8818-6 (Ubuntu 22.04 LTS), which also bundles about a dozen more.
The FIPS notice has the one bug worth your attention: CVE-2025-10263. Certain ARM processors can finish a broadcast TLB invalidation before memory writes through the invalidated mapping are globally observed, so a local attacker might write to memory after permission was revoked, slipping past memory protections to bump privileges.
Every notice runs the same choreography. After a standard update you reboot, and because of an unavoidable ABI change you must recompile and reinstall any third-party kernel modules, unless the standard metapackages take care of that. Several packages also sit behind Ubuntu Pro, so if that box is unchecked on your end you may want to fix it.
| USN | Affected release(s) | Kernel | CVEs | Key subsystems | |
|---|---|---|---|---|---|
| USN-8851-2 | Ubuntu 18.04 LTS | linux-raspi-5.4 | 3 (CVE-2025-38724, CVE-2026-53131, CVE-2026-53221) | NFS server daemon, IPv6, Netfilter | linux-image-5.4.0-1147-raspi 5.4.0-1147.160~18.04.1 |
| USN-8864-1 | Ubuntu 16.04 LTS, Ubuntu 14.04 LTS | linux, linux-aws, linux-fips, linux-kvm, linux-lts-xenial | 3 (same CVEs as above) | NFS server daemon, IPv6, Netfilter | e.g. linux-image-4.4.0-288-generic 4.4.0-288.322 |
| USN-8816-4 | Ubuntu 26.04 LTS | linux-gke | 101 | 38 subsystems (ARM64/S390/x86, DRBD, InfiniBand, IOMMU, MANA, NVME, TCM, Virtio, Xen, all major filesystems and networking stacks) | linux-image-7.0.0-1007-gke 7.0.0-1007.8 |
| USN-8818-6 | Ubuntu 22.04 LTS | linux-fips | 20 (incl. CVE-2025-10263) | ARM64, InfiniBand, network drivers, exFAT, NFS client/server, RDS, IPv4/IPv6, Netfilter | linux-image-5.15.0-194-fips 5.15.0-194.204+fips1 |
How to apply these Linux security updates
Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.
Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.
Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.
Debian/Ubuntu (apt)
The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.
sudo apt update sudo apt upgrade -y
Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)
On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.
sudo dnf check-update sudo dnf upgrade -y
or on older releases
sudo yum check-update sudo yum update
SUSE (zypper)
SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.
sudo zypper refresh sudo zypper update -y
