Security 11027 Published by

Today's Linux security roundups from eight distros push a wave of updates where browser engines take the biggest hit, led by Debian stuffing 232 CVEs into a single webkit2gtk advisory and SUSE claiming 302 in a kernel update that turns out to be just build headers. Chromium, Thunderbird, and Firefox show up across nearly every bulletin, meaning a hostile webpage or email stays executable until you apply the fix. The real Criticals worth a reboot window include SUSE's Tomcat/libtcnative smuggling patch, Red Hat's Satellite 6.19.5 entry, and Oracle's eight-hole FreeIPA roll on OL10. Most of the hundreds-of-CVE counts are just upstream releases backported and inflated by design, so patch the WebKit and Chromium entries first, then clear the Important items during normal maintenance.





Hundreds of CVEs hit today's Linux security updates. Two of them don't matter as much as the numbers suggest

Debian crammed 232 security fixes into a single WebKit advisory. SUSE claims 302 in its kernel update. That second number is almost entirely theater.

Let's talk about where the reboot windows should actually go today. Eight major distros pushed a stack of updates, and the newest stories are browser rendering engines going through a full purge. Debian's webkit2gtk advisory (DSA-6534-1) alone carries 232 CVEs. That's a staggering backlog for the engine behind much of the Linux desktop, spanning sandbox escapes and remote code execution.

You probably never think about that engine until it turns into 232 individual holes in one patch.

The SUSE kernel figure looks worse but is mostly paper tiger. openSUSE-SU-2026:11893-1 resolves 302 vulnerabilities, then ships it as kernel-devel, kernel-source, and kernel-macros. You're really just patching headers and build files. A few of those CVEs do look like local privilege escalations, so installing still makes sense, but this is not the crisis the headline implies. Head here to the full advisory if you want the breakdown.

Linux Security

The browsers are the real story

Browser updates show up in nearly every bulletin, and they mostly mean the same thing. A hostile webpage or email stays potentially executable until you apply the fix. Debian lists 32 CVEs for Chromium and 44 for Thunderbird. SUSE packed 108 CVEs into each of its two Chromium releases, bumping the browser to 154.0.8037.57. Red Hat's Firefox update pulls in 28 CVEs on the 140.16.0 ESR line.

That last number isn't actually alarming. It's the normal end-of-cycle volume for ESR releases, but the figures still warrant a glance. These are upstream drops the distros backported, so the counts are inflated by design. The risk is real regardless.

Not everything here wears a browser logo. Ubuntu's GStreamer Bad Plugins fix (CVE-2026-19387) lets a crafted WAV file hand an attacker a shell as your login user, and it touches every LTS from 14.04 through 26.04. That one's worth chasing.

Fedora kept it tight with a single sos update (FEDORA-2026-594e78463a). It closes a path-traversal hole in the tar extractor, which matters because that tool pokes at files all over the system. "Pokes at files" is exactly how a traversal turns from theory into a headline.

The enterprise stacks

If your servers sit on the commercial distros, both Red Hat and Oracle pushed their usual waves. Red Hat's only flat-out Critical entry is Satellite 6.19.5 (RHSA-2026:74503) for RHEL 9. Three other Critical-titled Satellite updates downgrade to Important in the body text, so a quick look before acting on a title is justified. Oracle's two Criticals land on OL10: a freerdp patch (CVE-2026-91949) and an eight-hole FreeIPA roll that lets unauthenticated LDAP clients grab administrator credentials.

AlmaLinux handed out the largest single browser advisory of the lot, with webkit2gtk3 carrying 322 CVEs for version 8. rsync got 17 fixes with a nastier spread, including command injection and path-confinement bypasses. Keep in mind that several packages repeat across releases here, so treat a duplicate notification as expected rather than a glitch.

Rocky and SUSE rounded out the roundup. SUSE's lone critical tag belongs to a Tomcat and libtcnative update on Leap 16.0, closing HTTP/2 request smuggling and a couple of WebSocket smuggling holes. If you serve Java web apps behind a proxy, that one lands. The rest of SUSE's list leans moderate, though glibc picked up a TOCTOU race in the dynamic loader and gimp picked up 10 CVEs tied to file parsing.

Here's the honest take: most of this bulletin is routine. The Criticals deserve a reboot window. The Important stuff you schedule, not sprint to at midnight. Those hundreds-of-CVE numbers are impressive on paper but almost always mean an upstream release got backported as a package.

Patch the WebKit and Chromium entries first, then work through the rest during normal maintenance windows. Each distro publishes its advisories under the IDs listed above, so head to those for exact version strings and full CVE lists before you run a mass update.

A Detailed Breakdown

AlmaLinux

AlmaLinux handed out another batch of security errata spanning versions 8, 9, and 10. If any of those are running on hardware you touch and you haven't patched, this is one worth clearing off the pile.

The obvious headliner is a critical WebKitGTK update for AlmaLinux 8 carrying more than 300 CVEs. Reading down that list, the entries start modestly, then collapse into an endless wall of Skia and ANGLE bugs: sandbox escapes, arbitrary code execution, use-after-free. It reads less like one advisory and more like the entire Chromium release history for a single afternoon.

The rsync update (ALSA-2026:74095) sits close behind with 17 security fixes and a genuinely nasty spread, including command injection, arbitrary file deletion, privilege escalation, and path confinement bypasses. rsync is common enough on servers and backups that these deserve an actual look rather than a blind update.

Firefox and Thunderbird get a heavy pass as well, with sandbox escapes and use-after-free spread across DOM, graphics, and JIT components. On the quieter end sit the one- or two-CVE updates: gawk, gdb, expat, libpcap, OpenSSH, FreeRDP, gvfs, and the PKI stack. FreeRDP lands as critical, which matters if you connect to remote desktops.

Three advisories you might see twice are gvfs, expat, and the PKI packages (pki-core and dogtag-pki). They show up across multiple AlmaLinux releases, so treat a duplicate notification as expected rather than a glitch.

AdvisoryPackageAlmaLinuxSeverityReleasedWhat it fixes
ALSA-2026:74084webkit2gtk38Critical2026-10-01322 CVEs (Skia, ANGLE, WebKitGTK)
ALSA-2026:73971thunderbird8Important2026-09-3044 CVEs across Firefox/Thunderbird (sandbox escapes, use-after-free)
ALSA-2026:74095rsync8Important2026-10-0117 CVEs plus 2 bug fixes
ALSA-2026:74132kernel-rt8Moderate2026-10-014 security fixes plus 2 bug fixes
ALSA-2026:74133kernel8Moderate2026-10-01Same 4 security fixes plus 2 bug fixes as kernel-rt
ALSA-2026:73425gdb8Important2026-09-30STABS debug parser out-of-bounds write (1 CVE)
ALSA-2026:73511gawk8Moderate2026-09-30Memory corruption plus DoS (2 CVEs)
ALSA-2026:73997gvfs8Important2026-10-01SFTP heap buffer overflow (1 CVE)
ALSA-2026:69098webkit2gtk39Important2026-09-3036 CVEs (Skia, ANGLE, WebKitGTK)
ALSA-2026:72623kernel9Important2026-10-0110 security fixes plus 2 bug fixes
ALSA-2026:72663expat9Important2026-10-01Quadratic-complexity DoS plus XML injection (2 CVEs)
ALSA-2026:74370gvfs9Important2026-10-01SFTP overflow plus local-root socket race (2 CVEs)
ALSA-2026:73766pki-core9Important2026-10-01Code execution via unsanitized profile plus REST ACL bypass (2 CVEs)
ALSA-2026:74442libpcap10Important2026-10-01Out-of-bounds read/write (1 CVE)
ALSA-2026:73954openssh10Moderate2026-10-01Brute-force aided by insufficient auth delay (1 CVE)
ALSA-2026:73979freerdp10Critical2026-10-01RDP protocol negotiation bypass (1 CVE)
ALSA-2026:73765dogtag-pki10Important2026-10-01Same 2 PKI CVEs as pki-core
ALSA-2026:73998gvfs10Important2026-10-01Same 2 CVEs as the gvfs 9 update
ALSA-2026:74001expat10Important2026-10-01Same 2 CVEs as the expat 9 update

Debian GNU/Linux

Debian shipped nine security advisories, split between new stable fixes and the slower bookworm LTS track. Chromium and Thunderbird show up twice each (once for trixie, once for bookworm), and the rest landed on a single track.

The webkit2gtk entry is the one likely to make you close the window. Debian packed 232 CVEs into one advisory, which is a staggering backlog for the rendering engine behind much of the Linux desktop. The consequences range from sandbox escapes and remote code execution to cross-origin data leaks. You probably never think about the engine behind your browser until it turns 232 individual holes into a single patch.

Chromium (32 CVEs) and Thunderbird (44 CVEs) round out the browser crowd, where the headline risk everywhere is arbitrary code execution. A hostile webpage or email stays potentially executable until you apply the update.

The smaller items deserve a look too. The network-manager-l2tp flaw lets someone who can create their own VPN connection climb to root, an upgrade worth doing if you share a machine. Node.js took 11 fixes for denial-of-service, bad certificate validation, and information leaks. libpng1.6 absorbed a single use-after-free that opens a denial-of-service gap, and libio-compress-perl picked up three, including a malformed zip date that throws an uncaught exception, a CPU-exhausting read loop, and an arbitrary-code path through an attacker-controlled glob.

PackageAdvisoryFixed versionDebian trackCVEs
network-manager-l2tpDLA-4808-11.20.8-1+deb12u1bookworm (LTS)4
webkit2gtkDSA-6534-12.54.0-1~deb13u1trixie (stable)232
nodejsDLA-4809-118.20.4+dfsg-1~deb12u3bookworm (LTS)11
libpng1.6DSA-6537-11.6.48-1+deb13u6trixie (stable)1
thunderbirdDSA-6536-11:140.17.0esr-1~deb13u1trixie (stable)44
chromiumDSA-6535-1154.0.8037.92-1~deb13u1trixie (stable)32
libio-compress-perlDLA-4812-12.204-1+deb12u1bookworm (LTS)3
chromiumDLA-4811-1154.0.8037.92-1~deb12u1bookworm (LTS)32
thunderbirdDLA-4810-11:140.17.0esr-1~deb12u1bookworm (LTS)44

Fedora Linux

Fedora pushed one security update that touches sos, the tool most sysops reach for when a box is on fire and they need someone to rummage through its logs. The fix (FEDORA-2026-594e78463a) closes a path-traversal hole in sos's tar extractor: symlinks and hardlinks pointing outside the archive weren't being validated, so a crafted archive could force arbitrary file writes rather than just landing where you told it to. Version 4.12.0-2.fc44 handles it, and it arrives with the same CVE number the upstream team used, so the fix tracks cleanly.

If you run sos regularly, the patch is worth ten seconds under dnf. You're not running a hostile tarball on purpose, but the whole point of the tool is that it pokes at files all over the system, and "pokes at files" is exactly how a traversal turns from theory into a headline.

PackageProductVersionAdvisoryCVE
sosFedora 444.12.0-2.fc44FEDORA-2026-594e78463aCVE-2026-79655

Oracle Linux

Oracle just pushed another errata wave across OL7 through OL10, spanning 40 advisories that blend security fixes with routine bug patches. If any of your servers sit on that stack, treat this as a patch day. The two Critical items are where your attention should land first.

OL10's freerdp update closes CVE-2026-91949, which makes the client bail after a failed authentication handshake. If you jump into Windows hosts with freerdp, grab that one. The second Critical is the freeipa roll for OL10, where eight separate holes arrive in a single advisory. Unauthenticated LDAP clients can now grab administrator credentials, and an impersonation path lets you forge a TGS ticket through trust relationships. Applying it while provisioning new FreeIPA trust links makes sense.

The browser stack jumps to the 140.16.0 ESR line on both OL8 and OL10. Firefox pulls in 28 CVEs and Thunderbird on OL10 lists 44. That's the normal end-of-cycle volume for these packages, but the numbers still warrant a review.

Ruby gets one CVE spread across three generations. OL9, OL8, and OL10 each ship a fix for CVE-2026-80212, the resolv memory-exhaustion bug that triggers when you throw unknown DNS types at it. The version strings differ, the underlying hole is identical, so clear out all four ruby advisories in one go.

OpenSSH on OL10 finishes the fix for the forwarding and tunneling security bypass, then adds corrections for an agent-locking interaction and a use-after-free in the client. Two kernel updates show up as well, with the OL9 tree absorbing 17 CVEs across DRM, crypto, and RDMA code, and the OL8 kernel carrying 32 more. gawk and expat each get their buffer-overflow and XML-injection fixes on OL9 and OL10.

The bugfix-only advisories make up the quieter half of the bulletin. systemd holds the biggest pile, including re-disabling unprivileged BPF by default and a genuinely messy round of fstab-generator patching. bootc gets two separate updates, while autofs, cockpit, gnome-shell, python3.12, and virt-v2v pick up smaller fixes. A fresh oracle-database-preinstall package lands as the first release for OL10.

OS versionAdvisoryPackageSeverityWhat it fixes
OL10ELSA-2026-73979freerdpCriticalCVE-2026-91949: abort after failed auth negotiation
OL10ELSA-2026-73765dogtag-pkiImportantCVE-2026-76561, CVE-2026-80110
OL10ELSA-2026-73429gawkModerateCVE-2026-40467/40468/40553: UAF and buffer/integer overflow
OL10ELSA-2026-73130thunderbirdImportant44 CVEs (140.16.0 ESR)
OL10ELSA-2026-71658python-cryptographyImportantCVE-2026-69249: X.509 signature validation budget
OL10ELSA-2026-72785rubyImportantCVE-2026-80212: resolv DoS
OL10ELSA-2026-72427ruby4.0ImportantCVE-2026-80212
OL10ELSA-2026-69129opensshImportantCVE-2026-59995/59999/73281/73282/73283
OL10ELBA-2026-74013bootcBugfixBackport PR #2485
OL10ELBA-2026-73430virt-v2vBugfixNBD from remote hosts; cleanup
OL10ELSA-2026-72279ipaCritical8 CVEs incl. unauth admin creds, XSS, DoS
OL10ELSA-2026-67872corosyncImportantCVE-2026-81665
OL10ELBA-2026-500166oracle-database-preinstall-19cBugfixFirst OL10 release
OL9ELSA-2026-73766pki-coreImportantCVE-2026-76561, CVE-2026-80110
OL9ELSA-2026-73512gawkModerateCVE-2026-40467/40468/40553
OL9ELSA-2026-72663expatImportantCVE-2026-66046/93990
OL9ELSA-2026-72623kernelImportant9 CVEs
OL9ELSA-2026-72484ruby:4.0ImportantCVE-2026-80212
OL9ELSA-2026-72485ruby:3.3ImportantCVE-2026-80212
OL9ELSA-2026-72286rubyImportantCVE-2026-80212
OL9ELBA-2026-74012bootcBugfixloader-entries handling
OL9ELBA-2026-67588systemdBugfixPile of fixes incl. BPF, fstab
OL9ELSA-2026-72424resteasyImportantCVE-2026-17615: unauthenticated file read
OL9ELSA-2026-73838nodejs:24ImportantCVE-2026-19534/84961/85152
OL9ELSA-2026-71700kernelImportant17 CVEs
OL8ELBA-2026-71329-1kernelBugfix32 CVEs incl. RDMA, bluetooth, nvme
OL8ELSA-2026-72285ruby:3.3ImportantCVE-2026-80212
OL8ELSA-2026-72448expatImportantCVE-2026-66046/93990
OL8ELSA-2026-72274postgresql:12ImportantMany CVEs incl. 2025-8714, 2026-18408
OL8ELSA-2026-67148-0osbuild-composerImportant6 CVEs
OL8ELSA-2026-71652firefoxImportant28 CVEs (140.16.0 ESR)
OL8ELBA-2026-73447autofsBugfixproximity and mask matching
OL8ELSA-2026-71608perl-DBIImportantCVE-2026-73194
OL8ELBA-2026-73450gnome-shellBugfixuserVerifier regression
OL8ELBA-2026-73438cockpitBugfixselinux, docs, hwinfo
OL8ELBA-2026-73446python3.12Bugfixexpat version requirement
OL7ELSA-2026-68707freerdpImportantMany CVEs on 2.1.1 and 2.2.0 lines
OL7ELSA-2026-65773-0glib2ModerateCVE-2026-15588/58010 through 58016
OL7ELSA-2026-62231-0libXfont2ImportantCVE-2026-44950/59679
OL7ELSA-2026-61234-0xmlrpc-cImportantCVE-2026-15928

Red Hat Enterprise Linux

Red Hat pushed out another batch of errata, and this one is a genuine mixed bag once you sort by urgency. Twenty-six advisories in total, and only a handful are actually Critical. Most of the rest sit in the Important bucket. You can skim a good chunk of it, but a few genuinely deserve a reboot window.

The clear standouts are three Satellite updates plus a freerdp patch aimed at RHEL 10.0. Satellite 6.19.5 (RHSA-2026:74503) is the only flat-out Critical entry, and it targets RHEL 9. Satellite 6.18.10 (74504) and 6.16.14 (74506) carry Critical headlines too, but their body text downgrades both to Important. That split is worth a glance before you act on the title. The freerdp Critical (74471) goes out to RHEL 10.0 EUS.

A kernel update splits across two ratings for RHEL 9: Important for the 9.6 EUS channel (74174) and Moderate for the standard stream (74438). OpenShift got routine packages and bug-fix releases for 4.17 and 4.18, plus a 4.12 cleanup that's rated low enough to mostly skip, even though the titles still call them Important and Moderate.

On the tooling side, you've got libpcap, qt, gvfs, skopeo, pcp, dracut, libvirt, and ghostscript all getting security bumps, almost all tagged Important. JBoss Web Server landed its 6.2.5 release in two flavors: a zip build that also covers Windows (73982) and a plain RHEL-only build (73981).

RHSA IDSeverityProductPlatform
74503CriticalSatellite 6.19.5RHEL 9
74504CriticalSatellite 6.18.10RHEL 9
74506CriticalSatellite 6.16.14RHEL 8, 9
74471CriticalfreerdpRHEL 10.0 EUS
73982ImportantJBoss Web Server 6.2.5 (zip)RHEL 8, 9, 10, Windows
73981ImportantJBoss Web Server 6.2.5RHEL 8, 9, 10
70585ImportantOpenShift 4.17.58 packages4.17
70586ImportantOpenShift 4.17.58 bug fixes4.17
70614ImportantOpenShift 4.18.56 packages4.18
70615ImportantOpenShift 4.18.56 bug fixes4.18
70645ImportantOpenShift 4.12.99 packages4.12
74442ImportantlibpcapRHEL 10
74441ImportantlibpcapRHEL 9
74444ImportantqtRHEL 7 ELS
74174ImportantkernelRHEL 9.6 EUS
74370ImportantgvfsRHEL 9
74581ImportantskopeoRHEL 9.6 EUS
74424ImportantlibvirtRHEL 9
74610ImportantfreerdpRHEL 7 ELS
74613ImportantpcpRHEL 8.4 (AMCUSS / EUS LL)
74612ImportantpcpRHEL 8.6 (AMCUSS / EUS LL)
74470ImportantfreerdpRHEL 9.2 SAP
74499ImportantdracutRHEL 6 ELS EXTENSION
74438ModeratekernelRHEL 9
74464ModerateghostscriptRHEL 10
70646ModerateOpenShift 4.12.99 bug fixes4.12

Rocky Linux

Rocky Linux has pushed a fresh batch of errata, and if you run any of these versions you should go patch. The list covers 16 advisories across Rocky Linux 8, 9, and 10, and only one of them actually deserves a wake-up call.

The standout is RLSA-2026:74084, a Critical fix for webkit2gtk3, the browser engine behind a good chunk of GTK desktop apps. That's the one you shouldn't let sit. Beyond it, the crowd is built entirely of Important-rated updates, with a handful of Moderate ones thrown in for balance. You'll notice the same packages repeating across releases, which is normal for a distro built to stick around. gvfs and openssh both show up more than once, and nodejs:24 lands on three different releases. Kernel updates for both the realtime and standard builds make an appearance, as do thunderbird, rsync, expat, dogtag-pki, pki-core, and ruby:2.5, the last of which drags along a pile of gem dependencies.

Nothing here names specific CVEs, so you'll want to open the errata pages if you care about exactly what each fix closes. The Moderate openssh entries aren't nothing, but they're the kind of thing you schedule rather than sprint to at midnight.

RLSA IDSeverityPackageAffected release(s)
RLSA-2026:74084Criticalwebkit2gtk3Rocky Linux 8
RLSA-2026:73997ImportantgvfsRocky Linux 8
RLSA-2026:73519Importantruby:2.5 (+ mysql2, bundler, pg, mongo, bson, abrt)Rocky Linux 8
RLSA-2026:74132Moderatekernel-rtRocky Linux 8
RLSA-2026:73971ImportantthunderbirdRocky Linux 8
RLSA-2026:74133ModeratekernelRocky Linux 8
RLSA-2026:74095ImportantrsyncRocky Linux 8
RLSA-2026:74085Importantnodejs:24Rocky Linux 8
RLSA-2026:74001ImportantexpatRocky Linux 10
RLSA-2026:73765Importantdogtag-pkiRocky Linux 10
RLSA-2026:73428Importantnodejs24Rocky Linux 10
RLSA-2026:73998ImportantgvfsRocky Linux 10
RLSA-2026:73954ModerateopensshRocky Linux 10
RLSA-2026:73955ModerateopensshRocky Linux 9
RLSA-2026:73766Importantpki-coreRocky Linux 9
RLSA-2026:73838Importantnodejs:24Rocky Linux 9

SUSE Linux

SUSE rolled out another batch of security fixes, and this one spans Tumbleweed, Leap 16.0, and a couple of SLE 15 SP7 variants. Twenty announcements show up, ratings running the usual spread. Only one carries the critical tag, and it belongs to the Tomcat and libtcnative stack on Leap 16.0.

The headline number goes to the kernel update (openSUSE-SU-2026:11893-1), which quietly resolves 302 vulnerabilities. You won't be running a new kernel here, though. This ships as kernel-devel, kernel-source, and kernel-macros, so you're really just patching headers and build files. Worth installing anyway, since a few of those CVEs look like they could be local privilege escalations.

The critical one, openSUSE-SU-2026:21984-1, hits Tomcat 9, 10, and 11 alongside libtcnative 1 and 2. It closes 15 security holes plus fixes 16 non-security bugs, and the scary ones include HTTP/2 request smuggling, WebSocket message smuggling, a buffer overread that crashes the JVM mid-handshake, and CRLs being ignored when the server key lives in a Java keystore. If you serve Java web apps behind a proxy, this lands.

Chromium shows up twice with 108 CVEs each, a backports build for SLE-15-SP7 and a fresh one for Leap 16.0, bumping the browser to 154.0.8037.57. That's a lot of numbered entries for one release, most of them the usual browser fare: use-after-free, buffer overflow, and type confusion spread across ANGLE, V8, and WebGL. If you haven't restarted the browser in a while, now's the time.

A few others deserve a glance. glibc (openSUSE-SU-2026:21968-1) packs 9 vulnerabilities, including CVE-2026-86805, a TOCTOU race in the dynamic loader that lets local attackers escalate privileges. Emacs gets fixed for CVE-2026-96442, which lets untrusted text files run code outside of Lisp mode, so the thing you assumed was safe to open actually isn't. gimp lands 10 CVEs tied to file parsing, several of them remote code execution through crafted TIF, SGI, ICO, and PSD files.

The rest lean moderate. Tumbleweed carries the bulk of the GA-media updates, including an 11-vulnerability php8 bump (openSUSE-SU-2026:11901-1) and a handful of X11 library fixes. libXi alone picks up 7 CVEs. Then there's the small surprise: mistral-vibe, a package you probably never expected to see in a security advisory. It has exactly one CVE, but the point still stands that you don't get to skip the update just because the name is unfamiliar.

AnnouncementRatingTargetPackage(s)CVEs
openSUSE-SU-2026:21984-1criticalLeap 16.0tomcat 9/10/11, libtcnative 1 & 2 (1.3.9 / 2.0.16)15 (+16 bug fixes)
openSUSE-SU-2026:0343-1importantBackports SLE-15-SP7chromium 154.0.8037.57108
openSUSE-SU-2026:21987-1importantLeap 16.0chromium 154.0.8037.57108
SUSE-SU-2026:4409-1importantLeap 15.4, SLE 15 SP7, Package Hubgimp 2.10.3010
openSUSE-SU-2026:21982-1importantLeap 16.0sccache 0.18.0~219 (+16 bug fixes)
openSUSE-SU-2026:21968-1importantLeap 16.0glibc 2.409 (+10 bug fixes)
openSUSE-SU-2026:21974-1importantLeap 16.0emacs 30.21 (+1 bug fix)
openSUSE-SU-2026:21973-1importantLeap 16.0ImageMagick 7.1.2.05 (+5 bug fixes)
openSUSE-SU-2026:21985-1importantLeap 16.0valkey 8.0.101 (+1 bug fix)
openSUSE-SU-2026:21977-1moderateLeap 16.0glib2 2.84.41 (+1 bug fix)
openSUSE-SU-2026:11901-1moderateTumbleweedphp8 8.5.1111
openSUSE-SU-2026:11893-1moderateTumbleweedkernel-devel, kernel-source, kernel-macros (7.2.8)302
openSUSE-SU-2026:11895-1moderateTumbleweedlibXi 1.8.37
openSUSE-SU-2026:11894-1moderateTumbleweedlibX11-6 1.8.133
openSUSE-SU-2026:11898-1moderateTumbleweedlibtcnative-1-0 1.3.93
openSUSE-SU-2026:11899-1moderateTumbleweedlibtcnative-2-0 2.0.163
openSUSE-SU-2026:11892-1moderateTumbleweedhelm3 3.22.02
openSUSE-SU-2026:11896-1moderateTumbleweedlibXpm 3.5.181
openSUSE-SU-2026:11897-1moderateTumbleweedlibXtst 1.2.51
openSUSE-SU-2026:11900-1moderateTumbleweedmistral-vibe 2.25.81

Ubuntu Linux

Ubuntu pushed out a stack of security notices. If you're on any LTS release and haven't run an update in a bit, several of these are worth a look. The fixes span a media plugin, the Django web framework, OpenStack DNS, and OpenSSL's newer QUIC code, so there's something here for nearly everyone.

The story with the most moving parts involves GStreamer Bad Plugins. CVE-2026-19387 comes from unchecked validation of multi-channel audio block sizes, so a crafted WAV file can crash a program or hand an attacker a shell as your login user. It touches every supported LTS, from 14.04 all the way up to 26.04.

Django got three separate fixes. GeoDjango mishandles spatial lookups on untrusted input, which an attacker could turn into outbound requests, file writes, or code execution, and that one is limited to 22.04 and newer. The other two are both caching slips: a Vary header set to an asterisk lets a remote user read cached data, and case-insensitive parsing of Cache-Control headers leaks that same stash. The Cache-Control hole skips the 18.04 line.

OpenStack Designate failed to validate overlapping zones, so an authenticated user can reroute DNS traffic to systems they control or knock it out entirely (CVE-2026-71193). Update and restart Designate, or the fix won't actually take.

The final pair both land on 26.04 alone. KCoreAddons mishandles shell quoting in KShell::quoteArgs, which opens a shell escape in anything relying on that method, and OpenSSL burns excessive CPU and memory during QUIC stream reassembly and packet buffering, both denial-of-service plays. OpenSSL wants a full reboot once updated; the rest just need a normal system update. On the older 18.04, 16.04, and 14.04 lines, several of these fixes ride behind Ubuntu Pro.

PackageVulnerabilityImpactVersion fixedCVEPost-update action
gstreamer1.0-plugins-bad (gst-plugins-bad1.0)Misvalidated multi-channel audio block sizeCrash or code running as login user1.28.2 (26.04) down to 1.2.4 (14.04)CVE-2026-19387Standard update
python-djangoGeoDjango lookups plus two caching bugsRCE, file writes, cached-data leaks5.2.9 (26.04) down to 1.6.11 (14.04)CVE-2026-15307, 6907, 8404Standard update
designateOverlapping DNS zones unvalidatedTraffic redirect or DoS22.0.0 (26.04) down to 2.1.0 (16.04)CVE-2026-71193Restart Designate
kf6-kcoreaddonsShell-argument quoting in KShell::quoteArgsShell escape6.24.0 (26.04)CVE-2026-41526Standard update
opensslQUIC reassembly CPU plus packet-buffer memoryDenial of service3.5.5-1ubuntu3.7 (26.04)CVE-2026-42772, 54873Reboot
libxpmZero-dimension XPM imagesResource exhaustion, leading to DoS3.5.17 (26.04, 24.04); 3.5.12 (22.04)CVE-2026-94287Standard update

How to apply these Linux security updates

Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.

Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.

Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.

Debian/Ubuntu (apt)

The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.

sudo apt update
sudo apt upgrade -y

Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)

On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.

sudo dnf check-update
sudo dnf upgrade -y

or on older releases

sudo yum check-update
sudo yum update

SUSE (zypper)

SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.

sudo zypper refresh
sudo zypper update -y