Debian shipped its standard batch of security updates today, but the combined volume across Fedora, Gentoo, RHEL, and SUSE makes this a Monday worth scanning before lunch. The headlines all point to the same recurring problem: bundled dependencies rotting in the dark, and web-facing services getting patched one CVE at a time. Docker, Rust toolchains, nginx, and PostgreSQL all landed critical arbitrary code execution and privilege escalation fixes that server admins should apply immediately. Meanwhile, RHEL and SUSE focused their updates on directory servers, curl, and the kernel, while Debian and SLE kept legacy systems from rotting in place with fresh LTS and ELA patches.
Today's Linux Security Roundup: Docker, Rust Toolchains, and a Swarm of Arbitrary Code Execution Fixes
Debian shipped its standard batch of security updates today, but the volume across Fedora, Gentoo, RHEL, and SUSE makes this a Monday worth scanning before lunch. The headlines all point to the same recurring problem. Bundled dependencies rotting in the dark, and web-facing services getting patched one CVE at a time.
If you manage Linux infrastructure, you know the rhythm. You pull the errata, triage by severity, and patch what actually runs in production. Today's batch is no exception, though a few of the fixes are worth a closer look.
Docker, Rust, and the Bundled Dependency Problem
The obvious headline is the docker.io advisory. The container engine and its BuildKit build tool carry seven CVEs tied to privilege escalation, host filesystem snooping, and authorization bypasses. Trixie users should upgrade to 26.1.5+dfsg1-9+deb13u1 without delay. Next, the OpenStack stack caught its fair share of attention. Neutron picked up a permission validation slip that could trip API access controls, while Ironic shipped fixes for unredacted sensitive properties, command injection through tenant-controlled binaries, and unguarded ramdisk endpoints. Bookworm administrators need to grab the patched version immediately.
Fedora pushed another round of security patches, and the headline is a systematic fix for several Rust developer tools on Fedora 43. tokei, bat, git-delta, lsd, pretty-git-prompt, and the interactive rebase tool all got rebuilt to drop their statically linked libgit2 in favor of the system library. Classic case of bundled and forgotten. That swap closes a whole string of CVEs that were hiding in the copy. If you run a local DNS cache, the PowerDNS Recursor updates for both Fedora 43 and 44 are worth grabbing. They patch a prefetch bug that let attackers keep poisoned cache entries lingering. Fedora 44 also gets JFrog CLI bumped to 2.119.0, which bundles fixes for a handful of SSH and container-related vulnerabilities. Head here to pull everything in with dnf upgrade, or target just the binaries you actually use.
Gentoo published three high-severity security advisories, and they all lead to the same conclusion. Patch now. The nginx advisory flags twenty issues, with the worst letting attackers execute arbitrary code on your system. PostgreSQL gets a similar treatment across five major versions, tying twenty-two CVEs to the same arbitrary execution risk. The X.Org stack and XWayland round out the batch with twenty-four vulnerabilities targeting the graphical server layers you run your desktop environment on. No workarounds are listed. The emerge commands in the advisory are your only real option. If you run any of these on a public-facing box, skip the staging environment experiment and update immediately.
SUSE just pushed a fresh round of security patches across its rolling and stable lines. If you run openSUSE Leap 16.0, you are looking at important ratings for both open-iscsi and Chromium. The Chromium fix here is worth a second look. Five separate use-after-free bugs across V8, TabStrip, Extensions, HTML, and Blink. You probably already knew to patch that one, but the explicit component list makes the blast radius easier to map. Tumbleweed got the heavier haul. containerized-data-importer1.66-api tops the tally with twelve CVEs, which is a lot of CVEs for a single API package. Kubernetes folks also picked up patches for kubevirt1.9-container-disk (ten CVEs) and chromedriver (five CVEs). If you write in Go, both the 1.25 and 1.26 toolchains landed in the same batch to patch nine vulnerabilities each.
Enterprise and Legacy Support Tracks
Another round of security patches landed in the Red Hat errata queue. The bulk of this batch sits at Important severity, with a handful of Moderate ratings tucked into gstreamer, butane, and glib2. 389 Directory Server leads the pack, followed closely by curl, libXfont2, bind, and the kernel. RHEL 9 and 10 take the brunt of the changes, though EUS streams and the SAP/Telecom specialty channels are getting their due. Every entry points straight to the CVEs and CVSS scores, so you can triage based on what actually runs in your environment. It's a rather predictable spread for a corporate distro, but the sheer volume across RHEL 8, 9, and 10 means you'll want to clear a maintenance window. Keep in mind that EUS streams are getting their own targeted fixes, which usually means you have a bit more breathing room than you would on a rolling release.
The legacy support tracks got their usual treatment. Debian's Unzip and apr-util both land in LTS advisories, with the former tied to arbitrary code execution on specially crafted archives and the latter covering denial of service and code execution vectors across five CVEs. Freexian pushed matching ELA patches for stretch and buster. Mozilla also refreshed the CA certificate bundle across five Debian releases to version 2.74, which keeps SSL validation current without requiring much ceremony from the admin. The SLE-15-SP7 backports release gets an important rating for git-cliff, mostly because of a bytes integer overflow and a Rust slice bounds check. The catch is that upstream jumped the CLI from 2.4.0 to 2.13.1 alongside the security ticket. That is a lot of feature accumulation wrapped in a CVE fix.
All updates are available now through your distribution's package manager. If you're managing fleets, target the advisories by their release dates and patch in order of severity. The CVEs don't wait.
Overview of updates
Debian GNU/Linux
Debian shipped its standard batch of security updates and the obvious headline is the docker.io advisory. The container engine and its BuildKit build tool carry seven CVEs tied to privilege escalation, host filesystem snooping, and authorization bypasses. Trixie users should upgrade to 26.1.5+dfsg1-9+deb13u1 without delay. The OpenStack stack also caught its fair share of attention. Neutron picked up a permission validation slip that could trip API access controls, while Ironic shipped fixes for unredacted sensitive properties, command injection through tenant-controlled binaries, and unguarded ramdisk endpoints. Bookworm administrators need to grab the patched version immediately.
The legacy support tracks got their usual treatment. Unzip and apr-util both land in LTS advisories, with the former tied to arbitrary code execution on specially crafted archives and the latter covering denial of service and code execution vectors across five CVEs. Freexian pushed matching ELA patches for stretch and buster, keeping older systems from rotting in place. Mozilla also refreshed the CA certificate bundle across five Debian releases to version 2.74, which keeps SSL validation current without requiring much ceremony from the admin.
| Package | Advisory ID | Affected Distro(s) | Issue Summary | Fixed Version |
|---|---|---|---|---|
| docker.io | DSA 6443-1 | Trixie | Privilege escalation, host file access, auth bypass in engine & BuildKit (7 CVEs) | 26.1.5+dfsg1-9+deb13u1 |
| unzip | DLA 4741-1 | Bookworm, Bullseye | Arbitrary code execution via crafted archives; stack/heap OOB crashes | 6.0-26+deb11u2, 6.0-28+deb12u1 |
| unzip | ELA-1811-1 | Buster, Stretch | Same Info-ZIP vulnerability and crash fixes as LTS branch | 6.0-21+deb9u4, 6.0-23+deb10u4 |
| apr-util | DLA 4742-1 | Bookworm, Bullseye | DoS and arbitrary code execution across 5 CVEs | 1.6.1-5+deb11u2, 1.6.3-1+deb12u1 |
| neutron | DSA 6444-1 | Trixie | Incorrect API permission validation (CVE-2026-55707) | 2:26.0.3-0+deb13u3 |
| ironic | DLA 4743-1 | Bookworm | Unredacted sensitive data, command injection, unguarded ramdisk endpoints (2 CVEs + OSSN) | 1:21.4.4-0+deb12u2 |
| ca-certificates | ELA-1810-1 | Stretch through Trixie | Mozilla CA bundle refresh to version 2.74 | 20250419deb12u1deb11u1deb10u1deb9u1 |
Fedora Linux
Fedora pushed another round of security patches and the headline is a systematic fix for several Rust developer tools on Fedora 43. tokei, bat, git-delta, lsd, pretty-git-prompt, and the interactive rebase tool all got rebuilt to drop their statically linked libgit2 in favor of the system library. That swap closes a whole string of CVEs that were hiding in the bundled copy. If you run a local DNS cache, the PowerDNS Recursor updates for both Fedora 43 and 44 are worth grabbing. They patch a prefetch bug that let attackers keep poisoned cache entries lingering. Fedora 44 also gets JFrog CLI bumped to 2.119.0, which bundles fixes for a handful of SSH and container-related vulnerabilities. You can run dnf upgrade to pull everything in, or use the specific advisory IDs if you want to target just the binaries you actually use.
| Package | Version | Release | OS | Advisory ID | What Changed |
|---|---|---|---|---|---|
| rust-tokei | 14.0.0 | 7.fc43 | Fedora 43 | FEDORA-2026-7ebec18d52 | Rebuild against system libgit2, patching 7+ CVEs |
| rust-git-delta | 0.19.1 | 7.fc43 | Fedora 43 | FEDORA-2026-7ebec18d52 | Rebuild against system libgit2, patching 7+ CVEs |
| rust-lsd | 1.2.0 | 8.fc43 | Fedora 43 | FEDORA-2026-7ebec18d52 | Rebuild against system libgit2, patching 7+ CVEs |
| rust-pretty-git-prompt | 0.2.2 | 11.fc43 | Fedora 43 | FEDORA-2026-7ebec18d52 | Rebuild against system libgit2, patching 7+ CVEs |
| rust-git-interactive-rebase-tool | 2.4.1 | 17.fc43 | Fedora 43 | FEDORA-2026-7ebec18d52 | Rebuild against system libgit2, patching 7+ CVEs |
| rust-bat | 0.26.1 | 3.fc43 | Fedora 43 | FEDORA-2026-7ebec18d52 | Rebuild against system libgit2, patching 7+ CVEs |
| pdns-recursor | 5.2.13 | 1.fc43 | Fedora 43 | FEDORA-2026-ac51ed6e75 | Upstream bump, fixes CVE-2026-52684 (DNS cache poisoning via prefetch) |
| jfrog-cli | 2.119.0 | 1.fc44 | Fedora 44 | FEDORA-2026-9f70b173c8 | Upstream bump, patches CVE-2025-47914, CVE-2026-42306, CVE-2026-46597, CVE-2026-39831 |
| pdns-recursor | 5.4.5 | 2.fc44 | Fedora 44 | FEDORA-2026-707054d631 | Upstream bump, fixes CVE-2026-52684 (DNS cache poisoning via prefetch) |
Gentoo Linux
Gentoo published three high-severity security advisories, and they all lead to the same conclusion: patch now. The nginx advisory flags twenty issues, with the worst letting attackers execute arbitrary code on your system. PostgreSQL gets a similar treatment across five major versions, tying twenty-two CVEs to the same arbitrary execution risk. The X.Org stack and XWayland round out the batch with twenty-four vulnerabilities targeting the graphical server layers you run your desktop environment on. No workarounds are listed, so the emerge commands in the advisory are your only real option. If you run any of these on a public-facing box, skip the staging environment experiment and update immediately.
| Advisory ID | Package | Severity | Vulnerable Versions | Fixed Versions | CVE Count | Worst-Case Impact |
|---|---|---|---|---|---|---|
| GLSA 202608-16 | www-servers/nginx | High | < 1.31.3-r1 | >= 1.31.3-r1 | 20 | Arbitrary code execution |
| GLSA 202608-15 | dev-db/postgresql (14, 15, 16, 17, 18) | High | < 14.23-r1, < 15.18-r1, < 16.14-r1, < 17.10, < 18.4 | >= 14.23-r1, >= 15.18-r1, >= 16.14-r1, >= 17.10, >= 18.4 | 22 | Arbitrary code execution |
| GLSA 202608-14 | x11-base/xorg-server & x11-base/xwayland | High | < 21.1.24, < 24.1.13 | >= 21.1.24, >= 24.1.13 | 24 | Graphical server / XWayland exploitation |
Red Hat Enterprise Linux
Another round of security patches landed in the Red Hat errata queue, and if you manage RHEL fleets, the spread should feel fairly predictable. The bulk of this batch sits at Important severity, with a handful of Moderate ratings tucked into gstreamer, butane, and glib2. You will spot 389 Directory Server leading the pack, followed closely by curl, libXfont2, bind, and the kernel. RHEL 9 and 10 take the brunt of the changes, though EUS streams and the SAP/Telecom specialty channels are getting their due. Every entry points straight to the CVEs and CVSS scores, so you can triage based on what actually runs in your environment.
| RHSA ID | Package | Severity | Affected Release | Notes |
|---|---|---|---|---|
| RHSA-2026:55435 | gstreamer1-plugins-ugly-free | Important | RHEL 10 | |
| RHSA-2026:55431 | vim | Important | RHEL 10.0 EUS | |
| RHSA-2026:55449 | libreswan | Important | RHEL 10.0 EUS | |
| RHSA-2026:55443 | kernel-rt | Important | RHEL 9.2 SAP | |
| RHSA-2026:55426 | 389-ds-base | Important | RHEL 9.6 EUS | |
| RHSA-2026:55422 | 389-ds-base | Important | RHEL 9.4 SAP | |
| RHSA-2026:55425 | 389-ds-base | Important | RHEL 10.0 EUS | |
| RHSA-2026:55421 | 389-ds-base | Important | RHEL 9.2 SAP | |
| RHSA-2026:55448 | libXfont2 | Important | RHEL 10 | |
| RHSA-2026:55434 | gstreamer1-plugins-good | Moderate | RHEL 10 | |
| RHSA-2026:55441 | bind | Important | RHEL 9.6 EUS | |
| RHSA-2026:55437 | bind | Important | RHEL 10 | |
| RHSA-2026:54515 | kernel | Important | RHEL 9.2 SAP | |
| RHSA-2026:55541 | nodejs22 | Important | RHEL 10 | |
| RHSA-2026:55532 | redhat-ds:11 | Important | RHEL 8 | Directory Server 11.9 |
| RHSA-2026:55525 | butane | Moderate | RHEL 9.2 SAP | |
| RHSA-2026:55520 | butane | Moderate | RHEL 9.6 EUS | |
| RHSA-2026:55440 | glib2 | Moderate | RHEL 9 | |
| RHSA-2026:55439 | curl | Important | RHEL 9 | |
| RHSA-2026:55442 | bind9.18 | Important | RHEL 9 | |
| RHSA-2026:55447 | libXfont2 | Important | RHEL 9 | |
| RHSA-2026:55436 | gstreamer1-plugins-good | Moderate | RHEL 9 | |
| RHSA-2026:55450 | curl | Important | RHEL 10 | |
| RHSA-2026:55432 | curl | Important | RHEL 10 | |
| RHSA-2026:55445 | kernel | Important | RHEL 10.0 EUS | Includes bug fix and enhancement updates |
| RHSA-2026:55433 | gstreamer1-plugins-bad-free | Important | RHEL 10 | |
| RHSA-2026:55446 | libXfont2 | Important | RHEL 8 | |
| RHSA-2026:55423 | 389-ds-base | Important | RHEL 9 | |
| RHSA-2026:55444 | kernel | Important | RHEL 8.8 SAP / Telecom | |
| RHSA-2026:55424 | 389-ds-base | Important | RHEL 10 | |
| RHSA-2026:55530 | 389-ds:1.4 | Important | RHEL 8 |
SUSE Linux
SUSE just pushed a fresh round of security patches across its rolling and stable lines. If you run openSUSE Leap 16.0, you are looking at important ratings for both open-iscsi and Chromium. The Chromium fix here is worth a second look: five separate use-after-free bugs across V8, TabStrip, Extensions, HTML, and Blink. You probably already knew to patch that one, but the explicit component list makes the blast radius easier to map.
Tumbleweed got the heavier haul. containerized-data-importer1.66-api tops the tally with twelve CVEs, which is a lot of CVEs for a single API package. Kubernetes folks also picked up patches for kubevirt1.9-container-disk (ten CVEs) and chromedriver (five CVEs, matching the browser itself). If you write in Go, both the 1.25 and 1.26 toolchains landed in the same batch to patch nine vulnerabilities each. The SLE-15-SP7 backports release gets an important rating for git-cliff, mostly because of a bytes integer overflow and a Rust slice bounds check. The catch is that upstream jumped the CLI from 2.4.0 to 2.13.1 alongside the security ticket. That is a lot of feature accumulation wrapped in a CVE fix.
| Package | Rating | Platform | CVEs Fixed | Notes |
|---|---|---|---|---|
| open-iscsi | Important | Leap 16.0 | 2 | Blocks remote MITM path traversal and local unprivileged isscsiuio socket access. |
| chromium | Important | Leap 16.0 | 5 | Five use-after-free bugs across V8, TabStrip, Extensions, HTML, and Blink. |
| chromedriver | Moderate | Tumbleweed | 5 | Pairs with the Chromium browser update. Same five use-after-free vulnerabilities. |
| go1.25 | Moderate | Tumbleweed | 9 | Standard Go security sweep for the stable release line. |
| go1.26 | Moderate | Tumbleweed | 9 | Paired alongside go1.25 for the same nine vulnerabilities. |
| ffmpeg-9 | Moderate | Tumbleweed | 6 | Covers the dev packages and shared libraries for the 9.x branch. |
| cargo-audit | Moderate | Tumbleweed | 1 | Fixes a bytes integer overflow in BytesMut:reserve. |
| cargo-c | Moderate | Tumbleweed | 1 | Also hits the bytes integer overflow CVE. |
| gzip | Moderate | Tumbleweed | 1 | Addresses a compression-related denial of service vector. |
| kubeshark-cli | Moderate | Tumbleweed | 1 | Fixes a container escape in the CLI tool. |
| kubevirt1.9-container-disk | Moderate | Tumbleweed | 10 | KVM virtualization package picks up ten CVEs across operator, launcher, and handler components. |
| containerized-data-importer1.66-api | Moderate | Tumbleweed | 12 | Highest tally in this batch, affecting the importer API, cloner, and controller. |
| git-cliff | Important | SLE-15-SP7 Backports | 2 | Upstream jumped from 2.4.0 to 2.13.1. Security patches cover a bytes overflow and a Rust slice bounds check. |
How to apply these Linux security updates
Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.
Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.
Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.
Debian/Ubuntu (apt)
The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.
sudo apt update sudo apt upgrade -y
Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)
On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.
sudo dnf check-update sudo dnf upgrade -y
or on older releases
sudo yum check-update sudo yum update
SUSE (zypper)
SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.
sudo zypper refresh sudo zypper update -y
Gentoo Linux
Updating Gentoo Linux is more involved than binary distributions because it's a source-based system with highly customizable packages.
sudo emerge --sync sudo emerge -avuDN @world
