Security 10979 Published by

Debian shipped its standard batch of security updates today, but the combined volume across Fedora, Gentoo, RHEL, and SUSE makes this a Monday worth scanning before lunch. The headlines all point to the same recurring problem: bundled dependencies rotting in the dark, and web-facing services getting patched one CVE at a time. Docker, Rust toolchains, nginx, and PostgreSQL all landed critical arbitrary code execution and privilege escalation fixes that server admins should apply immediately. Meanwhile, RHEL and SUSE focused their updates on directory servers, curl, and the kernel, while Debian and SLE kept legacy systems from rotting in place with fresh LTS and ELA patches.





Today's Linux Security Roundup: Docker, Rust Toolchains, and a Swarm of Arbitrary Code Execution Fixes

Debian shipped its standard batch of security updates today, but the volume across Fedora, Gentoo, RHEL, and SUSE makes this a Monday worth scanning before lunch. The headlines all point to the same recurring problem. Bundled dependencies rotting in the dark, and web-facing services getting patched one CVE at a time.

If you manage Linux infrastructure, you know the rhythm. You pull the errata, triage by severity, and patch what actually runs in production. Today's batch is no exception, though a few of the fixes are worth a closer look.

Lcsecupd

Docker, Rust, and the Bundled Dependency Problem

The obvious headline is the docker.io advisory. The container engine and its BuildKit build tool carry seven CVEs tied to privilege escalation, host filesystem snooping, and authorization bypasses. Trixie users should upgrade to 26.1.5+dfsg1-9+deb13u1 without delay. Next, the OpenStack stack caught its fair share of attention. Neutron picked up a permission validation slip that could trip API access controls, while Ironic shipped fixes for unredacted sensitive properties, command injection through tenant-controlled binaries, and unguarded ramdisk endpoints. Bookworm administrators need to grab the patched version immediately.

Fedora pushed another round of security patches, and the headline is a systematic fix for several Rust developer tools on Fedora 43. tokei, bat, git-delta, lsd, pretty-git-prompt, and the interactive rebase tool all got rebuilt to drop their statically linked libgit2 in favor of the system library. Classic case of bundled and forgotten. That swap closes a whole string of CVEs that were hiding in the copy. If you run a local DNS cache, the PowerDNS Recursor updates for both Fedora 43 and 44 are worth grabbing. They patch a prefetch bug that let attackers keep poisoned cache entries lingering. Fedora 44 also gets JFrog CLI bumped to 2.119.0, which bundles fixes for a handful of SSH and container-related vulnerabilities. Head here to pull everything in with dnf upgrade, or target just the binaries you actually use.

Gentoo published three high-severity security advisories, and they all lead to the same conclusion. Patch now. The nginx advisory flags twenty issues, with the worst letting attackers execute arbitrary code on your system. PostgreSQL gets a similar treatment across five major versions, tying twenty-two CVEs to the same arbitrary execution risk. The X.Org stack and XWayland round out the batch with twenty-four vulnerabilities targeting the graphical server layers you run your desktop environment on. No workarounds are listed. The emerge commands in the advisory are your only real option. If you run any of these on a public-facing box, skip the staging environment experiment and update immediately.

SUSE just pushed a fresh round of security patches across its rolling and stable lines. If you run openSUSE Leap 16.0, you are looking at important ratings for both open-iscsi and Chromium. The Chromium fix here is worth a second look. Five separate use-after-free bugs across V8, TabStrip, Extensions, HTML, and Blink. You probably already knew to patch that one, but the explicit component list makes the blast radius easier to map. Tumbleweed got the heavier haul. containerized-data-importer1.66-api tops the tally with twelve CVEs, which is a lot of CVEs for a single API package. Kubernetes folks also picked up patches for kubevirt1.9-container-disk (ten CVEs) and chromedriver (five CVEs). If you write in Go, both the 1.25 and 1.26 toolchains landed in the same batch to patch nine vulnerabilities each.

Enterprise and Legacy Support Tracks

Another round of security patches landed in the Red Hat errata queue. The bulk of this batch sits at Important severity, with a handful of Moderate ratings tucked into gstreamer, butane, and glib2. 389 Directory Server leads the pack, followed closely by curl, libXfont2, bind, and the kernel. RHEL 9 and 10 take the brunt of the changes, though EUS streams and the SAP/Telecom specialty channels are getting their due. Every entry points straight to the CVEs and CVSS scores, so you can triage based on what actually runs in your environment. It's a rather predictable spread for a corporate distro, but the sheer volume across RHEL 8, 9, and 10 means you'll want to clear a maintenance window. Keep in mind that EUS streams are getting their own targeted fixes, which usually means you have a bit more breathing room than you would on a rolling release.

The legacy support tracks got their usual treatment. Debian's Unzip and apr-util both land in LTS advisories, with the former tied to arbitrary code execution on specially crafted archives and the latter covering denial of service and code execution vectors across five CVEs. Freexian pushed matching ELA patches for stretch and buster. Mozilla also refreshed the CA certificate bundle across five Debian releases to version 2.74, which keeps SSL validation current without requiring much ceremony from the admin. The SLE-15-SP7 backports release gets an important rating for git-cliff, mostly because of a bytes integer overflow and a Rust slice bounds check. The catch is that upstream jumped the CLI from 2.4.0 to 2.13.1 alongside the security ticket. That is a lot of feature accumulation wrapped in a CVE fix.

All updates are available now through your distribution's package manager. If you're managing fleets, target the advisories by their release dates and patch in order of severity. The CVEs don't wait.

Overview of updates

Debian GNU/Linux

Debian shipped its standard batch of security updates and the obvious headline is the docker.io advisory. The container engine and its BuildKit build tool carry seven CVEs tied to privilege escalation, host filesystem snooping, and authorization bypasses. Trixie users should upgrade to 26.1.5+dfsg1-9+deb13u1 without delay. The OpenStack stack also caught its fair share of attention. Neutron picked up a permission validation slip that could trip API access controls, while Ironic shipped fixes for unredacted sensitive properties, command injection through tenant-controlled binaries, and unguarded ramdisk endpoints. Bookworm administrators need to grab the patched version immediately.

The legacy support tracks got their usual treatment. Unzip and apr-util both land in LTS advisories, with the former tied to arbitrary code execution on specially crafted archives and the latter covering denial of service and code execution vectors across five CVEs. Freexian pushed matching ELA patches for stretch and buster, keeping older systems from rotting in place. Mozilla also refreshed the CA certificate bundle across five Debian releases to version 2.74, which keeps SSL validation current without requiring much ceremony from the admin.

PackageAdvisory IDAffected Distro(s)Issue SummaryFixed Version
docker.ioDSA 6443-1TrixiePrivilege escalation, host file access, auth bypass in engine & BuildKit (7 CVEs)26.1.5+dfsg1-9+deb13u1
unzipDLA 4741-1Bookworm, BullseyeArbitrary code execution via crafted archives; stack/heap OOB crashes6.0-26+deb11u2, 6.0-28+deb12u1
unzipELA-1811-1Buster, StretchSame Info-ZIP vulnerability and crash fixes as LTS branch6.0-21+deb9u4, 6.0-23+deb10u4
apr-utilDLA 4742-1Bookworm, BullseyeDoS and arbitrary code execution across 5 CVEs1.6.1-5+deb11u2, 1.6.3-1+deb12u1
neutronDSA 6444-1TrixieIncorrect API permission validation (CVE-2026-55707)2:26.0.3-0+deb13u3
ironicDLA 4743-1BookwormUnredacted sensitive data, command injection, unguarded ramdisk endpoints (2 CVEs + OSSN)1:21.4.4-0+deb12u2
ca-certificatesELA-1810-1Stretch through TrixieMozilla CA bundle refresh to version 2.7420250419deb12u1deb11u1deb10u1deb9u1

Fedora Linux

Fedora pushed another round of security patches and the headline is a systematic fix for several Rust developer tools on Fedora 43. tokei, bat, git-delta, lsd, pretty-git-prompt, and the interactive rebase tool all got rebuilt to drop their statically linked libgit2 in favor of the system library. That swap closes a whole string of CVEs that were hiding in the bundled copy. If you run a local DNS cache, the PowerDNS Recursor updates for both Fedora 43 and 44 are worth grabbing. They patch a prefetch bug that let attackers keep poisoned cache entries lingering. Fedora 44 also gets JFrog CLI bumped to 2.119.0, which bundles fixes for a handful of SSH and container-related vulnerabilities. You can run dnf upgrade to pull everything in, or use the specific advisory IDs if you want to target just the binaries you actually use.

PackageVersionReleaseOSAdvisory IDWhat Changed
rust-tokei14.0.07.fc43Fedora 43FEDORA-2026-7ebec18d52Rebuild against system libgit2, patching 7+ CVEs
rust-git-delta0.19.17.fc43Fedora 43FEDORA-2026-7ebec18d52Rebuild against system libgit2, patching 7+ CVEs
rust-lsd1.2.08.fc43Fedora 43FEDORA-2026-7ebec18d52Rebuild against system libgit2, patching 7+ CVEs
rust-pretty-git-prompt0.2.211.fc43Fedora 43FEDORA-2026-7ebec18d52Rebuild against system libgit2, patching 7+ CVEs
rust-git-interactive-rebase-tool2.4.117.fc43Fedora 43FEDORA-2026-7ebec18d52Rebuild against system libgit2, patching 7+ CVEs
rust-bat0.26.13.fc43Fedora 43FEDORA-2026-7ebec18d52Rebuild against system libgit2, patching 7+ CVEs
pdns-recursor5.2.131.fc43Fedora 43FEDORA-2026-ac51ed6e75Upstream bump, fixes CVE-2026-52684 (DNS cache poisoning via prefetch)
jfrog-cli2.119.01.fc44Fedora 44FEDORA-2026-9f70b173c8Upstream bump, patches CVE-2025-47914, CVE-2026-42306, CVE-2026-46597, CVE-2026-39831
pdns-recursor5.4.52.fc44Fedora 44FEDORA-2026-707054d631Upstream bump, fixes CVE-2026-52684 (DNS cache poisoning via prefetch)

Gentoo Linux

Gentoo published three high-severity security advisories, and they all lead to the same conclusion: patch now. The nginx advisory flags twenty issues, with the worst letting attackers execute arbitrary code on your system. PostgreSQL gets a similar treatment across five major versions, tying twenty-two CVEs to the same arbitrary execution risk. The X.Org stack and XWayland round out the batch with twenty-four vulnerabilities targeting the graphical server layers you run your desktop environment on. No workarounds are listed, so the emerge commands in the advisory are your only real option. If you run any of these on a public-facing box, skip the staging environment experiment and update immediately.

Advisory IDPackageSeverityVulnerable VersionsFixed VersionsCVE CountWorst-Case Impact
GLSA 202608-16www-servers/nginxHigh< 1.31.3-r1>= 1.31.3-r120Arbitrary code execution
GLSA 202608-15dev-db/postgresql (14, 15, 16, 17, 18)High< 14.23-r1, < 15.18-r1, < 16.14-r1, < 17.10, < 18.4>= 14.23-r1, >= 15.18-r1, >= 16.14-r1, >= 17.10, >= 18.422Arbitrary code execution
GLSA 202608-14x11-base/xorg-server & x11-base/xwaylandHigh< 21.1.24, < 24.1.13>= 21.1.24, >= 24.1.1324Graphical server / XWayland exploitation

Red Hat Enterprise Linux

Another round of security patches landed in the Red Hat errata queue, and if you manage RHEL fleets, the spread should feel fairly predictable. The bulk of this batch sits at Important severity, with a handful of Moderate ratings tucked into gstreamer, butane, and glib2. You will spot 389 Directory Server leading the pack, followed closely by curl, libXfont2, bind, and the kernel. RHEL 9 and 10 take the brunt of the changes, though EUS streams and the SAP/Telecom specialty channels are getting their due. Every entry points straight to the CVEs and CVSS scores, so you can triage based on what actually runs in your environment.

RHSA IDPackageSeverityAffected ReleaseNotes
RHSA-2026:55435gstreamer1-plugins-ugly-freeImportantRHEL 10
RHSA-2026:55431vimImportantRHEL 10.0 EUS
RHSA-2026:55449libreswanImportantRHEL 10.0 EUS
RHSA-2026:55443kernel-rtImportantRHEL 9.2 SAP
RHSA-2026:55426389-ds-baseImportantRHEL 9.6 EUS
RHSA-2026:55422389-ds-baseImportantRHEL 9.4 SAP
RHSA-2026:55425389-ds-baseImportantRHEL 10.0 EUS
RHSA-2026:55421389-ds-baseImportantRHEL 9.2 SAP
RHSA-2026:55448libXfont2ImportantRHEL 10
RHSA-2026:55434gstreamer1-plugins-goodModerateRHEL 10
RHSA-2026:55441bindImportantRHEL 9.6 EUS
RHSA-2026:55437bindImportantRHEL 10
RHSA-2026:54515kernelImportantRHEL 9.2 SAP
RHSA-2026:55541nodejs22ImportantRHEL 10
RHSA-2026:55532redhat-ds:11ImportantRHEL 8Directory Server 11.9
RHSA-2026:55525butaneModerateRHEL 9.2 SAP
RHSA-2026:55520butaneModerateRHEL 9.6 EUS
RHSA-2026:55440glib2ModerateRHEL 9
RHSA-2026:55439curlImportantRHEL 9
RHSA-2026:55442bind9.18ImportantRHEL 9
RHSA-2026:55447libXfont2ImportantRHEL 9
RHSA-2026:55436gstreamer1-plugins-goodModerateRHEL 9
RHSA-2026:55450curlImportantRHEL 10
RHSA-2026:55432curlImportantRHEL 10
RHSA-2026:55445kernelImportantRHEL 10.0 EUSIncludes bug fix and enhancement updates
RHSA-2026:55433gstreamer1-plugins-bad-freeImportantRHEL 10
RHSA-2026:55446libXfont2ImportantRHEL 8
RHSA-2026:55423389-ds-baseImportantRHEL 9
RHSA-2026:55444kernelImportantRHEL 8.8 SAP / Telecom
RHSA-2026:55424389-ds-baseImportantRHEL 10
RHSA-2026:55530389-ds:1.4ImportantRHEL 8

SUSE Linux

SUSE just pushed a fresh round of security patches across its rolling and stable lines. If you run openSUSE Leap 16.0, you are looking at important ratings for both open-iscsi and Chromium. The Chromium fix here is worth a second look: five separate use-after-free bugs across V8, TabStrip, Extensions, HTML, and Blink. You probably already knew to patch that one, but the explicit component list makes the blast radius easier to map.

Tumbleweed got the heavier haul. containerized-data-importer1.66-api tops the tally with twelve CVEs, which is a lot of CVEs for a single API package. Kubernetes folks also picked up patches for kubevirt1.9-container-disk (ten CVEs) and chromedriver (five CVEs, matching the browser itself). If you write in Go, both the 1.25 and 1.26 toolchains landed in the same batch to patch nine vulnerabilities each. The SLE-15-SP7 backports release gets an important rating for git-cliff, mostly because of a bytes integer overflow and a Rust slice bounds check. The catch is that upstream jumped the CLI from 2.4.0 to 2.13.1 alongside the security ticket. That is a lot of feature accumulation wrapped in a CVE fix.

PackageRatingPlatformCVEs FixedNotes
open-iscsiImportantLeap 16.02Blocks remote MITM path traversal and local unprivileged isscsiuio socket access.
chromiumImportantLeap 16.05Five use-after-free bugs across V8, TabStrip, Extensions, HTML, and Blink.
chromedriverModerateTumbleweed5Pairs with the Chromium browser update. Same five use-after-free vulnerabilities.
go1.25ModerateTumbleweed9Standard Go security sweep for the stable release line.
go1.26ModerateTumbleweed9Paired alongside go1.25 for the same nine vulnerabilities.
ffmpeg-9ModerateTumbleweed6Covers the dev packages and shared libraries for the 9.x branch.
cargo-auditModerateTumbleweed1Fixes a bytes integer overflow in BytesMut:reserve.
cargo-cModerateTumbleweed1Also hits the bytes integer overflow CVE.
gzipModerateTumbleweed1Addresses a compression-related denial of service vector.
kubeshark-cliModerateTumbleweed1Fixes a container escape in the CLI tool.
kubevirt1.9-container-diskModerateTumbleweed10KVM virtualization package picks up ten CVEs across operator, launcher, and handler components.
containerized-data-importer1.66-apiModerateTumbleweed12Highest tally in this batch, affecting the importer API, cloner, and controller.
git-cliffImportantSLE-15-SP7 Backports2Upstream jumped from 2.4.0 to 2.13.1. Security patches cover a bytes overflow and a Rust slice bounds check.

How to apply these Linux security updates

Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.

Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.

Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.

Debian/Ubuntu (apt)

The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.

sudo apt update
sudo apt upgrade -y

Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)

On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.

sudo dnf check-update
sudo dnf upgrade -y

or on older releases

sudo yum check-update
sudo yum update

SUSE (zypper)

SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.

sudo zypper refresh
sudo zypper update -y

Gentoo Linux

Updating Gentoo Linux is more involved than binary distributions because it's a source-based system with highly customizable packages.

sudo emerge --sync
sudo emerge -avuDN @world