Tails 95 Published by

Tails has dropped version 7.10.1 as an emergency security patch just two weeks after 7.10 launched. The update locks down CVE-2026-64560 in the Linux kernel, preventing a malicious website from hijacking your Tor Browser session with root privileges. It also upgrades the expat XML parser to 2.8.2 to neutralize 20 distinct CVEs across LibreOffice, Audacity, and Git, while switching automatic upgrade payloads to zstd compression for faster downloads. Anyone on Tails 7.0 or later will get the patch automatically, though a manual USB reinstall remains a fully viable option that keeps Persistent Storage intact.



Tails 7.10.1 Patches Critical Kernel and XML Parser Vulnerabilities in Emergency Release

Tails is rolling out an emergency security patch today, pushing version 7.10.1 to fix two critical vulnerabilities that could compromise anonymous sessions. The release lands just 13 days after Tails 7.10 shipped, and it addresses both a Linux kernel flaw and a wide-ranging XML parser bug.

Privacy-focused operating systems rarely move this fast. Tails flagged CVE-2026-64560, a kernel privilege escalation bug that could let a malicious website handed over while using Tor Browser grab root access to your live session. There are no known exploits in the wild yet. The math is simple though. You visit one bad page. The kernel hands you admin rights. Your entire anonymous setup becomes someone else's sandbox.

Screenshot_from_2026_02_26_13_45_11

The Kernel and Browser Angle

The patch jumps the kernel to 6.12.100. Tails calls the scenario unlikely outside of targeted nation-state attacks, but the impact is exactly the kind of threat model this OS was built to defend against. You visit one bad page. The kernel hands you admin rights. Your entire anonymous setup becomes someone else's sandbox.

Strictly speaking, the Tails team says the attack requires a strong adversary with dedicated resources. For most users that's a non-issue. But when you're running Tails to stay off the radar of intelligence agencies or hostile corporations, "unlikely" doesn't mean much. Patch it now.

XML Parser and System-Wide Impact

Then there's the expat XML parser. The previous 7.10 build shipped version 2.7.1, which carries 20 distinct CVEs ranging from memory corruption to full system takeover. Craft a fake XML file, point it at LibreOffice, Audacity, or Git, and you could be looking at privilege escalation across your entire session. The update moves expat to 2.8.2, covering every advisory in Debian's DSA-6404-1.

I remember when the libxml2 and expat bugs back in 2022 turned a simple PDF download into a panic attack for privacy users. The expat situation here feels similar. You don't need to be browsing shady sites to trigger it. Opening a malformed attachment from a colleague does the trick. Tails isn't taking chances.

The patch isn't all red flags and kill switches. Tails is also switching automatic upgrade payloads to zstd compression, which matches the approach already used for USB images. The result is faster boot times and noticeably lighter downloads. The new image comes in roughly 70 MB smaller thanks to stripped firmware blobs, which matters if you're on a flaky connection or a metered link. It's a quiet change that actually helps people chasing download speeds on a hotel Wi-Fi that charges by the megabyte.

If you're on Tails 7.0 or later, the update will roll in automatically through the built-in upgrade tool. Manual USB reinstall works fine too, and your Persistent Storage stays intact.

Tails 7.10 dropped on July 23rd with a new GNOME shutdown screen and Celluloid swapping out the old video player. This patch adds nothing to that feature set. It's strictly damage control. Still, if you're running Tails for actual threat-model protection, delaying this update means leaving the front door unlocked. Head to the upgrade menu and let it run.

Head here for the download.