2026-09-16
Fedora's community respin effort has released a fresh batch of live ISOs dated September 15, repackage Fedora 44 around the current Linux kernel 7.2.5. They're available for nearly every desktop spin, including GNOME, KDE Plasma, MATE, Cinnamon, COSMIC, Xfce, Budgie, LXDE, LXQt, i3, and SOAS. The batch landed the same day Fedora 45 Beta dropped, giving users a current-stable-desktop option without an in-place upgrade.
Ubuntu 24.04.5 LTS (Noble Numbat) shipped on September 10, 2026 as a maintenance point release packing in security patches and high-severity bug fixes for a shorter post-install update cycle. Just days later, a desktop installer crash on the "Extended selection" option forced Canonical to pull the fresh amd64 Desktop ISO. The company rebuilt and reissued it as 24.04.5.1 on September 15, leaving every other artifact, server, cloud, netboot, WSL, and the official flavors, unchanged. Fresh installers should grab the 24.04.5.1 image, while existing 24.04 users can simply upgrade through Update Manager.
Today's roundup covers seven hardware reviews, spanning mini PCs, CPU coolers, OLED monitors, a foldable controller, and a flagship PSU. The GEEKOM A9 Max 2026 packs AMD's Ryzen AI 9 HX 470 but ships an overpriced single-channel base config that throttles performance. Meanwhile, value stands out in the ASRock Rock White 360 AIO at ~$89 and the pocketable Razer Prio controller at $99.99. Overall, the best picks for most buyers are the ASRock AIO and Razer Prio, while the GEEKOM and Noctua coolers are worth it only if configured correctly.
Godot 4.8 Dev 6, the sixth pre-release snapshot of the current feature cycle, announced by Thaddeus Crews. Its headline feature is screen-space contact shadows for directional lights, built on Bend Studios' approach and deliberately capped to eight lights for performance. It landed in under a week because two blockers, a macOS Metal startup crash and a Google Play upload failure, needed quick fixes ahead of September's feature freeze. XR users should note a new OpenXR Spatial Container regression tied to the multi-layer projection camera
GE-Proton 11-7 delivering an 85-patch Wineland overhaul that makes Wine's native Wayland driver finally usable for cross-process child-window rendering. The build extends work first introduced in 11-6, pushing past Valve's own Proton 11 and maturing the path that Windows launchers and embedded web panels rely on. Alongside it lands dozens of targeted fixes for games like Forza Horizon 5, Diablo IV, Black Desert Online, and DOOM Eternal, plus new Sony-to-XInput controller defaults and a rebased video stack. It's a large release, so GloriousEggroll flags several fixes as still needing retesting rather than declaring a clean sweep. Grab the tarball from the GitHub Releases page and force it per game through Steam's Compatibility settings.
The major Linux distributions coordinated a massive security sweep, targeting critical flaws across OpenSSL, nginx, rsync, and kernel networking stacks. Ubuntu’s NVIDIA kernel update alone quietly stuffed roughly three hundred CVEs into a single notice, while Qubes OS closed a dangerous format-string hole in its primary qube management helper. Most advisories land at "Important" severity, meaning systems administrators should prioritize the OpenSSL and kernel bumps on AlmaLinux, Oracle, Rocky, and RHEL before touching anything else. Keep in mind that several patches overlap with earlier HollowByte advisories and new Oracle kernel signing reworks may require matching package versions to keep secure boot functional.
2026-09-15
Devolutions shipped UniGetUI v2026.3.0 on September 15, 2026, its biggest feature release under the company's ownership in a while. The headline updates let you schedule four heavy background tasks—update checks, auto-updates, and local and cloud backups, on independent schedules, plus mark individual packages for automatic updates instead of applying it globally. It also brings real zero-footprint portable mode, expanded Start Menu shortcut controls, and security hardening against PowerShell injection and path-traversal attacks. You can download it from the Microsoft Store, WinGet, Scoop, Chocolatey, or the GitHub Releases page, with Windows, Linux, and macOS builds compiled with NativeAOT.
DXVK 3.1.1 shipped today, about two weeks after the 3.1 update, bringing Adobe Creative Suite support back after a botched SetBackgroundColor call left After Effects 2024 with a blank window. The patch also fixes a shader-compiler crash from ENB shaders, deadlocks in SpellForce 2 and The Sims: Medieval, and a handful of regressions in games like Corpse Party and Rayman 3. There's a recurring warning that some anti-virus software will likely flag the 32-bit builds, though those are almost certainly false positives. At the moment, master is already 21 commits ahead, so this patch is just the latest trim of the ambitious 3.0 rewrite's fallout.
Bazzite just released stable build 44.20260915, the daily Linux gaming distro's latest image built on Fedora's atomic desktops. The biggest change is UMU Launcher shipping for the first time, giving non-Steam Windows games a first-class launch path that shares Proton fixes without needing Steam. Bazzite also turned Wi-Fi power saving off by default to cut wireless latency, though you can still flip it back on inside Steam Gaming Mode. Beyond those two, the build bumps GNOME to 50.4, KDE Plasma to 6.7.5, and a handful of gaming packages, existing users can rebase in place via bazzite-rollback-helper.
NGINX released nginx 1.30.5 (stable) and 1.31.6 (mainline) today, both fixing CVE-2026-90439, a CVSS 6.9 heap buffer overflow in the HTTP/3 module that occurs only with OpenSSL 3.5.0 and earlier. The vulnerability affects versions 1.29.2 through 1.31.5 and can cause worker-process crashes or limited data corruption, though exploitation is non-deterministic and poses no control-plane or remote-code-execution risk. The stable 1.30.5 is a focused security-and-hardening patch, while mainline 1.31.6 additionally bundles bugfixes and new features like the Control API, JSON module, and predicate locations. Sites serving QUIC on older OpenSSL should upgrade soon, while plain HTTP/2 deployments are unaffected by this CVE.
Oracle released VirtualBox 7.2.18 today as a bug-fix and stability maintenance update rather than a feature drop. The release resolves notable crashes, including blue-screen failures on Windows 11 on ARM after saved-state restores and VM-process crashes on Linux hosts with 3D acceleration. It also adds kernel support for Linux 7.3 and RHEL 10.3, fixes VDI differencing image corruption, and patches a Shared Clipboard filename bug. As a practical maintenance update, it is available now from Oracle's download site, though affected users benefit most over those without existing issues.
Fedora shipped the Fedora Linux 45 Beta on September 15, 2026, handing testers a nearly complete preview roughly six months before the final October release. The beta is identical to the September 5 third candidate, meaning it locks in already-approved features rather than rolling out a fresh change set. Headline updates include the userspace kmscon console replacing legacy fbcon, enforced package signature checking, restricted ptrace access for unprivileged users, and a wave of toolchain bumps spanning Python 3.15, Go 1.27, GCC 16.2, and glibc 2.44. It's downloadable in nearly every edition and upgradable from an existing system via DNF, while the companion Asahi Remix adds out-of-the-box support for Apple M3 Macs.
Mango Wayland Compositor 0.17.1 shipped today as a corrective patch for a few regressions plus better cursor capture in Wine-backed games. The release quietly bundled 15 commits of new functionality past the 0.17.0 milestone, including a systemd session target, monitor-cycling keybinds, virtual monitor naming, and a global fullscreen idle-inhibition toggle. A versioning quirk is also worth flagging: the meson.build string stayed at 0.17.0 through 14 of those commits, so many bug reports filed against "0.17.0" actually referenced code now part of 0.17.1. There are no prebuilt binaries, so Arch users can grab the rolling git build with yay -S mangowm-git while other distros lag slightly behind.
Systemd v262-RC3, the third release candidate for its v262 development series, is now live and leans hard into security hardening, reproducible builds, and confidential computing. Its headline changes pin TPM-sealed credentials to the TPM's Storage Root Key to block credential-theft attacks and harden LUKS/TPM2 enrollment PINs with Argon2id. The release also lets systemd be built as a single static PID 1 binary for tiny containers and adds Intel TDX support to systemd-vmspawn alongside AMD's SEV-SNP. It ships a long list of backward-incompatible changes operators should plan for, with two features already marked for removal in v263.
Valve pushed two SteamOS updates to its testing channels on September 14, 2026: the 3.8.27 Beta build and an early 3.9.1 Preview, signaling it is polishing the current 3.8 stable line while prepping the next major release. The 3.8.27 Beta takes a narrow scope, fixing a fan-speed bug that reverts to BIOS control until a reboot, which affects both Steam Deck and third-party hardware.
Floxlor released 2.3.14 today as a full security update, with all four changes tagged [Security] in the changelog. Maintainer Michael Kaufmann (d00p) shipped it as the newest entry in a coordinated hardening sweep across the 2.3.x branch, following similar fixes in 2.3.10, 2.3.11, and 2.3.13. The patches close authorization gaps on server-wide reads, an XSS theme vector, CRLF/FTP injection, and cross-admin mail exposure, alongside two regular bug-fixes. Operators should update sooner rather than later, since at least one fix invalidates active sessions and pushes API-key rotation.
Today's hardware roundup covers two new MSI cases, with the panoramic, back-connect-friendly MAG PANO 110R PZ and the feature-packed MEG Maestro 900R pulling in opposite directions. The FPS Review settles an ongoing upgrade debate, weighing the older Ryzen 7 7700X3D against the Zen 5 9800X3D to see if the jump is worth your money. Asus' 4K ROG Swift PG27UCWM OLED earns its premium billing with 240 Hz at 4K, while two outlets agree the $1059 Steam Frame is excellent hardware held back by its price. Round out the day with a brisk Sandisk Optimus GX Pro 8100 SSD, a featherweight ATK gaming mouse, and be quiet!'s quiet TKL keyboard.
XanMod released three coordinated kernel updates on September 14, 2026, across its MAIN, LTS, and RT branches, matching upstream Linux 7.2.6 and 6.18.52 exactly. This is a security and stability-heavy point release, with roughly 1,800 commits in the mainline build and about 1,490 in the LTS pair. The mainline line centers on a major ksmbd/SMB security overhaul, while the LTS build hands AMD users new power-management knobs like raw EPP writes and plants an early seed of 802.11bn UHR WiFi support. Debian and Ubuntu users can install via XanMod's APT repository, though they should watch for DKMS module compatibility issues with newer kernels.
Heroic Games Launcher has rolled out 2.22.2, the second emergency patch in its 2.22 series and the one that repairs the breakage the first hotfix left behind. The new release focuses on newly reported Rockstar and Ubisoft regressions while also patching a range of other issues. Its standout addition is umu-driven Steam Runtime support for Linux-native GOG games, alongside a Legendary upgrade to 0.21.1 and several stability and Sideload fixes.
Ubuntu re-patches nginx to resolve a regression and close three CVEs, while simultaneously fixing local privilege escalation holes in libinput and dracut that affect the 24.04 and 26.04 releases. SUSE leads the enterprise charge with a Firefox update that quietly closes 139 vulnerabilities across SLE and Micro variants, alongside important patches for clamav and python39. Fedora and RHEL round out the wave with twelve and seventeen advisories respectively, targeting predictable session IDs in perl-Dancer2, memory leaks in perl-Protocol-HTTP2, and widespread nginx fixes across EL8 and EL9. Debian keeps it surgical with a single privilege escalation fix for the L2TP VPN plugin in trixie, though you will need to verify your Ubuntu Pro subscriptions to cover the remaining notices.
[ Archive ]