Product
Last Report

Click here to browse the Windows compatibility database

Click here to browse the Linux compatibility database

Click here to browse the macOS compatibility database

Date: 2026-04-12 18:21 | Last update:



2026-04-12

Security 10942 Published by Philipp Esselbach 0

This week brings a massive wave of patches across major distributions, with Red Hat and its clones facing the most urgent critical vulnerabilities in their Cockpit web interface. Administrators must prioritize these fixes immediately because memory handling flaws can allow remote code execution without authentication on newer platforms. Debian, Ubuntu, Fedora, SUSE, and Slackware users also need to update browsers and kernels to prevent potential security breaches on their networks today. Ignoring these advisories is a fast track to system compromise, so run the update commands for your distribution without delay.

Linux 3335 Published by Philipp Esselbach 0

Trisquel GNU/Linux 12.0 LTS arrives as a Long Term Support release that guarantees security updates until May 2029 while strictly adhering to the free software mandate. The project splits this update into distinct flavors like MATE and KDE for desktops while keeping a barebones LXDE edition alive for those stubborn machines from ten years ago. Users swapping over will find Abrowser 148 and Icedove 140 ship as defaults instead of forcing them to hunt for replacements later on. Kernel choices lean heavily on Linux-libre with version 6.8.x as standard but a Hardware Enablement Stack is available for anyone needing newer driver support.

Debian 10859 Ubuntu 7048 Published by Philipp Esselbach 0

XanMod has dropped new kernel versions 6.19.12 and 6.18.22 LTS/RT for Debian-based distributions that prioritize heavy workload performance over standard stability. These builds include specific optimizations like LLVM ThinLTO and Google's Multigenerational LRU framework to squeeze better throughput out of the hardware. Power users need to exercise caution since NVIDIA drivers and other DKMS modules often break without a manual update following these kernel jumps. Adding the official repository is the safest route to get everything working, provided you install the build dependencies first to avoid compilation headaches later.

SUSE 5616 Published by Philipp Esselbach 0

A series of moderate security advisories has been released for openSUSE Tumbleweed targeting several key packages on the GA media. Users should update libradcli10, tekton-cli, crun, perl-XML-Parser and python315 to resolve multiple identified vulnerabilities within their systems.

openSUSE-SU-2026:10528-1: moderate: libradcli10-1.5.0-1.1 on GA media
openSUSE-SU-2026:10529-1: moderate: tekton-cli-0.44.1-1.1 on GA media
openSUSE-SU-2026:10527-1: moderate: perl-XML-Parser-2.570.0-1.1 on GA media
openSUSE-SU-2026:10524-1: moderate: crun-1.27-1.1 on GA media
openSUSE-SU-2026:10522-1: moderate: python315-3.15.0~a8-1.1 on GA media

Slackware 1245 Published by Philipp Esselbach 0

New OpenSSL packages for Slackware 15.0 and -current fix critical security issues. Security flaws include potential use-after-free errors in DANE client code plus NULL pointer dereferences during CMS processing. Ken Zalewski prepared the patch by backporting from the OpenSSL-3.0 repo because the fixes were originally part of a premium release only available to subscribers.

openssl (SSA:2026-101-01)

Rocky Linux 886 Published by Philipp Esselbach 0

Several important security updates are now available for various packages running on different versions of Rocky Linux. For release nine specifically, users must update nodejs versions 22 and 24 to resolve critical issues within the software environment. Additionally, systems require moderate kernel updates alongside patches for kea and thunderbird across various supported versions.

RLSA-2026:7350: Important: nodejs:24 security update
RLSA-2026:7302: Important: nodejs:22 security update
RLSA-2026:7342: Important: kea security update
RLSA-2026:6917: Important: thunderbird security update
RLSA-2026:6570: Moderate: kernel security update
RLSA-2026:6572: Moderate: kernel-rt security update
RLSA-2026:6571: Moderate: kernel security update

Debian 10859 Published by Philipp Esselbach 0

A batch of Debian security advisories addresses serious vulnerabilities in popular packages including inetutils and webkit2gtk alongside a version upgrade for clamav. Specific flaws allow attackers to escalate privileges or cause process crashes through malicious network inputs and crafted web content. Memory corruption risks within libyaml-syck-perl and the gdk-pixbuf image loader also require immediate attention from system administrators. Upgrading these packages is essential because leaving them unpatched exposes systems to potential remote code execution or denial of service attacks.

Debian GNU/Linux 9 (Stretch) ELTS:
ELA-1680-1 clamav new upstream version

Debian GNU/Linux 9 (Stretch) and 10 (Buster) ELTS:
ELA-1679-1 libyaml-syck-perl security update

Debian GNU/Linux 11 (Bullseye) LTS:
[DLA 4527-1] inetutils security update
[DLA 4528-1] webkit2gtk security update

Debian GNU/Linux 12 (Bookworm) and 13 (Trixie):
[DSA 6206-1] gdk-pixbuf security update
2026-04-11

Software 44274 Published by Philipp Esselbach 0

This update to the Krita AI Diffusion plugin targets the visual artifacts and model errors that often plague generative painting sessions. Artists using Flux models will finally get relief from the border glitches that left ugly lines after internal resizing. Custom workflow creators benefit from a new reset button while seed controls expand to support much larger numbers for precise randomness. Legacy users get a reprieve as the installer attempts pulling older PyTorch versions for GTX cards that typically fail with newer builds.

Linux 3335 Published by Philipp Esselbach 0

Linux Kernel 6.1.168, 6.6.134, 6.12.81, 6.18.22, and 6.19.12 are now available. The USB gadget subsystem took the biggest hit with patches fixing race conditions that caused crashes when users unbound devices or entered suspend modes. Kernel memory safety also gets a boost by ensuring kallsyms and thermal zones handle module removal and power events without dangling pointers. It is exactly the kind of boring update that keeps systems from spontaneously rebooting during critical operations.

Reviews 52609 Published by Philipp Esselbach 0

Hardware reviewers are testing a new Shuttle barebone PC that accommodates modern Intel processors alongside improved cooling systems for the chassis. While budget builders appreciate the MSI air cooler, overclockers might find better value in a Silverstone liquid solution designed for RAM overclocking. The display market sees two significant QD-OLED updates from MSI, both offering high refresh rates and 4K resolution at lower price points than their predecessors. The roundup concludes with praise for Death Stranding 2 as a smarter sequel and an updated entry-level phone that improves specs without increasing costs.

Computers: Shuttle XPC slim DH810 Barebone Review
Cooling: MSI MAG COREFROZR AA13 CPU Cooler Review, Silverstone IceMyst Pro 360 Pro Review: Designed for RAM overclocking
Displays: MSI MPG 322UR QD-OLED X24 Review - Less Expensive and Even Better, MSI MAG 272UP X24 Review (4K/240Hz QD-OLED)
Gaming: Death Stranding 2: On the Beach Review – A brilliant sequel that I warmed up to surprisingly quickly
Mobile: iPhone 17e Review: Apple Just Perfected Its Entry-Level Phone
Power: Cooler Master MWE Bronze V2 230V 650W power supply review: A competent entry-level choice
Speakers: Creative Pebble Nova Review

Ubuntu 7048 Published by Philipp Esselbach 0

Ubuntu issued two security advisories fixing critical flaws in both MongoDB and QEMU software packages. The first notice warns that unauthenticated attackers might access sensitive data through a memory buffer issue within older MongoDB versions supported by Ubuntu 18.04 and 20.04 LTS. The QEMU virtualizer faces several distinct vulnerabilities across Ubuntu 22.04, 24.04, and 25.10 that could allow guest attackers to execute code or crash the system.

[USN-8160-1] MongoDB vulnerability
[USN-8161-1] QEMU vulnerabilities

SUSE 5616 Published by Philipp Esselbach 0

New security advisories have been released for both SUSE Linux Enterprise and openSUSE systems to address various vulnerabilities. Critical kernel live patches are available for multiple service pack levels including the latest updates for SP4 through SP6. Administrators must apply important fixes to specific packages like openssl, tigervnc, and various Python Django versions found on general media immediately. Moderate severity warnings also exist for openSUSE software releases that need attention too.

SUSE-SU-2026:1237-1: important: Security update for the Linux Kernel (Live Patch 47 for SUSE Linux Enterprise 15 SP4)
SUSE-SU-2026:1239-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 15 SP6)
SUSE-SU-2026:1254-1: important: Security update for the Linux Kernel (Live Patch 32 for SUSE Linux Enterprise 15 SP5)
SUSE-SU-2026:1257-1: important: Security update for openssl-1_1
SUSE-SU-2026:1252-1: important: Security update for tigervnc
SUSE-SU-2026:1248-1: important: Security update for the Linux Kernel (Live Patch 28 for SUSE Linux Enterprise 15 SP5)
openSUSE-SU-2026:10514-1: moderate: go1.25-1.25.9-1.1 on GA media
openSUSE-SU-2026:10517-1: moderate: python313-Django6-6.0.4-1.1 on GA media
openSUSE-SU-2026:10513-1: moderate: fontforge-20251009-6.1 on GA media
openSUSE-SU-2026:10516-1: moderate: python311-Django4-4.2.30-1.1 on GA media
openSUSE-SU-2026:10511-1: moderate: MozillaFirefox-149.0.2-1.1 on GA media
openSUSE-SU-2026:10510-1: moderate: sudo-1.9.17p2-2.1 on GA media
SUSE-SU-2026:1242-1: important: Security update for the Linux Kernel (Live Patch 45 for SUSE Linux Enterprise 15 SP4)

Rocky Linux 886 Published by Philipp Esselbach 0

Rocky Linux administrators need to apply new security patches for multiple packages including git-lfs and grafana variants. These advisories apply to systems running operating system versions eight through ten. While most notices are marked as important, a single update concerning libtiff is rated moderately due to lower risk factors. Detailed severity scores derived from the Common Vulnerability Scoring System list remain available for every identified issue via the official links.

RLSA-2026:7005: Important: git-lfs security update
RLSA-2026:7081: Moderate: libtiff security update
RLSA-2026:7259: Important: git-lfs security update
RLSA-2026:7011: Important: grafana security update
RLSA-2026:7009: Important: grafana-pcp security update

Red Hat 9386 Published by Philipp Esselbach 0

Security updates for cockpit are now available to address a serious flaw affecting Red Hat Enterprise Linux versions nine through ten. Attackers could potentially execute remote code without authentication by exploiting an injection vulnerability within SSH command line arguments. Red Hat Product Security has officially rated this issue as critical because of the high risk it poses to system integrity.

RHSA-2026:7382: Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection
RHSA-2026:7384: Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection
RHSA-2026:7383: Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection
RHSA-2026:7381: Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection

Debian 10859 Published by Philipp Esselbach 0

Debian security teams have released urgent updates for firefox-esr, chromium, and libyaml-syck-perl across several distributions. Firefox users need to install the new version to stop flaws that might enable arbitrary code execution through browser exploits. Across stable distributions, Chromium requires a massive patch covering dozens of CVEs designed to prevent denial of service attacks or data leaks. The perl library update fixes critical memory issues where missing terminators could allow attackers to read adjacent variables unexpectedly.

Debian GNU/Linux 10 (Buster) ELTS:
ELA-1679-1 libyaml-syck-perl security update

Debian GNU/Linux 11 (Bullseye) LTS:
[DLA 4526-1] firefox-esr security update

Debian GNU/Linux 12 (Bookworm) and 13 (Trixie):
[DSA 6205-1] chromium security update

AlmaLinux 2538 Published by Philipp Esselbach 0

AlmaLinux has issued numerous security updates for versions eight through ten. Covering applications ranging from database servers to font editors, these advisories highlight critical flaws that allow attackers to execute arbitrary code on vulnerable systems. Specific vulnerabilities include heap buffer overflows and uninitialized variables that enable remote code execution alongside denial of service attacks. System administrators should review the linked CVE pages to understand the impact and apply the necessary fixes immediately through their package managers.

ALSA-2026:6799: freerdp security update (Important)
ALSA-2026:6906: nginx security update (Important)
ALSA-2026:7080: nodejs22 security update (Important)
ALSA-2026:6463: openssh security update (Important)
ALSA-2026:7081: libtiff security update (Moderate)
ALSA-2026:6631: fontforge security update (Important)
ALSA-2026:6766: python3.9 security update (Important)
ALSA-2026:6923: nginx:1.24 security update (Important)
ALSA-2026:6462: openssh security update (Important)
ALSA-2026:6628: fontforge security update (Important)
ALSA-2025:4049: libtasn1 security update (Moderate)
ALSA-2025:4063: ruby:3.1 security update (Moderate)
ALSA-2025:2872: pcs security update (Important)
ALSA-2025:11047: pcs security update (Moderate)
ALSA-2025:3210: container-tools:rhel8 security update (Important)
ALSA-2025:3026: kernel security update (Important)
ALSA-2024:10987: pcs security update (Moderate)
ALSA-2025:3027: kernel-rt security update (Important)
ALSA-2025:3388: python-jinja2 security update (Important)
ALSA-2025:4048: xmlrpc-c security update (Moderate)
ALSA-2025:8254: pcs security update (Important)
ALSA-2025:12527: virt:rhel and virt-devel:rhel security update (Moderate)
ALSA-2026:6750: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, and gstreamer1-plugins-good security update (Important)
ALSA-2026:6949: go-toolset:rhel8 security update (Important)
ALSA-2026:6915: vim security update (Important)
ALSA-2026:6918: freerdp security update (Important)
ALSA-2026:6391: mysql:8.4 security update (Moderate)
ALSA-2026:6435: mariadb:10.11 security update (Moderate)
ALSA-2026:6461: openssh security update (Important)

[ Archive ]