2026-09-25
The Fedora RISC-V community published non-official Server, Cloud, and Container Beta images for Fedora 45 on September 25, giving developers a way to test the OS on real RISC-V hardware. The Server builds come in two flavors: a stable "Generic" kernel close to upstream and the broader "Omni" kernel that supports more boards at the cost of less-tested code. These images remain community-contributed rather than officially supported, so they're aimed at testing and building packages rather than production servers. If you've got a board like the VisionFive 2 sitting around, you can download them from Fedora's public infra and boot via QEMU or physical hardware.
Two Linux kernels have been released today. Kernel 7.2.8 bringing roughly 438 commits and LTS 6.18.54 around 397. Both are bug-fix and security backports led by Greg Kroah-Hartman, with the latest 6.18.54 supported until December 2028. The biggest changes target SMB/CIFS networking hardening, AMD GPU and IPsec fixes, and improved wireless and filesystem reliability.
A wave of distro security advisories landedtoday, and the same cluster of flaws is showing up across AlmaLinux, RHEL, Oracle Linux, Rocky Linux, and SUSE. The most urgent target is unbound, which received Critical ratings for DNSSEC remote code execution on nearly every major distribution. Fedora's webkitgtk 2.54.0 jump quietly fixed hundreds of ANGLE and Skia CVEs on top of its listed 26 WebKit bugs. If you run a DNSSEC resolver or a Chromium-based browser on any of these distros, point your patch commands at those two first.
VS Code 1.139.1 shipped on September 25, 2026 as a patch release, so the remote agent sessions and faster session lists you may have seen advertised had already arrived in 1.139. Only one of its four commits changes product behavior, fixing how managed settings behave when a server refresh fails. Before the patch, a failed refresh silently dropped enterprise policy controls for as long as the gap lasted, leaving restrictions quietly lifted every hour. The remaining three commits are release housekeeping: a version bump, a merge, and a skip for a flaky Linux test whose real fix sits on main.
Mageia 9 reached end of support on 30 September 2026, ending all security updates and patches for the ninth release of the community-run Linux distribution. The announcement, posted 25 September 2026 by contributor joselp on the official Mageia Blog, asked users to migrate to the current stable release, Mageia 10. Since unsupported releases stop receiving security advisories, devices still on 9 will remain exposed to any newly found vulnerabilities, especially servers. Users can upgrade in place through the system-tray tool or command line, or perform a clean install while being careful to back up any data first.
Amethyst Mod Manager 2.5.2 as a focused bug-fix release from independent developer ChrisDKN. The main fix repairs meson build files that were overlooked in 2.5.1 and would have broken collection installs, a core feature. Additional patches address UI scaling on handhelds like the Steam Deck, text legibility under certain themes, and regressions in the RDR2 and BSA/BA2 handlers.
The GMKtec Evo-X3 is the standout of today's reviews roundup, packing a Strix Halo chip and 128GB of unified memory into a mini PC that Tom's Hardware crowned its best AI machine, though $3,799.99 doubles its predecessor's price amid a market-wide RAM shortage. ASRock is making value headlines on two fronts: the X870E Challenger Wi-Fi White earns an Editors' Choice at $229 with flagship features, while the older X870 Challenger WiFi drops to just $170 at the cost of shared M.2 and USB4 lanes. On keyboards, the EPOMAKER HE75 V2 TMR takes Funky Kit's Editors' Choice at $129.99 with a versatile magnetic-mechanical hybrid design, beating out the faster but overpriced Razer Huntsman V3 Pro Low-Profile at €259.99. Meanwhile the MSI PRO B550M-P (2026) refreshes AM4 at $74.99 for budget rebuilders, and TechPowerUp's 35-GPU benchmark reveals Silent Hill: Townfall's lack of Intel XeSS and frame generation leaves AMD/Intel users needing DLSS or FSR.
Remi Collet refreshed his remi RPM repository on 25 September 2026, shipping patched PHP 8.5.11, 8.4.26, 8.3.35, and 8.2.34 for RHEL-family systems. The rebuild addresses a security cycle covering ten CVEs, including an FPM IPv6 ACL bypass, a TLS hostname-verification fallback, and cross-origin credential leaks, and Remi rates the update as strongly recommended. Packages are available in the remi-modular repository for RHEL 8 through 10 and Fedora 43 and up, built for both x86_64 and aarch64. Admins should verify the patched string across every SAPI after upgrading, and those still on the end-of-life PHP 8.1 should migrate to a supported branch.
openSUSE Leap 16.1 has entered its Release Candidate phase and is targeting a November 2026 general availability date. The project is running roughly a week behind its own roadmap but has no known release blockers as it produces about one build per week. The update brings major bumps across the stack, including KDE Plasma 6.6.4, QEMU 11, MariaDB 12, PHP 8.5, and LLVM 21. Most notably, Leap 16.1 will ship the same day as SLES 16.1, so users get enterprise-grade security patches immediately rather than waiting for a separate community update.
Faugus Launcher 2.4.1 has been released. The lightweight GTK4 app wraps the open-source UMU-Launcher to run Epic, GOG, and standalone non-Steam games on Linux without a terminal. Its main upgrade is a from-scratch backup system that lets you save individual games, prefixes, shortcuts, and Proton builds, plus layout tweaks, tabbed Settings, and per-game logging. Install 2.4.1 over 2.4.0 anyway since it's the version that actually cleared the store's review.
Samba 4.25.0 shipped as the first stable release of the new 4.25 series, opening the feature track for new deployments. The headline addition is experimental SMB3 persistent handles, which let clients keep open file handles valid after a server restart or outage to support transparent failover for VM storage and clustered databases. The release also adds a cluster functional level for safe rolling upgrades, cluster-wide rate limiting via a new ratelimitd daemon, and a Ceph RGW module that exports object storage buckets as SMB shares. Finally, AES encryption becomes the default for domain authentication under CVE-2026-20833, though the persistent handles remain experimental, carrying real performance costs and POSIX/NFS interoperability trade-offs.
Ungoogled Chromium 154.0.8037.57-1 has been released on top of Chromium 154.0.8037.57, the point release Google pushed to its stable channel two days earlier. That Chromium build carries an unusually large 108 security fixes, including a spread of Critical flaws in the GPU, graphics stack, and memory handling. The project strips out Google's web-service dependencies using a domain-substitution trick that reroutes every known Google domain to a dead qjz9zk address, though it keeps Safe Browsing off by default.
Goverlay 1.9.3 shipped today, adding native ReShade support to the popular open-source Linux gaming tool that wraps MangoHud, vkBasalt, and upscalers behind a clean GUI. The release also overhauls the bgmod launch wrapper to remove stray logs, preserves proxy DLLs, and fixes a Steam hang, while a new "Tweaks" tab manages per-game launch arguments. Maintainer Benjamim Gois, working with community contributors, tied the fixes directly to filed issues, closing requests on custom variables, launch commands, and ReShade duplicate effects.
2026-09-24
ML4W OS Dotfiles v2.16 shipped today, moving the dock into a standalone repository and collapsing configuration into single JSON files for the first time. The update wraps up the project's switch to Quickshell, dropping Waybar and nwg-dock-hyprland to fix Fedora 44 breaks while adding a new command-line tool for managing the dock. New features include a sidebar blue light filter switch, an option to route right-click clock actions to a custom calendar app, and shortcuts for opening your dotfiles and backup folders. Old config paths are gone, so users upgrading from v2.15.1 need to check their settings before installing since the dock autohide toggle has also moved into the new dock dialog.
KDE released the second beta of Plasma 6.8 today, carrying the pre-release number 6.7.91 ahead of the stable launch later this year. The headline update expands Union theming to legacy QtWidgets apps like Dolphin and Kate, finishing the second half of the engine's public preview. Kup, the btrfs-based backup scheduler, joins Plasma as a first-class module, making automatic backups to an external disk straightforward. The build also cuts X11 login support, defaults NVIDIA triple buffering, and packs in HDR, screen recording, and remote desktop improvements.
Rails 7.2.4 shipped as the fourth patch in the 7.2 line, bringing performance and reliability fixes with no new features or security advisories. Active Record took the biggest changes, including a method_missing performance regression fix and better PostgreSQL connection resilience under timeouts. Action Pack now returns a proper 405 Method Not Allowed for unsupported HTTP verbs, and several components picked up smaller speedups and parsing corrections. The core team recommends upgrading since patch releases preserve API compatibility, so expect no code changes.
Ruby on Rails 8.1.4 shipped today as a maintenance patch signed by release manager Rafael Mendonça França. It updates every core gem to 8.1.4, requires Ruby 3.2 or newer, and adds no new features or breaking changes. The release's most notable fixes include a denial-of-service guardrail on integer string coercion in Active Model, database connection-pool timeout handling in Active Record, and corrections for composite primary keys. Because it breaks no APIs, it's a recommended low-risk update for anyone still running the 8.1 line.
PostgreSQL 19 Beta 4 shipped today as the penultimate pre-release ahead of an October release candidate and possible general availability. It introduces a unified REPACK maintenance command with a CONCURRENTLY option, a WAIT command for reliable read-your-writes replication, and parallel autovacuum with a new scoring system. In a rare move, the community reverted several ambitious features, including SQL/PGQ, online checksum toggling, and partition merge/split, to protect reliability and the schedule. Operators should weigh breaking changes like JIT now off by default, RADIUS authentication removed, and forced standard_conforming_strings before upgrading.
Amethyst, the open-source Linux-native mod manager, just shipped version 2.5.1, adding official modding support for Hades and Hades II. The update folds a long-separate mod importer directly into the app, bringing the supported-game roster to nearly 100 titles. It also packs faster Nexus browsing, pausable downloads, and fixes to real installation bugs that broke Baldur's Gate 3 and Wabbajack modlists. Developed solo by ChrisDKN, the GPL-3.0 app is available via AppImage, Flatpak, and AUR, with a built-in update notifier.
Today's daily Linux security roundup landed across eight distros, led by Fedora's massive Chromium update carrying 58 CVEs. Critical fixes went to the unbound DNS resolver in both Red Hat and Rocky Linux, while Apache Unbound, IPA, and the Ansible Automation Platform also drew top-severity flags. Firefox, PostgreSQL, and the container toolchain (podman, runc, containernetworking-plugins) show up across nearly every distro, though patch effort varies by release. And in a rare twist, USN-8287-2 is Ubuntu apologizing for regressing its own earlier XDG Desktop Portal fix.
Mir 2.30.0 has shipped, bringing Canonical's Wayland compositor one step closer to a Rust-first future by making Rust a hard requirement to build. The server library's ABI was bumped to 69 while every other library stayed stable, so only shells and apps linked against mirserver need recompiling. Beyond the language shift, the release adds wl_fixes support, a typed wl_array wrapper, and fixes a long-standing multi-monitor regression on GBM/KMS hardware. For the first time, Canonical also published a formal roadmap outlining plans from Ubuntu 26.10 onward, including a Rust-based compositor and hardware-accelerated video playback.
Fwupd 2.1.8, the open-source Linux firmware-update daemon, released on 24 September 2026 with new cryptographic checks and more than twenty bug fixes. Its two headline features are a plugin that syncs bootupd when the EFI System Partition changes, and RSA-3072 signature verification for Lenovo accessories. Most of the release closes memory-safety holes attackers love, including a Synaptics buffer overwrite, a FocalTech integer underflow, and an LZMA decompression cap. Users on Fedora, Ubuntu, Debian, RHEL and other distros get the fixes automatically through their normal update flow, or via the fwupdmgr command line.
Today's reviews split neatly between budget parts that punch above their weight and gear that charges a premium without much reward. The NZXT S5 RGB ($49.99) and Lian Li RBO750B ($69.99) deliver surprising value, while the Corsair Warthog RS and be quiet! 1200W PSU ask for a premium worth debating. Sony's INZONE M10S II OLED pushes 540Hz with a refresh-saving matte coating, and both the Razer Viper V4 Pro and Logitech G Pro X3 have driven mouse latency to a sub-0.02ms floor. The broader takeaway is that efficiency, noise, and latency gaps between budget and flagship hardware have never been narrower.
Valve has shipped SteamVR Beta 2.18.1, which rebrands the default VR environment as "Aurora" and makes it the new factory-default shell. The update adds content-aware color tinting, gamepad-driven system UI navigation, and a bunch of binding and streaming fixes for Input and Steam Link. Linux gamers get the most tangible benefits, with fixes for async reprojection on AMD GPUs, GPU selection, and systems without systemd. All signs point toward Valve staging the software for its upcoming standalone Steam Frame headset, though no date or price has been announced.
Wireshark shipped two coordinated security updates with version 4.6.9 for its current stable line and 4.4.19 for the older "old stable" branch. Together the two releases close at least 35 vulnerabilities across the protocol dissectors that power the tool, with 19 fixes in 4.6.9 and 16 in 4.4.19. Most bugs are local crashes that require opening a crafted capture file, but several can be triggered remotely and a handful carry RCE potential, including defects flagged by Trend Micro's Zero Day Initiative. The updates add no new features, so the guidance is to patch both installations while verifying the signed tarballs before install.
Debian has launched the Inference Portal at inference.debian.net, a new service giving contributors shared, free AI model access sponsored by Scaleway's credits. Only active Debian Developers and Maintainers can sign in with their Salsa accounts to get an OpenAI-compatible API key, with two models available: DeepSeek V4 Flash and Zhipu's GLM-5.2. It's the infrastructure payoff from a razor-thin August 2026 vote that narrowly permitted AI-assisted contributions, and it enforces fair-use budgets ($25/week for developers, $10 for maintainers) while keeping prompt data in France under Scaleway's zero-retention policy.
Node.js 22.23.3 hit the shelves on September 23, 2026, as the latest patch in the 'Jod' LTS line. Its headline fix closes a heap use-after-free in the HTTP/2 stack that could crash servers or enable remote code execution. The release also adds two Node-API functions hat help native addon authors.
AM, the open-source AppImage package manager, has released version 10.6, adding the ability to run multiple instances at once without installations colliding. The feature fixes a problem introduced in 10.5, where users clicking "Install" too quickly would trigger conflicting operations and break in-progress downloads. The release also coincides with a catalog milestone of 3,000 AppImages across 3,594 unique applications, grown largely by volunteer contributors.
SparkyLinux 2026.09 "Tiamat" shipped as a semi-rolling Debian testing release, adding its first official Wayland edition built around the lightweight Labwc compositor. The new Labwc image is a bare-bones MinimalGUI build for power users, reusing Openbox's familiar configs while leaving out admin tools like Synaptic and Calamares. Beyond Wayland, "Tiamat" refreshed the stack across the board with Linux kernel 7.2.6, GCC 16, Python 3.14, and fresh desktop versions for KDE Plasma, MATE, Xfce, and LXQt. All seven amd64 ISOs are available to download now, though the GameOver, Multimedia, and Rescue special editions are still pending their update.
System76 has published COSMIC Epoch 1.9.0, the latest point release for its Rust-based desktop that now ships as the default in Pop!_OS. The update focuses on two new first-class apps: a bundled on-screen keyboard called cosmic-osk and a native image viewer and markup tool called cosmic-viewer. It also adds git-lfs as a required dependency and refreshes dozens of underlying components. Pop!_OS 24.04 LTS users will get it through a normal system update, while other distros can track the tagged release on GitHub and community repos.
[ Archive ]