News & Information       http://info.owt.com

Linux

07/30/2026   LinuxSecurity.com
Multiple vulnerabilities in ruby-rack can lead to denial of service, information disclosure, and potential request smuggling, with fixes available in updated versions for Debian 11 and 12.
07/30/2026   LinuxSecurity.com
On July 30, 2026, Mageia released updates to address a security vulnerability (CVE-2026-58055) related to HTTP request/response smuggling in versions 10 and 9.
07/30/2026   LinuxSecurity.com
Mageia 10 released updated packages addressing CVE-2026-9064, which resolves an unbounded LDAP controls count vulnerability leading to CPU and heap amplification and potential remote denial of service.
07/30/2026   LinuxSecurity.com
Mageia has released security updates for versions 9 and 10, addressing multiple vulnerabilities identified by CVEs 2026-9698 through 2026-60082.
07/30/2026   LinuxSecurity.com
Mageia has released updates to address three security vulnerabilities affecting versions 10 and 9, including heap buffer overflows related to bitmap scaling and font parsing.
07/30/2026   LinuxSecurity.com
SUSE has released an update for ImageMagick addressing three vulnerabilities, including heap buffer overwrite and code injection, for several versions of SUSE Linux Enterprise Server.
07/30/2026   LinuxSecurity.com
A security update for ImageMagick addresses three vulnerabilities, including buffer overflows and code injection, for SUSE and openSUSE products, enhancing overall application security.
07/30/2026   LinuxSecurity.com
A security update for ImageMagick addresses three vulnerabilities, including heap buffer overflows and code injection, affecting multiple SUSE products. Users are advised to apply the update.
07/30/2026   LinuxSecurity.com
A recent update for ImageMagick addresses five vulnerabilities, including heap buffer overflows and a memory leak, affecting various SUSE Linux Enterprise products.
07/30/2026   LinuxSecurity.com
A security update for perl-DBI addresses six vulnerabilities in various SUSE products, enhancing protection against issues such as arbitrary code execution, process crashes, and unauthorized file access.
07/30/2026   LinuxSecurity.com
A security update for perl-DBI addresses six vulnerabilities in various SUSE Linux products, including issues leading to arbitrary code execution and process crashes, effective with installation commands.
07/30/2026   LinuxSecurity.com
A security update for prometheus-ha_cluster_exporter addresses CVE-2026-39821, resolving a validation bypass and privilege escalation issue in various SUSE products. Users should apply the necessary patches.
07/30/2026   LinuxSecurity.com
A security update for apptainer addresses two vulnerabilities, fixing issues with privilege escalation and handling invalid UTF-8 input, applicable to several SUSE and openSUSE products.
07/30/2026   LinuxSecurity.com
SUSE has released a security update for apptainer addressing two vulnerabilities, CVE-2026-39821 and CVE-2026-56852, affecting multiple SUSE products, with installation instructions provided.
07/30/2026   LinuxSecurity.com
SUSE announced a security update for Tomcat 10, addressing two vulnerabilities, CVE-2026-59083 and CVE-2026-59084, along with several bug fixes and improvements to Tomcat version 10.1.57.
07/30/2026   LinuxSecurity.com
SUSE announced a security update for Tomcat addressing two vulnerabilities, including URL decoding issues, applicable to several SUSE Linux Enterprise products and requiring installation via zypper.
07/30/2026   LinuxSecurity.com
A security update for liboqs and oqs-provider addresses three vulnerabilities, includes five security fixes, and introduces various algorithm updates and optimizations for affected SUSE products.
07/30/2026   LinuxSecurity.com
SUSE has released an important security update for liboqs and oqs-provider, addressing multiple vulnerabilities, including issues in signature verification and uninitialized pointers, alongside algorithm deprecations and optimizations.
07/30/2026   LinuxSecurity.com
A security update for prometheus-ha_cluster_exporter addresses CVE-2026-39821, fixing a validation bypass and implementing additional features for SUSE Linux Enterprise Server for SAP Applications.
07/30/2026   LinuxSecurity.com
SUSE released an important security update for python-sh, addressing CVE-2026-54552, which involves an incomplete privilege drop vulnerability affecting multiple SUSE products.
07/23/2026   Linux Journal
Linux Kernel 7.1.4 Released with Bug Fixes, Security Updates, and Hardware Improvements

Greg Kroah-Hartman has announced the release of Linux Kernel 7.1.4, the latest stable maintenance update for the Linux 7.1 series. As with other stable kernel releases, version 7.1.4 focuses on fixing bugs, improving hardware compatibility, and addressing security and reliability issues without introducing new features. The update became available on July 18, 2026, and users of the Linux 7.1 branch are encouraged to upgrade as soon as possible.

Rather than changing the kernel's feature set, Linux 7.1.4 delivers dozens of targeted fixes collected from developers across multiple kernel subsystems, helping ensure a more stable experience for desktops, servers, embedded devices, and cloud deployments.

Another Important Stable Maintenance Release

The Linux stable branch exists to provide safe updates between major kernel versions. Every stable release undergoes review before being published and contains fixes that have already been tested in the mainline kernel.

Linux 7.1.4 continues this process by incorporating patches that resolve regressions, improve system stability, and fix issues reported by users since the release of Linux 7.1.3.

For most users, these maintenance updates are recommended because they improve reliability without altering existing functionality.

Bug Fixes Across Multiple Kernel Subsystems

Like previous stable releases, Linux 7.1.4 includes fixes spanning many areas of the kernel.

The update addresses issues affecting:

  • Memory management
  • File systems
  • Networking
  • Device drivers
  • Architecture-specific code
  • Core kernel infrastructure
  • USB and storage subsystems

These targeted patches help eliminate crashes, improve compatibility with newer hardware, and resolve edge cases that may only appear under specific workloads.

Improved Hardware Compatibility

One of the ongoing goals of Linux stable releases is expanding support for existing and newly released hardware.

Linux 7.1.4 includes updated drivers and compatibility fixes for various devices, helping improve support for:

  • Graphics hardware
  • Storage controllers
  • Networking devices
  • USB peripherals
  • Laptop components
  • ARM development boards

Although no major driver additions are expected in a maintenance release, incremental improvements like these often resolve hardware-specific bugs reported by users after earlier releases.

Security and Reliability Updates

Stable kernel releases also include security-related fixes that have been accepted into the maintenance branch.

07/21/2026   Linux Journal
Firefox 153 Released with HDR Video, Smarter PDF Tools, Better Privacy, and New Linux Improvements

Mozilla has officially released Firefox 153, bringing another round of improvements to its open-source web browser. The latest version introduces new multimedia capabilities, enhanced PDF editing tools, stronger privacy protections, better support for modern web technologies, and several features aimed at improving the browsing experience across Linux, Windows, and macOS. Firefox 153 became available on the stable release channel on July 21, 2026.

While this isn't a major redesign, Firefox 153 delivers a collection of practical updates that benefit both everyday users and web developers.

HDR Video Playback Comes to Windows

One of the headline features in Firefox 153 is support for High Dynamic Range (HDR) video playback on compatible Windows systems.

Users with HDR-capable displays and Windows HDR enabled can now enjoy richer colors, improved contrast, and brighter highlights when watching supported online video content. Mozilla notes that certain laptop displays offering only "HDR video streaming" are not currently supported, and some HDR videos recorded on mobile phones may still have limitations.

Although this feature is Windows-specific, it represents another step toward bringing Firefox in line with modern multimedia standards.

PDF Editing Becomes Even More Powerful

Mozilla continues expanding Firefox's built-in PDF editor, eliminating the need for third-party applications in many situations.

Firefox 153 introduces the ability to:

  • Merge multiple PDF documents
  • Insert images as new PDF pages
  • Continue using existing editing tools such as annotations, page organization, and text editing

These additions make Firefox an even more capable document viewer and editor, especially for users who frequently work with PDF files.

Stronger Privacy and Permission Controls

Privacy remains one of Firefox's biggest selling points, and version 153 introduces several enhancements designed to give users more visibility and control over website permissions.

New improvements include:

  • A visual indicator when a website is actively accessing your location
  • More restrictive default permissions for browser extensions accessing local files
  • Local Area Network (LAN) restrictions enabled by default for all users

These changes reduce unnecessary exposure of local resources while making it easier to understand what websites and extensions can access.

Experimental JPEG XL Support

Firefox 153 also adds experimental support for the JPEG XL image format, which many developers consider a promising successor to older image standards.

JPEG XL offers several advantages, including:

07/16/2026   Linux Journal
NanoKVM-Go Brings AI-Powered Hardware Control to Linux with a Compact USB-C KVM

Sipeed has introduced NanoKVM-Go, a compact USB-C KVM-over-IP device that combines remote hardware management with AI integration. Designed for Linux, Windows, macOS, and other USB-C devices, NanoKVM-Go allows users to remotely view and control a system through a web browser while exposing its keyboard, mouse, and display functions to AI agents via the Model Context Protocol (MCP).

Unlike traditional KVM-over-IP solutions that require multiple cables and dedicated networking hardware, NanoKVM-Go simplifies the setup into a single USB-C connection, making remote administration and AI-assisted automation more accessible for developers, system administrators, and homelab enthusiasts.

A Portable USB-C KVM

NanoKVM-Go is roughly the size of a smartwatch, measuring about 45 × 40 × 15 mm, yet it combines several functions into a single device.

Key hardware features include:

  • USB-C connection for video, audio, keyboard, mouse, and power
  • Wi-Fi 6 connectivity
  • Browser-based remote management
  • Support for virtual USB storage
  • Built-in Tailscale integration for secure remote access
  • Fanless aluminum enclosure with low power consumption

Because it connects over USB-C using DisplayPort Alt Mode, the device can manage a wide variety of hardware without requiring software installation on the target system.

Designed for Linux and Beyond

NanoKVM-Go supports numerous USB-C devices, including:

  • Linux desktops and laptops
  • Windows PCs
  • macOS systems
  • Mini PCs
  • Steam Deck
  • Android devices with DisplayPort Alt Mode
  • iPhone 15 and newer models
  • Tablets supporting USB-C video output

For Linux users, this provides an easy way to perform BIOS configuration, operating system installation, kernel debugging, or remote troubleshooting—even when the operating system is unavailable.

AI Integration Through MCP

One of NanoKVM-Go's defining features is its AI-native design.

Rather than simply streaming a desktop remotely, the device exposes its KVM functions as an MCP (Model Context Protocol) server, allowing compatible AI agents to interact with the connected computer using hardware-level keyboard and mouse input.

This enables AI systems to:

  • View the screen
  • Move the mouse
  • Type on the keyboard
  • Launch applications
  • Navigate user interfaces
  • Complete repetitive desktop workflows

Because control happens at the hardware level, AI agents can interact with systems regardless of the operating system installed.

07/14/2026   Linux Journal
AI Uncovers a 15-Year-Old Linux Kernel Root Vulnerability Hidden Since 2011

Artificial intelligence has helped uncover one of the most significant Linux kernel security flaws in recent years. Security researchers at Nebula Security announced the discovery of GhostLock (CVE-2026-43499), a critical local privilege escalation vulnerability that remained hidden in the Linux kernel for approximately 15 years before being identified by the company's AI-powered vulnerability research platform, VEGA.

The vulnerability affects Linux kernels dating back to version 2.6.39 (2011) and allows an unprivileged local user to obtain full root privileges on vulnerable systems. Its discovery not only highlights the importance of timely kernel updates but also demonstrates how AI is beginning to transform vulnerability research.

What Is GhostLock?

GhostLock is a use-after-free (UAF) vulnerability located in the Linux kernel's futex (fast userspace mutex) implementation.

Futexes are synchronization primitives that allow user-space applications to efficiently coordinate access to shared resources while minimizing expensive kernel interactions. Because they are widely used throughout Linux, any flaw within this subsystem can have broad security implications.

According to Nebula Security, incorrect handling of the remove_waiter() function can leave behind a dangling kernel pointer that an attacker can manipulate to execute arbitrary code with kernel privileges.

A Reliable Path to Root Access

One of the reasons GhostLock has attracted so much attention is the reported reliability of the exploit.

Researchers demonstrated that an attacker with nothing more than a standard local user account can escalate privileges to root in roughly five seconds, with a reported success rate of 97% on vulnerable systems.

Unlike many kernel exploits that are unstable or require highly specific system configurations, GhostLock appears to be both practical and repeatable, making it particularly concerning for administrators.

Container Escapes Are Also Possible

The implications extend beyond traditional Linux desktops and servers.

Researchers report that GhostLock can also be used to escape containers and compromise the underlying host operating system. Because containers share the host kernel, a successful privilege escalation inside a container can potentially grant root access to the host itself.

This makes the vulnerability especially important for environments running:

07/09/2026   Linux Journal
Azure Linux 4.0 Released: Microsoft Expands Its Enterprise Linux Platform Beyond the Cloud

Microsoft has officially unveiled Azure Linux 4.0, the latest version of its open-source Linux distribution designed for cloud infrastructure, enterprise workloads, and modern data centers. Formerly known as CBL-Mariner, Azure Linux has powered Microsoft's internal cloud services for years, but version 4.0 marks its biggest evolution yet by becoming a general-purpose server operating system that organizations can deploy both inside and outside Azure.

The release introduces updated core components, expanded hardware support, a predictable long-term lifecycle, and improved compatibility for enterprise environments, reinforcing Microsoft's growing investment in the Linux ecosystem.

A New Chapter for Azure Linux

Azure Linux began as Microsoft's internal operating system for Azure services, containers, and cloud infrastructure. Over time, it evolved into the foundation for many Azure-hosted workloads.

With Azure Linux 4.0, Microsoft is positioning the distribution as a broader enterprise Linux platform rather than one limited to Azure infrastructure. The operating system is now available through Azure virtual machine images, container images, and downloadable ISO files for testing and deployment in a wider range of environments.

Built for Enterprise and Cloud Workloads

Unlike desktop-focused Linux distributions, Azure Linux is optimized for infrastructure, virtualization, containers, and cloud-native applications.

Typical deployment scenarios include:

  • Cloud virtual machines
  • Kubernetes clusters
  • Container hosts
  • AI infrastructure
  • Edge computing
  • Enterprise servers

Microsoft has designed the distribution to provide a consistent operating system foundation across Azure services while remaining suitable for on-premises deployments.

Updated Core Components

Azure Linux 4.0 modernizes much of the operating system's software stack.

Highlights include:

  • Linux Kernel 7.0
  • glibc 2.42
  • OpenSSL 3.5
  • Python 3.13
  • OpenSSH 10
  • dnf5 as the default package manager

These updates improve hardware compatibility, application support, security, and overall system performance while providing developers with a more current software platform.

Security Remains a Primary Focus

Security continues to be one of Azure Linux's defining characteristics.

Version 4.0 includes:

07/07/2026   Linux Journal
KDE Plasma 6.7.1 Released with Stability Fixes, UI Improvements, and Better Wayland Reliability

The KDE Project has officially released KDE Plasma 6.7.1, the first maintenance update for the Plasma 6.7 desktop environment. Rather than introducing major new features, this point release focuses on polishing the desktop with a broad collection of bug fixes, translation updates, and performance improvements aimed at making Plasma 6.7 more reliable for everyday use.

As with previous Plasma maintenance releases, KDE developers have concentrated on resolving issues reported by the community soon after the launch of Plasma 6.7, ensuring users receive a smoother and more stable desktop experience.

A Maintenance Release Focused on Stability

KDE Plasma 6.7 introduced numerous new capabilities, including per-display virtual desktops, Wayland session restore, improvements to Plasma Bigscreen, and a refreshed theming system. Plasma 6.7.1 builds on that foundation by addressing early regressions and fine-tuning the overall desktop experience.

The update primarily delivers:

  • Bug fixes across core Plasma components
  • Updated translations
  • Performance refinements
  • Improved desktop reliability
  • Better overall user experience

Improvements Across the Desktop

Several of Plasma's core applications and components receive fixes in this release.

Notable improvements include:

  • Better reliability in the Kickoff Application Launcher
  • Fixes for Discover, KDE's software manager
  • Improvements to the KWin window manager
  • Various panel and desktop behavior corrections
  • Better handling of notifications and user interface elements

While most of these changes are relatively small on their own, together they help eliminate many of the rough edges users may have encountered after upgrading to Plasma 6.7.

Wayland Continues to Mature

Wayland remains the primary development focus for KDE Plasma, and version 6.7.1 continues refining the experience.

The update includes fixes affecting:

  • Window management
  • Session stability
  • Input handling
  • Display behavior
  • General compositor reliability

Over the past several Plasma releases, KDE developers have steadily shifted their attention toward making Wayland the best possible experience while continuing limited maintenance for X11.

Translation Updates for Global Users

Like most KDE maintenance releases, Plasma 6.7.1 incorporates a fresh batch of translation updates contributed by volunteers from around the world.

These updates improve:

07/02/2026   Linux Journal
PorteuX 2.6 Released with Linux 6.19, TLP Support, and Smarter Hardware Optimization

The PorteuX project has officially released PorteuX 2.6, bringing a new round of updates to the lightweight Slackware-based Linux distribution. Designed to be fast, portable, modular, and immutable, PorteuX continues to appeal to users who want a complete desktop operating system that can run efficiently from a USB drive or other removable media. The latest release introduces a newer Linux kernel, improved power management, updated desktop environments, and numerous performance and usability improvements.

Released just two months after PorteuX 2.5, version 2.6 focuses on refining the user experience while maintaining the distribution's minimalist philosophy.

Powered by Linux Kernel 6.19

At the heart of PorteuX 2.6 is the Linux 6.19 kernel series, bringing improved hardware compatibility, updated drivers, security fixes, and better support for modern processors and peripherals.

The updated kernel helps ensure smoother operation on both newer desktop hardware and laptops while continuing PorteuX's emphasis on speed and low resource usage.

Better Battery Life with TLP Support

One of the headline features in PorteuX 2.6 is support for TLP, the popular command-line utility used to optimize laptop battery life.

Available through the PorteuX AppStore, TLP automatically adjusts various power-saving settings, including CPU behavior and device power management, helping extend battery life without requiring constant manual tuning.

For laptop users, this addition makes PorteuX an even more attractive lightweight operating system.

Automatic CPU Microcode Loading

The release also introduces automatic loading of Intel and AMD CPU microcode when booting in non-fresh modes.

Microcode updates help address processor bugs, improve stability, and deliver security fixes directly from CPU manufacturers. Automating this process reduces the need for manual configuration while ensuring supported systems benefit from the latest firmware improvements.

Updated Desktop Environments

PorteuX continues to offer multiple desktop editions, each updated to recent upstream releases.

Version 2.6 includes:

  • GNOME 49.4
  • KDE Plasma 6.5.5
  • Xfce 4.20
  • Cinnamon 6.6
  • LXQt 2.3
  • MATE 1.28.2
  • COSMIC 1.0.8
  • LXDE 0.11.1

This broad selection allows users to choose between modern feature-rich desktops and extremely lightweight environments depending on their hardware and workflow.

Performance Improvements Throughout the System

Although PorteuX has always emphasized performance, version 2.6 introduces additional optimizations behind the scenes.

Developers report improvements including:

06/30/2026   Linux Journal
CachyOS June 2026 ISO Released with Hyprland Noctalia, Faster Performance, and Smarter System Tools

The CachyOS team has released the June 2026 ISO, delivering another feature-packed update for its Arch Linux-based distribution. Known for its aggressive performance optimizations and gaming-focused approach, CachyOS continues refining both the user experience and the underlying system with improvements ranging from compiler tuning to installer enhancements and new desktop options.

As the project's fourth major ISO refresh of the year, the June release emphasizes speed, usability, and modern hardware support while remaining fully compatible with Arch Linux's rolling-release ecosystem.

A New Hyprland Noctalia Desktop Experience

One of the headline additions is a new Hyprland Noctalia desktop option available directly from the installer.

Noctalia provides a polished, preconfigured Hyprland environment with a modern appearance, allowing users to enjoy a highly customizable Wayland compositor without spending hours configuring dotfiles after installation. The installer even includes a preview so users can see the desktop before selecting it.

For users interested in lightweight, keyboard-driven workflows, this new option makes Hyprland much more approachable.

Performance Optimizations Continue

Performance remains the defining characteristic of CachyOS, and the June 2026 release introduces several additional optimizations.

Notable improvements include:

  • Python packages now built using extended Profile-Guided Optimization (PGO)
  • A new GCC branch prediction tuning patch designed to improve performance on modern Intel and AMD processors
  • A fix for an OpenBLAS regression affecting high-core-count CPUs
  • Additional package-level optimizations throughout the distribution

These updates continue CachyOS's philosophy of extracting as much performance as possible from modern hardware.

Improved Package Management and Security

The June release also includes several important changes to package management.

One notable enhancement is network isolation for Pacman scriptlets and hooks, preventing installation scripts from accessing the network by default. This improves security during package installation and reduces the risk of unexpected behavior.

Additionally:

  • proton-cachyos has been renamed to proton-cachyos-native
  • The installer no longer includes the paru AUR helper
  • Users are now encouraged to use Shelly, available with both graphical and command-line interfaces

Installer Improvements

The installation experience has received considerable attention in this release.

Updates include: