Linux Security Roundup: Critical Patches for libzypp, 389-ds, FFmpeg, and curl

Published by

In mid-September 2026, several major Linux distributions, including SUSE, AlmaLinux, and Ubuntu, released critical security updates addressing vulnerabilities in key packages and services. Among the notable patches were critical updates for SUSE's libzypp package manager, AlmaLinux's 389 Directory Server, and numerous FFmpeg parsing flaws in Ubuntu. Additionally, Red Hat, Oracle, and Rocky Linux rolled out patches to secure their foundational stacks across various versions, while Debian and Fedora addressed a multitude of vulnerabilities affecting curl and Ruby's Rack framework. Users are urged to apply these updates promptly and be mindful that certain changes, particularly the NVIDIA kernel update in Ubuntu, necessitate a reboot and rebuilding of any unsigned third-party modules



Linux Security Roundup: Critical Patches for libzypp, 389-ds, FFmpeg, and curl

Mid-September 2026 shipped another heavy wave of security errata, led by Critical updates for SUSE's libzypp package manager and AlmaLinux's 389 Directory Server. Ubuntu posted the day's largest haul, closing roughly fifteen FFmpeg parsing flaws and a twenty-seven CVE NVIDIA kernel bump, while Debian and Fedora patched curl, Ruby Rack, and a 158-vulnerability Linux 6.1 kernel. Red Hat, Oracle Linux, and Rocky Linux kept the foundational stack and container runtimes locked down across RHEL and Oracle tracks 8 through 10, and Fedora 44 plugged a native CA trust validation bypass alongside HTTP/2 and proxy password fixes. Run your distro's standard update commands before the weekend, and keep in mind that Ubuntu's NVIDIA kernel ABI change will require a full reboot until you rebuild any unsigned third-party modules.

Linux Security Roundup: Critical Patches for libzypp, 389-ds, FFmpeg, and curl @ Linux Compatible