Linux Security Roundup: Critical Patches Hit 389-ds, xz, and Valkey Across Major Distributions
Rocky Linux and SUSE assigned Critical ratings to 389-ds-base and libzypp, while Slackware shipped xz 5.8.4 to patch a liblzma decoder memory safety bug. Ubuntu released USN-8675-2 for 26.04 LTS to harden Perl's Socket, regex engine, and Storable deserializer against information disclosure and integer overflows. Fedora 43 quietly rebased OpenSSL to 3.5.8 and backported roughly 45 FreeRDP CVEs, whereas AlmaLinux, Oracle, and Rocky shipped Valkey 8.0.10 alongside Thunderbird ESR rebuilds. Kernel updates from RHEL, Rocky, and Oracle patched memory corruption across exfat, Samba, and the Bluetooth stack, meaning administrators should prioritize those Critical-rated packages before the rest.
Linux Security Roundup: Critical Patches Hit 389-ds, xz, and Valkey Across Major Distributions
Recent critical security patches have been released for various Linux distributions including Rocky Linux, SUSE, Ubuntu, and Slackware, addressing vulnerabilities in key software components such as 389-ds-base and libzypp. Notably, Ubuntu's update targets Perl's Socket and regex engine to mitigate risks of information disclosure and integer overflows, while Slackware patched a memory safety bug in the xz package. Additionally, Fedora rebased OpenSSL to a newer version, fixing numerous CVEs, and both AlmaLinux and Oracle introduced updates for Valkey and Thunderbird addressing multiple vulnerabilities. Administrators are advised to prioritize these critical updates, especially those related to directory services and memory corruption, to maintain system security and integrity
