Linux Security Roundup: Kernel Patches, Go Runtime Fixes, and Critical Container CVEs

Published by

Recent Linux security updates have been released across various distributions, focusing on kernel network stack enhancements, Go runtime fixes, and critical container tooling vulnerabilities. AlmaLinux, Oracle Linux, and SUSE addressed numerous CVEs, including heap overflows, race conditions, and privilege escalation paths, while Debian's LTS team patched fourteen CVEs specifically for the xrdp server. Fedora 44 also delivered updates, particularly for the Bluetooth stack and Python dependencies, including a significant overhaul of the cryptography stack. System administrators are advised to prioritize these updates, especially concerning the Go runtime and kernel network patches, during their next maintenance window to mitigate potential security threats



Linux Security Roundup: Kernel Patches, Go Runtime Fixes, and Critical Container CVEs

Distributions across the board just shipped security updates, tightening the kernel network stack, updating the Go runtime, and patching critical container tooling flaws. AlmaLinux, Oracle Linux, and SUSE pushed Important advisories this week, closing dozens of CVEs that span heap overflows in rsyslog, race conditions in netfilter, and privilege escalation paths in xrdp and apptainer. Debian's LTS team delivered fourteen CVE fixes for xrdp on Bullseye and Bookworm, while Fedora 44 overhauled the Python cryptography stack and patched the local Bluetooth discovery vector. Sysadmins should prioritize the Go runtime patches and kernel network updates at their next maintenance window, as older XML parsers and legacy mingw OpenSSL builds continue to collect dust and predictable vulnerabilities.

Linux Security Roundup: Kernel Patches, Go Runtime Fixes, and Critical Container CVEs @ Linux Compatible