Linux Security Roundup: rsync 33 CVEs, Ubuntu Reboot Required, and Java Updates Hit All Major Distros
Major Linux distributions just released a coordinated wave of security advisories, with rsync bleeding 33 CVEs across Fedora and SUSE while OpenJDK updates target legacy Java runtimes across AlmaLinux, Oracle, Rocky, and Debian. Browsers also face a heavy purge, as Debian cleared 31 CVEs in Firefox ESR and both Fedora and SUSE shipped Chromium fixes for WebGL overflows and V8 type confusion. Ubuntu administrators should brace for a forced reboot, as eight kernel notices across four releases trigger unavoidable ABI changes that will break manually compiled third-party modules. PHP, curl, and kbd also received critical hardening patches to close SQL injection, NTLM regression, and local privilege escalation flaws, making today's package manager runs non-negotiable.
Linux Security Roundup: rsync 33 CVEs, Ubuntu Reboot Required, and Java Updates Hit All Major Distros
Major Linux distributions have recently issued a series of coordinated security updates addressing numerous vulnerabilities, including 33 CVEs associated with rsync and critical updates for Java across various platforms. Ubuntu users are particularly urged to prepare for mandatory reboots due to changes in the kernel that affect ABI compatibility, which will impact manually compiled third-party modules. Other updates include significant patches for browsers, with Debian addressing 31 CVEs in Firefox ESR and fixes for Chromium, as well as critical hardening for PHP, curl, and kbd to mitigate SQL injection and local privilege escalation vulnerabilities. To ensure system security, users are advised to promptly run the appropriate package manager commands for their distribution and verify that all patches have been successfully applied
