< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

14 clusters · 30 sources · 54 days · First seen · Last updated

Linux security patch wave continues (June–August 2026)

Overview

The coordinated response that began in late June has expanded into a multi‑month effort to remediate a record‑high volume of Linux‑related flaws. A June bulletin disclosed 1,888 vulnerabilities, including 324 kernel issues and a critical Chromium V8 exploit, prompting Red Hat to issue urgent errata for RHEL 7 ELS and RHEL 8 streams. Early July saw another wave of kernel and component updates from Ubuntu, Red Hat, Debian LTS and others, covering OpenVPN, OpenShift, Vim, nginx, and dozens of CVEs. The most notable discoveries were the Januscape (CVE‑2026‑53359) and GhostLock (CVE‑2026‑43499) kernel bugs, both patched in the mainline kernel after years of exposure and judged high‑severity for cloud-hosted KVM environments. Cloud providers such as Amazon, Google and Microsoft quickly applied the Januscape fix, while Ubuntu released its own kernel update and advised disabling nested virtualization until patched. Mid‑July, enterprise‑focused advisories from Oracle Linux, Red Hat, and Tenable Core added critical updates for kernels, OpenSSH, sudo, Python, Java and other core libraries. By early August, SUSE contributed a critical WebKit2GTK3 fix and a broader set of package patches across the Linux ecosystem, underscoring the sustained, cross‑distribution effort to harden both server and desktop platforms against an expanding threat landscape. Additional developments in late July confirmed the scale of the crisis. Qualys highlighted the RefluXFS race‑condition (CVE‑2026‑64600) in the XFS filesystem, estimating exposure of over 16 million installations and prompting immediate kernel updates from Red Hat, AlmaLinux, Oracle and others. LWN’s July 27‑28 bulletins listed dozens of package updates across AlmaLinux, Debian, Fedora, Mageia, Oracle Linux and Red Hat, extending the patch cadence. In mid-August, new kernel vulnerabilities emerged that threaten host isolation. Zapscape (CVE-2026-64561) was identified in the KVM hypervisor, where a stale-root check ordering flaw could allow a guest virtual machine to execute code on the host.

Entities

Debian · Red Hat · AlmaLinux · Linux kernel · openSUSE

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. 22 days ago

    [TECHNOLOGY] 2 sources
    Linux distributions release critical security patches for kernels and infrastructure

    Major Linux distributions including Ubuntu and Debian have released critical security patches for kernels, cloud infrastructure, and runtime tools like Redis and Podman to address remote execution and escapeRis

  2. 28 days ago

    [TECHNOLOGY] 2 sources
    openSUSE releases Leap 16 amid major Linux security updates

    openSUSE has launched Leap 16 for various platforms while SUSE issues critical security patches for Chromium, Dracut, and the Linux kernel to address multiple vulnerabilities.

  3. about 1 month ago

    [TECHNOLOGY] 8 sources
    Linux kernel vulnerabilities Zapscape and SCTPhantom enable host escape

    New Linux kernel vulnerabilities, Zapscape and SCTPhantom, allow attackers to escape virtual machine or container isolation to gain host-level control via use-after-free flaws.

  4. about 1 month ago

    [TECHNOLOGY] 2 sources
    Zapscape KVM Vulnerability (CVE‑2026‑64561) Threatens Linux Hosts

    Zapscape (CVE‑2026‑64561) is a critical KVM shadow‑MMU bug that lets a privileged guest VM escape to the host Linux kernel, affecting cloud and HPC environments; patches are urgently needed.

  5. about 1 month ago

    [TECHNOLOGY] 3 sources
    SUSE issues critical WebKit2GTK3 security update and multiple Linux package patches

    SUSE released a critical WebKit2GTK3 security patch and several moderate updates for openSUSE packages, while LWN.net reported a wide‑range of security updates across major Linux distributions on 4 Aug 2026.

  6. about 1 month ago

    [TECHNOLOGY] 5 sources
    Linux Distributions Deploy Massive Security Patches in Week 31, 2026

    Linux distributions issued critical patches for kernel, glibc, OpenSSH, Node.js, OpenSSL and more in week 31, 2026, with Ubuntu adding cloud‑kernel updates and Qubes OS fixing Xen vulnerabilities.

  7. about 2 months ago

    [TECHNOLOGY] 2 sources
    Linux security updates released for Tuesday and Wednesday

    LWN.net released Tuesday and Wednesday security bulletins with numerous package patches for major Linux distributions, dated late July 2026.

  8. about 2 months ago

    [TECHNOLOGY] 6 sources
    Critical Linux Kernel Flaw RefluXFS Exposes Millions of Systems

    Qualys disclosed a critical Linux XFS race‑condition (CVE‑2026‑64600) affecting millions, prompting kernel patches from AlmaLinux and other distros, while a Windows bfs.sys use‑after‑free (CVE‑2026‑50458) was也已

  9. about 2 months ago

    [TECHNOLOGY] 2 sources
    Enterprise Linux Distributions Issue Major 2026 Security Updates

    Tenable Core and Red Hat issue extensive 2026 security updates for Oracle Linux and RHEL, covering kernels, libraries and key enterprise tools.

  10. about 2 months ago

    [TECHNOLOGY] 3 sources
    Linux kernel Januscape vulnerability threatens global data centers

    A 16‑year‑old Linux kernel flaw called Januscape lets a VM escape its host, risking data‑center breaches; major cloud providers have patched it.

  11. 2 months ago

    [TECHNOLOGY] 2 sources
    Security patches roll out for Windows DWM and Ubuntu Linux kernel privilege‑escalation bugs

    Patches for Windows DWM (CVE‑2026‑20871) and Ubuntu Linux kernel (CVE‑2026‑53359) mitigate local privilege‑escalation bugs; Windows fixes include micropatches for legacy versions, Ubuntu advises disabling KVM‑n

  12. 2 months ago

    [TECHNOLOGY] 4 sources
    Linux KVM “Januscape” VM Escape and GhostLock Vulnerabilities Patched

    Critical Linux kernel bugs—Januscape VM escape (CVE‑2026‑53359) and GhostLock privilege escalation (CVE‑2026‑43499)—have been patched after years of existence; upgrades are urged to protect cloud hosts.

  13. 2 months ago

    [TECHNOLOGY] 2 sources
    Linux Distributions Release Critical Security Patches

    Ubuntu, Red Hat and Debian released extensive kernel, OpenVPN, nginx and other Linux security patches to fix hundreds of vulnerabilities.

  14. 3 months ago

    [TECHNOLOGY] 2 sources
    Linux and Red Hat security updates expose record 1,888 vulnerabilities

    June’s Linux patch bulletin listed a record 1,888 flaws, including an actively exploited Chromium bug, while Red Hat released important updates for perl‑IO‑Compress and libxslt on RHEL 7/8.

Sources

4sysops.com · avleonov.com · belgiannature.be · blog.0patch.com · blogspan.net · borncity.com · businesstechweekly.com · capecod.com · countryrebel.com · cybersecuritynews.com · dev.to · flagthis.com · hackaday.com · ithome.com · itinsight.pt · linuxcompatible.org · linuxiac.com · linuxpromagazine.com · linuxsecurity.com · lwn.net · old.lwn.net · omgubuntu.co.uk · opensourceforu.com · sapo.pt · sempreupdate.com.br · spacemoney.com.br · techrights.org · thecyberexpress.com · ubuntubuzz.com · ubuntulinux.org

This summary has been updated 8 times: see revision history