Security updates for Thursday
LWN's daily roundup covers security advisories from AlmaLinux, Debian, Fedora, SUSE, and Ubuntu, with patches for browsers, kernels, web servers, and core libraries.
Intelligence analysis by Llama

LWN.net's Thursday security update digest lists dozens of advisories across major Linux distributions, touching web servers (Apache, nginx, httpd), browsers (Chromium, Firefox ESR), kernels, and key system libraries. Routine but broad in coverage.
Think of a Linux computer like a big LEGO castle. Every day, someone finds a loose brick that could fall off, and the builders send out new bricks to fix them. This list shows that on Thursday, lots of different castles — from big server ones to home computers — got new bricks for things like their web doors, web browsers, and the core walls.
Analysis
A heavy day for web-facing packages
The Thursday batch leans heavily on internet-facing infrastructure. Apache2 picked up an Ubuntu Security Notice (USN-8589-1) covering the 14.04 through 20.04 LTS lines, while AlmaLinux pushed an httpd:2.4 update for EL8. SUSE simultaneously refreshed nginx and nine of its dynamic modules on Fedora 44 in a single advisory, illustrating how a single CVE in a web server tends to cascade across the module ecosystem. mail transfer agents and DNS resolvers were not spared: Debian DSA-6397-1 patched pdns-recursor, Ubuntu USN-8590-1 addressed exim4 across 22.04 through 26.04, and AlmaLinux updated dovecot for EL9 and EL10.
Browsers and crypto keep the long-term support crowd busy
Chromium and Firefox ESR each received fresh advisories. Debian's DSA-6396-1 covered Chromium for stable, while Fedora updated the browser for both F43 and F43/F44 branches. Firefox ESR was patched twice — once as DSA-6395-1 in Debian stable and again in Debian LTS as DLA-4695-1 — a sign that the ESR channel is being carried as a security-critical dependency on older releases. Kerberos also saw movement: Ubuntu USN-8585-1 updated krb5 on 22.04, 24.04, and 26.04, the kind of foundational change that matters to anyone running SSO or Kerberized services in production.
Kernels and language stacks form the long tail
The Linux kernel advisories alone account for nearly a third of the Ubuntu listings, with USN-8575-2, USN-8574-2, USN-8593-1, USN-8597-1, USN-8596-1, USN-8576-2, USN-8594-1, and USN-8595-1 covering aws, ibm, nvidia, oracle, oem-6.17, lowlatency, fips, and tegra variants. That kind of fan-out is typical for Ubuntu, which ships a separate signed kernel for each cloud, hardware, and security profile. Below the kernel, language runtimes also got attention: python-aiohttp was patched across every supported Ubuntu release (USN-8591-1), python-sqlparse and python3-sqlparse landed in SUSE's SLE and openSUSE channels, and tar (USN-8477-3) was reissued across the full Ubuntu matrix, suggesting an incomplete prior fix. The diversity of packages — glibc, libtiff, libarchive, libgphoto2, ImageMagick, GraphicsMagick, llvm, srt, giflib, gawk — underlines how a single advisory day can touch almost every layer of a typical Linux box.
Key points
- Web servers (Apache, nginx, httpd) and MTAs/DNS (exim4, dovecot, pdns-recursor) all received patches across multiple distributions.
- Chromium and Firefox ESR were updated in both Debian stable and LTS channels, plus Fedora.
- Ubuntu issued a large cluster of kernel advisories covering aws, ibm, nvidia, oracle, oem, lowlatency, fips, and tegra variants.
- python-aiohttp and tar were patched across the full Ubuntu LTS matrix, with tar being a reissue of an earlier fix.
- AlmaLinux refreshed glibc, grafana, and sssd across EL8, EL9, and EL10.
