A security- and maintenance-focused release with updates to Linux and bundled components, along with dependency updates. It also corrects minimal-initrd regressions and changes service startup, SSH defaults, kernel-module availability, and other operator-visible behavior and layout.
Action needed (18)
securitycritical
Linuxsecurity updatesLinuxwas updated with security fixes associated with advisories including CVE-2024-56757, CVE-2025-71239, and CVE-2026-31788.securityhighcurl security updates
curlwas updated with fixes for CVE-2025-10148 and CVE-2025-9086.securityhighexpat security update
expatwas updated with a fix for CVE-2025-59375.securityhighgnupg security updates
gnupgwas updated with fixes for CVE-2025-68972 and CVE-2025-68973.securityhighGo security updates
gowas updated with security fixes associated with CVE-2025-47910, CVE-2025-47912, CVE-2025-58183, and related advisories.securityhigh
intel-microcodesecurity updatesintel-microcodewas updated with fixes associated with CVE-2024-28956, CVE-2024-43420, CVE-2025-20012, and related advisories.securityhighlibxslt security updates
libxsltwas updated with fixes for CVE-2025-7424 and CVE-2025-7425.securityhigh
nvidia-driverssecurity updatesnvidia-driverswas updated with fixes for CVE-2025-23280, CVE-2025-23282, CVE-2025-23300, and related advisories.securityhighopenssl security updates
opensslwas updated with fixes for CVE-2025-9230, CVE-2025-9231, and CVE-2025-9232.securityhighPAM security updates
pamwas updated with fixes for CVE-2024-10041, CVE-2024-10963, CVE-2024-22365, and CVE-2025-6020.securitymediumbinutils security updates
binutilswas updated with fixes for CVE-2025-5244, CVE-2025-5245, and CVE-2025-8225.securitymediumcoreutils security update
coreutilswas updated with a fix for CVE-2025-5278.securitymediumlibpcre2 security update
libpcre2was updated with a fix for CVE-2025-58050.securitymedium
net-toolssecurity updatenet-toolswas updated with a fix for CVE-2025-46836.securitylowopenssh security updates
opensshwas updated with fixes for CVE-2025-61984 and CVE-2025-61985.securitylibxml2 update
libxml2was updated tolibxml2-20250908.breakingOpenSSH algorithm configuration defaults
Ciphers,MACs, andKexAlgorithmswere dropped from thesshdconfiguration. OpenSSH upstream defaults are used instead.breakingReduced first-stage initrd kernel modules
The set of kernel modules available in the first initrd is reduced.
Check if affected (1)
breakingAutomatic startup for overlaybd sysext services
Applies if you use the
overlaybd sysext.Services in the
overlaybd sysextwere configured to start automatically.