Hello TUXEDO Fans and Open-Source Enthusiasts!
Welcome to a new edition of This Week in TUXEDO OS. After a short winter break, our developer penguins are slowly returning from their well-deserved vacation – and diving straight back into work. Even if one or two flippers are still a bit sore from skiing: after all, you can code with a flipper, too. This time, we introduce Klevernote, a lightweight note-taking app for structured thoughts, as well as Unify, which lets you bundle social media services and web apps while keeping them neatly separated. As always, we also provide a concise overview of the latest developments around TUXEDO OS.
Enjoy reading,
The TUXEDO OS Team
Note: We would like to keep you updated on the latest developments in TUXEDO OS with the TWIX series and introduce you to exciting applications as well as practical tips related to the KDE desktop and TUXEDO OS. However, this section should not be a one-way street: your feedback, ideas, and suggestions for improvement are very welcome! For this purpose, we have created a thread on Reddit, where you can reach us directly.
Updates in TUXEDO OS
Nextcloud-Desktop 4.0.4~tux2
Added dependency libqt6webenginecore6-bin. Fixes an issue where the Nextcloud client could not be launched.
tuxedo-base-files 4.0.8~24.04~tux1
tuxedo-repository can now be used as an alternative to tuxedo-archive-keyring.
tuxedo-tomte 2.61.1
Switched the default from tuxedo-archive-keyring to tuxedo-repository.
tuxedo-drivers 4.18.2
Adjusted the default EC write method for NB02. Fixes an issue with stuck fan speeds.
tuxedo-suite 1.0.0
Intended for WebFAI and the “Tuxedofication” of existing systems. Note for Debian: installation with Recommends is required, e.g. apt install –install-recommends tuxedo-suite . Pulls in the following packages:
tuxedo-control-center
tuxedo-repository
tuxedo-tomte-light
linux-tuxedo (Ubuntu only)
upgrader 1.0.2–2tux1
Added neon-keyring as a dependency.
Reduced the reminder interval from 5 days to 2 days.
itinerary 24.12.3–0ubuntu2~tux1
Current TUXEDO OS image
Includes the fixed qt6-webengine packages (required by the Help Center, Nextcloud Desktop, and various applets).
Firefox 147.0
Various additional package updates since the last ISO.
KDE App of the Week: KleverNote - Markdown for Power Users
Last week, we introduced the simple note-taking app Marknote. KDE has even more to offer in this area, though. Today we recommend KleverNotes to you.
Features
KleverNotes is an application for creating and managing notes on your mobile and desktop devices. It also uses Markdown, but offers one significant advantage over Marknote: KleverNotes provides a live preview. While you are writing, you see the text in a split view not only as Markdown source code, but simultaneously as a formatted document. Alternatively, the view can be switched so that only one of the two representations is shown at a time.
In the demo view, KleverNotes shows the options for formatting your notes.
Basics
KleverNotes uses the Kirigami framework for desktop and mobile, stores notes using the CommonMark Markdown standard, and relies on the md4qt Markdown parser for Qt 6. This parser also supports GitHub extensions such as emojis, tables, or footnotes. The application allows organization into categories and groups, supports sketches and to-dos, and can be extended via plug-ins such as syntax highlighting, note linking, and PlantUML diagrams . Whether you write your notes directly in Markdown or edit them using the formatting toolbar at the top is entirely up to you. The current version 1.2.5 from October 2025 fixes rendering issues and improves the folder structure.
You can activate modules and plug-ins as needed in the settings.
Installation
KleverNotes is not preinstalled in TUXEDO OS, but is available in the Discover software shop as a Debian package and as a Flatpak. Alternatively, you can install the application via the console using the following command:
sudo apt update && sudo apt install klevernotes
The combination of live preview, the md4qt parser, and full support for the CommonMark standard makes KleverNotes—unlike pure WYSIWYG solutions such as Marknote—particularly well suited for Markdown power users.
Info: Are you interested in Plasma development and want to know what new features are planned and which programs have been recently updated? You can find a detailed overview in the weekly column This week in Plasma by KDE developer Nate Graham.
TUXEDO OS Tips & Tricks: Unify – Social Media in a Box
Today, it is almost impossible to avoid social media platforms such as Facebook, X, or Mastodon, as well as web-based services like Spotify or Netflix. Even users who consciously avoid proprietary offerings and rely on self-hosted services like Jellyfin, Plex, Navidrome, or Nextcloud quickly end up juggling countless browser tabs in daily use.
Things become even more complex when multiple social media channels are managed professionally or on a voluntary basis. In such cases, several accounts have to be handled in parallel. Solutions like multiple browser profiles or Firefox Multi-Account Containers work, but often result in a cluttered and hard-to-manage workflow.
Anyone who wants to deliberately separate social networks and web services from their regular browser should take a closer look at the web app aggregator Unify . The application bundles web services in its own interface and brings order to the desktop without sacrificing convenience.
All Web Apps in One Application – Yet Properly Separated
Unify is a web app aggregator based on Qt 6, Qt WebEngine, and Kirigami. Instead of mixing all services into a single context, Unify organizes individual web apps as so-called services , which can then be grouped into thematic workspaces such as work, communication, or media.
Each social media service and web app runs in its own container. Multiple accounts per service are possible, while logins, cookies, and sessions remain cleanly separated.
Each service runs in its own WebView with a clear separation of cookies, sessions, and logins. This makes it easy to use multiple accounts of the same service in parallel without constantly logging out and back in. This is a major advantage, especially for social media and web-based email.
Installation on TUXEDO OS is particularly straightforward via the Discover software manager. The official Flathub package is available there and integrates seamlessly into the system, while remaining distribution-independent and up to date.
Desktop Integration Instead of a Browser Replacement
Once set up, Unify brings together web applications such as Spotify, YouTube, Gmail, WhatsApp Web, or Mastodon in a single, desktop-native window. This keeps the desktop tidy, saves space in the window list, and provides a clearly structured workspace—especially on smaller displays.
To create a new service, assign a name and enter the URL. Signing in then works as usual directly within the integrated browser window.
Particularly pleasant is the close integration with the Linux desktop. Unify supports native notifications, screen sharing, as well as camera and microphone access. DRM-protected content from services like Netflix or Spotify can also be played back without issues thanks to Widevine support.
Unify integrates tightly with the desktop environment and forwards both notifications and media playback information system-wide.
Media enthusiasts will also appreciate the media session integration: active playback appears in the system with title and status information. This is complemented by automatic favicon detection, configurable keyboard shortcuts, and the ability to detach individual services into separate windows.
The TUXEDO Verdict: More Order, Fewer Tabs
Unify is an excellent solution for deliberately moving web services out of the browser while retaining full usability. Anyone looking to work more productively on Linux and bring order to their digital communication chaos will find a powerful, free tool with a clear desktop focus.
Ubuntu Security Updates
The security updates listed here from Ubuntu are directly integrated into TUXEDO OS:
USN-7963–1: libpng vulnerabilities : Several security issues were fixed in libpng.
IDs: CVE-2025–66293, CVE-2026–22695, CVE-2026–22801
Affects: Ubuntu 25.10, Ubuntu 25.04, Ubuntu 24.04 LTS, Ubuntu 22.04 LTS
USN-7962–1: cpp-httplib vulnerability : cpp-httplib could allow unintended access to network services if it received specially crafted network traffic.
IDs: CVE-2025–66570
Affects: Ubuntu 25.10, Ubuntu 25.04, Ubuntu 24.04 LTS, Ubuntu 22.04 LTS
USN-7961–1: Erlang vulnerability : Erlang could allow unintended access to network services.
IDs: CVE-2024–53846
Affects: Ubuntu 24.04 LTS
USN-7960–1: Rack vulnerabilities : Several security issues were fixed in Rack.
IDs: CVE-2025–61771, CVE-2025–59830, CVE-2025–61772
Affects: Ubuntu 25.10, Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS, Ubuntu 16.04 LTS
USN-7959–1: klibc vulnerabilities : klibc could be made to crash if it received specially crafted input.
IDs: CVE-2016–9843
Affects: Ubuntu 25.10, Ubuntu 25.04, Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS, Ubuntu 16.04 LTS, Ubuntu 14.04 LTS
USN-7958–1: AngularJS vulnerabilities : Several security issues were fixed in AngularJS.
IDs: CVE-2024–8372, CVE-2022–25844, CVE-2024–21490
Affects: Ubuntu 25.04, Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS, Ubuntu 16.04 LTS
USN-7927–3: urllib3 regression : USN-7927–1 introduced a regression in urllib3.
IDs: CVE-2025–66471
Affects: Ubuntu 25.10, Ubuntu 25.04, Ubuntu 24.04 LTS
USN-7957–1: WebKitGTK vulnerabilities : Several security issues were fixed in WebKitGTK.
IDs: CVE-2025–14174, CVE-2025–43535, CVE-2025–43531
Affects: Ubuntu 25.10, Ubuntu 25.04, Ubuntu 24.04 LTS, Ubuntu 22.04 LTS
USN-7956–1: Google Guest Agent vulnerability : Google Guest Agent could be made to crash if it received specially crafted network traffic.
IDs: CVE-2025–58181
Affects: Ubuntu 25.10, Ubuntu 25.04, Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS, Ubuntu 16.04 LTS
USN-7955–1: urllib3 vulnerability : urllib3 could be made to use excessive resources if it received specially crafted network traffic.
IDs: CVE-2026–21441
Affects: Ubuntu 25.10, Ubuntu 25.04, Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS
USN-7954–1: Libtasn1 vulnerabilities : Libtasn1 could be made to crash if it received specially crafted input.
IDs: CVE-2025–13151, CVE-2021–46848
Affects: Ubuntu 25.10, Ubuntu 25.04, Ubuntu 24.04 LTS, Ubuntu 22.04 LTS
USN-7953–1: PHP vulnerabilities : Several security issues were fixed in PHP.
IDs: CVE-2025–14180, CVE-2025–14177, CVE-2025–14178
Affects: Ubuntu 25.10, Ubuntu 25.04, Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS
USN-7952–1: libheif vulnerabilities : Several security issues were fixed in libheif.
IDs: CVE-2025–68431, CVE-2024–25269
Affects: Ubuntu 25.10, Ubuntu 25.04, Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS
USN-7951–1: Python vulnerability : Python could be made to crash if it received specially crafted network traffic.
IDs: CVE-2025–13836
Affects: Ubuntu 25.10, Ubuntu 25.04, Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS
USN-7950–1: Tornado vulnerabilities : Several security issues were fixed in Tornado.
IDs: CVE-2025–67725, CVE-2025–67726, CVE-2025–67724
Affects: Ubuntu 25.10, Ubuntu 25.04, Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS, Ubuntu 16.04 LTS
USN-7949–1: Sodium vulnerability : Sodium could be made to expose sensitive information.
IDs: CVE-2025–69277
Affects: Ubuntu 25.10, Ubuntu 25.04, Ubuntu 24.04 LTS, Ubuntu 22.04 LTS
USN-7948–1: GPSd vulnerabilities : Several security issues were fixed in GPSd.
IDs: CVE-2025–67268, CVE-2025–67269
Affects: Ubuntu 25.10, Ubuntu 25.04, Ubuntu 24.04 LTS, Ubuntu 22.04 LTS
Current BIOS/EC Versions
An EC/BIOS update affects key system components. Please ensure that you follow the instructions carefully and take your time. The process is usually completed quickly. If you have any doubts, our support team is happy to assist you. The following devices have BIOS/EC updates available:
Model
CPU
GPU
BIOS
EC
Intel ME
Stellaris 15 Gen3
Intel
RTX 3060
15.0.55.2751v6
Stellaris 15 Gen3
Intel
RTX 3070
15.0.55.2751v6
Stellaris 15 Gen3
Intel
RTX 3080
15.0.55.2751v6
Stellaris 17 Gen3
Intel i7–11800H
RTX 3060
15.0.55.2751v6
Stellaris 17 Gen3
Intel i7–11800H
RTX 3070
15.0.55.2751v6
Stellaris 17 Gen3
Intel i7–11800H
RTX 3080
15.0.55.2751v6