Hello TUXEDO Fans and Open-Source Enthusiasts!
This week marks another big step forward for TUXEDO in the area of system maintenance. Last December, we introduced TUXEDO Tomte Light , a cross-distribution tool for applying our TUXEDO Fix and Board packages. This was in preparation for TUXEDO Tomte 3 , released this week, which represents the new generation of system maintenance at TUXEDO. This week’s KDE App of the Week takes a crafty turn. We present KXStitch , an application for creating and editing cross-stitch patterns. In the TUXEDO OS Tips & Tricks section, we help you to access KDE Activities .
Enjoy reading,
The TUXEDO OS Team
Note: We would like to keep you updated on the latest developments in TUXEDO OS with the TWIX series and introduce you to exciting applications as well as practical tips related to the KDE desktop and TUXEDO OS. However, this section should not be a one-way street: your feedback, ideas, and suggestions for improvement are very welcome! For this purpose, we have created a thread on Reddit, where you can reach us directly.
Updates TUXEDO
tuxedo-tomte v3.0.3
complete rewrite on the base of tuxedo-tomte-light
tuxedo-suite v1.1.0
new dependency tuxedo-tomte instead of tuxedo-tomte-light
tuxedo-tomte-light v2.0.0
transitional package to tuxedo-tomte
tuxedo-tomte v3.0.4
fixes a display issue when running without root privileges
TUXEDO Control Center 3.0.5
uses tuxedo-systeminfos, if not available, it downloads the file
fixes profile manager save button
TUXEDO Control Center 3.0.6
no Tomte menu in Global Settings if Tomte is version 3.0.0 or higher, or if Tomte is not installed
nvidia-driver-assistant 0.23tux7
Fixes incorrect open-closed mapping, e.g. for the GT1030
systeminfos-script v3.0.20
fixes log path for Tomte 3.0
FAI v6.0.5–2.4.1
Fedora 43 temporarily removed from FAI
Updates TUXEDO OS
Thunderbird 140.11.1esr
KDE App of the Week: KXStitch - Cross Stitching made easy
This week, we are introducing the app KXStitch. The name refers to cross-stitching, a popular needlework technique in which small, even, X-shaped stitches are arranged on a piece of fabric to create pictures, patterns, or lettering. Today, anyone planning and managing patterns often relies on digital tools for the task. KXStitch is a KDE application specifically designed for creating and editing cross-stitch patterns and charts.
KXStitch: Designing or Refining Patterns
New patterns can be created from scratch on a freely configurable grid that can be resized at any time. Those who do not want to start with a blank canvas can import images in common graphic formats. KXStitch automatically reduces the number of colors and converts the image into stitches — either using only full stitches or including fractional stitches as well. Imported images can also be used as a background for manual tracing.
With KXStitch, you can design your own patterns and import images in common formats as templates.
Printing a Color Legend
Once a pattern is finished, it can be printed together with a color legend. This legend specifies which color and thread should be used for each symbol in the pattern, allowing the design to be used directly at the embroidery hoop. For color selection, KXStitch supports common embroidery thread palettes, including commercial thread brands such as DMC, Anchor, and Madeira. This ensures that the printed color numbers directly correspond to threads available in stores. Users who prefer their own combinations can also create custom palettes.
Reading Windows Formats
KXStitch can also open files in the PC Stitch format. This allows users switching from Windows and previously working with PC Stitch to continue using their existing pattern collections.
Availability
KXStitch is part of the KDE application collection, released under the GPL-2.0 license, and available in the package repositories of TUXEDO OS. It can be installed directly through the Discover software center or the package manager. Alternatively, it is also available on Flathub .
Machine Embroidery
KXStitch is intended exclusively for manual cross-stitching and therefore does not support machine embroidery formats. It can only save in its own native format. Machine-readable formats such as DST or PES, which embroidery machines require, are not exported. If you want to prepare patterns for embroidery machines under Linux, you can instead use the Ink/Stitch plug-in for Inkscape, which was specifically developed for computer-controlled machine embroidery.
Info: Are you interested in Plasma development and want to know what new features are planned and which programs have been recently updated? You can find a detailed overview in the weekly column This week in Plasma by KDE developer Nate Graham.
TUXEDO OS Tips & Tricks: KDE Activities: Multiple workspaces on a single desktop
Virtual desktops are a standard feature on Linux systems, helping users distribute windows across multiple desktops for a tidier workspace. KDE Plasma goes a step further with a considerably more powerful concept: KDE Activities ). While virtual desktops merely organize windows, Activities separate entire usage scenarios from one another – including widgets and wallpapers. If you have been relying solely on virtual desktops up to now, KDE Activities gives you what amounts to several completely separate working environments within the same Plasma session.
Virtual Desktops vs. Activities
The difference is not immediately obvious at first glance. Virtual desktops work like additional layers on your monitor: windows are distributed across them, and you switch back and forth between layers. The working environment itself, however, remains identical. Activities go considerably further. Each activity can have its own widgets and wallpapers, applications can be assigned to specific Activities, and window contexts can be managed separately. Activities can also be paused when not needed to conserve resources. This makes it possible to dedicate one activity exclusively to office work, for example, and another to leisure or multimedia.
Enabling and Managing Activities
The Activity Manager can be opened via the Plasma menu or with the keyboard shortcut Meta +Q . Alternatively, you can access it through System Settings. Use the New Activity option to create additional working environments and assign them names and optional icons. Typical examples would be separate Activities for work, writing, gaming, multimedia, or communication, between which you can switch at any time.
In System Settings you can create as many Activities as you like for different projects, hobbies, or work areas.
Assigning Applications to Activities
One particularly useful feature is the ability to assign applications to specific Activities. To do so, right-click on a window’s title bar and select under Activities where the application should appear. Alternatively, switch to the desired activity and launch the application there – it will automatically be associated with that activity. Right-clicking the taskbar entry lets you pin an application directly to the panel of the current Activity.
This means, for example, that a browser can be restricted to the work activity, a messenger kept exclusively in the private activity, and music software made available only in the multimedia environment. This is especially useful on laptops when no additional displays are connected.
Applications can be pinned to all Activities or to a specific one in several different ways.
Custom Widgets and Wallpapers
Each activity has its own desktop state. Widgets, panels, and wallpapers can all be configured differently. For instance, the work activity might feature a folder widget displaying project files, while the leisure activity could have a media controller or other multimedia widgets. Each activity can also have its own wallpaper, which makes Activities feel almost like entirely separate user accounts.
Pausing Activities
Activities that are not currently needed can be stopped in the Activity Manager. Plasma freezes the associated applications in the process, terminating the running programs and freeing up RAM, while saving the state and window arrangement for later resumption. This can be particularly useful on laptops when many programs are open simultaneously.
Tip: If Meta +Q is unresponsive
If Meta +Q does not respond, the service may have been disabled or it crashed. In that case, restarting the daemon in the background should help:
kquitapp6 kactivitymanagerd
kactivitymanagerd &
Summary
Virtual desktops and Activities complement each other perfectly in KDE Plasma. Desktops keep things organized within a single task, while Activities separate entire usage scenarios from one another. Anyone who uses Plasma intensively should take a closer look at this often-overlooked feature. An article on the KDE Blog is a great starting point and provides detailed practical examples.
Ubuntu Security Updates
The Ubuntu security updates listed here are generally incorporated directly into TUXEDO OS. Some updates are only available from Ubuntu for a fee and are therefore not made available to the community until a later date. Unfortunately, we have no control over this:
USN-8344–1: pip vulnerabilities : Several security issues were fixed in pip.
IDs: CVE-2025–66418, CVE-2025–66471, CVE-2024–35195.
Affects: Ubuntu 26.04 LTS, 24.04 LTS, 22.04 LTS.
USN-8339–1: OpenJDK 25 vulnerabilities : Several security issues were fixed in OpenJDK 25.
IDs: CVE-2026–22008, CVE-2026–22021, CVE-2026–34282 (+ 6 others).
Affects: Ubuntu 26.04 LTS, 25.10 , 24.04 LTS, 22.04 LTS.
USN-8340–1: LibreOffice vulnerability : LibreOffice could be made to crash or run programs as your login if it opened a specially crafted file.
IDs: CVE-2026–4430.
Affects: Ubuntu 24.04 LTS, 22.04 LTS.
USN-8336–1: PHP vulnerabilities : Several security issues were fixed in PHP.
IDs: CVE-2026–7259, CVE-2026–6722, CVE-2025–14179 (+ 6 others).
Affects: Ubuntu 26.04 LTS, 25.10 , 24.04 LTS, 22.04 LTS.
USN-8331–1: OpenJDK 11 vulnerabilities : Several security issues were fixed in OpenJDK 11.
IDs: CVE-2026–22021, CVE-2026–34282, CVE-2026–22013 (+ 5 others).
Affects: Ubuntu 26.04 LTS, 25.10 , 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS.
USN-8330–1: OpenJDK 8 vulnerabilities : Several security issues were fixed in OpenJDK 8.
IDs: CVE-2026–22021, CVE-2026–22013, CVE-2026–22007 (+ 4 others).
Affects: Ubuntu 26.04 LTS, 25.10 , 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS, 16.04 LTS.
USN-8329–1: FFmpeg vulnerability : FFmpeg could be made to crash if it received specially crafted input.
IDs: CVE-2024–36617.
Affects: Ubuntu 24.04 LTS.
USN-8328–1: OpenJDK 21 vulnerabilities : Several security issues were fixed in OpenJDK 21.
IDs: CVE-2026–22021, CVE-2026–34282, CVE-2026–22013 (+ 5 others).
Affects: Ubuntu 26.04 LTS, 25.10 , 24.04 LTS, 22.04 LTS, 20.04 LTS.
USN-8327–1: OpenJDK 17 vulnerabilities : Several security issues were fixed in OpenJDK 17.
IDs: CVE-2026–22021, CVE-2026–34282, CVE-2026–22013 (+ 5 others).
Affects: Ubuntu 26.04 LTS, 25.10 , 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS.
USN-8326–1: Foomuuri vulnerabilities : Several security issues were fixed in Foomuuri.
IDs: CVE-2025–67858, CVE-2025–67603.
Affects: Ubuntu 25.10 , 24.04 LTS.
USN-8325–1: tgt vulnerability : tgt could be made to generate an identical sequence of challenges.
IDs: CVE-2024–45751.
Affects: Ubuntu 24.04 LTS, 22.04 LTS, 18.04 LTS, 16.04 LTS, 14.04 LTS.
USN-8323–1: Postorius vulnerability : Postorius could be made to expose sensitive information over the network.
IDs: CVE-2026–44742.
Affects: Ubuntu 26.04 LTS, 25.10 , 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS.
USN-8322–1: Apache Commons BeanUtils vulnerability : Apache Commons BeanUtils could be made to run programs if it received specially crafted input.
IDs: CVE-2025–48734.
Affects: Ubuntu 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS, 16.04 LTS, 14.04 LTS.
USN-8320–1: Memcached vulnerabilities : Memcached could be made to expose sensitive information over the network.
IDs: CVE-2026–47784, CVE-2026–47783.
Affects: Ubuntu 26.04 LTS, 25.10 , 24.04 LTS, 22.04 LTS.
USN-8319–1: Libgcrypt vulnerabilities : Several security issues were fixed in Libgcrypt.
IDs: CVE-2026–41989, CVE-2026–41990.
Affects: Ubuntu 26.04 LTS, 25.10 , 24.04 LTS, 22.04 LTS.
USN-8318–1: libcaca vulnerability : libcaca could be made to crash or run programs as your login if it opened a specially crafted file.
IDs: CVE-2026–42046.
Affects: Ubuntu 26.04 LTS, 25.10 , 24.04 LTS, 22.04 LTS.
USN-8317–1: GStreamer Good Plugins vulnerabilities : Several security issues were fixed in GStreamer Good Plugins.
IDs: CVE-2026–46470, CVE-2026–46469.
Affects: Ubuntu 25.10 , 24.04 LTS, 22.04 LTS.
USN-8315–1: MediaWiki vulnerabilities : MediaWiki could be made to expose sensitive information over the network.
IDs: CVE-2026–34092, CVE-2026–34088, CVE-2026–34087.
Affects: Ubuntu 24.04 LTS, 22.04 LTS, 20.04 LTS.
USN-8313–1: XML-RPC for C and C++ vulnerabilities : Several security issues were fixed in XML-RPC for C and C++.
IDs: CVE-2022–25235, CVE-2022–25236.
Affects: Ubuntu 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS, 16.04 LTS, 14.04 LTS.
USN-8303–1: GitPython vulnerabilities : Several security issues were fixed in GitPython.
IDs: CVE-2026–42215, CVE-2023–41040, CVE-2026–44244 (+ 2 others).
Affects: Ubuntu 26.04 LTS, 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS, 16.04 LTS, 14.04 LTS.
USN-8278–2: Linux kernel (Azure) vulnerabilities : Several security issues were fixed in the Linux kernel.
IDs: CVE-2026–23168, CVE-2026–23193, CVE-2025–71200 (+ 193 others).
Affects: Ubuntu 24.04 LTS.
USN-8310–1: Linux kernel (Azure) vulnerabilities : Several security issues were fixed in the Linux kernel.
IDs: CVE-2026–23274, CVE-2025–71134, CVE-2025–71141 (+ 19 others).
Affects: Ubuntu 25.10 , 24.04 LTS.
USN-8309–1: libssh2 vulnerability : libssh2 could be made to crash if it received specially crafted network traffic.
IDs: CVE-2026–7598.
Affects: Ubuntu 26.04 LTS, 25.10 , 24.04 LTS.
USN-8307–1: ONNX vulnerability : ONNX could be made to overwrite arbitrary files if a user downloaded a specially crafted model archive.
IDs: CVE-2024–5187.
Affects: Ubuntu 24.04 LTS.
USN-8306–1: Samba vulnerabilities : Several security issues were fixed in Samba.
IDs: CVE-2026–4480, CVE-2026–1933, CVE-2026–3238 (+ 3 others).
Affects: Ubuntu 26.04 LTS, 25.10 , 24.04 LTS, 22.04 LTS.
USN-8304–1: Vim vulnerabilities : Several security issues were fixed in Vim.
IDs: CVE-2026–42307, CVE-2026–44656, CVE-2026–45130.
Affects: Ubuntu 26.04 LTS, 25.10 , 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS, 16.04 LTS, 14.04 LTS.
USN-8296–2: Linux kernel (NVIDIA Tegra) vulnerabilities : Several security issues were fixed in the Linux kernel.
IDs: CVE-2026–23168, CVE-2026–23193, CVE-2025–71200 (+ 186 others).
Affects: Ubuntu 24.04 LTS.
USN-8302–1: NLTK vulnerabilities : Several security issues were fixed in NLTK.
IDs: CVE-2026–33230, CVE-2026–0846, CVE-2026–33231 (+ 3 others).
Affects: Ubuntu 26.04 LTS, 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS, 16.04 LTS, 14.04 LTS.
USN-8301–1: SimpleEval vulnerability : SimpleEval could be made to run programs if it received specially crafted input.
IDs: CVE-2026–32640.
Affects: Ubuntu 26.04 LTS, 25.10 , 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS, 16.04 LTS.
USN-8300–1: ngtcp2 vulnerability : ngtcp2 could be made to run programs as your login if it received specially crafted network traffic when qlog was enabled.
IDs: CVE-2026–40170.
Affects: Ubuntu 26.04 LTS, 25.10 , 24.04 LTS, 22.04 LTS.
USN-8299–1: Rclone vulnerabilities : Several security issues were fixed in Rclone.
IDs: CVE-2026–41176, CVE-2026–41179.
Affects: Ubuntu 26.04 LTS, 25.10 , 24.04 LTS, 22.04 LTS, 20.04 LTS.
USN-8298–1: .NET vulnerability : .NET could be made to consume excessive resources if it received specially crafted network traffic.
IDs: CVE-2026–42899.
Affects: Ubuntu 26.04 LTS, 25.10 , 24.04 LTS, 22.04 LTS.