Hello TUXEDO Fans and Open-Source Enthusiasts!
It seems as though Debian is quietly conquering the world – or at least the physical foundations of our universe. Even CERN, long known as a stronghold for RHEL, is making a strategic shift for its industrial control systems, opting to rely on the stability and flexibility of Debian Linux moving forward.
The researchers' decision was highly pragmatic: while other distributions force older hardware into retirement through strict requirements, Debian remains a dependable foundation. By the end of 2026, over 2,200 specialized systems in Geneva are scheduled to be migrated to Debian 13 – a remarkable vote of confidence in the project. For those interested in a deeper dive into the technical details, this video presentation from the MiniDebConf offers fascinating insights.
Software diversity is also at the heart of our focus this week: we take a look at the revamped OpenShot 4.0 video editor and show you how the upcoming redesign of KDE Connect for Android will make communication between your smartphone and PC even more fluid. Enjoy browsing, testing, and experiencing Linux!
Enjoy reading,
The TUXEDO OS Team
Note: With the TWIX series, we keep you up to date with the latest developments around TUXEDO OS. We also introduce interesting applications and share practical tips and tricks for the KDE desktop and TUXEDO OS. At the same time, TWIX thrives on your feedback. We always welcome your suggestions, topic ideas, and proposals for improvement. Feel free to join the discussion in our TWIX thread on Reddit , where you can reach us directly. Of course, you are also welcome to contact us via any of our other social media channels.
Updates in TUXEDO OS
Mesa 26.1.6 (cumulative update)
WebFAI v6.0.5–2.9.0
Updated kernel from 6.11.11 to 7.1.5
Updated Windows VM installation script
Firefox 2:155.0~tux1
Thunderbird 3:153.2.0esr~tux1 (cumulative update)
linux v7.0.0–111030.30tux1
Update in deb.tuxedocomputers.com/ubuntu for Resolute
Fixed an issue causing a black screen on the Stellaris 16 Gen7 Intel after a long suspend
linux v7.0.0–111030.30~24.04.1tux1
Update in deb.tuxedocomputers.com/ubuntu for Noble
Fixed an issue causing a black screen on the Stellaris 16 Gen7 Intel after a long suspend
Nextcloud Desktop 34.0.2~tux1
KDE App of the Week: OpenShot 4.0 – Video Editing on Linux
For a long time, video editing on Linux was a difficult undertaking, with even dedicated Linux fans often finding Windows or macOS better equipped. While programs such as Kdenlive and OpenShot were available early on, they lagged behind commercial alternatives for quite some time in terms of features, stability, and professional workflows.
This has changed considerably in recent years: thanks to the continued development of Kdenlive and OpenShot, as well as the availability of professional solutions such as DaVinci Resolve, Linux now offers capable tools for a wide range of requirements.
One example is OpenShot 4.0 . The free and open-source video editor was released as a new major version on August 30. OpenShot is licensed under the GPLv3, is based on Qt, and is available for GNU/Linux as well as Windows and macOS. FFmpeg is used, among other things, to handle the various video, audio, and image formats.
OpenShot 4.0 runs smoothly on TUXEDO OS thanks to the AppImage format and provides a powerful, Qt-based environment for video editing directly on your TUXEDO notebook or desktop PC.
One of the larger new features is the recording view. Screen, webcam, microphone, and system audio can be recorded directly from OpenShot. On Linux, screen and webcam recording also works under Wayland via desktop portals. The individual sources are stored as project assets and can then be edited independently. This can be useful, for example, when creating tutorials where the webcam recording, screen capture, and audio need to be adjusted separately afterward.
Color, Effects, and Local AI
There are also several changes to post-production. The new color view provides color wheels, curves, and various video scopes, including a histogram, luma waveform, and vectorscope. There are also new one-click presets for frequently needed adjustments, such as contrast, shadows, and colors.
The new recording view in OpenShot 4.0 allows you to capture your screen, webcam, and microphone simultaneously – ideal for creating tutorials and informative explainer videos directly on your PC.
OpenShot 4.0 also includes a new Object Mask effect that can automatically detect and mask objects using the EfficientSAM model. The models are run locally, so the video material does not need to be transferred to an external cloud service for this purpose.
The new effects include Film Grain, Denoise, Shadow, Glow, and Displacement Map. Film Grain offers presets for 35 mm, 16 mm, and Super 8 film. Beat Sync and Audio Visualization can be used to synchronize visual elements with audio signals. There are also new ComfyUI templates for tasks such as noise reduction, speech enhancement, improving audio resolution, and repairing audio tracks.
More Convenience for the Timeline
OpenShot 4.0 also brings several changes to the timeline and user interface. These include an editable timecode field directly in the timeline, horizontal scrolling with the mouse wheel, context menus for keyframes, and a new „My Views“ menu for saved views. There are also smaller improvements to the handling of docks and tabs.
Performance has also been addressed. OpenShot 4.0 makes greater use of Qt 6 and includes optimizations for timeline rendering and effect processing. According to the developers, for example, the Blur effect is around 62 percent faster than in OpenShot 3.5.1.
Since the current version is neither included in the standard TUXEDO OS repositories nor available as a Flatpak, the officially provided AppImage is currently the easiest way to use OpenShot 4.0 on TUXEDO OS. You can run it directly without a classic installation and, if needed, conveniently integrate it into your application menu using Gear Lever . You can find further details in the TWIX 12–2026 .
OpenShot continues to focus on users looking for a relatively straightforward introduction to video editing. Kdenlive is a good option for more complex projects, while DaVinci Resolve provides a commercial alternative with a feature set geared more toward professional production workflows. The development of OpenShot 4.0 nevertheless shows that Linux now offers considerably more choice for video editing than it did a few years ago.
Info: Are you interested in Plasma development and want to know what new features are planned and which programs have been recently updated? You can find a detailed overview in the weekly column This week in Plasma by KDE developer Nate Graham.
TUXEDO OS Tips & Tricks: KDE Connect for Android Is Getting a Complete Redesign
This time, our Tips & Tricks section is not directly about Linux or KDE Plasma, but about Android. Nevertheless, the upcoming update to KDE Connect for Android is likely to be of interest to many readers. The extensive redesign is now available for testing and brings not only a new interface, but also substantial changes under the hood.
The developer describes the project as a much more extensive overhaul. In addition to the interface, large parts of the architecture may have been rewritten to better fit the new interaction concept. The work took almost two months. The developer is therefore explicitly asking users to test the new version and report any possible regressions.
If you want to try the new version, you can find the source code in the corresponding GitHub repository. The current test version is also available there as a release. However, the redesign should not yet be considered a fully finished version. The extensive changes can still cause problems, particularly when pairing devices and in certain edge cases.
New Home Screen and Easier Pairing
The most noticeable change is the new home screen. Instead of a traditional sidebar, it presents cards for connected devices. These cards also serve as shortcuts to frequently used functions. They display additional information such as whether the connection uses Wi-Fi or Bluetooth and the current battery level.
KDE Connect provides seamless integration between a Linux PC and smartphone. The image shows the clear home screen with central features such as media controls for convenient device management.
The shortcuts are the most significant genuinely new feature of the redesign. The idea is simple: many users regularly use only a handful of KDE Connect plugins. Instead of navigating through menus to access them, the required functions can now be launched directly from the home screen of the respective device.
Unavailable or not-yet-paired devices are kept out of this central view. This is intended to reduce the amount of information presented, particularly for new users. New devices can be added using a button in the bottom-right corner, which displays an indicator when devices are available. Already paired devices can be accessed separately.
The previous sidebar has also been removed. Until now, it served as the main menu at the same time, something the developer considers rather unusual for a modern Android application. The new home screen instead follows more familiar interaction patterns and is intended to make the application easier to understand at first glance.
Rethinking Pairing and Permissions
The new device-pairing dialog is particularly useful. Instead of relying on a notification that could easily be overlooked, KDE Connect now provides a dedicated overlay dialog. New devices can be paired directly from within the application, even when KDE Connect is not currently open.
The way Android permissions are handled has also been fundamentally changed. Previously, KDE Connect presented an extensive list of permissions, including some required for features users might never use. In the future, the application will request a permission only when the corresponding feature is actually needed.
The permission dialog follows the same design as the new pairing overlay and can also appear on top of other applications when required. If a feature is blocked because a permission is missing, the user should be made aware of this immediately. Android 17 also introduces a dedicated section for the permissions required by KDE Connect.
Clearer Separation of Settings
The device settings have also been reorganized. One important change concerns the distinction between global settings and options that apply only to a specific device. In the future, global options will be located in the general application settings.
The settings for an individual device will therefore primarily contain options that actually affect that device. A dedicated „Global Settings“ category provides a link to the corresponding options. This should make it easier to see whether a change affects KDE Connect as a whole or only the currently selected device.
Music Controls on a Single Screen
For plugins, the basic principle is to simplify and combine functions where appropriate, while making other features easier to understand. This is particularly apparent in the music controls. Functions that were previously spread across two tabs are now combined on a single screen.
Playback controls and media functions are centered around a large control element. Inputs and outputs remain visible separately and can each be selected and adjusted using their own dialogs. Both dialogs follow the same basic layout, making the interface more consistent.
Remote Controls with a Familiar Layout
The remote control for other devices has also not gained many new functions. Instead, it has primarily been redesigned to make its purpose clearer. Its layout is more closely modeled on traditional TV remotes. The developer deliberately uses so-called skeuomorphism – design elements that resemble real-world objects and can therefore make their function more intuitive.
The detailed settings allow you to manage your connections, while specialized modules such as remote input and presentation mode turn your smartphone into an efficient input device for your PC.
The detailed settings can be used to manage connections, while specialized modules such as Remote Input and Presentation Remote turn the smartphone into a practical input device for the PC.
A similar approach is used for the Remote Input plugin. The virtual touchpad is designed to look more like an actual touchpad, making its purpose immediately apparent. At the same time, the function for sending text has been integrated directly into the touchpad view, eliminating the need to switch to another section.
The touchpad also automatically adjusts its size when the Android keyboard is displayed. This allows the touchpad and keyboard to be used simultaneously. With the presentation remote, the most noticeable changes are the larger and more clearly emphasized buttons for the most important functions.
Almost Two Months of Work – Now It’s Time to Test
The developer emphasizes that this does not cover all of the changes. Many smaller adjustments would go beyond the scope of the blog post. The redesign was developed over a period of almost two months, with large language models also being used to assist with some of the more repetitive refactoring work.
This makes the new version particularly interesting for users who are willing to experiment. If you try it, keep an eye out for regressions and report any issues to the project where possible. The new pairing logic in particular has undergone extensive changes, but may still contain unknown edge cases. Feedback on the new design is also explicitly welcome.
Ubuntu Security Updates
The Ubuntu security updates listed here are generally incorporated directly into TUXEDO OS. Some updates are only available from Ubuntu for a fee and are therefore not made available to the community until a later date. Unfortunately, we have no control over this:
USN-8724–1: rabbitmq-c vulnerabilities : It was discovered that the rabbitmq-c command-line tools only accepted credentials on the command line, making them visible to other local users…
IDs: CVE-2026–59986, CVE-2026–61547, CVE-2023–35789, CVE-2026–44235 plus 1 others
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8720–1: GnuPG vulnerability : It was discovered that GnuPG incorrectly validated authentication tag lengths when parsing CMS messages encrypted with AES-GCM. An attacker could…
IDs: CVE-2026–57062
Affects: Ubuntu 24.04, Ubuntu 26.04
USN-8723–1: SPICE vdagent vulnerabilities : It was discovered that SPICE vdagent had an integer overflow in the buffer size calculation used when writing to the daemon socket. A malicious or…
IDs: CVE-2026–57965, CVE-2026–57966
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8722–1: libssh2 vulnerabilities : It was discovered that libssh2 incorrectly handled certain SFTP server responses. A remote attacker controlling an SSH server could use this issue to…
IDs: CVE-2026–66033, CVE-2026–66035, CVE-2026–66032
Affects: Ubuntu 24.04, Ubuntu 26.04
USN-8719–1: APR-util vulnerabilities : It was discovered that APR-util incorrectly performed password hash comparisons in a way that was not constant-time. An attacker could possibly use…
IDs: CVE-2025–49506, CVE-2026–34501, CVE-2026–34502, CVE-2026–32327
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8721–1: OpenSSH vulnerabilities : It was discovered that OpenSSH’s ssh-agent incorrectly handled interactions between agent locking and the session-bind@openssh.com extension. A…
IDs: CVE-2026–73281, CVE-2026–73283, CVE-2026–73282
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8718–1: SSSD vulnerability : It was discovered that SSSD did not properly validate authentication token lengths when processing PAM responder requests. A local attacker could…
IDs: CVE-2026–68743
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8716–1: FFmpeg vulnerabilities : It was discovered that FFmpeg incorrectly handled certain crafted media files in the VobSub subtitle demuxer. An attacker could possibly use this…
IDs: CVE-2026–65703, CVE-2026–64834, CVE-2026–75143, CVE-2026–65705 plus 10 others
Affects: Ubuntu 24.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8713–1: BioSig vulnerabilities : Mark Bereza and Lilith Wyatt discovered that BioSig incorrectly handled certain crafted input files. An attacker could possibly use this issue to…
IDs: CVE-2026–22891, CVE-2026–20777
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8712–1: pyasn1 vulnerabilities : It was discovered that pyasn1 did not properly bound the size of long-form tag identifiers when parsing BER, CER, or DER encoded data. An attacker…
IDs: CVE-2026–59885, CVE-2026–59886, CVE-2026–59884
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8711–1: Libgcrypt vulnerability : It was discovered that Libgcrypt had a timing-based side-channel flaw in its RSA implementation. A remote attacker could possibly use this issue to…
IDs: CVE-2024–2236
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8710–1: libevent vulnerabilities : Alexis Challande discovered that libevent incorrectly handled certain empty output buffers. An attacker could possibly use this issue to trigger a…
IDs: CVE-2026–63385, CVE-2026–63381, CVE-2026–63382, CVE-2026–63384 plus 1 others
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8709–1: ncurses vulnerability : It was discovered that ncurses incorrectly handled specially crafted terminfo database entries. A local attacker could possibly use this issue to…
IDs: CVE-2025–6141
Affects: Ubuntu 24.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8690–1: Pillow vulnerability : It was discovered that Pillow did not properly manage memory when processing certain image files. An attacker could possibly use this issue to cause…
IDs: CVE-2026–59198
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04
USN-8706–1: zlib vulnerability : It was discovered that zlib incorrectly handled negative length parameters in CRC32 combine functions. An attacker could use this issue to cause a…
IDs: CVE-2026–27171
Affects: Ubuntu 24.04, Ubuntu 26.04
USN-8704–1: GNU cpio vulnerabilities : It was discovered that cpio incorrectly sanitized hard-link targets when extracting tar archives in copy-in mode. If a user or automated system were…
IDs: CVE-2026–66485, CVE-2026–66484, CVE-2026–66486
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8705–1: OpenZFS vulnerability : It was discovered that OpenZFS incorrectly handled authorization checks for certain ioctl operations on Linux. A local attacker could possibly use…
IDs: CVE-2026–79619
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8703–1: WebKitGTK vulnerabilities : Several security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a…
IDs: CVE-2026–43742, CVE-2026–43713, CVE-2026–43707, CVE-2026–28955 plus 43 others
Affects: Ubuntu 24.04, Ubuntu 26.04
USN-8702–1: util-linux vulnerabilities : It was discovered that libblkid in util-linux had a heap use-after-free vulnerability during nested partition probing. An attacker who could present…
IDs: CVE-2026–53615, CVE-2026–13595, CVE-2026–53614, CVE-2026–27456 plus 3 others
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8701–1: UDisks vulnerability : It was discovered that UDisks did not correctly validate the caller identity when handling the as-user option in the…
IDs: CVE-2026–7867
Affects: Ubuntu 24.04, Ubuntu 26.04
USN-8700–1: MySQL vulnerabilities : Multiple security issues were discovered in MySQL. MySQL has been updated to 8.4.11 in Ubuntu 26.04 LTS. Ubuntu 22.04 LTS and Ubuntu 24.04 LTS…
IDs: CVE-2026–46936, CVE-2026–60183, CVE-2026–60585, CVE-2026–47023 plus 25 others
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8699–1: libssh vulnerabilities : It was discovered that libssh had a stack buffer overflow in its SFTP server when constructing directory listing entries for long filenames. An…
IDs: CVE-2026–59846, CVE-2026–59847, CVE-2026–59845, CVE-2026–59844 plus 5 others
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8698–1: FreeRDP vulnerabilities : It was discovered that FreeRDP contained multiple security issues. An attacker could possibly use these issues to obtain sensitive information, cause…
IDs: -
Affects: Ubuntu 24.04, Ubuntu 26.04
USN-8697–1: GNU Core Utilities vulnerabilities : It was discovered that GNU Core Utilities sort had a heap buffer under-read in its begfield() function. A local attacker could possibly use this…
IDs: CVE-2025–5278, CVE-2026–56391
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8696–1: Bind vulnerability : It was discovered that Bind incorrectly handled DNSSEC validation when a domain was covered by both NSEC and NSEC3 records with only one type having…
IDs: CVE-2026–13204
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8692–1: GNU diffutils vulnerability : It was discovered that GNU diffutils incorrectly handled certain integer arithmetic when mapping line ranges in diff3. A local attacker could…
IDs: CVE-2026–53910
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8691–1: attr vulnerability : It was discovered that attr incorrectly handled symbolic links while traversing directory paths. A local attacker who controlled a pathname component…
IDs: CVE-2026–54371
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04