Hello TUXEDO Fans and Open-Source Enthusiasts!
KDE has released the first beta of Plasma 6.8. The new version brings numerous improvements to Wayland, graphics, and usability while also marking an important milestone: Plasma will no longer provide a dedicated X11 session. NVIDIA users benefit from triple buffering enabled by default, while Spectacle can now also record audio during screen recordings. There are also improvements for multi-monitor setups, Wi-Fi, touch devices, and notifications.
Plasma 6.8 is particularly interesting for TUXEDO OS. With the planned move to Debian as its base, TUXEDO OS will have new opportunities to deliver current KDE versions to you more quickly. Instead of relying on the package versions of a fixed Ubuntu release, the Debian Testing model allows new Plasma releases to be adopted closer to their upstream release. The final version of Plasma 6.8 is scheduled for October 14, and we will keep you up to date on its progress.
In addition to TUXEDO OS news, we have our usual tips and recommendations for you. Our App of the Week is Kongress, while our Tip of the Week is the Terminal File Manager (tfm): This modern tool brings features such as tabs, a dual-pane view, and file previews from graphical file managers directly to your terminal. As usual, you will also find a summary of the latest TUXEDO OS updates.
Enjoy reading,
The TUXEDO OS Team
Note: With the TWIX series, we keep you up to date with the latest developments around TUXEDO OS. We also introduce interesting applications and share practical tips and tricks for the KDE desktop and TUXEDO OS. At the same time, TWIX thrives on your feedback. We always welcome your suggestions, topic ideas, and proposals for improvement. Feel free to join the discussion in our TWIX thread on Reddit , where you can reach us directly. Of course, you are also welcome to contact us via any of our other social media channels.
Updates in TUXEDO OS
New ISO for TUXEDO OS Noble
Boot Issues Resolved Due to Changes to Secure Boot Support
Users can now change their password in System Preferences
Chromium 153.0.8010.36
Firefox 156
Thunderbird 153.3.0esr
tuxedo-common-settings 1.3.11tux1
Added a Polkit rule for users to change their passwords in KDE System Settings
VirtualBox 7.2.6-dfsg-4tux2
Fix for incorrect version number in the VNC ExtPack
KDE App of the Week: Kongress - your digital conference compass
Anyone attending larger conferences such as FOSDEM or DebConf will know the problem: several talks run in parallel, interesting sessions overlap, and it is easy to lose track of the different tracks. With Kongress, KDE offers an application that presents conference schedules in a clear format and helps users put together their own personal timetable.
Curated selection
Kongress supports conferences that provide their schedules in a suitable format such as iCalendar. The application uses a curated selection of such events. It displays supported conferences with their sessions sorted by day and time. For individual talks, additional information such as title, room, and starting time can be viewed. Interesting sessions can be marked as favourites and then appear together in the personal schedule.
Kongress displays both upcoming and past conferences
Available for Plasma, Plasma Mobile, and Android
The application was originally developed around FOSDEM and has since become part of KDE Gear. Thanks to Kirigami, Kongress is also suitable for mobile devices. In addition to Plasma and Plasma Mobile, the application is available for Android through KDE’s F-Droid repository containing nightly builds. This makes sense for a conference app: you can conveniently prepare your personal schedule on your computer and then quickly check upcoming talks on your smartphone while on the move.
After selecting a conference, the schedule can be viewed in its entirety or by day. By marking sessions as favorites, you can access individual presentations directly.
Kongress uses the schedule data provided by conference organisers. Depending on the event, the application can also display information about rooms and venues. On Plasma, notifications can additionally be enabled for bookmarked talks. Kongress is particularly useful for larger events with several parallel tracks. Its benefits are more limited at smaller conferences, but with extensive schedules it can save a considerable amount of searching.
Availability
On TUXEDO OS, Kongress can be installed through Discover either as a Debian package or as a Flatpak. At the time of testing, the Android version 26.11.70 was considerably newer than the 25.12.3 release available on Flathub. Users running Kongress on Android should, however, keep in mind that this is a development version.
Info: Are you interested in Plasma development and want to know what new features are planned and which programs have been recently updated? You can find a detailed overview in the weekly column This week in Plasma by KDE developer Nate Graham.
TUXEDO OS Tips & Tricks: File Management in the Terminal
With tfm , a modern file manager is available directly in the terminal. It is more closely modeled on graphical file managers than traditional command-line tools. A sidebar, tabs, dual-pane view, previews and drag & drop are all included, alongside the usual file operations.
Operation is not limited to the keyboard. tfm is explicitly designed to work with the mouse and supports selecting, moving and renaming files using the mouse. For TUXEDO OS users, this makes it an interesting alternative to traditional file managers such as Dolphin when working in the terminal anyway.
The Terminal File Manager (tfm) in dual-pane mode under TUXEDO OS. The sidebar displays a file preview, while the integrated terminal provides quick access to the command line.
The settings menu of the Terminal File Manager can be opened using the Escape key. It provides various options for configuring the user interface and file management.
Nerd Fonts for Icons
To display the intended icons for files and folders, tfm requires a Nerd Font . These fonts contain additional characters and icons used by many terminal applications. Under TUXEDO OS, for example, JetBrainsMono Nerd Font can be installed with getnf JetBrainsMono .
If getnf is not installed yet, the tool can be set up together with curl . Afterwards, fc-cache -fv updates the font cache. tfm or the terminal should then be restarted so that the new font becomes available. The setup is therefore largely the same as in our previous Nerd Font tip .
Beta with a Few Rough Edges
tfm is currently still in beta. This can also be noticed under TUXEDO OS: During our tests, the Nerd Font icons were not reliably picked up on every start. In that case, folders and other elements appear without their intended graphical icons. Restarting tfm or the terminal may resolve the issue.
tfm in action: The short demonstration shows drag & drop, the integrated file preview and efficient file management in the clearly arranged dual-pane mode of the Terminal File Manager.
The graphical presentation should not be expected to be perfectly consistent either. The developer itself points out that a terminal-based interface still comes with various visual and functional peculiarities. If you want to try tfm, it is therefore advisable to start with non-critical files and not entrust important data solely to beta software.
Keyboard shortcut
Function
Esc
Open menu
Enter
Open file or folder
Backspace
Go up one directory level
F2
Rename file or folder
Tab
Switch between the two file panes
F5
Copy selection to the other pane
F6
Move selection to the other pane
Ctrl +C / Ctrl +X / Ctrl +V
Copy / Cut / Paste
Ctrl +D
Duplicate selection
Delete
Move selection to the trash
Ctrl +Z / Ctrl +Y
Undo / Redo
Ctrl +T / Ctrl +W
Open / Close tab
Ctrl +Tab
Switch between tabs
Alt +Enter
Show properties
Ctrl +H
Show hidden files
Ctrl +L
Open path bar
Ctrl +G
Switch between list and grid view
F9
Show / hide preview
F4
Open terminal in current directory
Ctrl +Shift +S
Connect to a server
Ctrl +Q
Quit tfm
Ubuntu Security Updates
The Ubuntu security updates listed here are generally incorporated directly into TUXEDO OS. Some updates are only available from Ubuntu for a fee and are therefore not made available to the community until a later date. Unfortunately, we have no control over this:
USN-8779–2: Bubblewrap regression : USN-8779–1 fixed vulnerabilities in Bubblewrap. Unfortunately, the fix for CVE-2026–87766 introduced a regression in symlink resolution, preventing…
IDs: -
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04
USN-8780–1: libsoup vulnerabilities : It was discovered that libsoup incorrectly handled certain URLs when using an HTTP proxy. A remote attacker could possibly use this issue to inject…
IDs: CVE-2026–1801, CVE-2026–1539, CVE-2026–1467
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8779–1: Bubblewrap vulnerabilities : It was discovered that Bubblewrap incorrectly handled certain temporary directories. A local attacker could possibly use this issue to cause a denial…
IDs: CVE-2019–12439, CVE-2026–87766
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04
USN-8778–1: GStreamer Good Plugins vulnerability : It was discovered that GStreamer Good Plugins did not limit the size of reassembly buffers when processing fragmented RTP packets. A remote attacker…
IDs: CVE-2026–18649
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8777–1: GNU Bison vulnerability : It was discovered that GNU Bison incorrectly handled grammar-defined configuration variables when generating HTML reports. An attacker could possibly…
IDs: CVE-2026–56389
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8775–1: SQLite vulnerability : It was discovered that SQLite was vulnerable to a buffer overflow in the sqlar extension. If a user were tricked into opening a specially crafted…
IDs: CVE-2026–39113
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04
USN-8736–2: Perl vulnerabilities : USN-8736–1 fixed vulnerabilities in Perl. This update provides the corresponding fix for Perl on Ubuntu 24.04 LTS. Original advisory details: It was…
IDs: CVE-2026–19487, CVE-2026–15534
Affects: Ubuntu 24.04
USN-8773–1: GNU Guix vulnerability : It was discovered that GNU Guix incorrectly made build outputs accessible to local users before their file metadata was finalized. A local attacker…
IDs: CVE-2024–52867, CVE-2024–27297
Affects: Ubuntu 24.04, Ubuntu 22.04
USN-8772–1: AOM vulnerabilities : It was discovered that AOM incorrectly handled the first-pass statistics buffer in Look-Ahead Processing (LAP) mode. An attacker could possibly use…
IDs: CVE-2026–56211, CVE-2026–56210, CVE-2026–56209, CVE-2026–56208
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8771–1: Valkey vulnerabilities : Madelyn Olson discovered that Valkey incorrectly handled TLS connections under certain conditions. A remote attacker could possibly use this issue to…
IDs: CVE-2026–85522, CVE-2026–56684, CVE-2026–63639
Affects: Ubuntu 24.04, Ubuntu 26.04
USN-8770–1: SimpleSAMLphp vulnerabilities : It was discovered that SimpleSAMLphp incorrectly validated cryptographic signatures in XML messages. An authenticated attacker could possibly use…
IDs: CVE-2024–52596, CVE-2025–27773, CVE-2019–3465
Affects: Ubuntu 24.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8769–1: phpseclib vulnerability : It was discovered that phpseclib did not perform padding validation in constant time when using AES in CBC mode. A remote attacker could possibly use…
IDs: CVE-2026–32935, CVE-2023–52892, CVE-2023–48795, CVE-2024–27355 plus 1 others
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8768–1: Shibboleth vulnerability : Florian Stuhlmann discovered that Shibboleth incorrectly escaped input when using the ODBC storage plugin. A remote attacker could possibly use this…
IDs: CVE-2025–9943
Affects: Ubuntu 24.04, Ubuntu 22.04, Ubuntu 20.04
USN-8767–1: Snapcast vulnerability : It was discovered that Snapcast incorrectly handled crafted JSON-RPC requests. A remote attacker could possibly use this issue to execute arbitrary…
IDs: CVE-2023–36177
Affects: Ubuntu 24.04, Ubuntu 22.04, Ubuntu 20.04
USN-8766–1: Suricata-Update vulnerability : Guillem Lefait discovered that Suricata-Update did not properly validate destination paths when extracting files referenced by downloaded rule…
IDs: CVE-2026–63347
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8765–1: python-sql vulnerability : Cédric Krier discovered that python-sql incorrectly escaped values passed to unary operators. An attacker could possibly use this issue to perform…
IDs: CVE-2024–9774
Affects: Ubuntu 24.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8762–1: polkit vulnerability : It was discovered that polkit incorrectly handled cookie input. A local attacker could possibly use this issue to cause polkit to crash, resulting in…
IDs: CVE-2026–85498
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8764–1: SRT vulnerabilities : It was discovered that SRT did not authenticate certain encryption control messages. A remote attacker could possibly use this issue to downgrade an…
IDs: CVE-2026–55868, CVE-2026–55869
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04
USN-8763–1: kitty vulnerabilities : It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could…
IDs: CVE-2026–42851, CVE-2026–42850, CVE-2026–54055, CVE-2026–54057
Affects: Ubuntu 24.04, Ubuntu 26.04
USN-8761–1: Linux kernel (Azure) vulnerabilities : Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects…
IDs: CVE-2026–64088, CVE-2026–64096, CVE-2026–64185, CVE-2026–64116 plus 91 others
Affects: Ubuntu 24.04
USN-8760–1: Linux kernel (NVIDIA) vulnerabilities : Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects…
IDs: CVE-2026–63869, CVE-2026–64493, CVE-2026–64244, CVE-2026–53266 plus 546 others
Affects: Ubuntu 24.04
USN-8759–1: WebOb vulnerabilities : It was discovered that WebOb incorrectly handled certain URLs. An attacker could possibly use this issue to control a redirect or forward to another…
IDs: CVE-2026–44889, CVE-2024–42353
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8739–2: ImageMagick vulnerabilities : USN-8739–1 fixed vulnerabilities in ImageMagick. This update provides the corresponding fixes for Ubuntu 24.04 LTS. Original advisory details: It was…
IDs: CVE-2026–61870, CVE-2026–61465, CVE-2026–61864, CVE-2026–61857 plus 11 others
Affects: Ubuntu 24.04
USN-8755–1: libvips vulnerability : It was discovered that libvips incorrectly handled specially crafted TIFF images when saving them as HEIF images. An attacker could possibly use this…
IDs: CVE-2025–29769
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04
USN-8754–1: Freeciv vulnerability : It was discovered that Freeciv incorrectly handled certain network packets, resulting in a stack overflow. A remote attacker could possibly use this…
IDs: CVE-2026–33250
Affects: Ubuntu 24.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8753–1: libinput vulnerability : It was discovered that libinput did not properly escape device properties. A local attacker could possibly use this issue to inject arbitrary udev…
IDs: CVE-2026–50292
Affects: Ubuntu 24.04, Ubuntu 26.04
USN-8752–1: Konsole vulnerability : It was discovered that Konsole incorrectly handled certain URLs under specific circumstances. A remote attacker could possibly use this issue to…
IDs: CVE-2025–49091
Affects: Ubuntu 24.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8563–5: nginx vulnerability : USN-8563–1 fixed vulnerabilities in nginx. The fix for CVE-2026–42533 was backed out in USN-8563–2 because it could cause a regression. This update…
IDs: CVE-2026–42533
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8749–1: CivetWeb vulnerabilities : It was discovered that CivetWeb did not correctly handle parsing certain URIs. A remote attacker could possibly use this issue to cause a denial of…
IDs: CVE-2025–9648, CVE-2025–55763
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
Current BIOS/EC Versions
An EC/BIOS update affects key system components. Please ensure that you follow the instructions carefully and take your time. The process is usually completed quickly. If you have any doubts, our support team is happy to assist you. The following devices have BIOS/EC updates available:
Model
CPU
GPU
BIOS
EC
Stellaris 16 Gen7
Intel
RTX 5070 Ti
N.1.33A27
2.11.00
Stellaris 16 Gen7
Intel
RTX 5070 Ti (mLED)
N.1.33A27
2.11.00
Stellaris 16 Gen7
Intel
RTX 5080
N.1.33A27
2.11.00
Stellaris 16 Gen7
Intel
RTX 5080 (mLED)
N.1.33A27
2.11.00
Stellaris 16 Gen7
Intel
RTX 5090
N.1.33A27
2.11.00
Stellaris 16 Gen7
Intel
RTX 5090 (mLED)
N.1.33A27
2.11.00
InfinityBook Max 15 Gen 10
Intel Core Ultra 7 255H
GeForce RTX 5050
N.1.15A12
1.10.00
InfinityBook Max 15 Gen 10
Intel Core Ultra 7 255H
GeForce RTX 5060
N.1.15A12
1.10.00
InfinityBook Max 15 Gen 10
Intel Core Ultra 7 255H
GeForce RTX 5070
N.1.15A12
1.10.00