Hello TUXEDO Fans and Open-Source Enthusiasts!
Soon there will be an official destination for everyone who wants to show their enthusiasm for KDE beyond the screen: the KDE project’s new fan shop is taking shape at merch.kde.org . In the future, all KDE-themed merchandise will be available there in one place.
First up is a sitting Konqi plushie , available for pre-order until October 17, 2026. Around half of the price goes to KDE e.V., and for now each person can order a maximum of two. Shipping is planned for February 2027.
In this issue, we introduce KWave, a lightweight audio editor that cuts, filters, and splits recordings into separate files. In our Tips & Tricks section, we show you how to copy text from screenshots using Spectacle’s text recognition. As always, we round things off with the latest updates.
Enjoy reading,
The TUXEDO OS Team
Note: With the TWIX series, we keep you up to date with the latest developments around TUXEDO OS. We also introduce interesting applications and share practical tips and tricks for the KDE desktop and TUXEDO OS. At the same time, TWIX thrives on your feedback. We always welcome your suggestions, topic ideas, and proposals for improvement. Feel free to join the discussion in our TWIX thread on Reddit , where you can reach us directly. Of course, you are also welcome to contact us via any of our other social media channels.
Updates in TUXEDO OS
TUXEDO Control Center 3.0.10
Added: Aquaris menu for Stellaris Gen8 Intel
Fixed: Corrected the execution path and download permissions for the backup path under Support » System Information
Fixed: Command execution issues related to refresh rate control
Thunderbird 153.3.1esr~tux1
kio-gdrive 25.12.3–0ubuntu1~tux1
Backport of the latest version from Ubuntu Resolute
Fixes potential dependency issues
Updates in TUXEDO OS based on Debian
New ISO Image for the Open Beta
The Open Beta of TUXEDO OS „Continuous Debian“ is moving into its next phase: The fifth ISO image brings back wpa_supplicant and changes the procedure for Btrfs rollbacks. It also contains important information for anyone already running an Open Beta installation… Read more
KDE App of the Week: Kwave – Audio Editing with KDE
If you want to edit audio files on Linux, you’ll quickly end up with comprehensive applications such as Audacity . For many everyday tasks, however, a large audio editor isn’t necessary. With Kwave , KDE offers a lightweight alternative that focuses on recording, cutting, and editing, and integrates seamlessly into Plasma.
As its name suggests, Kwave is a classic waveform editor. When you open an audio file, the application displays its signal graphically. You select regions with the mouse and then cut, copy, delete, or paste them somewhere else.
Multi-level undo and redo make even more extensive edits easier. In addition to single tracks, Kwave also handles multi-channel audio files, whose channels can be edited and played back separately. During playback, the application downmixes such files to mono or stereo if needed.
From Quick Cuts to Filters
Beyond simple cutting, Kwave comes with a range of audio editing tools. You can adjust or normalize the volume and fade sections in and out. For working with the frequency range, lowpass, bandpass, and notch filters as well as pitch shifting are available.
Further functions insert silence or noise, reverse selected regions, or change the sample rate. A sonagram also displays the frequency spectrum of a signal graphically. Since the functions are organized as plugins, Kwave offers a fairly broad set of tools despite its clear interface.
Kwave offers the most common tools for recording, cutting, and editing audio files. Effects are included as well.
Working with labels is particularly handy. They let you divide longer recordings into individual sections. Kwave can save the blocks between labels as separate files. This is ideal for splitting a concert recording into individual tracks or an audiobook into chapters.
Recording Audio Directly
Kwave isn’t just suited to post-processing existing files, it can also record audio itself. Among other things, you can specify the recording source, number of channels, sample rate, and sample format. If desired, the application limits the length of a recording or starts it at a set time.
One interesting feature is pre-recording. Kwave continuously writes a few seconds of audio into a ring buffer before the actual recording starts. When you trigger the recording, these seconds are preserved. A trigger level ensures that recording only begins once the input signal exceeds a certain volume.
All Common Formats Supported
When it comes to file formats, Kwave covers the most important candidates for everyday use. WAV, MP3, FLAC, as well as Ogg Vorbis and Opus can be imported and exported. Additional formats are supported via libaudiofile , although some of them are import-only.
This positions Kwave less as a production environment for complex music projects and more as a classic audio editor for everyday use. Whether you want to shorten a voice recording, cut out passages, correct levels, or split a recording, you’ll find everything you need without the overhead of a digital audio workstation.
Kwave is free software licensed under the GPL and part of KDE Gear. The application is not preinstalled on TUXEDO OS, but is available in the Discover software center as a native package or as a Flatpak . A detailed handbook helps you get started.
Info: Are you interested in Plasma development and want to know what new features are planned and which programs have been recently updated? You can find a detailed overview in the weekly column This week in Plasma by KDE developer Nate Graham.
TUXEDO OS Tips & Tricks: Copying Text from Images with Spectacle
An error code in an error message, the IBAN on a scanned invoice, or a command from a video tutorial: the text you need is right there on the screen, yet you can neither select nor copy it. Until now, the only option in such cases was tedious and error-prone manual typing.
Since Plasma 6.6 , KDE’s screenshot tool Spectacle takes this work off your hands. As TUXEDO OS currently ships Plasma 6.6.6, the feature is already available to you. Text recognition (OCR) converts text in images into selectable text and runs entirely locally on your computer.
Why the Button Is Missing at First
If you open Spectacle on TUXEDO OS, you will still look for the new feature in vain. Spectacle only provides the user interface, while the actual text recognition is handled by the OCR engine Tesseract. If it is not installed, Spectacle hides the Extract Text button and points this out in the settings with an i icon.
Installing Tesseract
Tesseract is available in the regular TUXEDO OS repositories and can be set up with a single command. Install the engine together with the language data for English and German (or mony other languages), as well as the module for detecting text orientation, in the terminal:
sudo apt update
sudo apt install tesseract-ocr tesseract-ocr-eng tesseract-ocr-deu tesseract-ocr-osd
The package with the -osd suffix detects the orientation of text, so Tesseract can also read rotated text. You can add further languages following the same pattern, for example tesseract-ocr-fra for French. Then close Spectacle completely, including from the system tray, and restart it.
Activating Languages in Spectacle
After installation, Spectacle shows a dedicated Text Recognition (OCR) section under Options » Configure Spectacle… instead of the notice. There, check the languages Spectacle should recognize. The list also shows which language packs are installed. Only select the languages you actually need, as this improves recognition accuracy.
After installing Tesseract, the available languages for text recognition appear in the Spectacle settings. Here you can specifically activate the languages from which you want to extract text.
Extracting Text from a Screen Region
Launch Spectacle with the Print key and drag a frame around the desired text. Next to Copy and Save , the Extract Text icon now appears. One click starts the recognition, and a notification offers to copy the text to the clipboard or open it in an editor such as Kate .
After taking a screenshot with Spectacle, the new text recognition icon lets you quickly extract content, which you can then copy directly or edit further.
Once text recognition is complete, a notification informs you and offers to copy the extracted text directly to the clipboard or edit it further.
The text opened in Kate illustrates the result of text recognition: while manual corrections are occasionally necessary, the feature makes everyday work considerably easier.
Combining it with other KDE applications is especially handy. For example, you can paste foreign-language text from screenshots into the lightweight translator Klaro, which we introduced in TWIX #10–2026 . Keep in mind, however: unlike text recognition, Klaro sends texts to online translation services.
Where Text Recognition Reaches Its Limits
Tesseract delivers very good results with clear on-screen text. With handwriting, heavily stylized fonts, or small, blurry sections, however, recognition accuracy drops noticeably. In such cases, zoom in before taking the screenshot, for example with Ctrl ++ in your browser, and then check the result carefully.
This applies especially to character strings such as IBANs, serial numbers, or license keys. Typical mix-ups include “0” and “O” (a zero or a capital O) or “1” and “l” (a one or a lowercase L), which can quickly lead to errors when pasted into a form. A quick comparison with the original saves you trouble.
Tip for the terminal: You can also use Tesseract without Spectacle, for example to read saved image files or folders of scans via script. The following command recognizes English text in an image file and outputs the result directly in the terminal instead of saving it to a file: tesseract image.webp - -l eng
Ubuntu Security Updates
The Ubuntu security updates listed here are generally incorporated directly into TUXEDO OS. Some updates are only available from Ubuntu for a fee and are therefore not made available to the community until a later date. Unfortunately, we have no control over this:
USN-8820–1: curl vulnerabilities : Eunsoo Kim discovered that curl incorrectly handled SASL negotiation for LDAP authentication in certain circumstances. A machine-in-the-middle…
IDs: CVE-2026–80229, CVE-2026–82209, CVE-2026–8927, CVE-2026–80230 and 4 more
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8817–1: Linux kernel vulnerabilities : It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made…
IDs: CVE-2026–63886, CVE-2026–53354, CVE-2026–63994, CVE-2026–53131 and 16 more
Affects: Ubuntu 24.04, Ubuntu 22.04
USN-8816–1: Linux kernel vulnerabilities : Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects…
IDs: CVE-2026–72064, CVE-2026–72355, CVE-2026–72222, CVE-2026–72393 and 97 more
Affects: Ubuntu 24.04, Ubuntu 26.04
USN-8815–1: libass vulnerabilities : It was discovered that libass incorrectly handled parsing operations for specific nested character strings. An attacker could use this issue to cause…
IDs: CVE-2020–26682, CVE-2026–61627, CVE-2026–61626, CVE-2020–24994
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 14.04
USN-8813–1: Expat vulnerabilities : It was discovered that Expat did not correctly handle certain integer arithmetic. An attacker could possibly use this issue to cause a denial of…
IDs: CVE-2026–56410, CVE-2026–66046, CVE-2026–56406, CVE-2026–56132 and 7 more
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8814–1: Octavia vulnerabilities : It was discovered that Octavia did not properly validate TLS cipher string fields in the Amphora provider driver. An authenticated attacker who owns…
IDs: CVE-2026–94571, CVE-2026–94572, CVE-2026–74248
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8812–1: GDAL vulnerabilities : It was discovered that GDAL incorrectly handled certain netCDF files. An attacker could possibly use this issue to execute arbitrary code. This issue…
IDs: CVE-2026–8088, CVE-2026–8084, CVE-2026–8086, CVE-2026–8213 and 3 more
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8810–1: ImageMagick vulnerabilities : It was discovered that ImageMagick did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of…
IDs: CVE-2026–34238, CVE-2026–40310, CVE-2026–33535, CVE-2026–40312 and 3 more
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8287–2: XDG Desktop Portal regression : USN-8287–1 fixed a vulnerability in XDG Desktop Portal. Unfortunately the fix for CVE-2026–40354 was incomplete and introduced a regression when…
IDs: -
Affects: Ubuntu 24.04, Ubuntu 26.04
USN-8809–1: libgit2 vulnerability : Kazuma Matsumoto and Isabel Mill discovered that libgit2 incorrectly handled certain repository URLs when using the SSH transport. A remote attacker…
IDs: CVE-2026–5917
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8808–1: SQL parse vulnerabilities : It was discovered that SQL parse contained multiple algorithmic complexity flaws when parsing SQL statements with deeply nested parentheses…
IDs: CVE-2026–54284, CVE-2026–71491, CVE-2026–59893
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8807–1: Open-iSNS vulnerability : It was discovered that Open-iSNS contained a double-free vulnerability when decoding malformed iSNS attributes. An unauthenticated attacker could…
IDs: CVE-2026–55995
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04
USN-8803–1: Sudo vulnerability : Guannan Wang, Zhanpeng Liu, and Guancheng Li discovered that Sudo failed to apply intercept policy checks when commands were executed under certain…
IDs: CVE-2026–82474
Affects: Ubuntu 24.04, Ubuntu 26.04
USN-8802–1: Linux kernel (Oracle) vulnerabilities : Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects…
IDs: CVE-2026–64182, CVE-2026–64127, CVE-2026–64097, CVE-2026–64056 and 94 more
Affects: Ubuntu 24.04, Ubuntu 22.04
USN-8728–2: Linux kernel (Azure) vulnerabilities : It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made…
IDs: CVE-2026–52938, CVE-2026–63881, CVE-2026–63896, CVE-2026–63811 and 1413 more
Affects: Ubuntu 24.04
USN-8729–4: Linux kernel (Low Latency) vulnerabilities : Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects…
IDs: CVE-2026–64088, CVE-2026–64096, CVE-2026–64185, CVE-2026–64116 and 93 more
Affects: Ubuntu 24.04, Ubuntu 22.04
USN-8801–1: Linux kernel (Azure CVM) vulnerabilities : It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made…
IDs: CVE-2026–53361, CVE-2026–52938, CVE-2025–10263, CVE-2026–53362 and 1 more
Affects: Ubuntu 24.04, Ubuntu 26.04
USN-8798–1: GStreamer Good Plugins vulnerabilities : It was discovered that GStreamer Good Plugins incorrectly parsed certain MRF files. A remote attacker could possibly use this issue to execute…
IDs: CVE-2026–18295, CVE-2026–18299, CVE-2026–18296, CVE-2026–18298
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8797–1: GStreamer Base Plugins vulnerability : It was discovered that GStreamer Base Plugins incorrectly handled certain OGG media files. A remote attacker could possibly use this issue to execute…
IDs: CVE-2026–18297
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8794–1: GLib vulnerabilities : It was discovered that GLib’s GDBus authentication mechanism failed to enforce length limitations on data lines read from a client. An…
IDs: CVE-2026–58013, CVE-2026–58016, CVE-2026–58011, CVE-2026–58015 and 5 more
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8796–1: OpenJDK 21 vulnerabilities : Kai Aizen discovered that the Networking component of OpenJDK 21 did not correctly handle user authentication. A remote attacker could possibly use…
IDs: CVE-2026–70907, CVE-2026–60589, CVE-2026–61308
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04
USN-8795–1: OpenJDK 17 vulnerabilities : Kai Aizen discovered that the Networking component of OpenJDK 17 did not correctly handle user authentication. A remote attacker could possibly use…
IDs: CVE-2026–61308, CVE-2026–60589, CVE-2026–70907
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04
USN-8790–1: Expat vulnerabilities : It was discovered that Expat could be made to allocate large amounts of memory when parsing a small crafted document. An attacker could possibly use…
IDs: CVE-2026–50219, CVE-2025–59375, CVE-2026–56408, CVE-2026–56412 and 8 more
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8793–1: Linux kernel (Azure CVM) vulnerabilities : Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects…
IDs: CVE-2026–31486, CVE-2026–46170, CVE-2026–31420, CVE-2026–46275 and 5 more
Affects: Ubuntu 24.04
USN-8729–3: Linux kernel vulnerabilities : Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects…
IDs: CVE-2026–64182, CVE-2026–64127, CVE-2026–64097, CVE-2026–64056 and 93 more
Affects: Ubuntu 24.04, Ubuntu 22.04
USN-8792–1: Memcached vulnerability : It was discovered that Memcached incorrectly handled ASCII authentication. A remote attacker could possibly use this issue to cause Memcached to…
IDs: CVE-2026–90698
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8791–1: Ghostscript vulnerability : It was discovered that Ghostscript incorrectly handled JPEG 2000 image components with mismatched subsampling factors. An attacker could possibly use…
IDs: CVE-2026–39919
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8787–1: libxml2 vulnerabilities : It was discovered that libxml2 incorrectly handled certain XML elements under certain circumstances. An attacker could possibly use this issue to…
IDs: CVE-2026–86140, CVE-2026–74860
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8786–1: rsyslog vulnerability : It was discovered that rsyslog incorrectly calculated buffer sizes when replacing strings. A remote attacker could possibly use this issue to cause…
IDs: CVE-2026–78002
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8789–1: strongSwan vulnerabilities : It was discovered that strongSwan incorrectly handled PKCS#7 containers in the openssl plugin. A remote attacker could possibly use this issue to…
IDs: CVE-2026–78124, CVE-2026–78131, CVE-2026–78134, CVE-2026–78129 and 7 more
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8788–1: ClamAV vulnerabilities : It was discovered that ClamAV incorrectly handled certain zip archive files. A remote attacker could possibly use this issue to cause ClamAV to…
IDs: CVE-2026–20348, CVE-2026–20347, CVE-2026–20346, CVE-2026–20345 and 3 more
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8785–1: OpenJDK 11 vulnerabilities : Kai Aizen discovered that the Networking component of OpenJDK 11 did not correctly handle user authentication. A remote attacker could possibly use…
IDs: CVE-2026–61308, CVE-2026–60589, CVE-2026–70907
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04
USN-8784–1: OpenJDK 8 vulnerabilities : Kai Aizen discovered that the Networking component of OpenJDK 8 did not correctly handle user authentication. A remote attacker could possibly use…
IDs: CVE-2026–70907, CVE-2026–60589, CVE-2026–61308
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8783–1: OpenJDK 25 vulnerabilities : Weber Leon discovered that the 2D component of OpenJDK 25 did not correctly handle user authentication. A remote attacker could possibly use this…
IDs: CVE-2026–61308, CVE-2026–70906, CVE-2026–70907, CVE-2026–60589
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8779–2: Bubblewrap regression : USN-8779–1 fixed vulnerabilities in Bubblewrap. Unfortunately, the fix for CVE-2026–87766 introduced a regression in symlink resolution, preventing…
IDs: -
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04
USN-8782–1: Rclone vulnerability : It was discovered that Rclone incorrectly handled unauthenticated requests to the remote control API. An attacker could possibly use this issue to…
IDs: CVE-2026–49980
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8781–1: Linux kernel (NVIDIA Tegra) vulnerabilities : It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made…
IDs: CVE-2026–53358, CVE-2026–53266, CVE-2026–74305, CVE-2025–38064 and 523 more
Affects: Ubuntu 24.04
USN-8761–2: Linux kernel (Azure FIPS) vulnerabilities : Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects…
IDs: CVE-2026–64182, CVE-2026–64127, CVE-2026–64097, CVE-2026–64056 and 91 more
Affects: Ubuntu 24.04
USN-8729–2: Linux kernel (Raspberry Pi Real-time) vulnerabilities : Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects…
IDs: CVE-2026–64182, CVE-2026–64127, CVE-2026–64097, CVE-2026–64056 and 93 more
Affects: Ubuntu 24.04