Hello TUXEDO Fans and Open-Source Enthusiasts!
This week brought some genuinely good news from our western neighbors. Both the Netherlands and France are developing workplace environments for public authorities that combine a Linux operating system with the Plasma desktop and an office suite. The Dutch had previously learned the hard way what a lack of digital sovereignty can mean. When the US government sanctioned the International Criminal Court (ICC) in The Hague in February 2025, then Chief Prosecutor Karim Khan stopped receiving business emails, while his private and institutional bank accounts in the affected jurisdictions were subsequently frozen.
The Dutch response to this experience is called Digitaal Autonome Workomgeving Overheid (DAWO). Behind the name lies an effort to create a largely autonomous working environment for the Dutch public administration, covering office and collaboration software, cloud services, identity management, and the infrastructure required for centralized system administration. The desktop systems are based on a custom implementation of NixOS called DAWO-NixOS, with KDE Plasma serving as the desktop environment.
The same combination is also being used in France, where NixOS likewise provides the foundation. In both countries, the choice fell on the relatively niche NixOS distribution mainly because of its declarative configuration model, which makes system setups reproducible and easy to deploy across additional machines. Packages and their dependencies are stored separately in the Nix store, while system configurations are versioned and can be rolled back if problems occur.
Our Open Beta for TUXEDO OS „Continuous Debian“ is also continuing according to plan. As the KDE App of the Week, this edition of TWIX introduces the new photo management application Fotos . The Tips and Tricks section focuses on the Dolphin file manager, which has a number of useful features that are not immediately obvious.
Enjoy reading,
The TUXEDO OS Team
Note: With the TWIX series, we keep you up to date with the latest developments around TUXEDO OS. We also introduce interesting applications and share practical tips and tricks for the KDE desktop and TUXEDO OS. At the same time, TWIX thrives on your feedback. We always welcome your suggestions, topic ideas, and proposals for improvement. Feel free to join the discussion in our TWIX thread on Reddit , where you can reach us directly. Of course, you are also welcome to contact us via any of our other social media channels.
Updates in TUXEDO OS
linux v7.0.0–111034.34tux1 for Ubuntu Resolute (26.04)
tuxedo-drivers v4.24.0
available for TUXEDO OS, Ubuntu, Fedora, openSUSE
Changelog
Thunderbird 153.4.0esr~tux1
Nextcloud-Desktop 34.0.4~tux1
KDE App of the Week: KDE Photos – A New Image Manager for the Plasma Desktop
If you open an image under Plasma, chances are you have been using Gwenview for many years. The image viewer has been part of the KDE desktop for more than two decades and, in addition to simply displaying images, offers numerous features for organizing and editing them. The veteran is now facing competition from within KDE itself. With Photos , formerly known as Koko , KDE is developing a younger alternative that began in 2017 as a gallery app for Plasma Mobile. Its touch-optimized interface made it particularly suitable for Linux smartphones, but the application is increasingly targeting the traditional desktop as well.
Koko Becomes Photos
Behind the distinctly generic name Photos lies the Koko application, whose project page still reveals its former name. Koko was created as a convergent image viewer based on Qt Quick and Kirigami. An application built this way adapts its interface to different screen sizes, making it suitable both for smartphones running Plasma Mobile and for desktop systems.
This technical foundation is precisely what fundamentally distinguishes Photos from the older Gwenview. Gwenview’s user interface is based on Qt Widgets and has been extended repeatedly over many years. It still works well, but KDE developers believe that its architecture now makes larger changes increasingly difficult. In particular, modernizing Gwenview for large image collections, GPU acceleration, HiDPI displays, or an interface suitable for mobile devices would require substantial changes to the codebase.
From Mobile Devices to the Desktop
Oliver Beard, Noah Davis, and other developers have extensively reworked Koko over the past year at their employer, Techpaladin Software . Their stated goal is to bring Photos to functional parity with Gwenview. The interface remains comparatively uncluttered. A sidebar provides access to different locations and collections, while the largest part of the window displays the available images. On a smartphone, Photos rearranges its controls and replaces parts of the sidebar with navigation better suited to narrow displays.
The Photos GUI is intuitive to use. The only issue we found is that the network connection doesn’t work as expected.
On the desktop, the gallery has gained considerably more functionality. Images can be sorted by name, size, creation date, modification date, or access date. Images containing GPS tags are automatically grouped by countries, states, and cities. The search function can filter the currently displayed collection by filename. For sorting, Photos follows the conventions used by the Dolphin file manager. The network view still looks unfinished at this point. Even network destinations already available in Dolphin don’t always appear there reliably, and Photos doesn’t offer its own setup option either.
Categorizing photos under the headings “Countries,” “States,” and “Cities” helps organize large collections.
The developers have also taken inspiration from Dolphin for navigation. A path bar shows the current directory and allows users to move to parent directories. A status indicator displays the number of items contained in the current location. As a result, Photos is gradually moving away from being a simple mobile gallery and toward becoming a conventional desktop image viewer.
More Than Just Viewing Images
File handling has also been expanded. The context menu can be used to copy images, open them with another application, print them, or display them in their containing directory. With Save As , you can create a copy or convert an image to another file format. Images can also be marked as favorites.
Photos is not intended to replace Dolphin, however. Some typical file manager functions are still missing. The developers are planning, for example, more convenient options for renaming and moving files, as well as drag-and-drop support between the gallery, navigation elements, and sidebar.
Photos becomes considerably more interesting when opening an individual image. Transparent areas can optionally be indicated using the familiar checkerboard pattern. On scaled displays, the image viewer now also takes the actual pixel density into account. A zoom level of 100 percent therefore means that one image pixel corresponds to one display pixel, even if the desktop itself is scaled to, for example, 150 percent.
The information view also displays metadata and allows users to assign ratings and tags. In the background, Photos maintains its own database, which can be used to access the image collection by time, location, or tags. This is one of the areas where the developers see greater long-term potential than with Gwenview.
Spectacle Helps With Editing
For image editing, Photos now uses technology that KDE users may already know from Spectacle. Its annotation tools were moved into the reusable KQuickImageEditor component and are therefore also available in Photos.
This means that images can not only be annotated with arrows, shapes, or text. The integrated editor also handles conventional tasks such as rotating, mirroring, cropping, and scaling. For quick changes, this saves users from having to launch a more comprehensive image editor.
The fact that several KDE applications use the same components is intentional. Photos also serves as a testing ground for how far more complex desktop applications can be built with Qt Quick and Kirigami. Improvements made for Photos may therefore later benefit other Kirigami applications as well.
A Replacement for Gwenview?
At the beginning of September, KDE developer Nate Graham openly suggested using Photos in place of Gwenview in the future. He highlighted in particular its better performance with large image collections and HiDPI displays, its convergent interface, and features such as favorites, timeline and location views, as well as the annotation tools adopted from Spectacle.
There has been no formal decision to replace Gwenview, however. Gwenview continues to be maintained and distributed. Graham is instead encouraging users and distributions to try Photos and report missing functionality or other problems. He already considers the current 26.08 release largely suitable for everyday use, while further improvements are planned for KDE Gear 26.12.
The developers themselves also acknowledge that Photos has not yet reached its final state. Alongside improved file management, further work is planned for the single-image view and the internal database.
Photos is therefore currently in an interesting transitional phase. The application has long since become more than the image gallery originally designed for Plasma Mobile, but it still does not match every detail of Gwenview’s feature set, which has matured over decades.
If this has made you curious to try Photos, TUXEDO OS offers both a Debian package and a Flatpak for installation through the Discover app store. Because the Flatpak provides the more recent version, it is currently the better choice.
**Info:** Are you interested in Plasma development and want to know what new features are planned and which programs have been recently updated? You can find a detailed overview in the weekly column
This week in Plasma by KDE developer Nate Graham.
TUXEDO OS Tips & Tricks for KDE’s File Manager Dolphin
Dolphin is one of those applications you use every day without giving it much thought. Opening folders, copying, renaming, or deleting files are tasks even users switching from Windows can handle from the start without any instructions. But this would not be KDE if the file manager did not hide a few functions beneath its comparatively uncluttered interface that are not immediately obvious. We present some of them.
1. Filter files instead of searching for them
If you only need to find a few specific files in a well-filled folder, you do not necessarily have to use the search function. Pressing Ctrl +I displays a filter bar at the bottom of the Dolphin window. As soon as you start typing, all entries whose file names do not contain the entered term disappear. Dolphin also supports globbing . Using the selection field to the right of the filter bar, placeholders such as * or ? are accepted. For example, *.png displays only PNG files, while holiday* matches all entries whose names begin with holiday . Especially in directories containing many files, this is often faster and more targeted than a normal text search.
The filter bar makes it easier to find entries with similar names
Unlike the search with Ctrl +F , the filter does not leave the current folder and does not search subdirectories either. Press Esc to hide the filter bar again. If you use it frequently, you can also leave it permanently visible.
2. Save a search permanently in Dolphin
The search interface opened in Dolphin with Ctrl +F can do more than simply find file names. Depending on the settings, Dolphin uses Baloo , the central background framework for file searching and indexing, to search file contents and can filter the results by criteria including file type, date range, rating, or assigned tags.
Baloo is more powerful than it may appear at first glance. More complex searches can be handed over to KFind.
Less well known is the option to save such a query. To do so, perform the desired search and then click the save icon on the right-hand side of the search bar. Dolphin then stores the query in the Search For section of the Places sidebar. Frequently used dynamic views, such as recently edited documents or files with a particular tag, can then be accessed with a single click.
The option to save a search is often overlooked. The results of frequently used searches can be brought up with a single mouse click.
3. The terminal follows Dolphin – and vice versa
Pressing F4 opens an integrated terminal at the bottom of the Dolphin window. The fact that it automatically starts in the directory currently being displayed is probably still relatively well known. More interesting, however, is that the link works in both directions.
With the terminal open, switch to another folder in Dolphin and the terminal’s working directory follows automatically. The reverse works in exactly the same way: for example, enter cd /etc in the terminal and the active Dolphin view will subsequently display /etc as well. This makes it easy to switch between graphical tools and shell commands without having to copy paths or navigate through the directory tree twice.
The link between Dolphin and Konsole works in both directions
However, the integrated terminal works only with local file systems. This synchronization therefore does not work with an SFTP or SMB directory opened via KIO.
4. Rename multiple files intelligently
Renaming a file with F2 is hardly worth a tip. However, if you select several files and then press F2 , Dolphin opens its batch renaming function. The hash serves as a placeholder for a consecutive number. Holiday-#.jpg , for example, becomes Holiday-1.jpg , Holiday-2.jpg , and so on.
There is a particularly useful special case involving files with different extensions: if you select Movie.mkv , Movie.srt , and Movie.nfo together, Dolphin can assign all three files the same new base name while preserving their respective file extensions. This makes it possible to rename related video, subtitle, and metadata files in a single operation.
5. Open remote computers directly from the address bar
Dolphin’s address bar is not limited to local paths. Press Ctrl +L to switch to editable mode and enter one of KDE’s KIO addresses. A computer with SSH access, for example, can be opened using fish://user@server . The KIO module kio-extras also supports the protocols SFTP, FTP, NFS, SMB, and WebDAV. Once a remote connection has been established, the remote files can largely be handled as if they were stored locally. Dolphin even shows which protocols are available on your system: completely clear the editable address bar and a selection list containing the protocols supported by KIO appears in front of it.
With an empty address bar, clicking file displays all supported protocols
6. Restore closed tabs
Tabs play a central role in Dolphin when it comes to keeping file management organized and avoiding the excessive opening of new application windows. Using the keyboard to control tabs saves an enormous amount of time in everyday use:
Ctrl +T : Opens a new tab, which by default opens the currently selected folder.
Ctrl +W : Closes the currently active tab.
Ctrl +TAB or Ctrl +Shift +TAB : Switches to the next or previous tab.
Ctrl +Shift +T : Reopens the most recently closed tab if you clicked the wrong thing.
The last closed tab can be reopened using the keyboard. For tabs closed some time ago, the menu is more useful.
If you want to see a list of all recently closed tabs, go to Go >> Recently Closed Tabs in the menu. The tabs can also be restored from this list.
The combination: Tabs + Split View
One of Dolphin’s most powerful features is that tabs and split view can be combined: every open tab can have its own independent split view. For example, in Tab 1 you can have your Downloads folder open on the left and a network drive on the right, while Tab 2 displays an entirely different pair of directories. This is ideal for complex copy operations between several servers.
7. Undo file operations with Ctrl+Z
Ctrl+Z does not work only in text editors or image editing applications. Dolphin can also use it to undo various file operations that have already been carried out.
The menu shows which action would be undone.
If, for example, you have renamed or moved a file or sent it to the Trash, the action can be undone with Ctrl+Z . In the Edit >> Undo menu, Dolphin also shows which specific action would currently be undone. Especially after an accidental drag-and-drop operation, this is often faster than first having to work out where a file was actually moved.
8. Compare files directly with each other
If you regularly compare configuration or text files, you should also install the Kompare package. If two files or folders are selected in Dolphin, the Compare Files function subsequently appears under Tools . Dolphin passes the selection directly to Kompare, which then displays the differences.
We will continue to work on more hidden tips and tricks for Dolphin or other KDE components in the future, so stay tuned.
Ubuntu Security Updates
The Ubuntu security updates listed here are generally incorporated directly into TUXEDO OS. Some updates are only available from Ubuntu for a fee and are therefore not made available to the community until a later date. Unfortunately, we have no control over this:
USN-8863–1: GStreamer Good Plugins vulnerabilities : Yazan Balawneh discovered that GStreamer Good Plugins incorrectly handled certain FLAC audio streams. An attacker could possibly use this issue to…
IDs: CVE-2026–17072, CVE-2026–73433, CVE-2026–73434, CVE-2026–88914
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8862–1: libXpm vulnerability : It was discovered that libXpm did not correctly handle XPM images with zero-dimension values. A local attacker could possibly use this issue to cause…
IDs: CVE-2026–94287
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8860–1: OpenStack Designate vulnerability : It was discovered that OpenStack Designate did not properly validate overlapping zones under certain circumstances. An authenticated user could…
IDs: CVE-2026–71193
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8858–1: Authen::SASL vulnerability : It was discovered that Authen::SASL, a Perl authentication library, did not properly validate login attempts. An attacker could possibly use this…
IDs: CVE-2026–86219
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8859–1: ImageMagick vulnerabilities : It was discovered that ImageMagick did not correctly handle certain images. An attacker could possibly use this issue to cause a denial of service or…
IDs: CVE-2026–93587, CVE-2026–93586, CVE-2026–93590, CVE-2026–56367 plus 2 others
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8855–1: GStreamer Bad Plugins vulnerability : It was discovered that GStreamer Bad Plugins incorrectly validated the size of multi-channel audio blocks. An attacker could possibly use this issue…
IDs: CVE-2026–19387
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8845–1: GVfs vulnerabilities : Keith Linneman discovered that GVfs did not properly validate data received from SFTP servers. An attacker could possibly use this issue to cause a…
IDs: CVE-2026–84268, CVE-2026–88924
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8816–3: Linux kernel (Oracle) vulnerabilities : Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects…
IDs: CVE-2026–72064, CVE-2026–72355, CVE-2026–72222, CVE-2026–72393 plus 97 others
Affects: Ubuntu 24.04
USN-8817–3: Linux kernel (AWS) vulnerabilities : It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made…
IDs: CVE-2026–63886, CVE-2026–53354, CVE-2026–63994, CVE-2026–53131 plus 16 others
Affects: Ubuntu 24.04, Ubuntu 22.04
USN-8854–1: OpenStack Keystone vulnerabilities : Grzegorz Grasza discovered that OpenStack Keystone did not consistently enforce restrictions for delegated authentication tokens. An authenticated…
IDs: CVE-2026–80182, CVE-2026–80184, CVE-2026–80183
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8852–1: OpenVPN vulnerabilities : It was discovered that OpenVPN had a use-after-free vulnerability in its TLS session handling. An attacker could possibly use this issue to cause…
IDs: CVE-2026–84471, CVE-2026–84732
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8848–1: Django vulnerabilities : Bence Nagy discovered that GeoDjango in Django incorrectly handled spatial lookups when processing untrusted input. A remote attacker could possibly…
IDs: CVE-2026–8404, CVE-2026–15307, CVE-2026–6907
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8817–2: Linux kernel (AWS FIPS) vulnerabilities : It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made…
IDs: CVE-2026–63886, CVE-2026–53354, CVE-2026–63994, CVE-2026–53131 plus 16 others
Affects: Ubuntu 24.04
USN-8847–1: OpenSSL vulnerabilities : It was discovered that OpenSSL incorrectly handled certain certificate revocation list distribution point names. An attacker could possibly use this…
IDs: CVE-2026–75806, CVE-2026–84782, CVE-2026–54872, CVE-2026–84784 plus 7 others
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8846–1: libheif vulnerabilities : Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain compressed metadata. A remote attacker could possibly use this issue to…
IDs: CVE-2026–84384, CVE-2026–84449, CVE-2026–84448, CVE-2026–84446 plus 1 others
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04
USN-8843–1: FreeIPMI vulnerabilities : It was discovered that FreeIPMI incorrectly handled certain malformed Fujitsu SEL long-text responses, leading to a stack-based buffer overflow. An…
IDs: CVE-2026–85507, CVE-2026–85504, CVE-2026–85505, CVE-2026–85508 plus 2 others
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8842–1: Linux kernel (NVIDIA) vulnerabilities : Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects…
IDs: CVE-2026–63887, CVE-2026–63912, CVE-2026–64000, CVE-2026–63886 plus 14 others
Affects: Ubuntu 24.04, Ubuntu 22.04
USN-8728–3: Linux kernel (Oracle) vulnerabilities : It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made…
IDs: CVE-2026–64191, CVE-2026–46159, CVE-2026–53297, CVE-2026–64067 plus 1413 others
Affects: Ubuntu 24.04
USN-8816–2: Linux kernel vulnerabilities : Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects…
IDs: CVE-2026–72442, CVE-2026–68477, CVE-2026–72064, CVE-2026–72393 plus 97 others
Affects: Ubuntu 24.04, Ubuntu 26.04
USN-8729–6: Linux kernel (AWS) vulnerabilities : Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects…
IDs: CVE-2026–64064, CVE-2026–52918, CVE-2026–64073, CVE-2026–52922 plus 93 others
Affects: Ubuntu 24.04, Ubuntu 22.04
USN-8841–1: Perl DBI module vulnerabilities : It was discovered that the Perl DBI module did not correctly handle certain integer arithmetic operations. An attacker could possibly use this issue…
IDs: CVE-2026–73194, CVE-2026–73193
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8840–1: libevent vulnerabilities : Michał Majchrowicz and Marcin Wyczechowski discovered that libevent incorrectly handled certain DNS responses. A remote attacker could possibly use…
IDs: CVE-2026–63387, CVE-2026–63388
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8839–1: Atril vulnerabilities : It was discovered that Atril did not properly sanitize command-line arguments in PDF /GoToR actions. If a user opened a specially crafted PDF file…
IDs: CVE-2019–1010006, CVE-2019–11459, CVE-2026–46529
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8838–1: catdoc vulnerabilities : It was discovered that catdoc had an integer overflow when processing shared string tables in malformed spreadsheet files. An attacker could possibly…
IDs: CVE-2024–54028, CVE-2024–52035, CVE-2024–48877
Affects: Ubuntu 24.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8837–1: pdfminer vulnerabilities : It was discovered that pdfminer did not safely parse specially crafted PDF files. An attacker could possibly use these issues to execute arbitrary…
IDs: CVE-2025–64512, CVE-2025–70559
Affects: Ubuntu 24.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8835–1: Emacs vulnerability : It was discovered that Emacs improperly handled specially crafted SVG images, resulting in memory corruption. An attacker could possibly use this…
IDs: CVE-2026–6861
Affects: Ubuntu 24.04, Ubuntu 26.04
USN-8832–1: Booth vulnerability : It was discovered that Booth did not properly validate message authentication codes under certain circumstances. A remote attacker could possibly use…
IDs: CVE-2024–3049
Affects: Ubuntu 24.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04
USN-8830–1: phpseclib vulnerabilities : It was discovered that phpseclib did not perform constant-time padding validation when using AES in CBC mode. A remote attacker could possibly use…
IDs: CVE-2026–44167, CVE-2026–32935, CVE-2026–40194
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8828–1: dracut vulnerabilities : It was discovered that dracut created initramfs images with overly permissive permissions under certain circumstances. A local attacker could…
IDs: CVE-2016–8637, CVE-2026–15816, CVE-2026–16445, CVE-2026–6893
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8827–1: Erlang vulnerabilities : It was discovered that the Erlang Port Mapper Daemon did not properly handle slow connections. A remote attacker could possibly use this issue to…
IDs: CVE-2026–23941, CVE-2026–59250, CVE-2026–74835, CVE-2026–73276 plus 15 others
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8836–1: FreeRDP vulnerabilities : It was discovered that FreeRDP contained multiple security issues. An attacker could possibly use these issues to obtain sensitive information, cause…
IDs: -
Affects: Ubuntu 24.04, Ubuntu 26.04
USN-8834–1: Exim vulnerabilities : It was discovered that Exim had an out-of-bounds write when Proxy-Protocol was used with an attacker-controlled proxy. A remote attacker could…
IDs: CVE-2026–94054, CVE-2026–94055, CVE-2026–94056, CVE-2026–94057
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8831–1: libvirt vulnerabilities : It was discovered that libvirt had an integer overflow vulnerability in the NodeGetFreePages RPC handler. A local attacker could possibly use this…
IDs: CVE-2026–77159, CVE-2026–18917
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04
USN-8826–1: LXC vulnerabilities : Maher Azzouzi discovered that LXC did not correctly handle logging certain failure messages. An attacker could possibly use this issue to leak…
IDs: CVE-2022–47952, CVE-2026–39402
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
USN-8825–1: Requests vulnerability : It was discovered that Requests did not correctly handle generating random temporary file paths. An attacker could possibly use this issue to execute…
IDs: CVE-2026–25645
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04
USN-8729–5: Linux kernel (AWS FIPS) vulnerabilities : Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects…
IDs: CVE-2026–64064, CVE-2026–52918, CVE-2026–64073, CVE-2026–52922 plus 93 others
Affects: Ubuntu 24.04
USN-8824–1: libpcap vulnerability : It was discovered that libpcap did not properly validate BPF instructions in some situation. An attacker could possibly use this issue to perform out…
IDs: CVE-2026–0799
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04, Ubuntu 14.04
USN-8823–1: PyJWT vulnerabilities : It was discovered that PyJWT incorrectly handled certain URIs when using PyJWKClient. A remote attacker could possibly use this issue to perform…
IDs: CVE-2026–48524, CVE-2026–48526, CVE-2026–48525, CVE-2026–48523 plus 1 others
Affects: Ubuntu 24.04, Ubuntu 26.04, Ubuntu 22.04, Ubuntu 20.04, Ubuntu 18.04, Ubuntu 16.04
Current BIOS/EC Versions
An EC/BIOS update affects key system components. Please ensure that you follow the instructions carefully and take your time. The process is usually completed quickly. If you have any doubts, our support team is happy to assist you. The following devices have BIOS/EC updates available:
Modell
CPU
GPU
BIOS
EC
InfinityBook Pro 15 Gen9
Intel
Intel
N.1.15A25
1.19.00
InfinityBook Pro 15 Gen10
Intel
Intel
N.1.17A13
1.20.00
InfinityBook Max 16 Gen10
Intel Core Ultra 9 275HX
RTX 5060
N.1.33A27
2.11.00
InfinityBook Max 16 Gen10
Intel Core Ultra 9 275HX
RTX 5060 (OLED)
N.1.33A27
2.11.00
InfinityBook Max 16 Gen10
Intel Core Ultra 9 275HX
RTX 5070
N.1.33A27
2.11.00
InfinityBook Max 16 Gen10
Intel Core Ultra 9 275HX
RTX 5070 (OLED)
N.1.33A27
2.11.00
Gemini 17 Gen4
Intel
Intel
1.07.11RTR5
1.09.04TR1