·
880 commits
to main
since this release
Changes since Stable 4593.2.5
Security fixes:
- Linux (CVE-2026-80888, CVE-2026-80893, CVE-2026-80892, CVE-2026-80891, CVE-2026-80890, CVE-2026-80902, CVE-2026-80901, CVE-2026-80889, CVE-2026-80887, CVE-2026-80707, CVE-2026-80716, CVE-2026-80714, CVE-2026-80711, CVE-2026-80710, CVE-2026-80709, CVE-2026-80723, CVE-2026-80722, CVE-2026-80718, CVE-2026-80717, CVE-2026-80678, CVE-2026-80686, CVE-2026-80684, CVE-2026-80681, CVE-2026-80706, CVE-2026-80704, CVE-2026-80703, CVE-2026-80702, CVE-2026-80700, CVE-2026-80680, CVE-2026-80696, CVE-2026-80695, CVE-2026-80694, CVE-2026-80691, CVE-2026-80689, CVE-2026-80679, CVE-2026-74581, CVE-2026-74579, CVE-2026-74546, CVE-2026-74555, CVE-2026-74553, CVE-2026-74552, CVE-2026-74551, CVE-2026-74550, CVE-2026-74577, CVE-2026-74576, CVE-2026-74549, CVE-2026-74575, CVE-2026-74574, CVE-2026-74572, CVE-2026-74569, CVE-2026-74567, CVE-2026-74566, CVE-2026-74548, CVE-2026-74565, CVE-2026-74564, CVE-2026-74563, CVE-2026-74557, CVE-2026-74556, CVE-2026-74547, CVE-2026-74505, CVE-2026-74512, CVE-2026-74511, CVE-2026-74510, CVE-2026-74545, CVE-2026-74509, CVE-2026-74543, CVE-2026-74541, CVE-2026-74540, CVE-2026-74536, CVE-2026-74535, CVE-2026-74508, CVE-2026-74532, CVE-2026-74531, CVE-2026-74525, CVE-2026-74507, CVE-2026-74524, CVE-2026-74523, CVE-2026-74522, CVE-2026-74519, CVE-2026-74518, CVE-2026-74516, CVE-2026-74515, CVE-2026-74461, CVE-2026-74470, CVE-2026-74469, CVE-2026-74468, CVE-2026-74467, CVE-2026-74504, CVE-2026-74503, CVE-2026-74502, CVE-2026-74501, CVE-2026-74465, CVE-2026-74500, CVE-2026-74499, CVE-2026-74498, CVE-2026-74497, CVE-2026-74495, CVE-2026-74493, CVE-2026-74492, CVE-2026-74464, CVE-2026-74490, CVE-2026-74488, CVE-2026-74485, CVE-2026-74484, CVE-2026-74482, CVE-2026-74481, CVE-2026-74463, CVE-2026-74480, CVE-2026-74478, CVE-2026-74476, CVE-2026-74475, CVE-2026-74473, CVE-2026-74472, CVE-2026-74471, CVE-2026-74440, CVE-2026-74448, CVE-2026-74447, CVE-2026-74446, CVE-2026-74445, CVE-2026-74444, CVE-2026-74443, CVE-2026-74460, CVE-2026-74442, CVE-2026-74459, CVE-2026-74458, CVE-2026-74457, CVE-2026-74456, CVE-2026-74455, CVE-2026-74454, CVE-2026-74453, CVE-2026-74452, CVE-2026-74451, CVE-2026-74441, CVE-2026-72111, CVE-2026-68451, CVE-2026-68452, CVE-2026-68367, CVE-2026-68322, CVE-2026-68276, CVE-2026-68273, CVE-2026-68267, CVE-2026-68266, CVE-2026-68264, CVE-2026-68254, CVE-2026-68253, CVE-2026-68198, CVE-2026-68169, CVE-2026-80733, CVE-2026-80732, CVE-2026-80731, CVE-2026-80730, CVE-2026-80728, CVE-2026-80739, CVE-2026-80736, CVE-2026-80726, CVE-2026-80708, CVE-2026-74714, CVE-2026-74722, CVE-2026-74720, CVE-2026-74719, CVE-2026-74718, CVE-2026-74717, CVE-2026-74732, CVE-2026-74730, CVE-2026-74726, CVE-2026-74725, CVE-2026-74724, CVE-2026-74689, CVE-2026-74688, CVE-2026-74685, CVE-2026-74712, CVE-2026-74710, CVE-2026-74705, CVE-2026-74704, CVE-2026-74701, CVE-2026-74683, CVE-2026-74700, CVE-2026-74696, CVE-2026-74694, CVE-2026-74693, CVE-2026-74692, CVE-2026-74691, CVE-2026-74682, CVE-2026-74649, CVE-2026-74658, CVE-2026-74657, CVE-2026-74656, CVE-2026-74655, CVE-2026-74654, CVE-2026-74680, CVE-2026-74679, CVE-2026-74678, CVE-2026-74677, CVE-2026-74676, CVE-2026-74675, CVE-2026-74673, CVE-2026-74671, CVE-2026-74670, CVE-2026-74669, CVE-2026-74651, CVE-2026-74668, CVE-2026-74667, CVE-2026-74666, CVE-2026-74665, CVE-2026-74664, CVE-2026-74663, CVE-2026-74661, CVE-2026-74660, CVE-2026-74659, CVE-2026-74650, CVE-2026-74615, CVE-2026-74624, CVE-2026-74623, CVE-2026-74622, CVE-2026-74621, CVE-2026-74620, CVE-2026-74619, CVE-2026-74648, CVE-2026-74647, CVE-2026-74646, CVE-2026-74618, CVE-2026-74642, CVE-2026-74641, CVE-2026-74636, CVE-2026-74635, CVE-2026-74634, CVE-2026-74632, CVE-2026-74631, CVE-2026-74630, CVE-2026-74625, CVE-2026-74616, CVE-2026-74585, CVE-2026-74594, CVE-2026-74592, CVE-2026-74590, CVE-2026-74589, CVE-2026-74588, CVE-2026-74614, CVE-2026-74613, CVE-2026-74612, CVE-2026-74610, CVE-2026-74609, CVE-2026-74608, CVE-2026-74606, CVE-2026-74587, CVE-2026-74604, CVE-2026-74603, CVE-2026-74598, CVE-2026-74597, CVE-2026-74595, CVE-2026-74586, CVE-2026-74583, CVE-2026-74582, CVE-2026-74580, CVE-2026-80903, CVE-2026-80912, CVE-2026-80911, CVE-2026-80910, CVE-2026-80909, CVE-2026-80908, CVE-2026-80907, CVE-2026-80906, CVE-2026-80913, CVE-2026-80904, CVE-2026-80894, CVE-2026-80749, CVE-2026-80744, CVE-2026-80743, CVE-2026-80742, CVE-2026-80757, CVE-2026-80756, CVE-2026-80754, CVE-2026-80752, CVE-2026-80727, CVE-2026-80715, CVE-2026-80578, CVE-2026-80587, CVE-2026-80586, CVE-2026-80585, CVE-2026-80584, CVE-2026-80589, CVE-2026-80531, CVE-2026-80540, CVE-2026-80539, CVE-2026-80577, CVE-2026-80576, CVE-2026-80575, CVE-2026-80574, CVE-2026-80573, CVE-2026-80535, CVE-2026-80570, CVE-2026-80569, CVE-2026-80568, CVE-2026-80567, CVE-2026-80566, CVE-2026-80565, CVE-2026-80563, CVE-2026-80561, CVE-2026-80534, CVE-2026-80560, CVE-2026-80559, CVE-2026-80558, CVE-2026-80556, CVE-2026-80555, CVE-2026-80554, CVE-2026-80553, CVE-2026-80552, CVE-2026-80551, CVE-2026-80533, CVE-2026-80550, CVE-2026-80549, CVE-2026-80548, CVE-2026-80547, CVE-2026-80541, CVE-2026-80532, CVE-2026-74743, CVE-2026-74742, CVE-2026-74740, CVE-2026-74739, CVE-2026-80530, CVE-2026-80529, CVE-2026-80528, CVE-2026-74737, CVE-2026-80527, CVE-2026-80526, CVE-2026-80525, CVE-2026-80522, CVE-2026-74736, CVE-2026-74748, CVE-2026-74746, CVE-2026-74744, CVE-2026-80918, CVE-2026-80917, CVE-2026-80915, CVE-2026-80916, CVE-2026-80823, CVE-2026-80791, CVE-2026-80800, CVE-2026-80799, CVE-2026-80798, CVE-2026-80797, CVE-2026-80795, CVE-2026-80794, CVE-2026-80820, CVE-2026-80819, CVE-2026-80815, CVE-2026-80814, CVE-2026-80812, CVE-2026-80793, CVE-2026-80809, CVE-2026-80808, CVE-2026-80805, CVE-2026-80803, CVE-2026-80802, CVE-2026-80801, CVE-2026-80792, CVE-2026-80767, CVE-2026-80765, CVE-2026-80764, CVE-2026-80763, CVE-2026-80790, CVE-2026-80789, CVE-2026-80788, CVE-2026-80784, CVE-2026-80782, CVE-2026-80781, CVE-2026-80779, CVE-2026-80772, CVE-2026-80771, CVE-2026-80770, CVE-2026-80759, CVE-2026-80737, CVE-2026-80725, CVE-2026-80590, CVE-2026-80923, CVE-2026-80921, CVE-2026-80922, CVE-2026-80839, CVE-2026-80848, CVE-2026-80846, CVE-2026-80845, CVE-2026-80844, CVE-2026-80843, CVE-2026-80842, CVE-2026-80864, CVE-2026-80863, CVE-2026-80862, CVE-2026-80856, CVE-2026-80855, CVE-2026-80854, CVE-2026-80852, CVE-2026-80851, CVE-2026-80850, CVE-2026-80849, CVE-2026-80840, CVE-2026-80824, CVE-2026-80832, CVE-2026-80831, CVE-2026-80830, CVE-2026-80829, CVE-2026-80828, CVE-2026-80827, CVE-2026-80826, CVE-2026-80838, CVE-2026-80837, CVE-2026-80835, CVE-2026-80825, CVE-2026-80796, CVE-2026-80807, CVE-2026-80806, CVE-2026-80766, CVE-2026-80762, CVE-2026-80783, CVE-2026-80780, CVE-2026-80774, CVE-2026-80768, CVE-2026-80755, CVE-2026-80914)
- bind (CVE-2025-40778, CVE-2025-40780, CVE-2025-8677)
- bubblewrap (CVE-2026-41163)
- c-ares (CVE-2025-62408)
- containerd (CVE-2026-47262, CVE-2026-50195, CVE-2026-53488, CVE-2026-53489, CVE-2026-53492)
- curl (CVE-2025-13034, CVE-2025-14017, CVE-2025-14524, CVE-2025-14819, CVE-2025-15079, CVE-2025-15224, CVE-2026-1965, CVE-2026-3783, CVE-2026-3784, CVE-2026-3805)
- expat (CVE-2026-24515, CVE-2026-25210, CVE-2026-32776, CVE-2026-32777, CVE-2026-32778, CVE-2026-41080, CVE-2026-45186)
- glib (CVE-2025-13601, CVE-2025-14087)
- glibc (CVE-2026-0861, CVE-2026-0915, CVE-2025-15281)
- gnupg (CVE-2026-24881, CVE-2026-24882, CVE-2026-24883)
- gnutls (CVE-2025-14831, CVE-2026-1584, CVE-2025-9820, CVE-2026-33845, CVE-2026-33846, CVE-2026-3832, CVE-2026-3833, CVE-2026-42009, CVE-2026-42010, CVE-2026-42011, CVE-2026-42012, CVE-2026-42013, CVE-2026-42014, CVE-2026-42015, CVE-2026-5260, CVE-2026-5419)
- go (CVE-2025-61726, CVE-2025-61728, CVE-2025-61730, CVE-2025-61731, CVE-2025-68119, CVE-2025-68121, CVE-2025-61732, CVE-2026-25679, CVE-2026-27139, CVE-2026-27142, CVE-2025-61727, CVE-2025-61729, CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-2026-32281, CVE-2026-32282, CVE-2026-32283, CVE-2026-32288, CVE-2026-32289, CVE-2026-33811, CVE-2026-33814, CVE-2026-39817, CVE-2026-39819, CVE-2026-39820, CVE-2026-39823, CVE-2026-39825, CVE-2026-39826, CVE-2026-39836, CVE-2026-42499, CVE-2026-42501)
- incus (CVE-2026-23953)
- intel-microcode (CVE-2025-31648)
- libarchive (CVE-2025-60753, CVE-2026-4426)
- libcap (CVE-2026-4878)
- libgcrypt (CVE-2026-41989)
- libpcap (CVE-2025-11961, CVE-2025-11964)
- libtasn1 (CVE-2025-13151)
- libxml2 (CVE-2026-0989, CVE-2026-0990, CVE-2026-0992, CVE-2026-1757, libxml2-20260415)
- libxslt (CVE-2025-10911, CVE-2025-11731)
- nvidia-drivers (CVE-2025-33219, CVE-2025-33221, CVE-2026-24182, CVE-2026-24187, CVE-2026-24190, CVE-2026-24192, CVE-2026-24193, CVE-2026-24194, CVE-2026-24195, CVE-2026-24196, CVE-2026-24197, CVE-2026-24198, CVE-2026-24199)
- openssh (CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414)
- openssl (CVE-2026-2673, CVE-2026-28386, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31790, CVE-2026-34180, CVE-2026-34181, CVE-2026-34182, CVE-2026-34183, CVE-2026-35188, CVE-2026-42764, CVE-2026-42765, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768, CVE-2026-42769, CVE-2026-42770, CVE-2026-42771, CVE-2026-45445, CVE-2026-45446, CVE-2026-45447, CVE-2026-7383, CVE-2026-9076)
- p11-kit (CVE-2026-2100)
- podman (CVE-2025-9566, CVE-2025-52881)
- rsync (CVE-2025-10158, CVE-2026-41035, CVE-2026-29518, CVE-2026-43617, CVE-2026-43618, CVE-2026-43619, CVE-2026-43620, CVE-2026-45232)
- runc (CVE-2026-41579)
- sssd (CVE-2025-11561, CVE-2026-6245)
- systemd (CVE-2026-40223, CVE-2026-40226, CVE-2026-40225)
- urllib3 (CVE-2025-66418, CVE-2025-66471)
- util-linux (CVE-2025-14104, CVE-2026-27456)
- xz-utils (CVE-2026-34743)
- zlib (CVE-2026-27171)
Bug fixes:
- Added full terminfo database to support modern terminals like foot and Alacritty.
- Fixed booting the VirtualBox image, which was broken since upstream Ignition changed how their VirtualBox support works. The Vagrant VirtualBox image was unaffected.
- Fixed using Ignition to create new partitions with number 0 to get the next available slot. (ignition#2234)
- Updated the GCE udev disk rules to include NVMe disks. (scripts#3606)
Changes:
- Exoscale: images are now built as 10G .qcow2 so they can be directly used with Exoscale Custom Templates (scripts#4075)
- Add EROFS tools for containerd (Flatcar#2047)
- Added Oracle Cloud Infrastructure images (flatcar/scripts#3846)
- Added kernel config options to support HuC firmware authentication which is required for Intel Arc (DG2) hardware offloading for video. (scripts#4019)
- All the legacy OEMs (CloudSigma, CloudStack, Exoscale, Vagrant, VirtualBox) have been converted to sysexts. The transition should be seamless, but the Flatcar team was only able to test VirtualBox with and without Vagrant, so please report any issues.
- Build AMD GPU driver as module (#3461)
- Dropped support for Equinix Metal (Packet). The servers are due to be switched off on June 30th 2026.
- Dropped support for Rackspace, including OnMetal. Rackspace-specific images are no longer built or published. Flatcar only had community level support for Rackspace, and the Flatcar team is no longer confident that this support actually works. Rackspace themselves have pivoted from being an independent cloud provider to being a management platform for other clouds.
- Dropped the "Oklo" release codename as it was never updated in a meaningful way.
- Dropped the VMware "insecure" image. This was added a long time ago, and it is not clear to the current Flatcar team what purpose it served. It included the Vagrant insecure SSH key but without the other Vagrant files. If you want to use Vagrant, then do so with VirtualBox or Parallels. If you want to deploy onto VMware quickly, then use the OVA image.
- Dropped the Vagrant VirtualBox image because the regular Vagrant image also targets VirtualBox. The only difference between them was that the former was geared for provisioning with Ignition and Afterburn rather than cloud-config and Vagrant itself. The Ignition support was broken when it was dropped by upstream. A single image can handle Ignition, cloud-config, and Vagrant. The Afterburn support has been dropped entirely.
- Enable VNC console serial logs on ARM64 QEMU/KVM instances (flatcar/scripts#2359)
- Moved systemd-sysext image mounting into the initrd, so that system extensions can better define the behavior of the final system at boot without workarounds to apply settings late at boot. This means
.wantssymlinks for systemd units work as expected now and, therefore, we dropped theensure-sysext.serviceworkaround. We still recommend extensions to keep their workarounds, e.g., using.upholdsinstead of.wants, to better support live reloading. A skipping logic prevents an extension refresh late at boot but only if no changes were found. For extensions that are not stored on a custom filesystem, such as a separate/varpartition, the new extension mounting from the initrd won't be able to load them early but they will be picked up late at boot through the extension refresh. This is another case where it's good if extensions keep workarounds for late loading. - OS-dependent sysexts (e.g., docker-flatcar, containerd-flatcar, podman, zfs, nvidia) are now cryptographically signed using dm-verity roothash signatures. This enables stricter sysext policies via systemd-sysext and provides a foundation for verifying user-provided extensions in future releases. The format changed from squashfs to erofs-based Discoverable Disk Images (DDI). OEM sysexts (e.g., oem-azure, oem-gce) are now also signed and built during the image phase to ensure consistent signing with the same ephemeral key. (scripts#3162)
- Refreshed the Vagrant and Vagrant Parallels images for use with recent Vagrant releases, adding implicit support for provisioning with Ignition (VirtualBox only) or cloud-config. Vagrant 2.2.5 is now required. See the revised documentation for further details.
- Refreshed the VirtualBox OVF (which is also used by the Vagrant image) so that VMs are configured with modern hardware, including a VirtIO storage controller and UEFI. The clock is configured for UTC rather than local time.
- Reworked how the OEM partition is mounted at boot time so that Ignition no longer has to handle this by itself, thereby requiring less patching. This should not affect any existing usage, but it is a significant underlying change, so it needs to be called out. Please report any unexpected issues. (flatcar/script#3934)
- Switched
/etc/from a custom overlayfs for A/B updates to using a systemd-confext extension providing the default contents by using systemd-confext in the mutable mode where/etc/gets used as upperdir scripts#3555 - enable
/dev/kfd/in amdgpu driver on AMD64
Updates:
- Linux (6.12.109 (includes 6.12.108, 6.12.107, 6.12.106, 6.12.105, 6.12.104, 6.12.103))
- Linux Firmware (20260519 (includes 20260410, 20260309, 20260221, 20260110))
- SDK: bubblewrap (0.11.2)
- SDK: catalyst (4.1.1)
- SDK: cmake (4.1.4)
- SDK: crossdev (20251214)
- SDK: edk2-bin (202605 (includes 202602, 202511, 202508, 202505, 202502, 202411))
- SDK: gnu-efi (4.0.4 (includes 4.0.3))
- SDK: go (1.26.3 (includes 1.25.8, 1.25.7, 1.25.6, 1.25.5))
- SDK: meson (1.9.2)
- SDK: perl (5.42.0)
- SDK: qemu (10.2.2 (includes 10.2.0, 10.1.0))
- SDK: rust (1.93.1 (includes 1.93.0, 1.92.0_p1, 1.91.0, 1.90.0))
- azure, dev, gce, sysext-python: python (3.12.13_p1)
- azure, dev, sysext-python: urllib3 (2.7.0 (includes 2.6.3))
- base, dev: adcli (0.9.3.1 (includes 0.9.3))
- base, dev: audit (4.1.4 (includes 4.1.3, 4.1.2, 4.1.1, 4.1.0))
- base, dev: bash (5.3_p9)
- base, dev: bind (9.18.42)
- base, dev: binutils-config (5.6)
- base, dev: binutils-libs (2.46.0)
- base, dev: bpftool (7.7.0)
- base, dev: btrfs-progs (6.19.1 (includes 6.19, 6.17.1))
- base, dev: c-ares (1.34.6)
- base, dev: checkpolicy (3.9)
- base, dev: cifs-utils (7.5)
- base, dev: conntrack-tools (1.4.9)
- base, dev: coreutils (9.11 (includes 9.10, 9.9))
- base, dev: cri-tools (1.33.0)
- base, dev: cryptsetup (2.8.6 (includes 2.8.4, 2.8.3, 2.8.2))
- base, dev: curl (8.19.0 (includes 8.18.0, 8.17.0))
- base, dev: dracut (110)
- base, dev: e2fsprogs (1.47.4)
- base, dev: elfutils (0.195 (includes 0.194))
- base, dev: ethtool (6.19)
- base, dev: expat (2.8.1 (includes 2.8.0, 2.7.5, 2.7.4))
- base, dev: gentoo-functions (1.7.6)
- base, dev: git (2.53.0 (includes 2.52.0))
- base, dev: glibc (2.42)
- base, dev: gnupg (2.5.18 (includes 2.5.17))
- base, dev: gnutls (3.8.13 (includes 3.8.12, 3.8.11))
- base, dev: hwdata (0.401)
- base, dev: intel-microcode (20260512_p20260513 (includes 20260227_p20260227, 20260210_p20260211))
- base, dev: iproute2 (6.19.0 (includes 6.18.0))
- base, dev: iptables (1.8.13 (includes 1.8.12))
- base, dev: kexec-tools (2.0.32)
- base, dev: less (692 (includes 691))
- base, dev: libarchive (3.8.7 (includes 3.8.6, 3.8.5, 3.8.4, 3.8.3, 3.8.2))
- base, dev: libcap (2.78 (includes 2.77))
- base, dev: libcap-ng (0.9.3 (includes 0.9.2, 0.9.1, 0.9))
- base, dev: libgcrypt (1.12.2 (includes 1.12.1, 1.12.0))
- base, dev: libgpg-error (1.59 (includes 1.58))
- base, dev: libksba (1.6.8)
- base, dev: libnetfilter_conntrack (1.1.1)
- base, dev: libnftnl (1.3.1)
- base, dev: libnl (3.12.0 (includes 3.11.0))
- base, dev: libnvme (1.16.1 (includes 1.16))
- base, dev: libpcap (1.10.6)
- base, dev: libpcre2 (10.47)
- base, dev: libselinux (3.9)
- base, dev: libsepol (3.9)
- base, dev: libsodium (1.0.22 (includes 1.0.21_p20260122))
- base, dev: libtasn1 (4.21.0)
- base, dev: libxml2 (2.15.3 (includes 2.15.2, 2.15.1, 2.15.0))
- base, dev: linux-headers (6.18)
- base, dev: lsof (4.99.6)
- base, dev: lvm2 (2.03.39 (includes 2.03.38, 2.03.37, 2.03.36, 2.03.35, 2.03.34, 2.03.33, 2.03.32, 2.03.31, 2.03.30, 2.03.29, 2.03.28, 2.03.27, 2.03.26, 2.03.25, 2.03.24, 2.03.23, 2.03.22))
- base, dev: mdadm (4.6 (includes 4.5))
- base, dev: multipath-tools (0.14.3 (includes 0.14.2, 0.14.1, 0.14.0, 0.13.0, 0.12.0, 0.11.0, 0.10.0, 0.9.9))
- base, dev: ncurses (6.5_p20251220)
- base, dev: nfs-utils (2.8.5 (includes 2.8.4, 2.8.3, 2.8.2, 2.8.1))
- base, dev: nftables (1.1.6)
- base, dev: nghttp2 (1.68.0 (includes 1.67.1, 1.67.0, 1.66.0))
- base, dev: ngtcp2 (1.22.1)
- base, dev: nvme-cli (2.16)
- base, dev: openssh (10.3_p1)
- base, dev: openssl (3.5.7 (includes 3.5.6))
- base, dev: p11-kit (0.26.2 (includes 0.26.1, 0.26.0, 0.25.10, 0.25.9, 0.25.8, 0.25.7, 0.25.6))
- base, dev: pam (1.7.2)
- base, dev: pambase (20251104)
- base, dev: parted (3.7)
- base, dev: pax-utils (1.3.10)
- base, dev: pciutils (3.15.0)
- base, dev: procps (4.0.6)
- base, dev: quota (4.11)
- base, dev: readline (8.3_p3)
- base, dev: rsync (3.4.3 (includes 3.4.2))
- base, dev: samba (4.23.6 (includes 4.23.5, 4.23.4, 4.23.3, 4.23.2, 4.23.1, 4.23.0))
- base, dev: selinux-base (2.20250618)
- base, dev: semodule-utils (3.9)
- base, dev: shadow (4.19.4 (includes 4.19.3, 4.19.2, 4.19.1, 4.19.0, 4.18.0, 4.17.0, 4.16.0, 4.15.0))
- base, dev: socat (1.8.1.1 (includes 1.8.1.0))
- base, dev: sqlite (3.51.3 (includes 3.51.2))
- base, dev: sssd (2.13.0 (includes 2.12.0, 2.11.0, 2.10.0, 2.9.8))
- base, dev: strace (6.19 (includes 6.18))
- base, dev: systemd (260.1 (includes 259.4, 258.3, 257.10))
- base, dev: tcpdump (4.99.6)
- base, dev: tdb (1.4.14)
- base, dev: tevent (0.17.1 (includes 0.17.0))
- base, dev: thin-provisioning-tools (1.3.1)
- base, dev: usbutils (019)
- base, dev: userspace-rcu (0.15.6 (includes 0.15.5))
- base, dev: util-linux (2.41.4 (includes 2.41.3))
- base, dev: whois (5.6.6)
- base, dev: wireguard-tools (1.0.20250521)
- base, dev: xfsprogs (6.19.0 (includes 6.18.0, 6.17.0))
- base, dev: xz-utils (5.8.3 (includes 5.8.2))
- base, dev: zlib (1.3.2)
- ca-certificates (3.128 (includes 3.127))
- dev, sysext-incus: squashfs-tools (4.7.5 (includes 4.7.4))
- dev: bash-completion (2.17.0)
- dev: binutils (2.46.0 (includes 2.45.1))
- dev: cJSON (1.7.19)
- dev: debugedit (5.3)
- dev: eselect (1.4.31)
- dev: file (5.47)
- dev: gcc-config (2.12.2)
- dev: gdb (17.1)
- dev: gentoolkit (0.7.2 (includes 0.7.1))
- dev: getuto (1.18)
- dev: iperf (3.21 (includes 3.20))
- dev: man-pages (6.17 (includes 6.16, 6.15, 6.14, 6.13, 6.12, 6.11))
- dev: minicom (2.11.1 (includes 2.11))
- dev: mpc (1.4.1 (includes 1.4.0))
- dev: portage (3.0.81 (includes 3.0.80, 3.0.79, 3.0.78, 3.0.77, 3.0.76, 3.0.75, 3.0.74, 3.0.73, 3.0.72, 3.0.71, 3.0.70))
- nss-usrfiles (2.43)
- open-vm-tools (13.0.10)
- shim (16.1 (includes 16.0))
- sysext-containerd: containerd (2.2.5 (includes 2.2.4, 2.2.3, 2.2.2, 2.2.1, 2.2.0))
- sysext-containerd: runc (1.4.3 (includes 1.4.2, 1.4.1, 1.4.0))
- sysext-docker: docker (28.2.2 (includes 28.2.1, 28.2.0, 28.1.1, 28.1.0))
- sysext-docker: docker-cli (29.1.3 (includes 29.1.2, 29.1.1, 29.1.0, 29.0.4, 29.0.3, 29.0.2, 29.0.1, 29.0.0, 28.5.2, 28.5.1, 28.5.0, 28.4.0, 28.3.0, 28.2.0, 28.1.0))
- sysext-incus, sysext-podman, vmware: fuse (3.18.2 (includes 3.18.1, 3.18.0))
- sysext-incus: dnsmasq (2.92_p2)
- sysext-incus: incus (6.0.5)
- sysext-incus: lxc (6.0.5)
- sysext-incus: lxcfs (6.0.5)
- sysext-nvidia-drivers-535, sysext-nvidia-drivers-535-open: nvidia-drivers (535.309.01 (includes 535.288.01))
- sysext-nvidia-drivers-570, sysext-nvidia-drivers-570-open: nvidia-drivers (570.211.01 (includes 570.207))
- sysext-overlaybd: accelerated-container-image (1.4.3 (includes 1.4.2, 1.4.1, 1.4.0))
- sysext-overlaybd: overlaybd (1.0.17)
- sysext-podman: aardvark-dns (1.17.0 (includes 1.16.0))
- sysext-podman: containers-common (0.64.2 (includes 0.64.1, 0.64.0))
- sysext-podman: containers-image (5.36.2 (includes 5.36.1, 5.36.0, 5.35.0))
- sysext-podman: containers-storage (1.59.1 (includes 1.59.0, 1.58.0))
- sysext-podman: fuse-overlayfs (1.16)
- sysext-podman: netavark (1.17.1 (includes 1.17.0))
- sysext-podman: passt (2025.12.15)
- sysext-podman: podman (5.7.1 (includes 5.7.0, 5.6.0))
- sysext-python: charset-normalizer (3.4.7 (includes 3.4.6, 3.4.5, 3.4.4))
- sysext-python: idna (3.14 (includes 3.13, 3.12, 3.11))
- sysext-python: jaraco-context (6.1.2 (includes 6.1.0))
- sysext-python: jaraco-functools (4.4.0)
- sysext-python: jaraco-text (4.2.0)
- sysext-python: linkify-it-py (2.1.0)
- sysext-python: more-itertools (11.0.2 (includes 11.0.1, 11.0.0))
- sysext-python: msgpack (1.1.2)
- sysext-python: packaging (26.1 (includes 26.0))
- sysext-python: pip (26.0.1 (includes 25.3))
- sysext-python: platformdirs (4.9.6 (includes 4.9.0, 4.8.0, 4.7.0, 4.6.0))
- sysext-python: requests (2.33.1 (includes 2.33.0))
- sysext-python: rich (15.0.0 (includes 14.3.0))
- sysext-python: setuptools-scm (10.0.5 (includes 10.0.0, 9.2.2))
- sysext-python: trove-classifiers (2026.1.14.14 (includes 2025.11.14.15))
- sysext-python: uc-micro-py (2.0.0)
- sysext-python: wheel (0.47.0 (includes 0.46.2, 0.46.1, 0.46.0))
- sysext-zfs: zfs (2.3.6 (includes 2.3.5, 2.3.4))
- systemd (260.4 (includes 260.3, 260.2, 258.2))
- vmware: libdnet (1.18.2)
- vmware: libxslt (1.1.45)
- vmware: xmlsec (1.3.10 (includes 1.3.9, 1.3.8))
Changes since Beta 4757.1.0
Security fixes:
- Linux (CVE-2026-80888, CVE-2026-80893, CVE-2026-80892, CVE-2026-80891, CVE-2026-80890, CVE-2026-80902, CVE-2026-80901, CVE-2026-80889, CVE-2026-80887, CVE-2026-80707, CVE-2026-80716, CVE-2026-80714, CVE-2026-80711, CVE-2026-80710, CVE-2026-80709, CVE-2026-80723, CVE-2026-80722, CVE-2026-80718, CVE-2026-80717, CVE-2026-80678, CVE-2026-80686, CVE-2026-80684, CVE-2026-80681, CVE-2026-80706, CVE-2026-80704, CVE-2026-80703, CVE-2026-80702, CVE-2026-80700, CVE-2026-80680, CVE-2026-80696, CVE-2026-80695, CVE-2026-80694, CVE-2026-80691, CVE-2026-80689, CVE-2026-80679, CVE-2026-74581, CVE-2026-74579, CVE-2026-74546, CVE-2026-74555, CVE-2026-74553, CVE-2026-74552, CVE-2026-74551, CVE-2026-74550, CVE-2026-74577, CVE-2026-74576, CVE-2026-74549, CVE-2026-74575, CVE-2026-74574, CVE-2026-74572, CVE-2026-74569, CVE-2026-74567, CVE-2026-74566, CVE-2026-74548, CVE-2026-74565, CVE-2026-74564, CVE-2026-74563, CVE-2026-74557, CVE-2026-74556, CVE-2026-74547, CVE-2026-74505, CVE-2026-74512, CVE-2026-74511, CVE-2026-74510, CVE-2026-74545, CVE-2026-74509, CVE-2026-74543, CVE-2026-74541, CVE-2026-74540, CVE-2026-74536, CVE-2026-74535, CVE-2026-74508, CVE-2026-74532, CVE-2026-74531, CVE-2026-74525, CVE-2026-74507, CVE-2026-74524, CVE-2026-74523, CVE-2026-74522, CVE-2026-74519, CVE-2026-74518, CVE-2026-74516, CVE-2026-74515, CVE-2026-74461, CVE-2026-74470, CVE-2026-74469, CVE-2026-74468, CVE-2026-74467, CVE-2026-74504, CVE-2026-74503, CVE-2026-74502, CVE-2026-74501, CVE-2026-74465, CVE-2026-74500, CVE-2026-74499, CVE-2026-74498, CVE-2026-74497, CVE-2026-74495, CVE-2026-74493, CVE-2026-74492, CVE-2026-74464, CVE-2026-74490, CVE-2026-74488, CVE-2026-74485, CVE-2026-74484, CVE-2026-74482, CVE-2026-74481, CVE-2026-74463, CVE-2026-74480, CVE-2026-74478, CVE-2026-74476, CVE-2026-74475, CVE-2026-74473, CVE-2026-74472, CVE-2026-74471, CVE-2026-74440, CVE-2026-74448, CVE-2026-74447, CVE-2026-74446, CVE-2026-74445, CVE-2026-74444, CVE-2026-74443, CVE-2026-74460, CVE-2026-74442, CVE-2026-74459, CVE-2026-74458, CVE-2026-74457, CVE-2026-74456, CVE-2026-74455, CVE-2026-74454, CVE-2026-74453, CVE-2026-74452, CVE-2026-74451, CVE-2026-74441, CVE-2026-72111, CVE-2026-68451, CVE-2026-68452, CVE-2026-68367, CVE-2026-68322, CVE-2026-68276, CVE-2026-68273, CVE-2026-68267, CVE-2026-68266, CVE-2026-68264, CVE-2026-68254, CVE-2026-68253, CVE-2026-68198, CVE-2026-68169, CVE-2026-80733, CVE-2026-80732, CVE-2026-80731, CVE-2026-80730, CVE-2026-80728, CVE-2026-80739, CVE-2026-80736, CVE-2026-80726, CVE-2026-80708, CVE-2026-74714, CVE-2026-74722, CVE-2026-74720, CVE-2026-74719, CVE-2026-74718, CVE-2026-74717, CVE-2026-74732, CVE-2026-74730, CVE-2026-74726, CVE-2026-74725, CVE-2026-74724, CVE-2026-74689, CVE-2026-74688, CVE-2026-74685, CVE-2026-74712, CVE-2026-74710, CVE-2026-74705, CVE-2026-74704, CVE-2026-74701, CVE-2026-74683, CVE-2026-74700, CVE-2026-74696, CVE-2026-74694, CVE-2026-74693, CVE-2026-74692, CVE-2026-74691, CVE-2026-74682, CVE-2026-74649, CVE-2026-74658, CVE-2026-74657, CVE-2026-74656, CVE-2026-74655, CVE-2026-74654, CVE-2026-74680, CVE-2026-74679, CVE-2026-74678, CVE-2026-74677, CVE-2026-74676, CVE-2026-74675, CVE-2026-74673, CVE-2026-74671, CVE-2026-74670, CVE-2026-74669, CVE-2026-74651, CVE-2026-74668, CVE-2026-74667, CVE-2026-74666, CVE-2026-74665, CVE-2026-74664, CVE-2026-74663, CVE-2026-74661, CVE-2026-74660, CVE-2026-74659, CVE-2026-74650, CVE-2026-74615, CVE-2026-74624, CVE-2026-74623, CVE-2026-74622, CVE-2026-74621, CVE-2026-74620, CVE-2026-74619, CVE-2026-74648, CVE-2026-74647, CVE-2026-74646, CVE-2026-74618, CVE-2026-74642, CVE-2026-74641, CVE-2026-74636, CVE-2026-74635, CVE-2026-74634, CVE-2026-74632, CVE-2026-74631, CVE-2026-74630, CVE-2026-74625, CVE-2026-74616, CVE-2026-74585, CVE-2026-74594, CVE-2026-74592, CVE-2026-74590, CVE-2026-74589, CVE-2026-74588, CVE-2026-74614, CVE-2026-74613, CVE-2026-74612, CVE-2026-74610, CVE-2026-74609, CVE-2026-74608, CVE-2026-74606, CVE-2026-74587, CVE-2026-74604, CVE-2026-74603, CVE-2026-74598, CVE-2026-74597, CVE-2026-74595, CVE-2026-74586, CVE-2026-74583, CVE-2026-74582, CVE-2026-74580, CVE-2026-80903, CVE-2026-80912, CVE-2026-80911, CVE-2026-80910, CVE-2026-80909, CVE-2026-80908, CVE-2026-80907, CVE-2026-80906, CVE-2026-80913, CVE-2026-80904, CVE-2026-80894, CVE-2026-80749, CVE-2026-80744, CVE-2026-80743, CVE-2026-80742, CVE-2026-80757, CVE-2026-80756, CVE-2026-80754, CVE-2026-80752, CVE-2026-80727, CVE-2026-80715, CVE-2026-80578, CVE-2026-80587, CVE-2026-80586, CVE-2026-80585, CVE-2026-80584, CVE-2026-80589, CVE-2026-80531, CVE-2026-80540, CVE-2026-80539, CVE-2026-80577, CVE-2026-80576, CVE-2026-80575, CVE-2026-80574, CVE-2026-80573, CVE-2026-80535, CVE-2026-80570, CVE-2026-80569, CVE-2026-80568, CVE-2026-80567, CVE-2026-80566, CVE-2026-80565, CVE-2026-80563, CVE-2026-80561, CVE-2026-80534, CVE-2026-80560, CVE-2026-80559, CVE-2026-80558, CVE-2026-80556, CVE-2026-80555, CVE-2026-80554, CVE-2026-80553, CVE-2026-80552, CVE-2026-80551, CVE-2026-80533, CVE-2026-80550, CVE-2026-80549, CVE-2026-80548, CVE-2026-80547, CVE-2026-80541, CVE-2026-80532, CVE-2026-74743, CVE-2026-74742, CVE-2026-74740, CVE-2026-74739, CVE-2026-80530, CVE-2026-80529, CVE-2026-80528, CVE-2026-74737, CVE-2026-80527, CVE-2026-80526, CVE-2026-80525, CVE-2026-80522, CVE-2026-74736, CVE-2026-74748, CVE-2026-74746, CVE-2026-74744, CVE-2026-80918, CVE-2026-80917, CVE-2026-80915, CVE-2026-80916, CVE-2026-80823, CVE-2026-80791, CVE-2026-80800, CVE-2026-80799, CVE-2026-80798, CVE-2026-80797, CVE-2026-80795, CVE-2026-80794, CVE-2026-80820, CVE-2026-80819, CVE-2026-80815, CVE-2026-80814, CVE-2026-80812, CVE-2026-80793, CVE-2026-80809, CVE-2026-80808, CVE-2026-80805, CVE-2026-80803, CVE-2026-80802, CVE-2026-80801, CVE-2026-80792, CVE-2026-80767, CVE-2026-80765, CVE-2026-80764, CVE-2026-80763, CVE-2026-80790, CVE-2026-80789, CVE-2026-80788, CVE-2026-80784, CVE-2026-80782, CVE-2026-80781, CVE-2026-80779, CVE-2026-80772, CVE-2026-80771, CVE-2026-80770, CVE-2026-80759, CVE-2026-80737, CVE-2026-80725, CVE-2026-80590, CVE-2026-80923, CVE-2026-80921, CVE-2026-80922, CVE-2026-80839, CVE-2026-80848, CVE-2026-80846, CVE-2026-80845, CVE-2026-80844, CVE-2026-80843, CVE-2026-80842, CVE-2026-80864, CVE-2026-80863, CVE-2026-80862, CVE-2026-80856, CVE-2026-80855, CVE-2026-80854, CVE-2026-80852, CVE-2026-80851, CVE-2026-80850, CVE-2026-80849, CVE-2026-80840, CVE-2026-80824, CVE-2026-80832, CVE-2026-80831, CVE-2026-80830, CVE-2026-80829, CVE-2026-80828, CVE-2026-80827, CVE-2026-80826, CVE-2026-80838, CVE-2026-80837, CVE-2026-80835, CVE-2026-80825, CVE-2026-80796, CVE-2026-80807, CVE-2026-80806, CVE-2026-80766, CVE-2026-80762, CVE-2026-80783, CVE-2026-80780, CVE-2026-80774, CVE-2026-80768, CVE-2026-80755, CVE-2026-80914)
- openssh (CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, CVE-2026-60002)