Heya folks! It's sync day, and that means it's time for the weekly Solus roundup! There is a lot to cover this time around.
Our kernels have been updated for more fixes. The mainline kernel version is now 7.0.9, while the LTS kernel is 6.18.32. These kernels contain fixes for Bluetooth, and updated patches for the DirtyFrag vulnerability. Check out the changelogs here and here for more.
LLVM has been updated this week to 21.1.8, unblocking several updates, like a newer Rust. If you want to know what's new in this version, head over here.
Big day for KDE Plasma users! This week, we have Qt, Frameworks, Plasma, and Gear updates. Qt6 has been updated to 6.11.1. Go here to see what's new in 6.11. KDE Frameworks has been updated to 6.26.0. Plasma has been updated to 6.6.5. Lastly, Gear has been updated to 26.04.1 (see also the changelog for 26.04.0).
We've made it so that Budgie and GNOME control centers, Powerdevil, and QuickShell aren't forced to depend on power-profiles-daemon. This means that you can now use a different power daemon, such as TLP (tlp-pd). power-profiles-daemon will still be installed by default on all Solus editions.
Ardour has been updated to 9.5. This release brings major updates and new features including: Dedicated Pianoroll, Note Brushing & Strumming, Quick Duplication, Region FX, Live Looping & Clip Launching, Real-Time Perceptual Analyze, and more. Check out the changelog here.
Lastly, we have a bunch of new additions to the repository:
- Syncthing Tray provides a tray icon and further platform integration for Syncthing. Syncthing GTK is already in the repositories but is geared more towards GNOME and GTK. Syncthing tray is a better fit for users using KDE Plasma as it has dolphin context menu support as well as a Plasmoid/Widget.
- Foot is a fast, lightweight, minimalist terminal emulator built specifically for Wayland. It is DE-agnostic and focuses on low overhead and speed, especially in dependencies, disk usage, and memory use. It includes server/daemon mode, scroll-back search, keyboard-driven URL detection, user-configurable font fallback, on-the-fly font and DPI resizing, color emoji support, IME support via text-input-v3, multi-seat support, true color, synchronized updates, and sixel image support.
- Aerion is a modern, lightweight email client inspired by Geary, focused on resource efficiency and a clean user experience. It supports Gmail, Outlook, Microsoft 365, and generic IMAP/SMTP, with conversation threading, rich text composition, contact sync, PGP/S/MIME, and multiple color themes. Built as a Linux-first app using Wails and Svelte, it avoids GNOME Online Accounts and uses direct mail access for a simpler, more self-contained setup. Keyboard-driven navigation and vim-style shortcuts make it a good fit for users who prefer fast, efficient workflows.
- BlexMono Nerd font (
font-blexmono-nerd) brings an alternative to the FiraCode Nerd Font with another popular style.
Security updates
We have a bunch of security updates this week. As always, install available updates to get the latest vulnerability protections.
- atril was updated to 1.28.3-48 (@EbonJaeger). Includes security fixes for CVE-2026-46529.
- bind-utils was updated to 9.20.23-40 (@EbonJaeger). Includes security fixes for CVE-2026-5946, CVE-2026-5950, CVE-2026-3592, CVE-2026-5947, CVE-2026-3039, CVE-2026-3593.
- botan3 was updated to 3.12.0-3 (@Jaredy899). Includes security fixes for CVE-2026-44378.
- containerd was updated to 2.3.1-73 (@Jaredy899). Includes security fixes for CVE-2026-46680.
- evince was updated to 48.4-70 (@EbonJaeger). Includes security fixes for CVE-2026-46529.
- imagemagick was updated to 7.1.2.23-217 (@Jaredy899). Includes security fixes for CVE-2026-45664, CVE-2026-45624, CVE-2026-45358, CVE-2026-42326, CVE-2026-40169, CVE-2026-45359, GHSA-hg5x-pmmv-4q7g, GHSA-rcr6-g7jc-f57g, GHSA-jcqp-6r6f-3mfx, GHSA-88wq-x9gc-45h8, GHSA-6gxq-f64p-5w6f, GHSA-v6qj-8rm4-fpgj, GHSA-j3pv-77gf-fw2g, GHSA-4g75-9r48-jf92, GHSA-533m-3wf6-c33v, GHSA-5r4x-w6p5-222q, GHSA-xf64-q5rg-85g5, GHSA-rw3g-wvj6-3p7w, GHSA-7gg8-qqx7-92g5, GHSA-p93h-f2jc-477j, GHSA-gj92-pwm7-jcmp, GHSA-36wm-hprc-mcf5, GHSA-85r7-8qr6-54gh, GHSA-3rvp-mpr5-qjm9.
- kitty was updated to 0.47.0-94 (@Jaredy899). Includes security fixes for CVE-2026-42850, CVE-2026-33633, CVE-2026-33642, CVE-2026-42851.
- libde265 was updated to 1.0.19-15 (@Jaredy899). Includes security fixes for CVE-2026-45383, CVE-2026-45382.
- libetpan was updated to 1.10-10 (@Jaredy899). Includes security fixes for CVE-2020-15953.
- libheif was updated to 1.22.0-60 (@Jaredy899, @Jaredy899). Includes security fixes for CVE-2026-32740, CVE-2026-32741, CVE-2026-47709, CVE-2026-32739, CVE-2026-47254, CVE-2026-32738, CVE-2026-41069, CVE-2026-41071, CVE-2026-47714, CVE-2026-32882, CVE-2026-47251, CVE-2026-47178, CVE-2026-48029, CVE-2026-32814, CVE-2026-47247, GHSA-p4r6-6972-g26m, GHSA-95jx-g5vf-cpp8, GHSA-9h96-c44j-jpq9, GHSA-jh2w-m72q-q595.
- libreoffice was updated to 25.8.7.3-206 (@Jaredy899). Includes security fixes for CVE-2026-4430.
- libvncserver was updated to 0.9.15-11 (@Jaredy899). Includes security fixes for CVE-2026-32853, CVE-2026-32854.
- moby was updated to 29.5.2-32 (@Jaredy899, @Jaredy899). Includes security fixes for CVE-2026-31431, CVE-2026-41567, CVE-2026-32288, CVE-2026-42306, CVE-2026-41568.
- papers was updated to 50.1-20 (@EbonJaeger). Includes security fixes for CVE-2026-46529.
- podofo was updated to 0.10.6-19 (@Jaredy899). Includes security fixes for CVE-2025-46205.
- postgresql was updated to 18.4-64 (@Jaredy899). Includes security fixes for CVE-2026-6575, CVE-2026-6475, CVE-2026-6638, CVE-2026-6478, CVE-2026-6476, CVE-2026-6474, CVE-2026-6477, CVE-2026-6479, CVE-2026-6637, CVE-2026-6473, CVE-2026-6472.
- putty was updated to 0.84-17 (@Jaredy899). Includes security fixes for CVE-2026-4115.
- rsync was updated to 3.4.3-22 (@EbonJaeger). Includes security fixes for CVE-2026-29518, CVE-2026-43620, CVE-2026-43619, CVE-2026-45232, CVE-2026-43618, CVE-2026-43617.
- ruby was updated to 4.0.5-34 (@Jaredy899). Includes security fixes for CVE-2026-46727.
- sunshine was updated to 2026.516.143833-20 (@HuricanDev). Includes security fixes for CVE-2026-32253, CVE-2025-54081.
- unbound was updated to 1.25.1-22 (@EbonJaeger). Includes security fixes for CVE-2026-42923, CVE-2026-40622, CVE-2026-42960, CVE-2026-44390, CVE-2026-42959, CVE-2026-42944, CVE-2026-33278, CVE-2026-41292, CVE-2026-42534, CVE-2026-32792, CVE-2026-44608.
- util-linux was updated to 2.41.4-57 (@Jaredy899). Includes security fixes for CVE-2026-27456.
- uv was updated to 0.11.15-15 (@palto42). Includes security fixes for GHSA-3cv2-h65g-fgmm, GHSA-4gg8-gxpx-9rph.
General updates
The full list of updated packages can be found here.
For the list of currently known issues, see the dedicated thread for it. If you begin experiencing a bug, please look for an issue on our issue tracker, and open a new one if one does not exist.
That’s all for this week, folks! We'll be here same time, same place next week for another roundup of the news!