<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/tumbleweed-monthly-update---august-2026-rhnq0fgtn" -->

---
title: Tumbleweed Monthly Update - August 2026 | daily.dev
description: August delivered 23 Tumbleweed snapshots covering desktop and security updates: KDE Plasma 6.7.4, KDE Frameworks 6.29.0, KDE Gear 26.08.0, GNOME Shell/mutter...
canonical: https://daily.dev/posts/tumbleweed-monthly-update---august-2026-rhnq0fgtn
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Tumbleweed Monthly Update - August 2026 | daily.dev
og:description: August delivered 23 Tumbleweed snapshots covering desktop and security updates: KDE Plasma 6.7.4, KDE Frameworks 6.29.0, KDE Gear 26.08.0, GNOME Shell/mutter...
og:url: https://daily.dev/posts/tumbleweed-monthly-update---august-2026-rhnq0fgtn
og:image: https://api.daily.dev/og/posts/rHNQ0Fgtn.png
og:image:alt: Tumbleweed Monthly Update - August 2026
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Tumbleweed Monthly Update - August 2026

**[openSUSE](https://daily.dev/sources/opensuse)** · 22 min read · 0 upvotes · 0 comments

## Summary

August delivered 23 Tumbleweed snapshots covering desktop and security updates: KDE Plasma 6.7.4, KDE Frameworks 6.29.0, KDE Gear 26.08.0, GNOME Shell/mutter 50.4, Mesa 26.2 series, and the Linux kernel progressing from 7.1.5 to 7.2.2 with extensive CVE fixes. Firefox 154.0 shipped over 40 security fixes, OpenSSH 10.5p1 fixed a critical agent-forwarding flaw, vim 9.2.0901 patched eight vulnerabilities, and postgresql18 18.6 addressed more than two dozen CVEs including RCE and SQLi issues. Additional critical security patches landed for libssh2, Samba 4.24.5, expat 2.8.2, c-ares, OpenSSL, flatpak 1.18.1, python-cryptography 50.0.0, GDM, udisks2, PHP 8.5.9, and multipath-tools, among others.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://news.opensuse.org/2026/09/02/tw-monthly-update-august>

## Questions this post answers

### What does postgresql18 18.6 fix and should I update right away?

PostgreSQL 18.6 is a major security release fixing more than two dozen CVEs, including remote code execution and denial of service issues. Notable fixes cover heap buffer overflows in regular expression matching, to_char formatting, and pg_stat_statements, a psql COPY FROM STDIN command injection issue, and a logical decoding flaw allowing arbitrary file dlopen. Database administrators should plan an update soon.

_daily.dev helps database teams keep track of urgent PostgreSQL security releases like this one._

### What critical vulnerability does OpenSSH 10.5p1 fix in agent forwarding?

OpenSSH 10.5p1 fixes a flaw where the interaction between ssh-agent locking and the session-bind@openssh.com extension was broken, allowing operations meant to be local-only to be performed remotely while the agent was locked. It also corrects the restrict keyword so it properly applies to tunnel forwarding, and fixes a potential realloc use-after-free when remote forwarding is added via the multiplexing socket.

_Teams relying on ssh-agent forwarding can track fixes like this via daily.dev before rolling out updates._

### What security issues were fixed in libssh2 in August 2026?

libssh2 received two rounds of critical patches: the first fixed a heap buffer overflow, and the second addressed arbitrary code execution via double-free in SFTP sessions, denial of service via integer underflow in AES-GCM cipher negotiation, a heap out-of-bounds read, and a heap buffer overflow during SSH negotiation. These are considered essential updates for any system using libssh2 for SSH or SFTP.

_Anyone maintaining SSH or SFTP infrastructure can follow libssh2 security patches through daily.dev._

## Similar posts on daily.dev

- [Tumbleweed Monthly Update - June 2026](https://daily.dev/posts/tumbleweed-monthly-update---june-2026-7ife66pbe) · openSUSE · 0 upvotes · 0 comments
- [Tumbleweed Monthly Update - May 2026](https://daily.dev/posts/tumbleweed-monthly-update---may-2026-y2ltzu25b) · openSUSE · 0 upvotes · 0 comments
- [Tumbleweed Monthly Update - October 2025](https://daily.dev/posts/tumbleweed-monthly-update---october-2025-xixy8va3l) · openSUSE · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#linux](https://daily.dev/tags/linux), [#postgresql](https://daily.dev/tags/postgresql), [#opensuse](https://daily.dev/tags/opensuse)

[View this post on daily.dev](https://daily.dev/posts/tumbleweed-monthly-update---august-2026-rhnq0fgtn)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Tumbleweed Monthly Update - August 2026","url":"https://daily.dev/posts/tumbleweed-monthly-update---august-2026-rhnq0fgtn","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/tumbleweed-monthly-update---august-2026-rhnq0fgtn"},"datePublished":"2026-09-02T08:10:31.846Z","dateModified":"2026-09-02T08:10:57.803Z","description":"August delivered 23 Tumbleweed snapshots covering desktop and security updates: KDE Plasma 6.7.4, KDE Frameworks 6.29.0, KDE Gear 26.08.0, GNOME Shell/mutter...","image":"https://media.daily.dev/image/upload/s--0_ODbtD2--/f_auto/v1722860399/public/Placeholder%2008","thumbnailUrl":"https://media.daily.dev/image/upload/s--0_ODbtD2--/f_auto/v1722860399/public/Placeholder%2008","isAccessibleForFree":true,"articleSection":"openSUSE","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"openSUSE","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/4d81d0e92717435b876f92aaa9c95d07","url":"https://daily.dev/sources/opensuse"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/tumbleweed-monthly-update---august-2026-rhnq0fgtn","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,linux,postgresql,opensuse","timeRequired":"PT22M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"openSUSE","item":"https://daily.dev/sources/opensuse"},{"@type":"ListItem","position":3,"name":"Tumbleweed Monthly Update - August 2026"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/tumbleweed-monthly-update---august-2026-rhnq0fgtn#faq","mainEntity":[{"@type":"Question","name":"What does postgresql18 18.6 fix and should I update right away?","acceptedAnswer":{"@type":"Answer","text":"PostgreSQL 18.6 is a major security release fixing more than two dozen CVEs, including remote code execution and denial of service issues. Notable fixes cover heap buffer overflows in regular expression matching, to_char formatting, and pg_stat_statements, a psql COPY FROM STDIN command injection issue, and a logical decoding flaw allowing arbitrary file dlopen. Database administrators should plan an update soon. daily.dev helps database teams keep track of urgent PostgreSQL security releases like this one."}},{"@type":"Question","name":"What critical vulnerability does OpenSSH 10.5p1 fix in agent forwarding?","acceptedAnswer":{"@type":"Answer","text":"OpenSSH 10.5p1 fixes a flaw where the interaction between ssh-agent locking and the session-bind@openssh.com extension was broken, allowing operations meant to be local-only to be performed remotely while the agent was locked. It also corrects the restrict keyword so it properly applies to tunnel forwarding, and fixes a potential realloc use-after-free when remote forwarding is added via the multiplexing socket. Teams relying on ssh-agent forwarding can track fixes like this via daily.dev before rolling out updates."}},{"@type":"Question","name":"What security issues were fixed in libssh2 in August 2026?","acceptedAnswer":{"@type":"Answer","text":"libssh2 received two rounds of critical patches: the first fixed a heap buffer overflow, and the second addressed arbitrary code execution via double-free in SFTP sessions, denial of service via integer underflow in AES-GCM cipher negotiation, a heap out-of-bounds read, and a heap buffer overflow during SSH negotiation. These are considered essential updates for any system using libssh2 for SSH or SFTP. Anyone maintaining SSH or SFTP infrastructure can follow libssh2 security patches through daily.dev."}}]}
```

