Keeping Linux Updated
The single most effective thing you can do to keep a Linux system secure is to apply security updates promptly. Most successful attacks exploit known vulnerabilities — vulnerabilities that have patches available and have for days, weeks, or months. Staying current closes the door before most attackers can walk through it.
Understanding the update pipeline
Upstream (kernel.org, nginx.org, etc.)
|
V
Distribution (Debian Security Team, Red Hat Product Security, etc.)
-- tests, backports, packages the patch
|
V
Repository (apt.debian.org, mirrors)
|
V
Your system (apt upgrade, dnf upgrade, pacman -Syu)
The distribution security team is the critical link: they review upstream patches, backport fixes to older stable versions when appropriate, and push packages to their repos. On major distributions, this typically takes hours to a few days for critical issues.
Update commands by distribution
Debian and Ubuntu
# Update package index (fetch latest package lists from repos)
sudo apt update
# List upgradable packages
apt list --upgradable
# List only security updates
apt list --upgradable 2>/dev/null | grep -i security
# Install all available updates
sudo apt upgrade
# Install updates including dependency changes (new packages, removals)
sudo apt full-upgrade
# Security updates only (Debian)
sudo apt-get upgrade -y --no-install-recommends $(apt-get --simulate upgrade 2>/dev/null | grep security | awk '{print $2}')
# Cleaner method for security-only on Ubuntu/Debian:
sudo unattended-upgrade --dry-run -d # preview
sudo unattended-upgrade # run
# Remove orphaned packages
sudo apt autoremove
# Clean package cache
sudo apt clean
sudo apt autoclean # remove outdated cached packages
Fedora and RHEL/CentOS
# Check for updates
sudo dnf check-update
# Check for security updates only
sudo dnf check-update --security
# Install all updates
sudo dnf upgrade --refresh
# Install security updates only
sudo dnf upgrade --security
# Install a specific advisory
sudo dnf upgrade --advisory FEDORA-2026-abc123
# Show changelogs for pending updates
sudo dnf upgrade --changelog
# Show which CVEs are fixed by pending updates
sudo dnf updateinfo list security
# Remove orphaned packages
sudo dnf autoremove
Arch Linux
# Arch has a rolling release model: all updates are current
# There is no separate "security update" stream
# Sync package database
sudo pacman -Sy
# Full system upgrade
sudo pacman -Syu
# Check Arch Linux security advisories
# https://security.archlinux.org/
# Install the arch-audit tool:
sudo pacman -S arch-audit
arch-audit # lists packages with known CVEs
openSUSE
# Refresh repos
sudo zypper refresh
# List available patches (security patches are labelled)
zypper list-patches --category security
# Install security patches only
sudo zypper patch --category security
# Full system update
sudo zypper update
# Distribution upgrade (Tumbleweed)
sudo zypper dup
Checking if a reboot is needed
# Debian/Ubuntu: check for a pending reboot flag
cat /var/run/reboot-required
cat /var/run/reboot-required.pkgs # which packages triggered it
# Fedora/RHEL: check if reboot or service restart is needed
sudo needs-restarting
sudo needs-restarting -r # reboot-only check (exit code 0 = no reboot needed)
sudo needs-restarting -s # services that need restarting
# Check if running kernel differs from installed kernel
uname -r # running kernel version
rpm -q kernel | tail -1 # latest installed kernel (Fedora/RHEL)
dpkg -l linux-image-* | grep ^ii | tail -1 # latest installed kernel (Debian/Ubuntu)
# If these differ, you need to reboot
# Install needrestart (Debian/Ubuntu) for automatic service restart detection
sudo apt install needrestart
sudo needrestart # check what needs restarting
Automatic security updates
Debian and Ubuntu: unattended-upgrades
# Install
sudo apt install unattended-upgrades apt-listchanges
# Interactive configuration
sudo dpkg-reconfigure --priority=low unattended-upgrades
# Manual configuration: /etc/apt/apt.conf.d/50unattended-upgrades
sudo nano /etc/apt/apt.conf.d/50unattended-upgrades
Unattended-Upgrade::Allowed-Origins {
"${distro_id}:${distro_codename}";
"${distro_id}:${distro_codename}-security";
"${distro_id}ESMApps:${distro_codename}-apps-security";
"${distro_id}ESM:${distro_codename}-infra-security";
};
// Automatically remove unused packages
Unattended-Upgrade::Remove-Unused-Dependencies "true";
// Reboot automatically if needed (at a specific time)
Unattended-Upgrade::Automatic-Reboot "false";
Unattended-Upgrade::Automatic-Reboot-Time "03:00";
// Email notification on failure
Unattended-Upgrade::Mail "admin@example.com";
Unattended-Upgrade::MailReport "on-change";
# Enable automatic update checking
sudo nano /etc/apt/apt.conf.d/20auto-upgrades
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "1";
APT::Periodic::Download-Upgradeable-Packages "1";
APT::Periodic::AutocleanInterval "7";
# Test the configuration (dry run)
sudo unattended-upgrade --dry-run -d
# Run manually
sudo unattended-upgrade
# View the log
sudo tail -f /var/log/unattended-upgrades/unattended-upgrades.log
Fedora and RHEL: dnf-automatic
# Install
sudo dnf install dnf-automatic
# Configure: /etc/dnf/automatic.conf
sudo nano /etc/dnf/automatic.conf
[commands]
# What to do: default (check only), download-only, or security, or yes
upgrade_type = security
apply_updates = yes
download_updates = yes
[emitters]
emit_via = motd,email # notification method
[email]
email_from = dnf-automatic@server.example.com
email_to = admin@example.com
email_host = localhost
# Enable and start the timer
sudo systemctl enable --now dnf-automatic.timer
# Check when it last ran
sudo systemctl status dnf-automatic.timer
sudo journalctl -u dnf-automatic
Kernel updates
Kernel updates patch the most security-sensitive code on your system but require a reboot to take effect.
# Check current kernel
uname -r
# See all installed kernels (Fedora/RHEL)
rpm -q kernel
# See all installed kernels (Debian/Ubuntu)
dpkg -l 'linux-image-*' | grep ^ii
# After a kernel update, reboot to use the new kernel
sudo reboot
# On reboot, GRUB lists available kernels
# The newest installed kernel is selected by default
# Remove old kernels (keep at least one backup)
# Fedora/RHEL: dnf keeps 3 kernels by default
sudo dnf remove --oldinstallonly --setopt installonly_limit=2
# Debian/Ubuntu:
sudo apt autoremove # removes kernels not in use
Live kernel patching (enterprise)
For high-availability systems where reboots are costly:
# Ubuntu: Livepatch (requires Ubuntu Pro subscription for production use)
sudo snap install canonical-livepatch
sudo canonical-livepatch enable <token>
sudo canonical-livepatch status
# Fedora/RHEL: kpatch (for compatible kernel versions)
sudo dnf install kpatch kpatch-dnf
sudo kpatch list
Monitoring for security advisories
# Ubuntu Security Notices
curl -s https://ubuntu.com/security/notices.rss | grep '<title>' | head -10
# Arch Linux security advisories
arch-audit
# Debian Security Tracker
# https://security-tracker.debian.org/tracker/
# Check if specific CVE affects your system
# Fedora/RHEL:
sudo dnf updateinfo list --cve CVE-2024-12345
sudo dnf upgrade --cve CVE-2024-12345 # fix a specific CVE
# Check if any installed package has a known CVE (Arch)
arch-audit --format "%n: %c (%s)" | grep -v "No known"
Update best practices
# Before updating a production server:
# 1. Take a snapshot (VM/cloud) or Btrfs/LVM snapshot
sudo btrfs subvolume snapshot / /snapshots/pre-update-$(date +%F)
# or: cloud provider snapshot via API/console
# 2. Check changelogs for potentially disruptive changes
sudo apt-get upgrade --simulate # preview what will change
sudo dnf upgrade --changelog
# 3. Apply updates in a maintenance window when possible
# 4. Verify services are healthy after update
sudo systemctl --failed
sudo journalctl -p err -b
# 5. Keep old kernels available as fallback
# (both apt autoremove and dnf --oldinstallonly handle this)
Frequently Asked Questions
How often should I update my Linux system?
Security updates should be applied as soon as they are available, ideally within 24-48 hours for critical vulnerabilities. Regular package updates (new features, bug fixes) can be batched and applied weekly or monthly. The reason for urgency on security patches is that most attacks exploit known vulnerabilities — vulnerabilities that already have patches available. Once a vulnerability is publicly disclosed, attackers begin scanning for unpatched systems within hours. Servers with a public internet presence are at the highest risk from delayed patching.
What is the difference between a security update and a regular update?
A security update patches a specific vulnerability — a bug that could allow an attacker to gain unauthorized access, execute code, or cause denial of service. These are the updates that matter most for system security. A regular update may fix non-security bugs, add new features, improve performance, or update translations. Both types are delivered through the same package manager, but most distributions tag security updates specially so they can be installed separately. For servers, applying security updates immediately and deferring feature updates until a scheduled maintenance window is a common practice.
Do I need to reboot after updating Linux?
Not always, but sometimes. On Debian and Ubuntu, needrestart (install it with apt install needrestart) checks which services need to be restarted after a library update and can restart them automatically. A kernel update always requires a reboot to take effect — the new kernel is installed to disk, but the running kernel does not change until you reboot. Check if a reboot is needed with: on Debian/Ubuntu, cat /var/run/reboot-required; on Fedora/RHEL, needs-restarting -r. Enterprise Linux distributions offer kpatch and livepatch for applying kernel security patches without a reboot, but these are complex and typically used for high-availability servers.
What are automatic security updates and are they safe?
Automatic security updates apply security patches without human intervention. On Debian and Ubuntu, this is handled by the unattended-upgrades package; on Fedora and RHEL, by dnf-automatic. They are configured to apply only security patches (not all updates), reducing the risk of an update breaking something. For most servers, automatic security updates are the right choice because the risk of a known unpatched vulnerability is usually higher than the small risk of a security patch breaking something. The main exceptions are highly customised systems where any package change requires testing, or systems governed by a formal change management process.
How do I check which packages have security updates available?
On Debian and Ubuntu: sudo apt update && apt list —upgradable 2>/dev/null | grep -i security. On Fedora and RHEL: sudo dnf check-update —security. On Arch Linux: sudo pacman -Sy && pacman -Qu (all updates are security-relevant since Arch only keeps one version per package). On openSUSE: sudo zypper ref && zypper list-updates -t patch. You can also use security advisory feeds from your distribution (Debian Security Tracker, Red Hat Errata, Ubuntu Security Notices) to monitor for vulnerabilities in software you run before the patch is available.
How do I roll back a bad update on Linux?
On Debian and Ubuntu, you can downgrade a package with apt install package=version (find the old version with apt-cache showpkg package). On Fedora and RHEL, use dnf downgrade package to revert to the previous version. On Arch Linux, you can install old packages from the package cache (/var/cache/pacman/pkg/) with pacman -U /var/cache/pacman/pkg/package-version.pkg.tar.zst. For more robust rollback on systems with Btrfs filesystems, tools like Snapper (openSUSE) or Timeshift can roll back the entire filesystem to a pre-update snapshot. On virtual machines and cloud instances, snapshots at the hypervisor level provide the most reliable rollback option.