Passer au contenu principal

Version 7.2.8-rc.1 2026-07-23

Unraid OS 7.2.8-rc.1 is a release candidate maintenance release focused on security-related base package updates, Linux kernel 6.12.96-Unraid, Unraid API 4.36.1, Docker, ZFS, and expanded Intel wireless firmware coverage.

Upgrading

For step-by-step instructions, see Updating Unraid. Questions about your license?

Known issues

  • No new release-specific known issues were identified. See the Unraid OS 7.2.7 release notes for earlier known issues.

Notes

  • Kernel-coupled ZFS modules passed compatibility checks for 6.12.96-Unraid.

Rolling back

  • No new rollback warnings. Review rollback notes for Unraid OS 7.2.7 before downgrading.

Changes vs. Unraid OS 7.2.7

Security

  • Security: Includes security-related updates across base distro packages. Detailed package CVE annotations are listed under Base distro updates.
  • Security: Fixed a WebGUI update.php path-traversal command execution vulnerability, CVE-2026-3838.

Networking / Hardware

  • New: Added 304 Intel iwlwifi firmware files.

Docker

  • Docker VLAN auto-networks can fall back to the configured Docker gateway so containers keep outbound connectivity.

Linux kernel

  • Linux kernel: update to 6.12.96-Unraid.

Base distro updates

Added packages (5)

  • iotop-c: version 1.31-1_SBo
  • libcbor: version 0.14.0
  • libdisplay-info: version 0.3.0
  • libfido2: version 1.17.0-2
  • libmaxminddb: version 1.13.3

Updated packages (182)

  • aaa_libraries: version 15.1-45 -> 15.1-51
  • acl: version 2.3.2 -> 2.4.0
  • adwaita-icon-theme: version 49.0 -> 50.0
  • at-spi2-core: version 2.58.1 -> 2.60.5
  • attr: version 2.5.2 -> 2.6.0
  • bash: version 5.3.003 -> 5.3.015-2
  • bash-completion: version 2.16.0 -> 2.18.0
  • bind: version 9.20.22 -> 9.20.24-2 (NVD: CVE-2026-3039, CVE-2026-3592, CVE-2026-5946, CVE-2026-5950)
  • brotli: version 1.1.0-3 -> 1.2.0
  • btrfs-progs: version 6.17 -> 7.1
  • ca-certificates: version 20251003 -> 20260717
  • cifs-utils: version 7.4 -> 7.7
  • coreutils: version 9.8-2 -> 9.11
  • cryptsetup: version 2.8.1 -> 2.8.6
  • curl: version 8.20.0 -> 8.21.0 (NVD: CVE-2026-8286, CVE-2026-8924, CVE-2026-8925, CVE-2026-8926, CVE-2026-8927, CVE-2026-8932, CVE-2026-9079, CVE-2026-9080, CVE-2026-9545, CVE-2026-9546, CVE-2026-9547, CVE-2026-10536, CVE-2026-11352, CVE-2026-11564, CVE-2026-11586, CVE-2026-11856, CVE-2026-12064)
  • dmidecode: version 3.6 -> 3.7
  • dnsmasq: version 2.91 -> 2.93 (CVE-2026-2291; NVD: CVE-2026-12725, CVE-2026-12969)
  • docker: version 29.5.1-1_LT -> 29.5.3-1_LT
  • dynamix.unraid.net: version 4.32.3-2 -> 4.36.1
  • e2fsprogs: version 1.47.3 -> 1.47.4
  • editres: version 1.0.9 -> 1.1.1
  • elfutils: version 0.193 -> 0.195
  • elogind: version 255.17 -> 255.27
  • etc: version 15.1-15 -> 15.1-17
  • ethtool: version 6.15 -> 7.1
  • eudev: version 3.2.14-2 -> 3.2.14-4
  • exfatprogs: version 1.3.0 -> 1.4.2
  • file: version 5.46-2 -> 5.48
  • findutils: version 4.10.0 -> 4.11.0
  • fontconfig: version 2.17.1-5 -> 2.18.2
  • freeglut: version 3.6.0 -> 3.8.0
  • freetype: version 2.14.1 -> 2.14.3
  • fuse3: version 3.16.2 -> 3.16.2-2
  • gawk: version 5.3.2 -> 5.4.1
  • gdk-pixbuf2: version 2.44.4-2 -> 2.44.7
  • git: version 2.51.1 -> 2.55.0
  • glew: version 2.2.0-3 -> 2.3.1
  • glib2: version 2.86.1 -> 2.88.2
  • glibc-zoneinfo: version 2025b -> 2026c
  • graphite2: version 1.3.14-3 -> 1.3.15-2
  • grub: version 2.12-18 -> 2.14-3
  • gtk+3: version 3.24.51 -> 3.24.52
  • harfbuzz: version 12.1.0 -> 14.2.1
  • htop: version 3.4.1 -> 3.5.2
  • icu4c: version 77.1 -> 78.3
  • infozip: version 6.0-7 -> 6.0-8 (CVE-2014-8139, CVE-2014-8140, CVE-2014-8141, CVE-2016-9844, CVE-2018-18384, CVE-2018-1000035, CVE-2021-4217, CVE-2022-0529, CVE-2022-0530)
  • iperf3: version 3.18-1cf -> 3.21-1cf (NVD: CVE-2025-54349, CVE-2025-54350)
  • iproute2: version 6.17.0 -> 7.1.0-2
  • iptables: version 1.8.11 -> 1.8.13
  • jansson: version 2.14.1 -> 2.15.1
  • jemalloc: version 5.3.0-2 -> 5.3.1
  • json-c: version 0.18_20240915 -> 0.19
  • kbd: version 2.9.0 -> 2.10.0
  • krb5: version 1.22.1-2 -> 1.22.2-3
  • less: version 685 -> 704
  • libX11: version 1.8.12-2 -> 1.8.13
  • libXcomposite: version 0.4.6 -> 0.4.7
  • libXdamage: version 1.1.6 -> 1.1.7
  • libXext: version 1.3.6 -> 1.3.7
  • libXfont2: version 2.0.7 -> 2.0.8 (CVE-2026-56001, CVE-2026-56002, CVE-2026-56003)
  • libXi: version 1.8.2 -> 1.8.3
  • libXinerama: version 1.1.5 -> 1.1.6
  • libXmu: version 1.2.1 -> 1.3.1
  • libXrandr: version 1.5.4 -> 1.5.5
  • libXxf86dga: version 1.1.6 -> 1.1.7
  • libXxf86vm: version 1.1.6 -> 1.1.7
  • libarchive: version 3.8.7 -> 3.8.8 (security fix noted; no CVE IDs listed)
  • libcap-ng: version 0.8.5-2 -> 0.9.3
  • libdeflate: version 1.24 -> 1.25
  • libdrm: version 2.4.127 -> 2.4.134
  • libedit: version 20251016_3.1 -> 20260512_3.1
  • libevdev: version 1.13.5 -> 1.13.6
  • libevent: version 2.1.12-4 -> 2.1.13 (security fix noted; no CVE IDs listed)
  • libffi: version 3.5.2 -> 3.7.1
  • libfontenc: version 1.1.8 -> 1.1.9
  • libgcrypt: version 1.11.2 -> 1.12.2
  • libgpg-error: version 1.56 -> 1.61 (security fix noted; no CVE IDs listed)
  • libidn: version 1.43 -> 1.44 (security fix noted; no CVE IDs listed)
  • libjpeg-turbo: version 3.1.2 -> 3.2.0
  • libnetfilter_conntrack: version 1.1.0 -> 1.1.1
  • libnftnl: version 1.3.0 -> 1.3.1
  • libnl3: version 3.11.0 -> 3.12.0
  • libnvme: version 1.15 -> 1.16.2
  • libpciaccess: version 0.18.1 -> 0.19
  • libpng: version 1.6.57 -> 1.6.58
  • libpsl: version 0.21.5 -> 0.23.0
  • libseccomp: version 2.6.0 -> 2.6.1 (security fix noted; no CVE IDs listed)
  • libssh: version 0.12.0 -> 0.12.1 (CVE-2026-15370, CVE-2026-59842, CVE-2026-59843, CVE-2026-59844, CVE-2026-59845, CVE-2026-59846, CVE-2026-59847, CVE-2026-59848, CVE-2026-59849, CVE-2026-59850, CVE-2026-59851)
  • libtiff: version 4.7.1 -> 4.7.2
  • libunistring: version 1.4.1 -> 1.4.2
  • liburing: version 2.12 -> 2.15
  • libusb: version 1.0.29 -> 1.0.30
  • libusb-compat: version 0.1.8 -> 0.1.9
  • libuv: version 1.51.0 -> 1.52.1
  • libvirt: version 11.7.0-1cf_LT -> 12.2.0-1cf_LT
  • libvirt-php: version 0.5.8-8.3.31_LT -> 0.5.8-8.4.23_LT
  • libx86: version 1.1-5 -> 1.1.1
  • libxkbcommon: version 1.11.0 -> 1.13.2
  • libxkbfile: version 1.1.3 -> 1.2.0
  • listres: version 1.0.6 -> 1.0.7
  • lmdb: version 0.9.33 -> 1.0.0-2
  • lsof: version 4.99.5 -> 4.99.7
  • lvm2: version 2.03.35 -> 2.03.41-2
  • lzip: version 1.25 -> 1.26
  • lzlib: version 1.15 -> 1.16
  • mcelog: version 207 -> 212
  • mesa: version 25.2.5 -> 26.1.5
  • mkfontscale: version 1.2.3 -> 1.2.4
  • nano: version 8.6 -> 9.1
  • ncurses: version 6.5_20250816 -> 6.6
  • net-tools: version 20181103_0eebece-3 -> 20181103_0eebece-5 (CVE-2025-46836)
  • nfs-utils: version 2.8.4 -> 2.9.1
  • nghttp2: version 1.67.1 -> 1.69.0
  • nghttp3: version 1.12.0 -> 1.17.0
  • nginx: version 1.30.1-1_SBo_LT -> 1.30.3-1_SBo_LT (NVD: CVE-2026-9256, CVE-2026-42055, CVE-2026-48142)
  • ngtcp2: version 1.22.1 -> 1.24.0
  • noto-fonts-ttf: version 2025.10.01 -> 2026.07.01
  • ntfs-3g: version 2022.10.3 -> 2026.7.7
  • ntp: version 4.2.8p18-7 -> 4.2.8p18-8
  • nvme-cli: version 2.15 -> 2.16
  • openssh: version 10.2p1 -> 10.4p1-2 (security fix noted; no CVE IDs listed)
  • openssl: version 3.5.6-2 -> 3.5.7 (CVE-2026-34182, CVE-2026-34183, CVE-2026-42764, CVE-2026-45447; NVD: CVE-2026-7383, CVE-2026-9076, CVE-2026-34180, CVE-2026-34181, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768, CVE-2026-42769, CVE-2026-42770, CVE-2026-45445, CVE-2026-45446)
  • ovmf: version unraid202502 -> stable202602-2
  • p11-kit: version 0.26.2 -> 0.26.4 (CVE-2026-13757)
  • pam: version 1.7.1 -> 1.7.2-2
  • pango: version 1.56.4 -> 1.58.0
  • parted: version 3.6 -> 3.7
  • pciutils: version 3.14.0 -> 3.15.0
  • pcre2: version 10.46 -> 10.47
  • perl: version 5.42.0 -> 5.42.2-2
  • php: version 8.3.31-1_LT -> 8.4.23-1_LT (CVE-2026-14355)
  • pkgtools: version 15.1-30 -> 15.1-32
  • procps-ng: version 4.0.5 -> 4.0.6
  • qemu: version 9.2.3-1cf_LT -> 10.2.3-1_SBo_LT (NVD: CVE-2025-54566, CVE-2025-54567)
  • rclone: version 1.70.1-1_SBo_LT -> 1.72.0-1_SBo_LT
  • readline: version 8.3.001-2 -> 8.3.003
  • rsync: version 3.4.1 -> 3.4.4
  • samba: version 4.22.8-1_LT -> 4.22.10-2_LT (CVE-2026-1933, CVE-2026-2340, CVE-2026-3012, CVE-2026-3238, CVE-2026-4408, CVE-2026-4480)
  • sed: version 4.9 -> 4.10
  • setxkbmap: version 1.3.4 -> 1.3.5
  • shadow: version 4.18.0 -> 4.19.4-6 (security fix noted; no CVE IDs listed)
  • spirv-llvm-translator: version 21.1.1 -> 22.1.4
  • sqlite: version 3.50.4 -> 3.53.3 (NVD: CVE-2026-11822, CVE-2026-11824)
  • sysstat: version 12.7.8 -> 12.7.9
  • sysvinit: version 3.15 -> 3.18-2
  • sysvinit-scripts: version 15.1-35 -> 15.1-40
  • talloc: version 2.4.3 -> 2.4.4
  • tdb: version 1.4.14 -> 1.4.15
  • telnet: version 0.17-7 -> 0.17-8 (CVE-2020-10188)
  • tree: version 2.2.1 -> 2.3.2
  • userspace-rcu: version 0.15.3 -> 0.15.6
  • util-linux: version 2.41.2 -> 2.42.2
  • virglrenderer: version 1.1.1-1cf -> 1.2.0-1cf
  • virtiofsd: version 1.13.1-1cf -> 1.13.2-1cf
  • wayland: version 1.24.0 -> 1.26.0
  • which: version 2.23 -> 2.25
  • wireguard-tools: version 1.0.20250521 -> 1.0.20260223
  • wireless-regdb: version 2025.10.07 -> 2026.05.30
  • xauth: version 1.1.4 -> 1.1.5
  • xclock: version 1.1.1 -> 1.2.1
  • xev: version 1.2.6 -> 1.2.7
  • xfsprogs: version 6.17.0 -> 7.1.1
  • xinit: version 1.4.4 -> 1.4.4-2
  • xkbcomp: version 1.4.7 -> 1.5.0
  • xkbutils: version 1.0.6 -> 1.0.7
  • xkeyboard-config: version 2.46 -> 2.48
  • xkill: version 1.0.6 -> 1.0.7
  • xload: version 1.2.0 -> 1.2.1
  • xlsatoms: version 1.1.4 -> 1.1.5
  • xlsclients: version 1.1.5 -> 1.1.6
  • xmodmap: version 1.0.11 -> 1.0.12
  • xorg-server: version 21.1.22-2 -> 21.1.24 (CVE-2026-55999, CVE-2026-56000)
  • xrandr: version 1.5.3 -> 1.5.4
  • xrdb: version 1.2.2 -> 1.2.3
  • xrefresh: version 1.1.0 -> 1.1.1
  • xset: version 1.2.5 -> 1.2.6
  • xsetroot: version 1.1.3 -> 1.1.4
  • xterm: version 403 -> 410
  • xwd: version 1.0.9 -> 1.0.10
  • xwininfo: version 1.1.6 -> 1.1.7
  • xwud: version 1.0.7 -> 1.0.8
  • zfs: version 2.3.4_6.12.90_Unraid-2_LT -> 2.3.8_6.12.96_Unraid-1_LT