Version 7.2.8-rc.1 2026-07-23
Unraid OS 7.2.8-rc.1 is a release candidate maintenance release focused on security-related base package updates, Linux kernel 6.12.96-Unraid, Unraid API 4.36.1, Docker, ZFS, and expanded Intel wireless firmware coverage.
Upgrading
For step-by-step instructions, see Updating Unraid. Questions about your license?
Known issues
- No new release-specific known issues were identified. See the Unraid OS 7.2.7 release notes for earlier known issues.
Notes
- Kernel-coupled ZFS modules passed compatibility checks for 6.12.96-Unraid.
Rolling back
- No new rollback warnings. Review rollback notes for Unraid OS 7.2.7 before downgrading.
Changes vs. Unraid OS 7.2.7
Security
- Security: Includes security-related updates across base distro packages. Detailed package CVE annotations are listed under Base distro updates.
- Security: Fixed a WebGUI
update.phppath-traversal command execution vulnerability, CVE-2026-3838.
Networking / Hardware
- New: Added 304 Intel iwlwifi firmware files.
Docker
- Docker VLAN auto-networks can fall back to the configured Docker gateway so containers keep outbound connectivity.
Linux kernel
- Linux kernel: update to 6.12.96-Unraid.
Base distro updates
Added packages (5)
- iotop-c: version 1.31-1_SBo
- libcbor: version 0.14.0
- libdisplay-info: version 0.3.0
- libfido2: version 1.17.0-2
- libmaxminddb: version 1.13.3
Updated packages (182)
- aaa_libraries: version 15.1-45 -> 15.1-51
- acl: version 2.3.2 -> 2.4.0
- adwaita-icon-theme: version 49.0 -> 50.0
- at-spi2-core: version 2.58.1 -> 2.60.5
- attr: version 2.5.2 -> 2.6.0
- bash: version 5.3.003 -> 5.3.015-2
- bash-completion: version 2.16.0 -> 2.18.0
- bind: version 9.20.22 -> 9.20.24-2 (NVD: CVE-2026-3039, CVE-2026-3592, CVE-2026-5946, CVE-2026-5950)
- brotli: version 1.1.0-3 -> 1.2.0
- btrfs-progs: version 6.17 -> 7.1
- ca-certificates: version 20251003 -> 20260717
- cifs-utils: version 7.4 -> 7.7
- coreutils: version 9.8-2 -> 9.11
- cryptsetup: version 2.8.1 -> 2.8.6
- curl: version 8.20.0 -> 8.21.0 (NVD: CVE-2026-8286, CVE-2026-8924, CVE-2026-8925, CVE-2026-8926, CVE-2026-8927, CVE-2026-8932, CVE-2026-9079, CVE-2026-9080, CVE-2026-9545, CVE-2026-9546, CVE-2026-9547, CVE-2026-10536, CVE-2026-11352, CVE-2026-11564, CVE-2026-11586, CVE-2026-11856, CVE-2026-12064)
- dmidecode: version 3.6 -> 3.7
- dnsmasq: version 2.91 -> 2.93 (CVE-2026-2291; NVD: CVE-2026-12725, CVE-2026-12969)
- docker: version 29.5.1-1_LT -> 29.5.3-1_LT
- dynamix.unraid.net: version 4.32.3-2 -> 4.36.1
- e2fsprogs: version 1.47.3 -> 1.47.4
- editres: version 1.0.9 -> 1.1.1
- elfutils: version 0.193 -> 0.195
- elogind: version 255.17 -> 255.27
- etc: version 15.1-15 -> 15.1-17
- ethtool: version 6.15 -> 7.1
- eudev: version 3.2.14-2 -> 3.2.14-4
- exfatprogs: version 1.3.0 -> 1.4.2
- file: version 5.46-2 -> 5.48
- findutils: version 4.10.0 -> 4.11.0
- fontconfig: version 2.17.1-5 -> 2.18.2
- freeglut: version 3.6.0 -> 3.8.0
- freetype: version 2.14.1 -> 2.14.3
- fuse3: version 3.16.2 -> 3.16.2-2
- gawk: version 5.3.2 -> 5.4.1
- gdk-pixbuf2: version 2.44.4-2 -> 2.44.7
- git: version 2.51.1 -> 2.55.0
- glew: version 2.2.0-3 -> 2.3.1
- glib2: version 2.86.1 -> 2.88.2
- glibc-zoneinfo: version 2025b -> 2026c
- graphite2: version 1.3.14-3 -> 1.3.15-2
- grub: version 2.12-18 -> 2.14-3
- gtk+3: version 3.24.51 -> 3.24.52
- harfbuzz: version 12.1.0 -> 14.2.1
- htop: version 3.4.1 -> 3.5.2
- icu4c: version 77.1 -> 78.3
- infozip: version 6.0-7 -> 6.0-8 (CVE-2014-8139, CVE-2014-8140, CVE-2014-8141, CVE-2016-9844, CVE-2018-18384, CVE-2018-1000035, CVE-2021-4217, CVE-2022-0529, CVE-2022-0530)
- iperf3: version 3.18-1cf -> 3.21-1cf (NVD: CVE-2025-54349, CVE-2025-54350)
- iproute2: version 6.17.0 -> 7.1.0-2
- iptables: version 1.8.11 -> 1.8.13
- jansson: version 2.14.1 -> 2.15.1
- jemalloc: version 5.3.0-2 -> 5.3.1
- json-c: version 0.18_20240915 -> 0.19
- kbd: version 2.9.0 -> 2.10.0
- krb5: version 1.22.1-2 -> 1.22.2-3
- less: version 685 -> 704
- libX11: version 1.8.12-2 -> 1.8.13
- libXcomposite: version 0.4.6 -> 0.4.7
- libXdamage: version 1.1.6 -> 1.1.7
- libXext: version 1.3.6 -> 1.3.7
- libXfont2: version 2.0.7 -> 2.0.8 (CVE-2026-56001, CVE-2026-56002, CVE-2026-56003)
- libXi: version 1.8.2 -> 1.8.3
- libXinerama: version 1.1.5 -> 1.1.6
- libXmu: version 1.2.1 -> 1.3.1
- libXrandr: version 1.5.4 -> 1.5.5
- libXxf86dga: version 1.1.6 -> 1.1.7
- libXxf86vm: version 1.1.6 -> 1.1.7
- libarchive: version 3.8.7 -> 3.8.8 (security fix noted; no CVE IDs listed)
- libcap-ng: version 0.8.5-2 -> 0.9.3
- libdeflate: version 1.24 -> 1.25
- libdrm: version 2.4.127 -> 2.4.134
- libedit: version 20251016_3.1 -> 20260512_3.1
- libevdev: version 1.13.5 -> 1.13.6
- libevent: version 2.1.12-4 -> 2.1.13 (security fix noted; no CVE IDs listed)
- libffi: version 3.5.2 -> 3.7.1
- libfontenc: version 1.1.8 -> 1.1.9
- libgcrypt: version 1.11.2 -> 1.12.2
- libgpg-error: version 1.56 -> 1.61 (security fix noted; no CVE IDs listed)
- libidn: version 1.43 -> 1.44 (security fix noted; no CVE IDs listed)
- libjpeg-turbo: version 3.1.2 -> 3.2.0
- libnetfilter_conntrack: version 1.1.0 -> 1.1.1
- libnftnl: version 1.3.0 -> 1.3.1
- libnl3: version 3.11.0 -> 3.12.0
- libnvme: version 1.15 -> 1.16.2
- libpciaccess: version 0.18.1 -> 0.19
- libpng: version 1.6.57 -> 1.6.58
- libpsl: version 0.21.5 -> 0.23.0
- libseccomp: version 2.6.0 -> 2.6.1 (security fix noted; no CVE IDs listed)
- libssh: version 0.12.0 -> 0.12.1 (CVE-2026-15370, CVE-2026-59842, CVE-2026-59843, CVE-2026-59844, CVE-2026-59845, CVE-2026-59846, CVE-2026-59847, CVE-2026-59848, CVE-2026-59849, CVE-2026-59850, CVE-2026-59851)
- libtiff: version 4.7.1 -> 4.7.2
- libunistring: version 1.4.1 -> 1.4.2
- liburing: version 2.12 -> 2.15
- libusb: version 1.0.29 -> 1.0.30
- libusb-compat: version 0.1.8 -> 0.1.9
- libuv: version 1.51.0 -> 1.52.1
- libvirt: version 11.7.0-1cf_LT -> 12.2.0-1cf_LT
- libvirt-php: version 0.5.8-8.3.31_LT -> 0.5.8-8.4.23_LT
- libx86: version 1.1-5 -> 1.1.1
- libxkbcommon: version 1.11.0 -> 1.13.2
- libxkbfile: version 1.1.3 -> 1.2.0
- listres: version 1.0.6 -> 1.0.7
- lmdb: version 0.9.33 -> 1.0.0-2
- lsof: version 4.99.5 -> 4.99.7
- lvm2: version 2.03.35 -> 2.03.41-2
- lzip: version 1.25 -> 1.26
- lzlib: version 1.15 -> 1.16
- mcelog: version 207 -> 212
- mesa: version 25.2.5 -> 26.1.5
- mkfontscale: version 1.2.3 -> 1.2.4
- nano: version 8.6 -> 9.1
- ncurses: version 6.5_20250816 -> 6.6
- net-tools: version 20181103_0eebece-3 -> 20181103_0eebece-5 (CVE-2025-46836)
- nfs-utils: version 2.8.4 -> 2.9.1
- nghttp2: version 1.67.1 -> 1.69.0
- nghttp3: version 1.12.0 -> 1.17.0
- nginx: version 1.30.1-1_SBo_LT -> 1.30.3-1_SBo_LT (NVD: CVE-2026-9256, CVE-2026-42055, CVE-2026-48142)
- ngtcp2: version 1.22.1 -> 1.24.0
- noto-fonts-ttf: version 2025.10.01 -> 2026.07.01
- ntfs-3g: version 2022.10.3 -> 2026.7.7
- ntp: version 4.2.8p18-7 -> 4.2.8p18-8
- nvme-cli: version 2.15 -> 2.16
- openssh: version 10.2p1 -> 10.4p1-2 (security fix noted; no CVE IDs listed)
- openssl: version 3.5.6-2 -> 3.5.7 (CVE-2026-34182, CVE-2026-34183, CVE-2026-42764, CVE-2026-45447; NVD: CVE-2026-7383, CVE-2026-9076, CVE-2026-34180, CVE-2026-34181, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768, CVE-2026-42769, CVE-2026-42770, CVE-2026-45445, CVE-2026-45446)
- ovmf: version unraid202502 -> stable202602-2
- p11-kit: version 0.26.2 -> 0.26.4 (CVE-2026-13757)
- pam: version 1.7.1 -> 1.7.2-2
- pango: version 1.56.4 -> 1.58.0
- parted: version 3.6 -> 3.7
- pciutils: version 3.14.0 -> 3.15.0
- pcre2: version 10.46 -> 10.47
- perl: version 5.42.0 -> 5.42.2-2
- php: version 8.3.31-1_LT -> 8.4.23-1_LT (CVE-2026-14355)
- pkgtools: version 15.1-30 -> 15.1-32
- procps-ng: version 4.0.5 -> 4.0.6
- qemu: version 9.2.3-1cf_LT -> 10.2.3-1_SBo_LT (NVD: CVE-2025-54566, CVE-2025-54567)
- rclone: version 1.70.1-1_SBo_LT -> 1.72.0-1_SBo_LT
- readline: version 8.3.001-2 -> 8.3.003
- rsync: version 3.4.1 -> 3.4.4
- samba: version 4.22.8-1_LT -> 4.22.10-2_LT (CVE-2026-1933, CVE-2026-2340, CVE-2026-3012, CVE-2026-3238, CVE-2026-4408, CVE-2026-4480)
- sed: version 4.9 -> 4.10
- setxkbmap: version 1.3.4 -> 1.3.5
- shadow: version 4.18.0 -> 4.19.4-6 (security fix noted; no CVE IDs listed)
- spirv-llvm-translator: version 21.1.1 -> 22.1.4
- sqlite: version 3.50.4 -> 3.53.3 (NVD: CVE-2026-11822, CVE-2026-11824)
- sysstat: version 12.7.8 -> 12.7.9
- sysvinit: version 3.15 -> 3.18-2
- sysvinit-scripts: version 15.1-35 -> 15.1-40
- talloc: version 2.4.3 -> 2.4.4
- tdb: version 1.4.14 -> 1.4.15
- telnet: version 0.17-7 -> 0.17-8 (CVE-2020-10188)
- tree: version 2.2.1 -> 2.3.2
- userspace-rcu: version 0.15.3 -> 0.15.6
- util-linux: version 2.41.2 -> 2.42.2
- virglrenderer: version 1.1.1-1cf -> 1.2.0-1cf
- virtiofsd: version 1.13.1-1cf -> 1.13.2-1cf
- wayland: version 1.24.0 -> 1.26.0
- which: version 2.23 -> 2.25
- wireguard-tools: version 1.0.20250521 -> 1.0.20260223
- wireless-regdb: version 2025.10.07 -> 2026.05.30
- xauth: version 1.1.4 -> 1.1.5
- xclock: version 1.1.1 -> 1.2.1
- xev: version 1.2.6 -> 1.2.7
- xfsprogs: version 6.17.0 -> 7.1.1
- xinit: version 1.4.4 -> 1.4.4-2
- xkbcomp: version 1.4.7 -> 1.5.0
- xkbutils: version 1.0.6 -> 1.0.7
- xkeyboard-config: version 2.46 -> 2.48
- xkill: version 1.0.6 -> 1.0.7
- xload: version 1.2.0 -> 1.2.1
- xlsatoms: version 1.1.4 -> 1.1.5
- xlsclients: version 1.1.5 -> 1.1.6
- xmodmap: version 1.0.11 -> 1.0.12
- xorg-server: version 21.1.22-2 -> 21.1.24 (CVE-2026-55999, CVE-2026-56000)
- xrandr: version 1.5.3 -> 1.5.4
- xrdb: version 1.2.2 -> 1.2.3
- xrefresh: version 1.1.0 -> 1.1.1
- xset: version 1.2.5 -> 1.2.6
- xsetroot: version 1.1.3 -> 1.1.4
- xterm: version 403 -> 410
- xwd: version 1.0.9 -> 1.0.10
- xwininfo: version 1.1.6 -> 1.1.7
- xwud: version 1.0.7 -> 1.0.8
- zfs: version 2.3.4_6.12.90_Unraid-2_LT -> 2.3.8_6.12.96_Unraid-1_LT