Linux Basics 2 · Lesson 6 · 35 min

Updates done right

Most break-ins don't use clever new tricks. They use holes that were fixed months ago on servers nobody updated. Keeping a server updated is the single most important security habit. You'll also learn what to do after an update, when a reboot is really needed, and how to let the machine patch itself safely at night.

You will learn

  • Checking for updates, and telling security updates from the rest
  • Security-only updates: dnf upgrade --security vs Ubuntu's -security pocket
  • After updating: which services need a restart, and does the kernel need a reboot?
  • Automatic updates: dnf-automatic and unattended-upgrades
  • Reboot etiquette on a server

What's waiting?

Rocky / RHEL
dnf check-update                  # everything that has a newer version
dnf updateinfo                    # summary: security / bugfix notices
dnf updateinfo list --security    # which packages, which advisory (RLSA-…)
Ubuntu / Debian
sudo apt update                   # refresh the lists first!
apt list --upgradable             # …/noble-security = security fix
                                  # …/noble-updates  = normal update

Security advisories have names and a severity: Rocky calls them RLSA (Rocky Linux Security Advisory) with Critical, Important, Moderate or Low. Ubuntu publishes USN notices and puts security fixes in the -security pocket.

Install them

Rocky / RHEL
sudo dnf upgrade --security   # only security fixes
sudo dnf upgrade              # everything
rpm -q kernel                 # kernels are INSTALLED side by side, not replaced
Ubuntu / Debian
sudo unattended-upgrade -v    # only security fixes (what the nightly job does)
sudo apt upgrade              # everything
dpkg -l 'linux-image*'        # kernels, side by side

Why keep the old kernel? If the new one won't boot, you pick the old one from the boot menu. Both families keep the last few automatically.

Updated… now what? Restarts and reboots

Updating a file on disk doesn't change programs that are already running. They keep the old code in memory until they restart. And the kernel only changes when the machine boots.

Rocky / RHEL
dnf needs-restarting -r       # "Reboot is required…" (exit code 1)
sudo dnf needs-restarting -s  # services still running old libraries
sudo systemctl restart sshd   # restart those, or…
sudo reboot                   # …reboot for a new kernel
Ubuntu / Debian
ls /var/run/reboot-required       # exists = reboot needed
cat /var/run/reboot-required.pkgs # which packages want it
sudo reboot
uname -r                          # the new kernel is running
Reboot etiquette

A reboot kicks everyone off and stops every service for a minute or two. On a real server: tell people first, pick a quiet time, make sure you can get back in if something goes wrong (console access), and check that services came back afterwards (systemctl --failed). Servers behind a load balancer get rebooted one at a time.

Automatic updates

Humans forget. For security fixes, most servers should patch themselves every night.

Rocky: dnf-automatic
sudo dnf install dnf-automatic
sudoedit /etc/dnf/automatic.conf
  # upgrade_type = security
  # apply_updates = yes
sudo systemctl enable --now dnf-automatic.timer
systemctl list-timers 'dnf-*'
Ubuntu: unattended-upgrades
# installed and ON by default:
cat /etc/apt/apt.conf.d/20auto-upgrades
# what, and whether to reboot:
sudoedit /etc/apt/apt.conf.d/50unattended-upgrades
systemctl list-timers 'apt-daily*'
less /var/log/unattended-upgrades/unattended-upgrades.log

Automatic reboots are a bigger decision: great for a single web server at 3 a.m., risky for a database in the middle of work. Ubuntu has Unattended-Upgrade::Automatic-Reboot "true"; and a reboot time. Many teams prefer to patch automatically and reboot on a schedule they control.

Holding a package back

Sometimes an update breaks something and you need time. sudo apt-mark hold nginx (Ubuntu) or the versionlock plugin (sudo dnf versionlock add nginx, Rocky) pins a package. Remember to release it: a held package gets no security fixes.

Practice: patch Tuesday 🩹

This server has five updates waiting, some of them security fixes, including a new kernel. Install them the careful way, reboot into the new kernel, then set up automatic security updates. (Here the reboot takes a second, not a minute.)

Quick check

1. You updated OpenSSL. Is the running SSH server now protected?

2. How do you know an Ubuntu server needs a reboot?

3. Why install only security updates automatically, and not everything?

Finished the missions and the quiz? Mark it done to track your progress.