Updates done right
Most break-ins don't use clever new tricks. They use holes that were fixed months ago on servers nobody updated. Keeping a server updated is the single most important security habit. You'll also learn what to do after an update, when a reboot is really needed, and how to let the machine patch itself safely at night.
You will learn
- Checking for updates, and telling security updates from the rest
- Security-only updates:
dnf upgrade --securityvs Ubuntu's-securitypocket - After updating: which services need a restart, and does the kernel need a reboot?
- Automatic updates: dnf-automatic and unattended-upgrades
- Reboot etiquette on a server
What's waiting?
dnf check-update # everything that has a newer version dnf updateinfo # summary: security / bugfix notices dnf updateinfo list --security # which packages, which advisory (RLSA-…)
sudo apt update # refresh the lists first! apt list --upgradable # …/noble-security = security fix # …/noble-updates = normal update
Security advisories have names and a severity: Rocky calls them RLSA (Rocky Linux Security Advisory) with Critical, Important, Moderate or Low. Ubuntu publishes USN notices and puts security fixes in the -security pocket.
Install them
sudo dnf upgrade --security # only security fixes sudo dnf upgrade # everything rpm -q kernel # kernels are INSTALLED side by side, not replaced
sudo unattended-upgrade -v # only security fixes (what the nightly job does) sudo apt upgrade # everything dpkg -l 'linux-image*' # kernels, side by side
Why keep the old kernel? If the new one won't boot, you pick the old one from the boot menu. Both families keep the last few automatically.
Updated… now what? Restarts and reboots
Updating a file on disk doesn't change programs that are already running. They keep the old code in memory until they restart. And the kernel only changes when the machine boots.
dnf needs-restarting -r # "Reboot is required…" (exit code 1) sudo dnf needs-restarting -s # services still running old libraries sudo systemctl restart sshd # restart those, or… sudo reboot # …reboot for a new kernel
ls /var/run/reboot-required # exists = reboot needed cat /var/run/reboot-required.pkgs # which packages want it sudo reboot uname -r # the new kernel is running
A reboot kicks everyone off and stops every service for a minute or two. On a real server: tell people first, pick a quiet time, make sure you can get back in if something goes wrong (console access), and check that services came back afterwards (systemctl --failed). Servers behind a load balancer get rebooted one at a time.
Automatic updates
Humans forget. For security fixes, most servers should patch themselves every night.
sudo dnf install dnf-automatic sudoedit /etc/dnf/automatic.conf # upgrade_type = security # apply_updates = yes sudo systemctl enable --now dnf-automatic.timer systemctl list-timers 'dnf-*'
# installed and ON by default: cat /etc/apt/apt.conf.d/20auto-upgrades # what, and whether to reboot: sudoedit /etc/apt/apt.conf.d/50unattended-upgrades systemctl list-timers 'apt-daily*' less /var/log/unattended-upgrades/unattended-upgrades.log
Automatic reboots are a bigger decision: great for a single web server at 3 a.m., risky for a database in the middle of work. Ubuntu has Unattended-Upgrade::Automatic-Reboot "true"; and a reboot time. Many teams prefer to patch automatically and reboot on a schedule they control.
Sometimes an update breaks something and you need time. sudo apt-mark hold nginx (Ubuntu) or the versionlock plugin (sudo dnf versionlock add nginx, Rocky) pins a package. Remember to release it: a held package gets no security fixes.
Practice: patch Tuesday 🩹
This server has five updates waiting, some of them security fixes, including a new kernel. Install them the careful way, reboot into the new kernel, then set up automatic security updates. (Here the reboot takes a second, not a minute.)
Quick check
1. You updated OpenSSL. Is the running SSH server now protected?
✓ Restart the services that use it (needs-restarting -s lists them), or reboot.
2. How do you know an Ubuntu server needs a reboot?
✓ uname -r only changes AFTER the reboot.
3. Why install only security updates automatically, and not everything?
✓ A common compromise: security automatically every night, the rest in a planned window.