[Security Notice]: When installing from the OC9.6 ISO using the "Server Installation" option, the system will, by default, enable the SSH service (sshd) and open TCP port 22 for remote login. No other network ports are opened by default unless additional services are manually installed and enabled. [2026-05-26]:We are pleased to announce the release of the first version of OpenCloudOS 9.6, version 20260514.1, which will serve as the baseline release of OC9.6 and includes kernel version kernel-6.6.119-49.21.oc9. The file pointing relationship is as follows: baseline/OpenCloudOS-9.6-aarch64-boot.iso -> 20260514.1/OpenCloudOS-9.6-20260514.1-aarch64-boot.iso baseline/OpenCloudOS-9.6-aarch64-minimal.iso -> 20260514.1/OpenCloudOS-9.6-20260514.1-aarch64-minimal.iso baseline/OpenCloudOS-9.6-aarch64-everything.iso -> 20260514.1/OpenCloudOS-9.6-20260514.1-aarch64-everything.iso [2026-07-24]: Update monthly version OpenCloudOS-9.6-20260708.0. Typically includes: fixed rpm packages for recently discovered bugs, security fixes, and optimization or upgrades for some rpm packages. Special note the following updates: - ** kernel ** has been updated to kernel-6.6.119-50.12, fixes critical CVEs CVE-2026-46331, CVE-2026-43494, CVE-2026-46333, CVE-2026-43503, CVE-2026-46300, CVE-2026-43284, CVE-2026-31431, CVE-2026-43500, CVE-2026-46243, and disables CONFIG_INET_ESPINTCP/CONFIG_INET6_ESPINTCP to mitigate the Fragnesia vulnerability. Additional high-severity fixes address sched/fair DELAY_DEQUEUE starvation, reweight_entity() double-counting, mm/swap workingset shadow overlap panic, XFS null pointer dereference in log recovery, and NULL pointer crashes in psi/fuse/cpuset. Networking bugfixes cover net/sched pedit COW page cache corruption, net/skb shared-frag marker propagation, macsec SA cleanup in softirq context, and sched tg->load_avg unfairness. New features include HAOC kernel code pre-integration, mlnx DOCA 3.4 driver, mpt3sas driver upgrade to 57.00.00.00, UFFD_FEATURE_WP_ASYNC support, cgroup v2 role, x86_64 syscall dispatch table optimization, and CPU microcode late-loading. Platform enhancements sync OCK patches for Intel Clearwater Forest/SNC, AMD Zen6, 海光 family 18h model 18h, 龙芯 LoongArch, 鲲鹏 kunpeng950, 兆芯 microcode/KVM, 申威 SW64, ZTE Dinghai NIC, and Linkdata controllers. Also fixes over 80 additional non-critical CVEs across net, crypto, fs, and driver subsystems. Refer to the rpm package changelog for the complete list of changes. - ** gcc ** has been updated to 12.3.1.8-4, adding support for HYGON C86-4G series processors, backporting Zhaoxin lujiazui, yongfeng, and shijidadao architecture enablements, and applying an Intel patch to slightly discourage DFmode moves between SSE_REGS and GENERAL_REGS. - ** glibc ** has been updated to 2.38-49, fixing CVE-2025-15281 (wordexp WRDE_REUSE reset), CVE-2026-0915 (NSS DNS getnetbyaddr), and CVE-2026-0861 (memalign alignment overflow check). It also fixes regressions in posix_memalign() and malloc/free core counting, addresses pthread condition variable compatibility and lost wakeup issues, and fixes sem_open O_CREAT handling and CVE-2025-8058 double-free in regcomp. Additionally, it backports Hygon model 0x8 support, NT threshold adjustment, AVX512/AVX fast unaligned load optimizations, cache computation fix under hypervisors, adds SW64 ISA support, and syncs LoongArch upstream changes. - ** openssl ** has been updated to 3.0.12-27, fixing CVE-2026-34182, CVE-2026-45447, CVE-2026-22795, CVE-2026-22796, CVE-2025-69418, CVE-2025-68160, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2025-15467, CVE-2024-13176, CVE-2024-9143, CVE-2024-41996, CVE-2024-6119, CVE-2024-5535, CVE-2024-2511, CVE-2024-4741, and CVE-2024-4603. It also fixes multiple memory leaks, DH key computation error handling, OSSL_STORE EOF check, SM2 key encoding, and SM2 CMS signature support, and adds SW64 architecture support and QAT engine enablement.