IGEL OS Creator =============== Firmware version 12.8.3 Release date 2026-08-21 Last update of this document 2026-08-21 Supported Devices ------------------------------------------------------------------------------- [> Supported IGEL OS 12 devices](https://kb.igel.com/os12-supported-hardware) Component Versions ------------------------------------------------------------------------------- | Components | | |-------------------------------------------|----------------------------------| | MESA OpenGL Stack | 25.0.7-2igel1750243685 | | VDPAU Library Version | 1.5-2 | | Graphics Driver INTEL | 2.99.917+git20210115-1igel1654609037 | | Graphics Driver ATI/RADEON | 22.0.0-1igel1704966675 | | Graphics Driver ATI/AMDGPU | 25.0.0-1igel1763123370 | | Graphics Driver Nouveau (Nvidia Legacy) | 1.0.18-1igel1739362211 | | Graphics Driver VMware | 13.3.0-3igel1713934792 | | Graphics Driver QXL (Spice) | 0.1.6-1.1igel1742818532 | | Graphics Driver FBDEV | 0.5.0-2igel1654609009 | | Graphics Driver VESA | 2.6.0-2igel1739365508 | | Input Driver Evdev | 2.11.0-1igel1772008331 | | Input Driver Elographics | 1.4.4-1igel1746697619 | | Input Driver Synaptics | 1.9.2-1+b2igel1742818828 | | Input Driver VMMouse | 13.1.0-1ubuntu2igel1628499891 | | Input Driver Wacom | 1.2.4-1igel1772694990 | | Kernel | 6.18.6 #mainline-lxos12-g1785933202C | | Xorg X11 Server | 21.1.23-1igel1780396689 | | Lightdm Graphical Login Manager | 1.26.0-8igel1772701866 | | ISC DHCP Client | 4.4.3-P1-2 | | ModemManager | 1.24.2-2igel1763114076 | | WebKit2Gtk | 2.50.4-1~deb12u1igel1767851277 | | Python3 | 3.11.2 | | Virtualbox Guest Utils | 7.2.4-dfsg-1igel1763634473 | | Virtualbox X11 Guest Utils | 7.2.4-dfsg-1igel1763634473 | | Open VM Tools | 12.2.0-1+deb12u4 | | Open VM Desktop Tools | 12.2.0-1+deb12u4 | Release Notes of installable IGEL OS 12 base system ================================================================================ # Changes since: 12.8.2 LTS ## New Features - **WiFi** - Added a parameter for showing only managed wireless networks in the wifi tray app. When enabled, the user cannot connect to unmanaged SSIDs. | Parameter | Registry | Type | Value | | ------ | ------ | ------ | ------ | | `Show only managed wireless networks` | `network.interfaces.wirelesslan.device0.show_only_managed_ssids` | bool | enabled / *disabled* (default) | - **Smartcard** - Added a parameter to enable or disable support for the Kerberos smart card PKINIT PAChecksum2 extension. This parameter must be enabled when using Windows Server 2025 or later. | Parameter | Registry | Value | | ------ | ------ | ------ | | Send PAChecksum2 in PKINIT | auth.krb5.realms.pkinit.pkinit_send_pachecksum2 | true(default)/false | - **Hardware** - Added a parameter to configure the Intel DSP driver on the ClearCube CD7042. | Parameter | Registry | Range | Value | | ------ | ------ | ------ | ------ | | `Force the audio DSP driver. Use "Legacy HD-Audio" when the auto-detected driver fails to create a sound card.` | `system.sound_driver.snd_intel_dspcfg.dsp_driver` | [Default][Legacy HD-Audio][Intel SST][Intel SOF][Intel AVS] | *Default* | - **Dual Boot BC/DR (IGEL OS)** - Enhanced Boot Menu Design for BC&DR - Improved GRUB reliability and operational behavior. ## Security Fixes - Fixed krb5 security issue CVE-2026-11850. - Fixed libvncserver security issues CVE-2026-50538 and CVE-2026-44988. - Fixed libwebsockets security issue CVE-2026-10650. - Fixed opensc security issue CVE-2026-10275. - Fixed xorg-server security issues CVE-2026-50256, CVE-2026-50257, CVE-2026-50258, CVE-2026-50259, CVE-2026-50260, CVE-2026-50261, CVE-2026-50262 and CVE-2026-50263. - Fixed bind9 security issues CVE-2026-5950, CVE-2026-5946, CVE-2026-3592 and CVE-2026-3039. - Fixed gvfs security issues CVE-2026-28296 and CVE-2026-28295. - Fixed glibc security issues CVE-2026-4438, CVE-2026-4437, CVE-2026-4046, CVE-2026-0915, CVE-2026-0861 and CVE-2025-15281. - Fixed libcap2 security issue CVE-2026-4878. - Fixed libexif security issues CVE-2026-40386, CVE-2026-40385 and CVE-2026-32775. - Fixed libgcrypt20 security issue CVE-2026-41989. - Fixed haveged security issue CVE-2026-41054. - Fixed samba security issues CVE-2026-2340, CVE-2026-3012, CVE-2026-3238, CVE-2026-4480 and CVE-2026-4408. - Fixed openjpeg2 security issue CVE-2026-6192. - Fixed poppler security issues CVE-2026-10118, CVE-2025-52885 and CVE-2025-43718. - Fixed python3.11 security issues CVE-2026-6100, CVE-2026-4519, CVE-2026-4224, CVE-2026-3644, CVE-2026-2297, CVE-2026-0672, CVE-2025-13462, CVE-2023-52425, CVE-2026-1299, CVE-2026-0865, CVE-2026-0672, CVE-2025-8291, CVE-2025-8194, CVE-2025-6075, CVE-2025-6069, CVE-2025-4516, CVE-2025-15282, CVE-2025-13837, CVE-2025-13836, CVE-2025-12084 and CVE-2025-11468. - Fixed openssl security issues CVE-2026-9076, CVE-2026-7383, CVE-2026-45447, CVE-2026-45446, CVE-2026-45445, CVE-2026-42770, CVE-2026-42766, CVE-2026-34182 and CVE-2026-34180. - Fixed taglib security issue CVE-2023-47466. - Fixed rsync security issues CVE-2026-45232, CVE-2026-43620, CVE-2026-43619, CVE-2026-43618, CVE-2026-43617 and CVE-2026-29518. - Fixed sed security issue CVE-2026-5958. - Fixed openssl1.1 security issues CVE-2026-28390, CVE-2026-28389, CVE-2026-28388, CVE-2026-28387, CVE-2026-22796, CVE-2026-22795, CVE-2025-9230, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2025-69418, CVE-2025-68160, CVE-2024-9143, CVE-2024-5535, CVE-2024-4741, CVE-2024-2511, CVE-2024-13176, CVE-2024-0727, CVE-2023-5678, CVE-2023-3817, CVE-2023-3446, CVE-2023-2650, CVE-2023-0466, CVE-2023-0465, CVE-2023-0464, CVE-2023-0286, CVE-2023-0215, CVE-2022-4450, CVE-2022-4304, CVE-2022-2097, CVE-2022-2068, CVE-2022-1292, CVE-2022-0778, CVE-2021-4160, CVE-2021-3712, CVE-2021-3711, CVE-2021-3450, CVE-2021-3449, CVE-2021-23841, CVE-2021-23840, CVE-2020-1971 and CVE-2020-1967. - Updated ca-certificates package to version 20260601. - Fixed openvpn security issues CVE-2026-13698, CVE-2026-13122, CVE-2026-12996, CVE-2026-12932, CVE-2026-12117 and CVE-2026-11771. - Updated wireless-regdb package to version 2026.05.30. - Fixed jq security issues CVE-2026-54679, CVE-2026-49839, CVE-2026-47770, CVE-2026-44777, CVE-2026-43896, CVE-2026-43895, CVE-2026-43894, CVE-2026-41257, CVE-2026-41256, CVE-2026-40164, CVE-2026-39979, CVE-2026-39956, CVE-2026-33948, CVE-2026-33947 and CVE-2026-32316. - Fixed librabbitmq security issues CVE-2026-44236 and CVE-2026-44235. - Fixed python-urllib3 security issue CVE-2026-44431. - Fixed gst-libav1.0 security issue CVE-2026-52717. - Fixed gst-plugins-bad1.0 security issues CVE-2026-53701, CVE-2026-52719 and CVE-2026-52718. - Fixed gst-plugins-good1.0 security issues CVE-2026-5056, CVE-2026-46470, CVE-2026-46469, CVE-2026-39044, CVE-2026-39043 and CVE-2026-1940. - Fixed libarchive security issues CVE-2026-5745 and CVE-2026-14164. - Fixed nss security issues CVE-2026-6772, CVE-2026-6767, CVE-2026-6766 and CVE-2026-12318. - Fixed libcaca security issue CVE-2026-42046. - Fixed curl security issues CVE-2026-7168, CVE-2026-5773, CVE-2026-3784, CVE-2026-3783, CVE-2025-14819, CVE-2025-14524 and CVE-2025-10148. - Fixed giflib security issues CVE-2026-26740 and CVE-2026-23868. - Fixed graphite2 security issue CVE-2026-50593. - Fixed xz-utils security issue CVE-2026-34743. - Fixed protobuf security issues CVE-2026-6409, CVE-2026-0994, CVE-2025-4565 and CVE-2024-7254. - Fixed libxfont security issues CVE-2026-56003, CVE-2026-56002 and CVE-2026-56001. - Fixed libxml2 security issues CVE-2026-1757, CVE-2026-0992, CVE-2026-0990, CVE-2026-0989, CVE-2025-8732 and CVE-2025-49794. - Fixed python-xmltodict security issue CVE-2025-9375. - Fixed sshfs-fuse security issues CVE-2026-48711 and CVE-2026-47187. - Fixed openssh security issues CVE-2026-60002, CVE-2026-60001, CVE-2026-60000, CVE-2026-59999, CVE-2026-59998, CVE-2026-59997, CVE-2026-59996 and CVE-2026-59995. - Fixed spice-vdagent security issues CVE-2026-57966 and CVE-2026-57965. ## Resolved Issues - Added a refresh button to the Display Tray application to recover displays that could sporadically appear black in multi-monitor setups. - Fixed autostart notification of sessions in case session restart is active. - Fixed the user session not being properly closed when the system was suspended with no login method configured. - Fixed Hyper-V guest OS capabilities (Hyper-V is not officially supported). - Fixed USB Access Control deny rules not correctly blocking USB storage devices or interface devices such as smart card readers. - Fixed login mask not appearing on Dell devices when disclaimer is enabled. - **VMware Horizon** - Fixed Horizon windows not being placed on the correct monitor according to the startMonitor configuration. - **App Management** - Fixed IGEL App deployment when `Action after app assignment from UMS` was set to `Nothing` and devices were moved between directories in UMS with different IGEL App assignments. - **Network** - Fixed PAC file evaluation results not being applied correctly. - Fixed a potential crash when searching for hidden Wi-Fi networks by SSID. - Fixed PPP compatibility with NetworkManager by reverting to version 2.4.9 with the latest security updates. - **Smartcard** - Fixed Active Directory/Kerberos logon with smartcard to Windows Server 2025 based Active Directory domains by implementing PKINIT PAChecksum2 extension. Added a parameter to switch support of the extension: | Parameter | Registry | Value | | ------ | ------ | ------ | | Send PAChecksum2 in PKINIT | auth.krb5.realms.pkinit.pkinit_send_pachecksum2 | true(default)/false | - **HID** - Fixed issue with HP SmartCard keyboards which needed an extra key press to wake up at boot. Affected models: - TPC-C001K - SK-2027 - **Audio** - Fixed internal microphone not found issue with HP 255 G10 laptop. - **Hardware** - Fixed issue where the system and taskbar remained unresponsive for up to 90 seconds after the first resume following a reboot. - Fixed touchpad support for the Lenovo T14 Gen 6 with Intel Lunar Lake CPU. - Fixed flickering of full-HD webcam (Logitech HD Pro Webcam C920) - **Remote Management** - Fixed log collection via UMS hanging for an extended period if X11 or a user systemd session was no longer available. - Fixed Custom Corporate Identity (CI) not being applied after upgrading from IGEL OS 11 to IGEL OS 12. - Improved stability when multiple commands are sent close to each other which modify device state. - Fixed a bug where the system failed to prompt for a package manager update after a network change (for example, when connecting to a VPN). - Fixed measuring of the UTC Unix Epoch time. - Fixed transferring of the system information to the UMS. - Fixed a rare case where remote manager stopped responding if multiple files failed download. - **Dual Boot BC/DR (IGEL OS)** - Fixed BC&DR boot menu falling back to text mode due to missing theme files - Fixed the dual boot loader not recognizing Windows boot entries containing hexadecimal digits. - **IGEL Desktop** - Fixed desktop folders for sessions that could not be opened. - Fixed mixed colors in tray panel for certain theme and color combinations. - Fixed bug of using non-supported display resolutions by filtering them out. - Fixed broken input in captive portal window for wireless networks. ## Known Issues - The Display Settings setup page does not yet provide a Monitor Info button. - In very rare cases all apps are lost after an update. Should this be the case, an error message is shown "Opening system App Journal failed." - if the device is manged, the apps will be reinstalled after a reboot. - Increased writeable cache partition size (by default). First boot with 12.4.x and newer may take more time (once) when updating from a 12.2.x or older base system app. - Automatic proxy configuration: PAC file URL does not support https scheme. - When TPM PCR+PIN device encryption is enabled, an additional PIN entry is required the first time a new base system release is booted. - The "Always on Top" feature in the context menu does not work with full-screen-windows. - When using Keycloak as SSO provider, cookies are not forwarded to the user session after a successful login. This may cause users to be prompted to authenticate again within a browser session - Shadowing may flicker on older Intel devices without modesetting due to limitations of the legacy graphics driver. - **OSC Installer** - On Lenovo T14 Gen 6 Intel devices, the OSC may display a black screen with no desktop during a standard boot. A failsafe boot is required to access the OSC installer system. - **App Management** - Downgrades to versions prior to 12.7.0 are possible - despite the implemented downgrade limit - via the Local App Portal or using igelpkgctl through local terminal. In UMS-managed environments, disabling the Local App Portal is recommended to ensure version control. If the older shim bootloader signature (in 12.6.1 PR1 or earlier) is revoked and Secure Boot is enabled, the device may become unbootable. Verify boot compatibility before downgrading. - **Chromium** - Downgrading base system to earlier versions may result in reset of the Chromium profile partition. - **Network** - In some cases, network is not working in combination of Lenovo K14 Gen1 (AMD) and Lenovo Universal Dock. There is a kernel bugreport open but no proper fix so far. - Device configured as Wake on LAN proxy can be shut down by the user or admin - **WiFi** - WiFi chipset BE200 does not work reliable in WiFi 7 networks. - **HID** - Some touchpads are recognized as touchpad and mouse. This results in showing possible user settings for both variants. - Browser windows cannot be moved using touch input, while other applications are unaffected. This has been observed with Firefox, Microsoft Edge, and Chromium. - Workaround: Enable server-side window decoration. - Browser windows require two touch interactions to be moved when using client-side window decorations. The first touch does not initiate window movement, leading to inconsistent touchscreen behavior. This has been observed with Firefox, Microsoft Edge, and Chromium; other applications are unaffected. - Workaround: Enable server-side window decoration in the browser application. - **Application Launcher** - The Zoom session currently appears without an icon in the Application Launcher. - **Setup Assistant** - Timezone auto-detection is currently not functional (due to discontinued location service). The timezone must be set manually (as interims / alternative solution). - **Audio** - Headset mic via jack is not working on LG 27CN650 and LG 34CN650. - Audio devices may not be available in audio tray app. Workaround: Enable Pulseaudio backend by registry key: | Parameter | Registry | Range | Value | | ------ | ------ | ------ | ------ | | `Audiobackend` | `multimedia.audiobackend` | [pipewire][pulseaudio] | *pipewire* | - The Audio Tray App may incorrectly display a plugged-in Audio-Jack-Headset as Built-in Audio / HDMI / DiplayPort instead of the correct headset name. Audio and Microphone functionality would still work correctly. - On several hardware configurations, the internal audio is no longer available for selection when an audio jack is connected. - After suspend/resume, the audio tray icon may sporadically disappear and audio playback is not possible. - **Multimedia** - Lenovo L13 Gen5 and L14 Gen5 Intel video codec errors (graphic glitches during accelerated video playback) - **Hardware** - Wake on LAN is not functional on Lenovo K14 Gen1 - Built-in fingerprint sensor is not supported on HP mt440 G3 and mt645 G7/G8. - If using 6 x 4K@60Hz monitors on HP t755/t740 with the additional graphic card, one or two of the monitors may stay black after coming back from DPMS off state. This is caused by using the additional graphic card as primary, which only has 512MB VRAM (the VRAM is not sufficient in this configuration). Possible solution: Increasing the VRAM size of the iGPU to 2048MiB in BIOS (maybe 1024MiB may also work) and activate IGEL registry key `x.drivers.swap_card0_with_card1` so the iGPU will become the Primary GPU. Connector names will be changed with that! - Wake up from suspend via UMS does not work on HP mt645 G7 devices. Workaround: Disable system suspend and use shutdown instead. - Rotation of displays connected to the Lenovo ThinkPad USB-C Hybrid Dock may fail. - Display configuration of displays connected to HP G5 Docking Station may fail on HP t655. Furthermore displays connected to HP G5 Docking Station may not work anymore after system suspend and resume independent from the used hardware. - On Lenovo ThinkPad L13 Intel Gen5, the functions keys Ctrl+Fn+F9, Ctrl+Fn+F10 and Ctrl+Fn+F11 are not mapped. - On Lenovo ThinkPad models equipped with AMD graphics, when connected to a USB-C Universal Dock driving multiple 4K displays via DisplayPort, system boot or reboot may result in incomplete display initialization. In these cases, one or more external displays may remain black while others function normally. Disconnecting and reconnecting the dock restores full multi-display functionality. - When using an HP G5 Dock, disconnecting and reconnecting the dock may cause display configurations (such as display order, resolution, and orientation) to be lost. After reconnection, displays may revert to default settings, requiring manual reconfiguration. For some devices, this issue can be mitigated by setting the registry key `x.xserver0.quirks.dp_mst_hotplug` to Never. - Dell Wyse 3040 devices with 2 GB RAM may experience poor operating performance. - HP mt645 G8 devices with HP USB-C Dock G6 do not wake from suspend and cannot be powered off via UMS. - Wake-on-LAN is not working on Lenovo ThinkPad L15 Gen 4 AMD and Lenovo ThinkPad L16 Gen1 AMD devices from suspended or powered-off states. - On LG 34CR650 AIO devices, changing an external monitors orientation to Inverted can cause the internal display to turn black until reboot. - When a device is connected to an HP E27K G5 monitor via USB-C, it may wake from suspend automatically after approximately 20 seconds. - Sporadic system freezes may occur on newer AMD chipsets (AMD Ryzen AI) with the amdgpu graphics driver. - **Accessibility** - The screen reader (accessibility feature) currently does not work with the following apps: - IGEL Setup - IGEL First Boot Wizard - IGEL Start Menu - IGEL System Tray apps (volume, network, notifications, ...) - VPN and SSO login dialogs - **Dual Boot BC/DR (IGEL OS)** - The IGEL Dual Boot menu sometimes does not accurately reflect the presence of a UD-Pocket: - If the "fast boot" BIOS option is turned on for HP devices, the state won't be updated between reboots. Turning off "fast boot" provides accurate detection. - The boot loader doesn't currently detect UD Pockets on Lenovo devices. Using the Lenovo boot menu (F12) allows booting from UD Pockets directly but the "fast boot" BIOS option also interfere with the detection of USB boot devices. - **IGEL Desktop** - On-screen keyboard sporadically crashes when typing. - If two monitors are configured in a vertical layout (one above the other), and those monitors are configured with "auto-detect" resolution, saving leads to a wrong layout order. - There are some UI elements that are not yet translated in all available user interface languages. - In very rare cases, the Start menu or panel may not be visible after boot. A reboot will restore visibility in such cases. - In multi-monitor setups, the task switcher is only displayed on one monitor instead of all connected displays. - After a fresh installation, the scrolling method shown in the Tray App may not match the actual behavior. This is resolved after a reboot. - When launching an application via Omnissa Horizon, the taskbar may briefly disappear before reappearing. - After changing the primary display and reassigning the taskbar monitor, icons move correctly but the taskbar remains on the original monitor. - With Taskbar auto hide set to Always the taskbar may invert its behavior (show/hide) after a delay, becoming visible when the cursor is away and hidden when hovering over it. - When using a taskbar spanning two monitors, the taskbar does not remain visible on the second monitor while a fullscreen session is active on the first. This prevents access to tray applications without leaving the fullscreen session. - **Licensing** - Manual deployment of add-on licenses for IGEL Agent for Imprivata licenses (via UMS) is only possible after finished installation of IGEL Agent for Imprivata app on device. - Endpoints that have a Starter License but no Workspace Edition license will not receive device settings or app management from UMS if add-on licenses are installed. Workaround: Either remove the add-on licenses or assign a valid Workspace Edition (or Workspace Edition Demo) license. - **Mobile Broadband** - F11 flight mode function key does not switch off mobile broadband on HP Elite mt645 G7. (Deactivate mobile broadband in Network / Mobile Broadband settings)