• Urgent security alert for Fedora Linux 40 and Fedora Rawhide users

    Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Urgent security alert for Fedora Linux 40 and Fedora Rawhide users

    Author
    Topic
    #2654941

    https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users

    Editor’s note: This post has been updated to more clearly articulate the affected versions of Fedora Linux and add additional mitigation methods.

    Yesterday, Red Hat Information Risk and Security and Red Hat Product Security learned that the latest versions of the “xz” tools and libraries contain malicious code that appears to be intended to allow unauthorized access. Specifically, this code is present in versions 5.6.0 and 5.6.1 of the libraries. Fedora Linux 40 users may have received version 5.6.0, depending on the timing of system updates. Fedora Rawhide users may have received version 5.6.0 or 5.6.1. This vulnerability was assigned CVE-2024-3094.

    PLEASE IMMEDIATELY STOP USAGE OF ANY FEDORA RAWHIDE INSTANCES for work or personal activity. Fedora Rawhide will be reverted to xz-5.4.x shortly, and once that is done, Fedora Rawhide instances can safely be redeployed. Note that Fedora Rawhide is the development distribution of Fedora Linux, and serves as the basis for future Fedora Linux builds (in this case, the yet-to-be-released Fedora Linux 41)…

    Reply To: Urgent security alert for Fedora Linux 40 and Fedora Rawhide users

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: