Changes since Alpha 4515.0.1
Security fixes:
- Linux (CVE-2025-40275, CVE-2025-40274, CVE-2025-40273, CVE-2025-40272, CVE-2025-40271, CVE-2025-40289, CVE-2025-40288, CVE-2025-40287, CVE-2025-40269, CVE-2025-40286, CVE-2025-40285, CVE-2025-40284, CVE-2025-40283, CVE-2025-40282, CVE-2025-40281, CVE-2025-40280, CVE-2025-40279, CVE-2025-40278, CVE-2025-40277, CVE-2025-40268, CVE-2025-40214, CVE-2025-40212, CVE-2024-58087, CVE-2024-57879, CVE-2024-57880, CVE-2024-55642, CVE-2024-55641, CVE-2024-55639, CVE-2024-54683, CVE-2024-54460, CVE-2024-54191, CVE-2024-53689, CVE-2024-53682, CVE-2024-53687, CVE-2024-56770, CVE-2024-56661, CVE-2024-56660, CVE-2024-56659, CVE-2024-56658, CVE-2024-56657, CVE-2024-56656, CVE-2024-56655, CVE-2024-56675, CVE-2024-56674, CVE-2024-56673, CVE-2024-56672, CVE-2024-56654, CVE-2024-56671, CVE-2024-56670, CVE-2024-56669, CVE-2024-56668, CVE-2024-56667, CVE-2024-56666, CVE-2024-56665, CVE-2024-56664, CVE-2024-56663, CVE-2024-56662, CVE-2024-56652, CVE-2024-56653, CVE-2024-53241, CVE-2024-53240, CVE-2025-40261, CVE-2025-40266, CVE-2025-40264, CVE-2025-40263, CVE-2025-40262, CVE-2025-40254, CVE-2025-40253, CVE-2025-40252, CVE-2025-40251, CVE-2025-40250, CVE-2025-40259, CVE-2025-40258, CVE-2025-40257, CVE-2025-40246, CVE-2025-40248, CVE-2025-40345)
- coreutils (CVE-2025-5278)
- go (CVE-2025-47912, CVE-2025-58183, CVE-2025-58185, CVE-2025-58186, CVE-2025-58187, CVE-2025-58188, CVE-2025-58189, CVE-2025-61723, CVE-2025-61724, CVE-2025-61725)
- pam (CVE-2024-22365, CVE-2024-10041, CVE-2024-10963, CVE-2025-6020)
Bug fixes:
- Dropped debug symbols from containerd, incus, and overlaybd system extensions to reduce download size.
Changes:
/etc/shadow,/etc/gshadoware now owned by theshadowgroup,/usr/bin/unix_chkpwd,/usr/bin/chageand/usr/bin/expiryare now also owned by theshadowgroup with a sticky bit enabled.
Updates:
- Linux (6.12.61 (includes 6.12.59, 6.12.60))
- Linux firmware (20251125 (includes 20251111))
- base, dev: btrfs-progs (6.17)
- base, dev: cifs-utils (7.4)
- base, dev: coreutils (9.8)
- base, dev: hwdata (0.400 (includes 0.399))
- base, dev: inih (62 (includes 61))
- base, dev: intel-microcode (20251111_p20251112)
- base, dev: iproute2 (6.17.0)
- base, dev: jose (14 (includes 13))
- base, dev: kbd (2.9.0)
- base, dev: less (685)
- base, dev: libgpg-error (1.56)
- base, dev: libtirpc (1.3.7)
- base, dev: openssl (3.5.4 (includes 3.5.0, 3.5.1, 3.5.2, 3.5.3))
- base, dev: pam (1.7.1 (includes 1.6.0, 1.6.1, 1.7.0))
- base, dev: pambase (20251013)
- base, dev: samba (4.22.5 (includes 4.22.4))
- base, dev: strace (6.17)
- base, dev: thin-provisioning-tools (1.3.0 (includes 1.0.11, 1.0.12, 1.0.13, 1.0.14, 1.1.0, 1.2.0, 1.2.1, 1.2.2))
- base, dev: util-linux (2.41.2)
- ca-certificates (3.119 (includes 3.118.1))
- dev: portage (3.0.69.3 (includes 3.0.69, 3.0.69.1, 3.0.69.2))
- ignition (2.24.0)
- sdk: cmake (4.1.2 (includes 4.0, 4.1, 4.1.1))
- sdk: go (1.25.3)
- sdk: meson (1.9.1 (includes 1.8.0))
- sdk: nasm (3.01 (includes 3.00))
- sysext-overlaybd: overlaybd (1.0.16)
- sysext-podman: aardvark-dns (1.15.0)
- sysext-podman: netavark (1.16.1 (includes 1.16.0))
- sysext-python: more-itertools (10.8.0)
- sysext-python: platformdirs (4.5.0)
- sysext-python: resolvelib (1.2.1)
- sysext-python: rich (14.2.0)
- sysext-python: setuptools-scm (9.2.0 (includes 9.0.0, 9.1.0))
- sysext-python: trove-classifiers (2025.9.11.17 (includes 2025.9.8.13, 2025.9.9.12))