Changes since Beta 4515.1.0
Security fixes:
- Linux (CVE-2025-68335, CVE-2025-68332, CVE-2025-68337, CVE-2025-68336, CVE-2025-68265, CVE-2025-68266, CVE-2025-68263, CVE-2025-68261, CVE-2025-68259, CVE-2025-68258, CVE-2025-68257, CVE-2025-68256, CVE-2025-68264, CVE-2025-68254, CVE-2025-68255, CVE-2025-68764, CVE-2025-68766, CVE-2025-68765, CVE-2025-68759, CVE-2025-68758, CVE-2025-68757, CVE-2025-68756, CVE-2025-68753, CVE-2025-68763, CVE-2025-68744, CVE-2025-68742, CVE-2025-68741, CVE-2025-68740, CVE-2025-68748, CVE-2025-68747, CVE-2025-68746, CVE-2025-68724, CVE-2025-68380, CVE-2025-68379, CVE-2025-68378, CVE-2025-68733, CVE-2025-68732, CVE-2025-68728, CVE-2025-68727, CVE-2025-68374, CVE-2025-68352, CVE-2025-68349, CVE-2025-68348, CVE-2025-68347, CVE-2025-68372, CVE-2025-68371, CVE-2025-68369, CVE-2025-68367, CVE-2025-68366, CVE-2025-68364, CVE-2025-68346, CVE-2025-68363, CVE-2025-68362, CVE-2025-68361, CVE-2025-68356, CVE-2025-68354, CVE-2025-68344, CVE-2025-68325, CVE-2025-68324, CVE-2025-71157, CVE-2025-71156, CVE-2025-71154, CVE-2025-71153, CVE-2025-71151, CVE-2025-71150, CVE-2025-71149, CVE-2025-71148, CVE-2025-71146, CVE-2025-71147, CVE-2025-71143, CVE-2025-71140, CVE-2025-71138, CVE-2025-71137, CVE-2025-71136, CVE-2025-71135, CVE-2025-71133, CVE-2025-71132, CVE-2025-71131, CVE-2025-71130, CVE-2025-71129, CVE-2025-71111, CVE-2025-71109, CVE-2025-71108, CVE-2025-71107, CVE-2025-71105, CVE-2025-71126, CVE-2025-71125, CVE-2025-71123, CVE-2025-71122, CVE-2025-71104, CVE-2025-71121, CVE-2025-71120, CVE-2025-71119, CVE-2025-71118, CVE-2025-71116, CVE-2025-71114, CVE-2025-71113, CVE-2025-71112, CVE-2025-71102, CVE-2025-71079, CVE-2025-71087, CVE-2025-71086, CVE-2025-71085, CVE-2025-71084, CVE-2025-71083, CVE-2025-71082, CVE-2025-71101, CVE-2025-71100, CVE-2025-71099, CVE-2025-71081, CVE-2025-71098, CVE-2025-71097, CVE-2025-71096, CVE-2025-71095, CVE-2025-71094, CVE-2025-71093, CVE-2025-71091, CVE-2025-71089, CVE-2025-71080, CVE-2025-71078, CVE-2025-71064, CVE-2025-71073, CVE-2025-71072, CVE-2025-71071, CVE-2025-71069, CVE-2025-71068, CVE-2025-71067, CVE-2025-71066, CVE-2025-71077, CVE-2025-71076, CVE-2025-71075, CVE-2025-71065, CVE-2025-68820, CVE-2025-68822, CVE-2025-68821, CVE-2025-68785, CVE-2025-68794, CVE-2025-68789, CVE-2025-68819, CVE-2025-68818, CVE-2025-68817, CVE-2025-68816, CVE-2025-68815, CVE-2025-68788, CVE-2025-68814, CVE-2025-68813, CVE-2025-68811, CVE-2025-68810, CVE-2025-68809, CVE-2025-68808, CVE-2025-68806, CVE-2025-68787, CVE-2025-68804, CVE-2025-68803, CVE-2025-68802, CVE-2025-68801, CVE-2025-68800, CVE-2025-68799, CVE-2025-68798, CVE-2025-68797, CVE-2025-68796, CVE-2025-68795, CVE-2025-68786, CVE-2025-68776, CVE-2025-68775, CVE-2025-68774, CVE-2025-68773, CVE-2025-68772, CVE-2025-68771, CVE-2025-68770, CVE-2025-68769, CVE-2025-68784, CVE-2025-68783, CVE-2025-68782, CVE-2025-68781, CVE-2025-68780, CVE-2025-68778, CVE-2025-68777, CVE-2025-68767, CVE-2025-71144, CVE-2025-71134, CVE-2025-71127, CVE-2025-71088, CVE-2026-22982, CVE-2026-22980, CVE-2026-22979, CVE-2026-22978, CVE-2026-22994, CVE-2025-71160, CVE-2026-22992, CVE-2026-22991, CVE-2026-22990, CVE-2026-22989, CVE-2026-22988, CVE-2026-22984, CVE-2026-22977, CVE-2026-22976)
- coreutils (CVE-2025-5278)
- go (CVE-2025-47912, CVE-2025-58183, CVE-2025-58185, CVE-2025-58186, CVE-2025-58187, CVE-2025-58188, CVE-2025-58189, CVE-2025-61723, CVE-2025-61724, CVE-2025-61725)
- pam (CVE-2024-22365, CVE-2024-10041, CVE-2024-10963, CVE-2025-6020)
- openssl (CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796)
Bug fixes:
- Dropped debug symbols from containerd, incus, and overlaybd system extensions to reduce download size.
Changes:
- Dropped Ciphers, MACs, and KexAlgorithms from the sshd configuration so that the OpenSSH upstream defaults are used. This introduces post-quantum key exchange algorithms for better security. (Flatcar#1921). Users requiring legacy Ciphers, MACs, and/or KexAlgos can override / re-enable this by deploying a custom drop-in config to
/etc/ssh/sshd_config.d/. /etc/shadow,/etc/gshadoware now owned by theshadowgroup,/usr/bin/unix_chkpwd,/usr/bin/chageand/usr/bin/expiryare now also owned by theshadowgroup with a sticky bit enabled.
Updates:
- Ignition (2.24.0)
- Linux (6.12.66 (includes 6.12.65, 6.12.64, 6.12.63, 6.12.62, 6.12.59))
- Linux Firmware (20251125 (includes 20251111))
- SDK: cmake (4.1.2 (includes 4.1.1, 4.1, 4.0))
- SDK: go (1.25.3)
- SDK: meson (1.9.1 (includes 1.8.0))
- SDK: nasm (3.01 (includes 3.00))
- base, dev: btrfs-progs (6.17)
- base, dev: cifs-utils (7.4)
- base, dev: coreutils (9.8)
- base, dev: hwdata (0.400 (includes 0.399))
- base, dev: inih (62 (includes 61))
- base, dev: intel-microcode (20251111_p20251112)
- base, dev: iproute2 (6.17.0)
- base, dev: jose (14 (includes 13))
- base, dev: kbd (2.9.0)
- base, dev: less (685)
- base, dev: libgpg-error (1.56)
- base, dev: libtirpc (1.3.7)
- base, dev: pam (1.7.1 (includes 1.7.0, 1.6.1, 1.6.0))
- base, dev: pambase (20251013)
- base, dev: samba (4.22.5 (includes 4.22.4))
- base, dev: strace (6.17)
- base, dev: thin-provisioning-tools (1.3.0 (includes 1.2.2, 1.2.1, 1.2.0, 1.1.0, 1.0.14, 1.0.13, 1.0.12, 1.0.11))
- base, dev: util-linux (2.41.2)
- ca-certificates (3.120)
- dev: portage (3.0.69.3 (includes 3.0.69.2, 3.0.69.1, 3.0.69))
- sysext-overlaybd: overlaybd (1.0.16)
- sysext-podman: aardvark-dns (1.15.0)
- sysext-podman: netavark (1.16.1 (includes 1.16.0))
- sysext-python: more-itertools (10.8.0)
- sysext-python: platformdirs (4.5.0)
- sysext-python: resolvelib (1.2.1)
- sysext-python: rich (14.2.0)
- sysext-python: setuptools-scm (9.2.0 (includes 9.1.0, 9.0.0))
- sysext-python: trove-classifiers (2025.9.11.17 (includes 2025.9.9.12, 2025.9.8.13))
- openssl (3.5.5)