Changes since LTS 3510.3.6
- Linux (Please refer to the Go/No-Go document for the list of CVEs resolved)
- Go (CVE-2022-41723, CVE-2022-41724, CVE-2022-41725, CVE-2023-24532, CVE-2023-24534, CVE-2023-24536, CVE-2023-24537, CVE-2023-24538, CVE-2023-24539, CVE-2023-24540, CVE-2023-29400, CVE-2023-29402, CVE-2023-29403, CVE-2023-29404, CVE-2023-29405, CVE-2023-29406, CVE-2023-29409, CVE-2023-39318, CVE-2023-39319, CVE-2023-39320, CVE-2023-39321, CVE-2023-39322, CVE-2023-39323, CVE-2023-39325, CVE-2023-39326, CVE-2023-45285, CVE-2023-45288, CVE-2023-45289, CVE-2023-45290, CVE-2024-24783, CVE-2024-24784, CVE-2024-24785, CVE-2024-24788, CVE-2024-24789, CVE-2024-24790, CVE-2024-24791)
- Linux Firmware (CVE-2023-31315)
- SDK: dnsmasq (CVE-2022-0934)
- SDK: nasm (CVE-2019-6290, CVE-2019-6291, CVE-2019-8343, CVE-2020-21528, CVE-2021-33450, CVE-2021-33452, CVE-2022-44368, CVE-2022-44369, CVE-2022-44370)
- SDK: perl (CVE-2023-47038)
- SDK: pkgconf (CVE-2023-24056)
- SDK: python (CVE-2023-24329, CVE-2023-40217, CVE-2023-41105, CVE-2023-6597, CVE-2024-0450, gh-81194, gh-113659, gh-102388, gh-114572, gh-115243)
- SDK: qemu (CVE-2023-0330, CVE-2023-2861)
- SDK: re2c (CVE-2022-23901)
- SDK: Rust (CVE-2023-38497)
- VMware: open-vm-tools (CVE-2023-34058, CVE-2023-34059, CVE-2023-20867)
- bash (CVE-2022-3715)
- binutils (CVE-2022-38533, CVE-2022-4285, CVE-2023-1579, CVE-2023-2222, CVE-2023-1972)
- c-ares (CVE-2022-4904, CVE-2023-31124, CVE-2023-31130, CVE-2023-31147, CVE-2023-32067, CVE-2024-25629)
- containerd (CVE-2023-25153, CVE-2023-25173)
- coreutils (coreutils-2024-03-28, CVE-2024-0684)
- curl (CVE-2023-23914, CVE-2023-23915, CVE-2023-23916, CVE-2023-27533, CVE-2023-27534, CVE-2023-27535, CVE-2023-27536, CVE-2023-27537, CVE-2023-27538, CVE-2023-28319, CVE-2023-28320, CVE-2023-28321, CVE-2023-28322, CVE-2023-32001, CVE-2023-38039, CVE-2023-38545, CVE-2023-38546, CVE-2023-46218, CVE-2023-46219, CVE-2024-2004, CVE-2024-2379, CVE-2024-2398, CVE-2024-2466, CVE-2024-6197, CVE-2024-6874, CVE-2024-7264)
- dnsmasq (CVE-2023-28450, CVE-2023-50387, CVE-2023-50868)
- e2fsprogs (CVE-2022-1304)
- expat (CVE-2023-52425, CVE-2024-28757, CVE-2024-45490)
- gcc (CVE-2023-4039)
- git (CVE-2023-22490, CVE-2023-23946, CVE-2023-25652, CVE-2023-25815, CVE-2023-29007, CVE-2024-32002, CVE-2024-32004, CVE-2024-32020, CVE-2024-32021, CVE-2024-32465)
- glib (CVE-2024-34397)
- glibc (CVE-2023-4527, CVE-2023-4806, CVE-2023-4911, CVE-2023-5156, CVE-2023-6246, CVE-2023-6779, CVE-2023-6780, CVE-2024-2961, CVE-2024-33599, CVE-2024-33600, CVE-2024-33601, CVE-2024-33602)
- gnupg (gnupg-2024-01-25)
- gnutls (CVE-2023-0361, CVE-2023-5981, CVE-2024-0567, CVE-2024-0553, CVE-2024-28834, CVE-2024-28835)
- grub (CVE-2020-10713, CVE-2020-14372, CVE-2020-25632, CVE-2020-25647, CVE-2020-27749, CVE-2020-27779, CVE-2021-20225, CVE-2021-20233, CVE-2021-3981, CVE-2021-3695, CVE-2021-3696, CVE-2021-3697, CVE-2022-28733, CVE-2022-28734, CVE-2022-28735, CVE-2022-28736, CVE-2022-28737, CVE-2022-2601, CVE-2022-3775, CVE-2023-4692, CVE-2023-4693)
- intel-microcode (CVE-2022-21216, CVE-2022-33196, CVE-2022-38090, CVE-2022-40982, CVE-2022-41804, CVE-2023-23908, CVE-2023-22655, CVE-2023-28746, CVE-2023-38575, CVE-2023-39368, CVE-2023-43490, CVE-2023-23583, CVE-2023-45733, CVE-2023-45745, CVE-2023-46103, CVE-2023-47855)
- less (CVE-2022-46663, CVE-2024-32487)
- libarchive (CVE-2024-26256, CVE-2024-37407, libarchive-20230729)
- libcap (CVE-2023-2602, CVE-2023-2603)
- libmicrohttpd (CVE-2023-27371)
- libtirpc (libtirpc-rhbg-2138317, libtirpc-rhbg-2150611, libtirpc-rhbg-2224666)
- libuv (CVE-2024-24806)
- libxml2 (CVE-2023-28484, CVE-2023-29469, CVE-2023-45322, CVE-2024-25062, CVE-2024-34459, libxml2-20230428)
- lua (CVE-2022-33099)
- mit-krb5 (CVE-2023-36054, CVE-2024-26461, CVE-2024-26462, CVE-2024-37370, CVE-2024-37371)
- ncurses (CVE-2023-29491)
- nghttp2 (CVE-2023-44487, CVE-2024-28182)
- nvidia-drivers (CVE-2023-25515, CVE-2023-25516)
- openldap (CVE-2023-2953)
- openssh (CVE-2023-25136, CVE-2024-6387, CVE-2023-38408, CVE-2023-28531, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385)
- openssl (CVE-2022-4203, CVE-2022-4304, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0286, CVE-2023-0401, CVE-2023-3817, CVE-2023-5363, CVE-2023-5678, CVE-2023-5678, CVE-2023-6129, CVE-2023-6237, CVE-2024-0727, CVE-2023-0464, CVE-2023-0465, CVE-2023-0466, CVE-2023-1255, CVE-2023-2650), CVE-2023-2975, CVE-2023-3446)
- procps (CVE-2023-4016)
- protobuf (CVE-2022-1941)
- runc (CVE-2023-25809, CVE-2023-27561, CVE-2023-28642, CVE-2024-21626)
- samba (CVE-2021-44142, CVE-2022-1615, CVE-2023-4091)
- shadow (CVE-2023-29383)
- sudo (CVE-2023-27320, CVE-2023-28486, CVE-2023-28487, CVE-2023-42465)
- sysext-docker: Docker (CVE-2023-28840, CVE-2023-28841, CVE-2023-28842, CVE-2024-24557, CVE-2024-29018)
- sysext-podman: podman (CVE-2024-3727)
- tar (CVE-2022-48303)
- torcx (CVE-2022-32149, CVE-2022-28948)
- tpm2-tools (CVE-2024-29038, CVE-2024-29039, CVE-2024-29040)
- traceroute (CVE-2023-46316)
- vim (CVE-2023-0288, CVE-2023-0433, CVE-2023-1127, CVE-2023-1175, CVE-2023-1170, CVE-2023-2609, CVE-2023-2610, CVE-2023-2426, CVE-2023-48231, CVE-2023-48232, CVE-2023-48233, CVE-2023-48234, CVE-2023-48235, CVE-2023-48236, CVE-2023-48237, CVE-2023-48706, CVE-2023-5344, CVE-2023-5441, CVE-2023-5535, CVE-2023-46246)
- zlib (CVE-2023-45853, CVE-2023-20900)
Bug fixes:
- Ensured that
/var/log/journal/
is created early enough for systemd-journald to persist the logs on first boot (bootengine#60, baselayout#29) - Fixed
journalctl --user
permission issue (Flatcar#989) - Added a workaround for old airgapped/proxied update-engine clients to be able to update to this release (Flatcar#1332, update_engine#38)
- Added AWS EKS support for versions 1.24-1.28. Fixed
/usr/share/amazon/eks/download-kubelet.sh
to include download paths for these versions. (scripts#1210) - Added qemu-guest-agent to ARM64 images (flatcar/flatcar#1593)
- AWS: Fixed the Amazon SSM agent that was crashing. (Flatcar#1307)
- CloudSigma: Disabled the new DHCP RapidCommit feature which is enabled by default since systemd 255. CloudSigma provides an incompatible implementation which results in cloud-init not being applied as no IP is issued. See: (flatcar/scripts#2016)- Fixed issue file generation from '/etc/issue.d' (scripts#2018)
- Deleted files in
/etc
that have a tmpfiles rule that normally would recreate them will now show up again through the/etc
lowerdir (Flatcar#1265, bootengine#79) - Disabled user-configdrive.service on OpenStack when config drive is used, which caused the hostname to be overwritten. The coreos-cloudinit.service unit already runs on OpenStack if the system is not configured via ignition. (Flatcar#1385)
- Ensured that the folder
/var/log/sssd
is created if it doesn't exist, required forsssd.service
(Flatcar#1096) - Fixed a bug resulting in coreos-cloudinit resetting the instance hostname to 'localhost' if no metadata could be found (coreos-cloudinit#25)
- Fixed a miscompilation of getfacl causing it to dump core when executed (scripts#809)
- Fixed bad usage of gpg that prevented flatcar-install from being used with custom signing keys (Flatcar#1471)
- Fixed bug in handling renamed network interfaces when generating login issue (init#102)
- Fixed iterating over the OEM update payload signatures which prevented the AWS OEM update to 3745.x.y (update-engine#31)
- Fixed oem-cloudinit.service on Equinix Metal. The availability check now uses the https://metadata.platformequinix.com/metadata endpoint. (scripts#2222)
- Fixed quotes handling for update-engine (Flatcar#1209)
- Fixed slow boots PXE and ISO boots caused by the decrypt-root.service. (Flatcar#1514)
- Fixed supplying extension update payloads with a custom base URL in Nebraska (Flatcar#1281)
- Fixed that systemd-sysext images can extend directories where Flatcar extensions are also shipping files, e.g., that the sysext-bakery Kubernetes extension works when OEM extensions are present (sysext-bakery#50)
- Fixed the handling of OEM update payloads in a Nebraska response with self-hosted packages (ue-rs#49)
- Fixed the initrd option in the QEMU launcher script. It was -R, but this was already taken by the read-only pflash option, so use -r instead. (scripts#2239)
- Fixed the missing
/etc/extensions/
symlinks for the inbuilt Docker/containerd systemd-sysext images on update from Beta 3760.1.0 (update_engine#32) - Fixed the postinstall hook failure when updating from Azure instances without OEM systemd-sysext images to Flatcar Alpha 3745.x.y (update_engine#29)
- Fixes kubevirt vm creation by ensuring that /dev/vhost-net exists (Flatcar#1336)
- Fix ownership of systemd units shipped with built-in docker/containerd sysexts. The files shipped on production images were accidentally owned by 1000:1000 instead of 0:0. This uid/gid is not present on Flatcar images but would be assigned to the first created user. Due to contents of sysexts and /usr being readonly on Flatcar, the invalid permissions can't be used to escalate privileges. (scripts#2266)
- Fix the RemainAfterExit clause in nvidia.service (Flatcar#1169)
- GCP: Fixed OS Login enabling (scripts#1445)
- Hetzner: Fixed duplicated prefix in the Afterburn metadata (scripts#2141)
- Made
sshkeys.service
more robust to only runcoreos-metadata-sshkeys@core.service
when not masked and also retry on failure (init#112) - Removed custom CloudSigma coreos-cloudinit service configuration since it will be called with the cloudsigma oem anyway. The restart of the service can also cause the serial port to be stuck in an nondeterministic state which breaks future runs.
- Resolved kmod static nodes creation in bootengine (bootengine#85)
- Restored support for custom OEMs supplied in the PXE boot where
/usr/share/oem
brings the OEM partition contents (Flatcar#1376) - Restored the reboot warning and delay for non-SSH console sessions (locksmith#21)
- Set TTY used for fetching server_context to RAW mode before running cloudinit on cloudsigma (scripts#1280)
- Worked around a bash regression in
flatcar-install
and added error reporting for disk write failures (Flatcar#1059)
Changes:
- Added a new
flatcar-reset
tool and boot logic for selective OS resets to reconfigure the system with Ignition while avoiding config drift (bootengine#55, init#91) - Added
pigz
to the image, a parallel gzip implementation, which is useful to speed up the (de)compression for large container image imports/exports (coreos-overlay#2504) - Enabled elfutils support in systemd-coredump. A backtrace will now appear in the journal for any program that dumps core (coreos-overlay#2489)
/etc
is now set up as overlayfs with the original/etc
folder being the store for changed files/directories and/usr/share/flatcar/etc
providing the lower default directory tree (bootengine#53, scripts#666)- Improved the OS reset tool to offer preview, backup and restore (init#94)
- On boot any files in
/etc
that are the same as provided by the booted/usr/share/flatcar/etc
default for the overlay mount on/etc
are deleted to ensure that future updates of/usr/share/flatcar/etc
are propagated - to opt out create/etc/.no-dup-update
in case you want to keep an unmodified config file as is or because you fear that a future Flatcar version may use the same file as you at which point your copy is cleaned up and any other future Flatcar changes would be applied (bootengine#54) - Switched systemd log reporting to the combined format of both unit description, as before, and now the unit name to easily find the unit (coreos-overlay#2436)
- Added zram-generator package to the image (scripts#1772)
- Added Akamai / Linode images (flatcar/scripts#1806)
- Added azure-nvme-utils to the image, which is used by udev to create symlinks for NVMe disks on Azure v6 instances under /dev/disk/azure/. (scripts#1950)
- Added Hetzner images (flatcar/scripts#1880)
- Added Hyper-V VHDX image (flatcar/scripts#1791)
- Added Ignition Clevis support for encrypted disks unlocked with a TPM2 device or a Tang server (scripts#1560)
- Added KubeVirt qcow2 image for amd64/arm64 (flatcar/scripts#1962)
- Added Scaleway images (flatcar/scripts#1683)
- Added support for multipart MIME userdata in coreos-cloudinit. Ignition now detects multipart userdata and delegates execution to coreos-cloudinit. (scripts#873)
- Added support for unlocking the rootfs with a TPM set up by systemd-cryptenroll (bootengine#93)
- Added TLS Kernel module (scripts#865)
- Add Intel igc driver to support I225/I226 family NICs. (flatcar/scripts#1786)
- A new format
qemu_uefi_secure
is introduced to test Flatcar for SecureBoot-enabled features. The format will be later merged intoqemu_uefi
. - As part of the update to Catalyst 4 (used to build the SDK), the coreos package repository has been renamed to coreos-overlay to match its directory name. This will be reflected in package listings and package manager output. (flatcar/scripts#2115)
- AWS OEM images now use a systemd-sysext image for layering additional platform-specific software on top of
/usr
- Azure and QEMU OEM images now use systemd-sysext images for layering additional platform-specific software on top of
/usr
. For Azure images this also means that the image has a normal Python installation available through the sysext image. The OEM software is still not updated but this will be added soon. - Azure, HyperV: Added daemons
kvp
,vss
, andfcopy
for better HyperV hypervisor integration with Flatcar guests (scripts#2309). - Backported systemd-sysext mutable overlays functionality from yet-unreleased systemd v256. (flatcar/scripts#1753)
- Changed coreos-cloudinit to now set the short hostname instead of the FQDN when fetched from the metadata service (coreos-cloudinit#19)
(changelog, upstream pr). - Change nvidia.service to type oneshot (from the default "simple") so the subsequent services (configured with "Requires/After") are executed after the driver installation is successfully finished (flatcar/Flatcar#1136)
- Consequently,
update_engine
will not perform torcx sanity checks post-update anymore.
- Consequently,
- cri-tools, runc, containerd, docker, and docker-cli are now built from Gentoo upstream ebuilds. Docker received a major version upgrade - it was updated to Docker 24 (from Docker 20; see “updates”).
- Disabled real-time priority for multipathd as it prevents the cgroups2 cpu controller from working. (flatcar/scripts#1771)
- Docker will remove the
btrfs
driver entirely in a future version. Please consider migrating your deployments to theoverlay2
driver.
- Docker will remove the
- Enabled amd-pstate,amd-pstate-epp cpufreq drivers for some AMD CPUs in the kernel. (flatcar/scripts#1770)
- Enabled ntpd by default on AWS & GCP, enabled chronyd by default on Azure. The native time sync source is used on each cloud. (scripts#1792)
- Enabled the GRUB TPM2 module to measure the boot code path and files into PCR 8+9 in UEFI (scripts#1861)
- Enabled the ptp_vmw module in the kernel.
- Enabled the virtio GPU driver (scripts#830)
- Enable mpi3mr kernel module for Broadcom Storage/RAID-Controllers (flatcar/scripts#2355)
- GCP OEM images now use a systemd-sysext image for layering additional platform-specific software on top of
/usr
and being part of the OEM A/B updates (flatcar#1146) - Hetzner: Added
COREOS_HETZNER_PRIVATE_IPV4_0
Afterburn attribute for Hetzner private IPs (scripts#2141) - Hyper-V images, both .vhd and .vhdx files are available as
zip
compressed, switching frombzip2
to a built-in available Windows compression -zip
(scripts#1878) - libcrypt is now provided by the libxcrypt library instead of glibc. Glibc libcrypt was deprecated long time ago.
- Migrated the NVIDIA installer from the Azure/AWS OEM partition to
/usr
to make it available on all platforms (scripts#932, Flatcar#1077) - Migrate to Type=notify in containerd.service. Changed the unit to Type=notify, utilizing the existing containerd support for sd_notify call after socket setup.
- Moved a mountpoint of the OEM partition from
/usr/share/oem
to/oem
./usr/share/oem
became a symlink to/oem
for backward compatibility. Despite the move, the initrd images providing files through/usr/share/oem
should keep using/usr/share/oem
. The move was done to enable activating the OEM sysext images that are placed in the OEM partition.- NOTE that if you are already using btrfs-backed Docker storage and are upgrading to this new version, Docker will automatically use the
btrfs
storage driver for backwards-compatibility with your deployment. - NOTE The docker btrfs storage driver has been de-prioritised; BTRFS backed storage will now default to the
overlay2
driver
- NOTE that if you are already using btrfs-backed Docker storage and are upgrading to this new version, Docker will automatically use the
- OEM vendor tools are now A/B updated if they are shipped as systemd-sysext images, the migration happens when both partitions require a systemd-sysext OEM image - note that this will delete the
nvidia.service
from/etc
on Azure because it's now part of/usr
(Flatcar#60) - OpenStack, Brightbox: Added the
flatcar.autologin
kernel cmdline parameter by default as the hypervisor manages access to the console (scripts#1866) - Provided a Podman Flatcar extension as optional systemd-sysext image with the release. Write 'podman' to
/etc/flatcar/enabled-sysext.conf
through Ignition and the sysext will be installed during provisioning (scripts#1964) - Provided a Python Flatcar extension as optional systemd-sysext image with the release. Write 'python' to
/etc/flatcar/enabled-sysext.conf
through Ignition and the sysext will be installed during provisioning (scripts#1979) - OpenStack: Changed metadata hostname source order. The service first tries with the config drive then fallback on the metadata service. (bootengine#96)
- Provided a ZFS-2.2.2 Flatcar extension as optional systemd-sysext image with the release. Write 'zfs' to
/etc/flatcar/enabled-sysext.conf
through Ignition and the sysext will be installed during provisioning. ZFS support is experimental and ZFS is not supported for the root partition. (flatcar/scripts#1742)- Relevant changes: scripts#1216, update_engine#30, Mantle#466, Mantle#465.
- Removed
actool
from the image andacbuild
from the SDK as these tools are deprecated and not used (scripts#1817) - ⚠ Removed coreos-cloudinit support for automatic keys conversion (e.g
reboot-strategy
->reboot_strategy
) (scripts#1687) - Removed Linux drivers for Mellanox Technologies Switch ASICs family and Spectrum/Spectrum-2/Spectrum-3/Spectrum-4 Ethernet Switch ASICs to reduce the initrd size on AMD64 by ~5MB (flatcar/scripts#1734). This change is part of the effort to reduce the initrd size (flatcar#1381).
- Removed unused grub executable duplicate files and removed grub modules that are already assembled in the grub executable (scripts#1955).
- Replace nmap netcat with openbsd variant. The license didn't get an exception from CNCF. Something about the definition of "derivative works" being too broad.
- Reworked the VMware OEM software to be shipped as A/B updated systemd-sysext image
- Scaleway: images are now provided directly as
.qcow2
to ease the import on Scaleway (scripts#1953) - SDK: Experimental support for prefix builds to create distro independent, portable, self-contained applications w/ all dependencies included. With contributions from chewi and HappyTobi.
- Started shipping default ssh client and ssh daemon configs in
/etc/ssh/ssh_config
and/etc/ssh/sshd_config
which include config snippets in/etc/ssh/ssh_config.d
and/etc/ssh/sshd_config.d
, respectively. - Switched ptp_kvm from kernel builtin to module.
- The default VM memory was bumped to 2 GB in the Qemu script and for VMware OVFs
- The
docker build
command will now use buildx as its backend as the old one became deprecated and a loud "DEPRECATED" information is printed every time it's used. - The kernel security module Landlock is now enabled for programs to sandbox themselves (flatcar/scripts#2158)
- The open-vm-tools package in VMware OEM now comes with vmhgfs-fuse, udev rules, pam and vgauth
- Torcx entered deprecation 2 years ago in favour of deploying plain Docker binaries
- Torcx has been removed entirely; if you use torcx to extend the Flatcar base OS image, please refer to our conversion script and to the sysext documentation mentioned above for migrating.
- torcx was replaced by systemd-sysext in the OS image. Learn more about sysext and how to customise OS images here.
- Updated locksmith to use non-deprecated resource control options in the systemd unit (Locksmith#20)
- Update generation SLSA provenance info from v0.2 to v1.0.
Using the btrfs driver can still be enforced by creating a respective docker config at/etc/docker/daemon.json
. - ⚠️ Dropped support for niftycloud and interoute. For interoute we haven't been generating the images for some time already. (TODO) ⚠️
(which is now also a legacy option because systemd-sysext offers a more robust and better structured way of customisation, including OS independent updates).
Updates
- AWS: amazon-ssm-agent (3.2.985.0)
- Azure: WALinuxAgent (2.9.1.1)
- Go (1.21.13 (includes 1.20.14, 1.20.13, 1.20.12, 1.20.11, 1.20.10, 1.20.9, 1.20.8, 1.20.7, 1.20.6, 1.20.5, 1.20.4, 1.19.13, 1.19.12, 1.19.11, 1.19.10, 1.19.9, 1.19.8, 1.19.7, 1.19.6))
- Ignition (2.19.0 (includes 2.18.0, 2.17.0, 2.16.2, 2.16.1, 2.16.0))
- Linux (6.6.74 (includes 6.6.73, 6.6.72, 6.6.71, 6.6.70, 6.6.69, 6.6.68, 6.6.67, 6.6.66, 6.6.65, 6.6.64, 6.6.63, 6.6.62, 6.6.61, 6.6.60, 6.6.59, 6.6.58, 6.6.57, 6.6.56, 6.6.55, 6.6.54, 6.6.53, 6.6.52, 6.6.51, 6.6.50, 6.6.49, 6.6.48, 6.6.47, 6.6.46, 6.6.45, 6.6.44, 6.6.43, 6.6.42, 6.6.41, 6.6.40, 6.6.39, 6.6.38, 6.6.37, 6.6.36, 6.6.35, 6.6.34, 6.6.33, 6.6.32, 6.6.31, 6.6.30, 6.6.29, 6.6.28, 6.6.27, 6.6.26, 6.6.25, 6.6.24, 6.6.23, 6.6.22, 6.6.21, 6.6.20, 6.6.19, 6.6.18, 6.6.17, 6.6.16, 6.6.15, 6.6.14, 6.6.13, 6.6.12, 6.6.11, 6.6.10, 6.6.9, 6.6.8, 6.6.7, 6.6, 6.1.66, 6.1.65, 6.1.64, 6.1.63, 6.1.62, 6.1.61, 6.1.60, 6.1.59, 6.1.58, 6.1.57, 6.1.56, 6.1.55, 6.1.54, 6.1.53, 6.1.52, 6.1.51, 6.1.50, 6.1.49, 6.1.48, 6.1.47, 6.1.46, 6.1.45, 6.1.44, 6.1.43, 6.1.42, 6.1.41, 6.1.40, 6.1.39, 6.1.38, 6.1.37, 6.1.36, 6.1.35, 6.1.34, 6.1.33, 6.1.32, 6.1.31, 6.1.30, 6.1.29, 6.1.28, 6.1.27, 6.1, 5.15.108, 5.15.107, 5.15.106, 5.15.105, 5.15.104, 5.15.103, 5.15.102, 5.15.101, 5.15.100, 5.15.99))
- Linux Firmware (20240811 (includes 20240709, 20240610, 20240513, 20240410, 20240312, 20240220, 20240115, 20231211, 20231111, 20231030, 20230919, 20230804, 20230625, 20230515, 20230404, 20230310, 20230210))
- SDK: Rust (1.80.1 (includes 1.80.0, 1.79.0, 1.78.0, 1.77.2, 1.77.1, 1.77.0, 1.76.0, 1.75.0, 1.74.1, 1.73.0, 1.72.1, 1.72.0, 1.71.1, 1.71.0, 1.70.0, 1.68.2, 1.68.0, 1.67.1))
- SDK: cmake (3.25.2)
- SDK: dnsmasq (2.89)
- SDK: go (1.21.12 (includes 1.21))
- SDK: make (4.4.1 (includes 4.4))
- SDK: man-db (2.11.2)
- SDK: man-pages (6.03)
- SDK: meson (1.5.1)
- SDK: nano (7.2)
- SDK: nasm (2.16.01)
- SDK: pahole (1.27 (includes 1.25, 1.24))
- SDK: perf (6.3)
- SDK: perl (5.38.2 (includes 5.36.1))
- SDK: portage (3.0.65 (includes 3.0.63, 3.0.61, 3.0.59, 3.0.49, 3.0.46, 3.0.44))
- SDK: python (3.11.9 (includes 3.11.8, 3.11.7, 3.11.6, 3.11.5, 3.11.3, 3.10.12, 3.10.11, 3.10.10, 3.10.9, 3.10))
- SDK: python-packaging (23.2)
- SDK: python-platformdirs (3.11.0)
- SDK: qemu (8.2.3 (includes 8.0.4, 8.1.5, 8.0.3, 7.2.3))
- SDK: repo (2.37)
- VMware: libdnet (1.16.2 (includes 1.16))
- VMware: open-vm-tools (12.3.5 (includes 12.3.0, 12.2.5))
- acl (2.3.2)
- acpid (2.0.34)
- afterburn (5.6.0 (includes 5.5.1, 5.5.0))
- attr (2.5.2)
- audit (3.1.2 (includes 3.1.1))
- azure: azure-nvme-utils (0.2.0)
- bash (5.2_p21 (includes 5.2))
- bind-tools (9.16.48 (includes 9.16.42, 9.16.41, 9.16.37))
- binutils (2.42 (includes 2.41, 2.40))
- bpftool (6.9.2 (includes 6.8.2, 6.7.6, 6.5.7, 6.3, 6.2.1))
- btrfs-progs (6.9.2 (includes 6.0.2, 6.0))
- c-ares (1.29.0 (includes 1.28.1, 1.28.0, 1.27.0, 1.26.0, 1.25.0, 1.21.0, 1.19.1, 1.19.0))
- cJSON (1.7.18 (includes 1.7.17, 1.7.16))
- checkpolicy (3.6 (includes 3.5))
- cifs-utils (7.0)
- conntrack-tools (1.4.8)
- containerd (1.7.21 (includes 1.7.20, 1.7.19, 1.7.18, 1.7.17, 1.7.16, 1.7.15, 1.7.14, 1.7.13, 1.7.12, 1.7.11, 1.7.10, 1.7.9, 1.7.8, 1.7.7, 1.7.6, 1.7.5, 1.7.4, 1.7.3, 1.7.2, 1.6.21, 1.6.20, 1.6.19, 1.6.18))
- coreutils (9.5 (includes 9.4, 9.3, 9.1))
- cri-tools (1.27.0)
- cryptsetup (2.7.2 (includes 2.7.1, 2.7.0, 2.6.1, 2.6.0, 2.5.0))
- curl (8.9.1 (includes 8.9.0, 8.8.0, 8.7.1, 8.7.0, 8.6.0, 8.5.0, 8.4.0, 8.3.0, 8.2.1, 8.2.0, 8.1.2, 8.1.0, 8.0.1, 7.88.1, 7.88.0))
- debianutils (5.7)
- dev: iperf (3.15)
- dev: minicom (2.9)
- dev: smartmontools (7.4)
- diffutils (3.10 (includes 3.9))
- ding-libs (0.6.2)
- e2fsprogs (1.47.1 (includes 1.47.0, 1.46.6))
- efibootmgr (18)
- efivar (38)
- elfutils (0.191 (includes 0.190, 0.189))
- ethtool (6.9 (includes 6.7, 6.6, 6.5, 6.4, 6.3, 6.2))
- expat (2.6.3 (includes 2.6.2, 2.6.1, 2.6.0))
- file (5.45)
- findutils (4.10.0 (includes 4.9.0))
- gawk (5.3.0 (includes 5.2.2))
- gcc (13.3.1_p20240614 (includes 13.2, 12.2.1))
- gdb (13.2 (includes 13.1.90))
- gdbm (1.23)
- gentoolkit (0.6.3)
- gettext (0.22.4)
- gflags (2.2.2)
- git (2.44.2 (includes 2.44.1, 2.44.0, 2.43.2, 2.43.0, 2.42.0, 2.41.0, 2.39.3, 2.39.2))
- glib (2.78.6 (includes 2.78.5, 2.78.4, 2.78.3, 2.76.4, 2.76.3, 2.76.2, 2.74.6, 2.74.5))
- glibc (2.38 (includes 2.37))
- glog (0.6.0)
- gmp (6.3.0)
- gnuconfig (20230731)
- gnupg (2.4.5 (includes 2.4.4, 2.2.42))
- gnutls (3.8.5 (includes 3.8.4, 3.8.2, 3.8.0))
- gptfdisk (1.0.9)
- grep (3.11 (includes 3.8))
- groff (1.23.0)
- grub (2.06)
- gzip (1.13)
- hwdata (0.383 (includes 0.382, 0.376, 0.375, 0.374, 0.373, 0.372, 0.371, 0.367))
- ignition (2.15.0)
- inih (58 (includes 57, 56))
- intel-microcode (20240514_p20240514 (includes 20240312, 20231114_p20231114, 20230808, 20230613, 20230512, 20230214))
- iperf (3.16 (includes 3.14, 3.13))
- iproute2 (6.8.0 (includes 6.7.0, 6.6.0, 6.5.0, 6.4.0, 6.3.0, 6.2.0))
- ipset (7.22 (includes 7.21, 7.20, 7.19, 7.17))
- iputils (20240117 (includes 20231222, 20221126))
- ipvsadm (1.31 (includes 1.30, 1.29, 1.28))
- jq (1.7.1 (includes 1.7))
- json-c (0.17)
- kbd (2.6.4 (includes 2.6.1, 2.6.0, 2.5.1))
- kexec-tools (2.0.28 (includes 2.0.24))
- keyutils (1.6.3 (includes 1.6.2))
- kmod (32 (includes 31, 30))
- ldb (2.4.4 (includes 2.4.3, 2.4.2))
- less (643 (includes 633, 632, 608))
- libarchive (3.7.4 (includes 3.7.3, 3.7.2, 3.7.1, 3.7.0, 3.6.2))
- libassuan (2.5.7 (includes 2.5.6))
- libbsd (0.11.8 (includes 0.11.7))
- libcap (2.70 (includes 2.69))
- libcap-ng (0.8.5 (includes 0.8.4))
- libdnet (1.18.0 (includes 1.16.4))
- libffi (3.4.4 (includes 3.4.3, 3.4.2))
- libgcrypt (1.10.3 (includes 1.10.2, 1.10.1))
- libgpg-error (1.49 (includes 1.47, 1.46))
- libidn2 (2.3.7 (includes 2.3.4))
- libksba (1.6.7 (includes 1.6.6, 1.6.5, 1.6.4))
- liblinear (246)
- libmd (1.1.0)
- libmicrohttpd (1.0.1 (includes 1.0.0, 0.9.77, 0.9.76))
- libmnl (1.0.5)
- libnetfilter_conntrack (1.0.9)
- libnetfilter_cthelper (1.0.1)
- libnetfilter_cttimeout (1.0.1)
- libnfnetlink (1.0.2)
- libnftnl (1.2.6 (includes 1.2.5))
- libnl (3.9.0 (includes 3.8.0))
- libnsl (2.0.1)
- libnvme (1.9 (includes 1.8, 1.7.1, 1.7, 1.5))
- libpcap (1.10.4 (includes 1.10.3, 1.10.2))
- libpcre (8.45)
- libpcre2 (10.43 (includes 10.42))
- libpipeline (1.5.7)
- libpng (1.6.43 (includes 1.6.42, 1.6.41))
- libpsl (0.21.5)
- libseccomp (2.5.5)
- libselinux (3.6 (includes 3.5))
- libsemanage (3.6 (includes 3.5))
- libsepol (3.6 (includes 3.5))
- libsodium (1.0.19)
- libtirpc (1.3.4)
- libunistring (1.2 (includes 1.1))
- libunwind (1.8.1 (includes 1.8.0, 1.7.2, 1.7.0))
- liburing (2.3)
- libusb (1.0.27 (includes 1.0.26))
- libuv (1.48.0 (includes 1.47.0, 1.46.0, 1.45.0))
- libverto (0.3.2)
- libxml2 (2.12.7 (includes 2.12.6, 2.12.5, 2.12.4, 2.11.5, 2.11.4, 2.10.4))
- libxslt (1.1.39 (includes 1.1.38))
- linux-pam (1.5.3)
- lshw (02.20.2b)
- lsof (4.99.3 (includes 4.99.2, 4.99.1, 4.99.0, 4.98.0))
- lua (5.4.6 (includes 5.4.4))
- lz4 (1.10.0 (includes 1.9.4))
- mime-types (2.1.54)
- mit-krb5 (1.21.3 (includes 1.21.2))
- mpc (1.3.1 (includes 1.3.0))
- mpfr (4.2.1)
- multipath-tools (0.9.8 (includes 0.9.7, 0.9.5, 0.9.4))
- ncurses (6.4)
- nettle (3.9.1)
- nghttp2 (1.62.1 (includes 1.61.0, 1.60.0, 1.59.0, 1.58.0, 1.57.0, 1.56.0, 1.55.1, 1.55.0, 1.54.0, 1.53.0, 1.52.0))
- nmap (7.95 (includes 7.94))
- npth (1.7)
- nspr (4.35)
- ntp (4.2.8p17)
- nvidia-drivers (535.104.05)
- nvme-cli (2.9.1 (includes 2.9, 2.8, 2.7.1, 2.7, 2.6, 2.5, 2.3))
- open-iscsi (2.1.10)
- open-isns (0.102)
- openldap (2.6.4 (includes 2.6.3, 2.6, 2.5.14, 2.5))
- openssh (9.7_p1 (includes 9.6p1, 9.5p1, 9.4p1, 9.3, 9.2))
- openssl (3.2.3 (includes 3.2.1, 3.0.12, 3.0.9, 3.0.8))
- parted (3.6)
- pax-utils (1.3.7)
- pciutils (3.13.0 (includes 3.12.0, 3.10.0, 3.9.0))
- pigz (2.8)
- pinentry (1.2.1)
- policycoreutils (3.6 (includes 3.5))
- popt (1.19)
- procps (4.0.4 (includes 4.0.3, 4.0.0))
- protobuf (21.12 (includes 21.11, 21.10, 21.9))
- psmisc (23.6)
- qemu-guest-agent (8.2.0 (includes 8.0.3, 8.0.0, 7.1.0))
- quota (4.09)
- readline (8.2_p7 (includes 8.2))
- rpcsvc-proto (1.4.4)
- rsync (3.3.0)
- runc (1.1.13 (includes 1.1.12, 1.1.9, 1.1.8, 1.1.7, 1.1.5))
- samba (4.18.9 (includes 4.18.8, 4.18.4))
- sed (4.9 (includes 4.9))
- selinux-base (2.20231002 (includes 2.20221101))
- selinux-base-policy (2.20231002 (includes 2.20221101))
- selinux-container (2.20231002 (includes 2.20221101))
- selinux-dbus (2.20231002)
- selinux-refpolicy (2.20240226)
- selinux-sssd (2.20231002 (includes 2.20221101))
- selinux-unconfined (2.20231002 (includes 2.20221101))
- semodule-utils (3.6 (includes 3.5))
- shim (15.8)
- smartmontools (7.3)
- socat (1.7.4.4)
- sqlite (3.46.0 (includes 3.45.3, 3.45.1, 3.44.2, 3.43.2, 3.42.0, 3.41.2))
- squashfs-tools (4.6.1 (includes 4.6))
- strace (6.9 (includes 6.6, 6.4, 6.3, 6.2, 6.1))
- sudo (1.9.15p5 (includes 1.9.13p3))
- sysext-docker: docker (26.1.0 (includes 25.0, 24.0.9, 24.0.6, 23.0, 20.10.24))
- sysext-podman: aardvark-dns (1.11.0)
- sysext-podman: containers-common (0.59.1)
- sysext-podman: podman (5.0.3)
- sysext-python: jaraco-text (3.12.1)
- sysext-python: more-itertools (10.4.0)
- sysext-python: pip (24.2 (includes 24.1.2))
- sysext-python: setuptools (72.1.0 (includes 71.1.0, 71.0.0, 70.3.0, 70.1.1, 70.1.0, 70.0.0, 69.5.1, 69.5.0, 69.4.2, 69.4.1, 69.4.0, 69.3.1, 69.3.0, 69.2.0))
- sysext-python: trove-classifiers (2024.7.2)
- sysext-python: wheel (0.44.0)
- sysext-zfs: zfs (2.2.5 (includes 2.2.4))
- systemd (255.8 (includes 255.4, 255.3))
- talloc (2.4.1 (includes 2.4.0, 2.3.4))
- tar (1.35)
- tcpdump (4.99.4)
- tdb (1.4.9 (includes 1.4.8, 1.4.7, 1.4.6))
- tevent (0.15.0 (includes 0.14.1, 0.14.0, 0.13.0, 0.12.1))
- thin-provisioning-tools (1.0.10 (includes 1.0.6))
- tpm2-tools (5.7 (includes 5.6.1, 5.6))
- tpm2-tss (4.1.3 (includes 4.0.2))
- traceroute (2.1.5 (includes 2.1.4, 2.1.3, 2.1.1))
- usbutils (017 (includes 016, 015))
- userspace-rcu (0.14.0)
- util-linux (2.39.4 (includes 2.39.3, 2.39.2, 2.38.1))
- vim (9.1.0366 (includes 9.1, 9.0.2167, 9.0.2092, 9.0.1678, 9.0.1677, 9.0.1503, 9.0.1403, 9.0.1363))
- VMWare: open-vm-tools (12.4.5 (includes 12.4.0, 12.2.0))
- wget (1.24.5 (includes 1.21.4))
- whois (5.5.21 (includes 5.5.20, 5.5.18, 5.5.17))
- xfsprogs (6.8.0 (includes 6.6.0, 6.4.0, 6.3.0))
- xmlsec (1.3.3 (includes 1.3.2))
- xz-utils (5.6.2 (includes 5.4.6, 5.4.5, 5.4.3, 5.4.2))
- zfs (2.2.3)
- zlib (1.3.1 (includes 1.3))
- zstd (1.5.6 (includes 1.5.5, 1.5.4, 1.5.2, 1.5.1, 1.5.0))
Changes since Stable 4081.2.1
Security fixes:
- Linux (CVE-2024-57876, CVE-2024-57874, CVE-2025-23128, CVE-2025-23125, CVE-2024-57850, CVE-2024-57849, CVE-2024-57843, CVE-2024-48875, CVE-2024-48873, CVE-2024-47809, CVE-2024-47143, CVE-2024-47141, CVE-2024-45828, CVE-2024-43098, CVE-2024-53680, CVE-2024-52332, CVE-2024-50051, CVE-2024-48881, CVE-2024-41935, CVE-2024-56787, CVE-2024-56786, CVE-2024-56785, CVE-2024-56783, CVE-2024-56781, CVE-2024-56640, CVE-2024-56638, CVE-2024-56637, CVE-2024-56636, CVE-2024-56635, CVE-2024-56634, CVE-2024-56651, CVE-2024-56633, CVE-2024-56650, CVE-2024-56649, CVE-2024-56648, CVE-2024-56645, CVE-2024-56644, CVE-2024-56643, CVE-2024-56642, CVE-2024-56641, CVE-2024-56631, CVE-2024-56615, CVE-2024-56623, CVE-2024-56622, CVE-2024-56619, CVE-2024-56617, CVE-2024-56630, CVE-2024-56629, CVE-2024-56628, CVE-2024-56627, CVE-2024-56626, CVE-2024-56625, CVE-2024-56616, CVE-2024-56592, CVE-2024-56590, CVE-2024-56589, CVE-2024-56587, CVE-2024-56614, CVE-2024-56613, CVE-2024-56586, CVE-2024-56611, CVE-2024-56610, CVE-2024-56606, CVE-2024-56605, CVE-2024-56604, CVE-2024-56603, CVE-2024-56585, CVE-2024-56602, CVE-2024-56601, CVE-2024-56600, CVE-2024-56598, CVE-2024-56597, CVE-2024-56596, CVE-2024-56595, CVE-2024-56594, CVE-2024-56593, CVE-2024-56583, CVE-2024-56584, CVE-2024-56565, CVE-2024-56568, CVE-2024-53196, CVE-2024-55639, CVE-2024-54683, CVE-2024-53687, CVE-2024-56770, CVE-2024-56661, CVE-2024-56660, CVE-2024-56659, CVE-2024-56658, CVE-2024-56657, CVE-2024-56655, CVE-2024-56675, CVE-2024-56672, CVE-2024-56654, CVE-2024-56670, CVE-2024-56667, CVE-2024-56665, CVE-2024-56664, CVE-2024-56663, CVE-2024-56662, CVE-2024-56653, CVE-2024-53241, CVE-2024-53240, CVE-2024-53690, CVE-2024-49571, CVE-2024-49568, CVE-2024-47408, CVE-2024-57791, CVE-2024-56372, CVE-2024-56369, CVE-2024-55916, CVE-2024-55881, CVE-2024-54680, CVE-2024-46896, CVE-2024-56719, CVE-2024-56718, CVE-2024-56717, CVE-2024-56716, CVE-2024-56715, CVE-2024-56709, CVE-2024-53164, CVE-2024-57946, CVE-2024-57807, CVE-2024-57798, CVE-2024-57792, CVE-2024-56766, CVE-2024-56765, CVE-2024-56763, CVE-2024-56762, CVE-2024-56760, CVE-2024-56769, CVE-2024-56767, CVE-2023-52881, CVE-2023-52654, CVE-2024-57938, CVE-2024-57933, CVE-2024-57932, CVE-2024-57930, CVE-2024-57931, CVE-2024-57841, CVE-2024-57802, CVE-2024-57801, CVE-2024-54031, CVE-2024-39282, CVE-2024-36476, CVE-2024-57896, CVE-2025-21629, CVE-2024-57903, CVE-2024-57902, CVE-2024-57901, CVE-2024-57900, CVE-2024-57899, CVE-2024-57897, CVE-2024-57890, CVE-2024-57889, CVE-2024-57887, CVE-2024-57885, CVE-2024-57884, CVE-2024-57895, CVE-2024-57894, CVE-2024-57893, CVE-2024-57892, CVE-2024-57882, CVE-2024-53685, CVE-2025-21658, CVE-2025-21656, CVE-2024-57945, CVE-2025-21664, CVE-2025-21663, CVE-2025-21662, CVE-2025-21660, CVE-2024-57939, CVE-2024-57940, CVE-2025-21655, CVE-2024-57913, CVE-2024-57912, CVE-2024-57911, CVE-2024-57910, CVE-2024-57908, CVE-2024-57907, CVE-2024-57929, CVE-2024-57926, CVE-2024-57925, CVE-2024-57906, CVE-2024-57922, CVE-2024-57917, CVE-2024-57916, CVE-2024-57915, CVE-2024-57904, CVE-2025-21654, CVE-2025-21653, CVE-2025-21652, CVE-2025-21640, CVE-2025-21639, CVE-2025-21638, CVE-2025-21637, CVE-2025-21636, CVE-2025-21648, CVE-2025-21647, CVE-2025-21646, CVE-2025-21645, CVE-2025-21642, CVE-2025-21631, CVE-2025-21632)