Comments

50 Comments
BZ#2271585 CVE-2024-2905 rpm-ostree: world-readable /etc/shadow file
BZ#2274140 CVE-2024-2905 rpm-ostree: world-readable /etc/shadow file [fedora-all]
BZ#2271585 CVE-2024-2905 rpm-ostree: world-readable /etc/shadow file
BZ#2274140 CVE-2024-2905 rpm-ostree: world-readable /etc/shadow file [fedora-all]

Whoops, sorry, good catch

karma

Looks like this does not impact F39, so this update should be fine: https://github.com/coreos/rpm-ostree/issues/4765

karma

This is likely the source of https://bugzilla.redhat.com/show_bug.cgi?id=2252000

Downvoting until we figure it out.

karma

This pulls in dnf on Silverblue (https://github.com/fedora-silverblue/issue-tracker/issues/521) so we should fix that first.

karma

Downvoting to prevent an automatic push to stable until we investigate the issue listed above.