Lucene search

K
fedoraFedoraFEDORA:0981A2044BBC
HistoryApr 10, 2024 - 4:06 a.m.

[SECURITY] Fedora 39 Update: rpm-ostree-2024.4-6.fc39

2024-04-1004:06:21
lists.fedoraproject.org
10
fedora 39
rpm-ostree
hybrid system
atomic upgrades
package layering

6.2 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.3 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.5%

rpm-ostree is a hybrid image/package system. It supports “composing” packages on a build server into an OSTree repository, which can then be replicated by client systems with atomic upgrades. Additionally, unlike many “pure” image systems, with rpm-ostree each client system can layer on additional packages, providing a “best of both worlds” approach.

OSVersionArchitecturePackageVersionFilename
Fedora39anyrpm-ostree< 2024.4UNKNOWN

6.2 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.3 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.5%