#Linux admins there is a #CentOS_Stream 9 kernel flaw that lets local attackers escalate to root privileges.There is no patch yet but #RedHat is advising administrators to disable the CAKE Qdisc module as a workaround. The SSD advisory explicitly scope this UAF/LPE to CentOS 9, not “all Linux kernels” or even all sch_cake users. I suspect a lot of us have moved away from CentOS in recent years but if you are using it take appropriate steps.

https://cybersecuritynews.com/centos-9-vulnerability/

New CentOS 9 Vulnerability Lets Attackers Escalate to Root Privileges - PoC Released

A critical use-after-free (UAF) vulnerability in the Linux kernel's sch_cake queuing discipline (Qdisc) affects CentOS 9, allowing local users to gain root privileges.

Cyber Security News

#PSA for #CentOS #CentOS_Stream users - if you need fixed #OpenSSL builds immediately you can use the #CentOS_ProposedUpdates builds (not available for i686 due to Community Build Service limitations)

`sudo dnf install centos-release-proposed_updates && sudo dnf update 'openssl*'`

https://openssl-library.org/news/vulnerabilities/#2026

These are based on the MRs in progress for the official @centos Stream package and will be cleanly upgradable to the final build

#security

https://openssl-library.org/news/vulnerabilities/#2026

Vulnerabilities | OpenSSL Library

@jonathanspw for #CentOS_Stream #HyperscaleSIG users, freetype-2.10.4-10.3.hs.el9 is out with the same PR

The #ProposedUpdates SIG will also carry the fix intended for Stream 9 once we are set up next week

Thank you @Conan_Kudo for the declarative #Linux #distribution compose tool, #Kurchu, that we are now using for #CentOSHyperscale images

@centos #CentOS_Stream #CentOSConnect #FLOSSConf #FLOSSConference #FOSDEMFringe

To the person asking for the #Evolution #email client for #CentOS_Stream 10 - I just checked with #ebranch and there are only 9 packages needed, so I'll try and get it into either @fedora #EPEL or if there are conflicting dependencies, into the @gnome repo we're currently incubating in the #HyperscaleSIG

#Fedora
@fosdem #FOSDEM2025 #FOSDEMFringe
#Linux

Neue Linux-Distribution CentOS Stream erlaubt Einflussnahme auf RHEL-Entwicklung

Das neue CentOS Stream soll als Rolling-Release-Distribution Neuerungen in RHEL/CentOS Community und Entwicklern künftig früher zugänglich machen.