Fedora 37 has been postponed by two weeks due to a critical vulnerability in OpenSSL

The Fedora project developers have announced the postponement of the Fedora 37 release to November 15 due to the need to fix a critical vulnerability in the OpenSSL library. Since the details of the vulnerability will only be disclosed on November 1, it is unclear how long it will take to implement the fix in the distribution, prompting the decision to delay the release by two weeks. This is not the first delay—initially, the Fedora 37 release was expected on October 18 but has been postponed twice (to October 25 and November 1) due to unmet quality criteria.

Currently, there are 3 issues in the final test builds that remain unaddressed, which are classified as blocking for the release. In addition to the need to fix the vulnerability in OpenSSL, issues include a hang of the KWin compositor when starting a KDE Plasma session on Wayland with the nomodeset (basic graphics) mode set in UEFI, and a hang of the gnome-calendar application when editing recurring events.

The critical vulnerability in OpenSSL only affects the 3.0.x branch; releases 1.1.1x are not vulnerable. The OpenSSL 3.0 branch is already in use in distributions such as Ubuntu 22.04, CentOS Stream 9, RHEL 9, OpenMandriva 4.2, Gentoo, Fedora 36, and Debian Testing/Unstable. In SUSE Linux Enterprise 15 SP4 and openSUSE Leap 15.4, packages with OpenSSL 3.0 are available optionally, while the system packages use the 1.1.1 branch. The 1.x branches of OpenSSL remain in Debian 11, Arch Linux, Void Linux, Ubuntu 20.04, Slackware, ALT Linux, RHEL 8, OpenWrt, and Alpine Linux 3.16.

The vulnerability is categorized as critical, with details yet to be disclosed, but it is considered as dangerous as the notorious Heartbleed vulnerability. The critical severity level suggests the potential for remote attacks on typical configurations. Critical issues may include problems leading to remote memory content leaks, serverexecution of the attacker's code, or compromise of server private keys. The fix, OpenSSL 3.0.7, addressing the issue and information about the nature of the vulnerability will be published on November 1.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster