The developers of the Rocky Linux distribution announced the creation of a separate repository for the unscheduled release of urgent package updates to address vulnerabilities, which is not synchronized with the repositories of Red Hat Enterprise Linux. It is noted that the Rocky Linux project adheres to the principle of being as close as possible to the package base of RHEL, while the emerging security threats necessitate an exception.
The 'security' repository will publish only emergency updates that are compiled when critical vulnerability information is disclosed without prior notice and a working exploit is available, but RHEL developers have not yet been able to compile fixes. Such situations have been observed with vulnerabilities like Copy Fail, Dirty Frag, and Fragnesia.
Thanks to the 'security' repository, the Rocky Linux project will be able to independently and promptly publish updates, without waiting for Red Hat to do so. After a fix is released by RHEL, the package published for RHEL will replace the one from Rocky Linux. By default, the 'security' repository is disabled and requires the command 'sudo dnf --enablerepo=security update' to be activated.
Meanwhile, the Alma Linux distribution has released package updates for the prompt resolution of vulnerabilities such as ssh-keysign-pwn, NGINX Rift, Fragnesia, Dirty Frag, and Copy Fail without waiting for RHEL. Initially, the packages were placed in the 'almalinux-testing' test repository and then moved to the main one.
Source: opennet.ru
