I-Fedora 37 ilibazisekile iiveki ezimbini ngenxa yokuba sesichengeni esibalulekileyo kwi-OpenSSL

Abaphuhlisi beprojekthi yeFedora babhengeze ukuhlehliswa kokukhululwa kwe-Fedora 37 ukuya kwi-15 kaNovemba ngenxa yesidingo sokuphelisa ubuthathaka obubalulekileyo kwithala leencwadi le-OpenSSL. Ekubeni idatha malunga neyona nto inobungozi iya kubhengezwa kuphela ngoNovemba 1 kwaye akucaci ukuba kuya kuthatha ixesha elingakanani ukuphumeza ukukhuselwa ekusasazeni, kwagqitywa ukuba kuhlehliswe ukukhululwa kwiiveki ezi-2. Eli akulona ixesha lokuqala lokukhululwa kwe-Fedora 37 kulindeleke ngo-Oktobha 18, kodwa yahlehliswa kabini (ngo-Oktobha 25 kunye noNovemba 1) ngenxa yokungaphumeleli ukuhlangabezana nemilinganiselo yomgangatho.

Okwangoku, imiba ye-3 ihlala ingalungiswanga kuvavanyo lokugqibela olwakhayo kwaye ihlelwa njengokuthintela ukukhutshwa. Ukongeza kwisidingo sokulungisa ubuthathaka kwi openssl, umphathi wekwin ujinga xa eqala iseshoni ye Plasma yaseWayland-based xa indlela imiselwe kwi nomodeset (imizobo esisiseko) kwi UEFI, kwaye isicelo sekhalenda ye-gnome siyaba ngumkhenkce xa uhlela uphinda-phinda. iziganeko.

Ubuthathaka obubalulekileyo kwi-OpenSSL buchaphazela kuphela isebe le-3.0.x; Ukukhutshwa kwe-1.1.1x akuchaphazeleki. Isebe le-OpenSSL 3.0 sele lisetyenziswe kunikezelo olunje Ubuntu 22.04, CentOS Stream 9, RHEL 9, OpenMandriva 4.2, Gentoo, Fedora 36, ​​​​Debian Testing / Unstable. Kwi-SUSE Linux Enterprise 15 SP4 kunye ne-openSUSE Leap 15.4, iipakethe ezine-OpenSSL 3.0 ziyafumaneka ngokuzikhethela, iipakethe zesixokelelwano zisebenzisa i-1.1.1 yesebe. Debian 1, Arch Linux, Void Linux, Ubuntu 11, Slackware, ALT Linux, RHEL 20.04, OpenWrt, Alpine Linux 8 zihlala kumasebe e-OpenSSL 3.16.x.

Ubuthathaka buhlelwa njengobubalulekileyo; iinkcukacha azikanikezelwa, kodwa ngokobungqongqo ingxaki isondele kubuthathaka obuvakalayo beHeartbleed. Inqanaba elibalulekileyo lengozi lithetha ukuba nokwenzeka kohlaselo olukude kuqwalaselo oluqhelekileyo. Iingxaki ezikhokelela ekuvuzeni okude kwimixholo yememori yeseva, ukuphunyezwa kwekhowudi yomhlaseli, okanye ukuthotywa kwezitshixo zabucala zeseva kunokuchazwa njengento ebalulekileyo. Ipetshi ye-OpenSSL 3.0.7 elungisa ingxaki kunye nolwazi malunga nobume bobuthathaka iya kupapashwa nge-1 kaNovemba.

umthombo: opennet.ru

Yongeza izimvo