Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 38: 2024-f2305d485f Critical Update for Firecracker Rust-vmm

fedora
Calendar Grey February 14, 2024
Dist Fedora Esm H88
This release of Fedora 38 resolves critical vulnerabilities in firecracker through improvements in rust-vmm modules, ensuring essential security patches.
Update rust-vmm components and their consumers to address CVE-2023-50711

Summary

Firecracker is an open source virtualization technology that is purpose-built

for creating and managing secure, multi-tenant container and function-based

services that provide serverless operational models. Firecracker runs

workloads in lightweight virtual machines, called microVMs, which combine the

security and isolation properties provided by hardware virtualization

technology with the speed and flexibility of containers.

This package does not include all of the security features of an official

release. It is not production ready without additional sandboxing.

Update Information:

Update rust-vmm components and their consumers to address CVE-2023-50711

Change Log

* Sun Jan 28 2024 David Michael - 1.6.0-6 - Sync linux-loader with the upstream version fixing the vmm-sys-util CVE. * Wed Jan 24 2024 Fedora Release Engineering - 1.6.0-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 David Michael - 1.6.0-4 - Backport the userfaultfd update for its unrecognized ioctl fixes. * Fri Jan 19 2024 Fedora Release Engineering - 1.6.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Thu Jan 11 2024 David Michael - 1.6.0-2 - Backport changes to update vmm-sys-util for CVE-2023-50711.

References

Fedora Update Notification FEDORA-2024-f2305d485f 2024-02-14 01:11:43.154092 Name : firecracker Product : Fedora 38 Version : 1.6.0 Release : 6.fc38 URL : https://firecracker-microvm.github.io/ Summary : Secure and fast microVMs for serverless computing Description : Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant container and function-based services that provide serverless operational models. Firecracker runs workloads in lightweight virtual machines, called microVMs, which combine the security and isolation properties provided by hardware virtualization technology with the speed and flexibility of containers. This package does not include all of the security features of an official release. It is not production ready without additional sandboxing.

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-f2305d485f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: firecracker
Product: Fedora 38
Version: 1.6.0
Release: 6.fc38
Summary: Secure and fast microVMs for serverless computing

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here