Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 39 Firecracker ADVISORY: FEDORA-2024-04877592b7 Critical Update

fedora
Calendar Grey February 10, 2024
Dist Fedora Esm H88
A critical vulnerability CVE-2023-50711 in Firecracker components affects Fedora 39. All users must update systems to reduce risks of unauthorized access
Update rust-vmm components and their consumers to address CVE-2023-50711

Summary

Firecracker is an open source virtualization technology that is purpose-built

for creating and managing secure, multi-tenant container and function-based

services that provide serverless operational models. Firecracker runs

workloads in lightweight virtual machines, called microVMs, which combine the

security and isolation properties provided by hardware virtualization

technology with the speed and flexibility of containers.

This package does not include all of the security features of an official

release. It is not production ready without additional sandboxing.

Update Information:

Update rust-vmm components and their consumers to address CVE-2023-50711

Change Log

* Sun Jan 28 2024 David Michael - 1.6.0-6 - Sync linux-loader with the upstream version fixing the vmm-sys-util CVE. * Wed Jan 24 2024 Fedora Release Engineering - 1.6.0-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 David Michael - 1.6.0-4 - Backport the userfaultfd update for its unrecognized ioctl fixes. * Fri Jan 19 2024 Fedora Release Engineering - 1.6.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Thu Jan 11 2024 David Michael - 1.6.0-2 - Backport changes to update vmm-sys-util for CVE-2023-50711.

References

Fedora Update Notification FEDORA-2024-04877592b7 2024-02-10 01:24:59.648730 Name : firecracker Product : Fedora 39 Version : 1.6.0 Release : 6.fc39 URL : https://firecracker-microvm.github.io/ Summary : Secure and fast microVMs for serverless computing Description : Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant container and function-based services that provide serverless operational models. Firecracker runs workloads in lightweight virtual machines, called microVMs, which combine the security and isolation properties provided by hardware virtualization technology with the speed and flexibility of containers. This package does not include all of the security features of an official release. It is not production ready without additional sandboxing.

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-04877592b7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: firecracker
Product: Fedora 39
Version: 1.6.0
Release: 6.fc39
Summary: Secure and fast microVMs for serverless computing

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here