rpm-ostree is a hybrid image/package system. It supports
"composing" packages on a build server into an OSTree repository,
which can then be replicated by client systems with atomic upgrades.
Additionally, unlike many "pure" image systems, with rpm-ostree
each client system can layer on additional packages, providing
a "best of both worlds" approach.
Update Information:
Release 2025.8
* Wed May 7 2025 Joseph Marrero Corchado
[ 1 ] Bug #2357941 - CVE-2025-3416 rpm-ostree: rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch` [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2357941
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f566d6a4ad' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.