The latest beta edition of Ubuntu and other Linux distributions is delayed due to security issues with xz-utils

The beta version of Ubuntu 24. 04 will be released on time, the developers confirmed, following considerations about a major security threat.

Instead of being released on April 4, the most recent edition of Ubuntu, which is also codenamed Noble Numbat, will now be released on April 11 after Canonical developers delayed the release by a week due to the discovery of CVE-2024-3094. A critical vulnerability recently discovered in XZ-Utils.

XZ-utils is a set of data compression libraries and equipment used in primary Linux distributions. The vulnerability was introduced in XZ Edition 5. 6. 0 via a pseudonymous attacker and also persisted in Edition 5. 6. 1.

Most Linux distributions seem to be affected by the flaw. Ubuntu 24. 04 (but earlier versions), Red Hat, Fedora Rawhide, and Fedora 40, as well as some versions of Kali Linux and some Arch Linux installation media, are affected.

Red Hat Enterprise Linux (RHEL), solid versions of Debian, as well as Linux Mint, Gentoo Linux, Alpine Linux and Amazon Linux are affected, he said.

In the Discourse post, Canonical stated that it would “delete and rebuild all binary packages that had been created for Noble Numbat after the CVE-2024-3094 code was committed to xz-utils (Feb. 26), in newly provisioned build environments. “the most recent Ubuntu edition of the vulnerability that earned a severity score of 10. 0.

Tom’s Hardware speculates that the release of the latest 24. 04 edition, scheduled for April 25, could also be delayed. A Mastodon poll, conducted through a former Canonical employee, showed that out of 100 respondents, a narrow majority (56% vs. 44%) expect the issue to be published on time.

Earlier this week, Binarly launched a flexible scanner to make vulnerabilities faster, more transparent, and with fewer false positives.

Sead is a veteran freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, knowledge breaches, legislation, and regulations). Over the course of his career, which spans more than a decade, he has written for media outlets, including Al Jazeera Balkans. He has also facilitated several modules on content writing for Represent Communications.

No, the government doesn’t fine you for a traffic violation – it’s malware.

Germany to make encryption a legal right

Asus ROG Flow X13 review: Your 13-inch gaming friend

TechRadar is from Future US Inc. , a leading foreign media organization and virtual publisher. Visit our corporate website.

Leave a Comment

Your email address will not be published. Required fields are marked *