Security issue CVE-2024-2905: World-readable /etc/shadow & /etc/gshadow on Fedora CoreOS, IoT, Atomic Desktops (including Silverblue & Kinoite)
(discussion.fedoraproject.org)
from joojmachine@lemmy.ml to linux@lemmy.ml on 10 Apr 2024 17:03
https://lemmy.ml/post/14295584
from joojmachine@lemmy.ml to linux@lemmy.ml on 10 Apr 2024 17:03
https://lemmy.ml/post/14295584
Just a heads-up for the newer Fedora Atomic users out there, and a focus on this part for the longer-term users:
This only impacts new installations and not updated systems thus systems installed from artifacts before those releases are not impacted (Fedora 38 or earlier).
threaded - newest
Isn’t selinux enabled by default? Hence, most won’t be affected.
I’m not sure you’re right, I can’t find information regarding whether users are confined by default on Fedora (Red Hat docs seem to indicate the users are unconfined by default).
Edit: They are not, see docs.fedoraproject.org/…/selinux-getting-started/…, specifically:
ls -Z in any user home will show they are unconfined_u (so will id -Z).