Fedora Project :fedora: on Nostr: "Due to a bug in rpm-ostree, the '/etc/[g]shadow[-]' files in Fedora CoreOS, Fedora ...
"Due to a bug in rpm-ostree, the '/etc/[g]shadow[-]' files in Fedora CoreOS, Fedora IoT and Fedora Atomic Desktops have the world-readable bit set.
To fix impacted systems immediately, run the following command as root:
$ chmod --verbose 0000 /etc/shadow /etc/gshadow /etc/shadow- /etc/gshadow-
For more details, notably the full list of affected versions, see: https://github.com/coreos/rpm-ostree/security/advisories/GHSA-2m76-cwhg-7wv6 "
- [@siosm](https://floss.social/@siosm), Fedora maintainer
#Fedora #FedoraAtomic #FedoraCoreOS #CoreOS #Silverblue #Kinoite
To fix impacted systems immediately, run the following command as root:
$ chmod --verbose 0000 /etc/shadow /etc/gshadow /etc/shadow- /etc/gshadow-
For more details, notably the full list of affected versions, see: https://github.com/coreos/rpm-ostree/security/advisories/GHSA-2m76-cwhg-7wv6 "
- [@siosm](https://floss.social/@siosm), Fedora maintainer
#Fedora #FedoraAtomic #FedoraCoreOS #CoreOS #Silverblue #Kinoite