RATATOSKRATATOSK
로그인

Flatcar Container Linux

stable-4757.2.0Provisioning & Runtime
2026년 9월 14일

ACTION 41OTHER 56

보안 취약점 수정과 시스템 및 선택 구성 요소의 의존성 갱신이 중심인 유지보수 릴리스입니다. 일부 플랫폼과 이미지 지원이 바뀌었고 업그레이드 시 새 요구 사항이 적용되지만, 주요 설정 동작의 변화는 설명되어 있지 않습니다.

조치 필요 (41)

  • securitycriticalcontainerd 보안 취약점 수정

    containerdCVE-2026-47262을 비롯한 보안 취약점을 수정했습니다.

  • securitycriticalgo 보안 취약점 수정

    goCVE-2025-61726을 비롯한 보안 취약점을 수정했습니다.

  • securityhighbind 보안 취약점 수정

    bindCVE-2025-40778을 비롯한 보안 취약점을 수정했습니다.

  • securityhighglib 보안 취약점 수정

    glibCVE-2025-13601을 비롯한 보안 취약점을 수정했습니다.

  • securityhighglibc 보안 취약점 수정

    glibcCVE-2026-0861을 비롯한 보안 취약점을 수정했습니다.

  • securityhighgnutls 보안 취약점 수정

    gnutlsCVE-2025-14831을 비롯한 보안 취약점을 수정했습니다.

  • securityhighincus 보안 취약점 수정

    incusCVE-2026-23953을 수정했습니다.

  • securityhighlibtasn1 보안 취약점 수정

    libtasn1CVE-2025-13151을 수정했습니다.

  • securityhighnvidia-drivers 보안 취약점 수정

    nvidia-driversCVE-2025-33219를 비롯한 보안 취약점을 수정했습니다.

  • securityhighpodman 보안 취약점 수정

    podmanCVE-2025-9566을 비롯한 보안 취약점을 수정했습니다.

  • securityhighsssd 보안 취약점 수정

    sssdCVE-2025-11561을 비롯한 보안 취약점을 수정했습니다.

  • securityhighurllib3 보안 취약점 수정

    urllib3CVE-2025-66418을 비롯한 보안 취약점을 수정했습니다.

  • securityhighopenssh 보안 취약점 추가 수정

    opensshCVE-2026-59995를 비롯한 보안 취약점을 수정했습니다.

  • securitymediumc-ares 보안 취약점 수정

    c-aresCVE-2025-62408을 수정했습니다.

  • securityhighcurl 보안 취약점 수정

    curlCVE-2025-13034을 비롯한 보안 취약점을 수정했습니다.

  • securitymediumlibarchive 보안 취약점 수정

    libarchiveCVE-2025-60753을 비롯한 보안 취약점을 수정했습니다.

  • securitymediumlibxml2 보안 취약점 수정

    libxml2CVE-2026-0989을 비롯한 보안 취약점을 수정했습니다.

  • securitymediumlibxslt 보안 취약점 수정

    libxsltCVE-2025-10911을 비롯한 보안 취약점을 수정했습니다.

  • securitymediump11-kit 보안 취약점 수정

    p11-kitCVE-2026-2100을 수정했습니다.

  • securityhighrsync 보안 취약점 수정

    rsyncCVE-2025-10158을 비롯한 보안 취약점을 수정했습니다.

  • securitymediumutil-linux 보안 취약점 수정

    util-linuxCVE-2025-14104를 비롯한 보안 취약점을 수정했습니다.

  • securitylowintel-microcode 보안 취약점 수정

    intel-microcodeCVE-2025-31648을 수정했습니다.

  • securitylowlibpcap 보안 취약점 수정

    libpcapCVE-2025-11961을 비롯한 보안 취약점을 수정했습니다.

  • securitycriticalLinux 보안 취약점 수정

    Linux에서 보고된 보안 취약점을 수정했습니다. CVE-2026-68169을 비롯한 여러 권고 사항이 반영되었습니다.

  • securityhighbubblewrap 보안 취약점 수정

    bubblewrapCVE-2026-41163을 수정했습니다.

  • securitymediumexpat 보안 취약점 수정

    expatCVE-2026-24515을 비롯한 보안 취약점을 수정했습니다.

  • securityhighgnupg 보안 취약점 수정

    gnupgCVE-2026-24881을 비롯한 보안 취약점을 수정했습니다.

  • securitymediumlibcap 보안 취약점 수정

    libcapCVE-2026-4878을 수정했습니다.

  • securitymediumlibgcrypt 보안 취약점 수정

    libgcryptCVE-2026-41989을 수정했습니다.

  • securityhighopenssh 보안 취약점 수정

    opensshCVE-2026-35385를 비롯한 보안 취약점을 수정했습니다.

  • securitycriticalopenssl 보안 취약점 수정

    opensslCVE-2026-2673을 비롯한 보안 취약점을 수정했습니다.

  • securitylowrunc 보안 취약점 수정

    runcCVE-2026-41579을 수정했습니다.

  • securitymediumsystemd 보안 취약점 수정

    systemdCVE-2026-40223을 비롯한 보안 취약점을 수정했습니다.

  • securitylowxz-utils 보안 취약점 수정

    xz-utilsCVE-2026-34743을 수정했습니다.

  • securitylowzlib 보안 취약점 수정

    zlibCVE-2026-27171을 수정했습니다.

  • breakingEquinix Metal (Packet) 지원 중단

    Equinix Metal (Packet) 지원을 중단했습니다.

  • breakingRackspaceOnMetal 지원 중단

    RackspaceOnMetal을 포함한 지원을 중단했습니다.

  • breakingOklo 릴리스 코드 이름 폐기

    Oklo 릴리스 코드 이름을 폐기했습니다.

  • breakingVMware insecure 이미지 폐기

    VMware insecure 이미지를 폐기했습니다.

  • breakingVagrant VirtualBox 이미지 폐기

    Vagrant VirtualBox 이미지를 폐기했습니다.

  • breakingVagrant 2.2.5 요구

    이제 Vagrant 2.2.5가 필요합니다.

그 외 기록된 변경 56건 전체value changes 46 · additions 5 · constraints 2 · fixes 2 · renames 1

value changes (46)

  • images are now built as 10G .qcow2
  • Build AMD GPU driver as module
  • Moved systemd-sysext image mounting into the initrd
  • OS-dependent sysexts (e.g., docker-flatcar, containerd-flatcar, podman, zfs, nvidia) are now cryptographically signed using dm-verity roothash signatures.
  • VMs are configured with modern hardware, including a VirtIO storage controller and UEFI.
  • Reworked how the OEM partition is mounted at boot time
  • Switched /etc/ from a custom overlayfs for A/B updates to using a systemd-confext extension
  • - Linux ([6.12.109]
  • - Linux Firmware ([20260519]
  • python ([3.12.13_p1]
  • urllib3 ([2.7.0]
  • adcli ([0.9.3.1]
  • audit ([4.1.4]
  • bash ([5.3_p9]
  • bind ([9.18.42]
  • binutils-config ([5.6]
  • binutils-libs ([2.46.0]
  • bpftool ([7.7.0]
  • btrfs-progs ([6.19.1]
  • c-ares ([1.34.6]
  • checkpolicy ([3.9]
  • cifs-utils ([7.5]
  • conntrack-tools ([1.4.9]
  • coreutils ([9.11]
  • cri-tools ([1.33.0]
  • cryptsetup ([2.8.6]
  • curl ([8.19.0]
  • dracut ([110]
  • e2fsprogs ([1.47.4]
  • elfutils ([0.195]
  • ethtool ([6.19]
  • expat ([2.8.1]
  • gentoo-functions ([1.7.6]
  • git ([2.53.0]
  • glibc ([2.42]
  • gnupg ([2.5.18]
  • gnutls ([3.8.13]
  • hwdata ([0.401]
  • intel-microcode ([20260512_p20260513]
  • iproute2 ([6.19.0]
  • iptables ([1.8.13]
  • kexec-tools ([2.0.32]
  • less ([692]
  • libarchive ([3.8.7]
  • libcap ([2.78]
  • libcap-ng ([0.9.3]

additions (5)

  • Added full terminfo database to support modern terminals like foot and Alacritty.
  • Add EROFS tools for containerd
  • Added Oracle Cloud Infrastructure images
  • Enable VNC console serial logs on ARM64 QEMU/KVM instances
  • enable /dev/kfd/ in amdgpu driver on AMD64

constraints (2)

  • Updated the GCE udev disk rules to include NVMe disks.
  • Added kernel config options to support HuC firmware authentication

fixes (2)

  • Fixed booting the VirtualBox image
  • Fixed using Ignition to create new partitions with number 0

renames (1)

  • All the legacy OEMs (CloudSigma, CloudStack, Exoscale, Vagrant, VirtualBox) have been converted to sysexts.
Flatcar Container Linux 스택에 추가

조치가 필요한 릴리스가 나왔을 때 주간 메일로 알려드립니다. 이번 릴리스의 보안 패치와 브레이킹 체인지 같은 것들입니다.

스택에 추가