This Week in TUXEDO OS #36-2024 - TUXEDO Computers

  ATTENTION: To use our store you have to activate JavaScript and deactivate script blockers!  
Thank you for your understanding!

This Week in TUXEDO OS #36-2024

Hello TUXEDO fans and open source enthusiasts!

This week, our penguins have been focussing on TUXEDO OS 4, which will soon be released on the basis of Ubuntu 24.04. We have published a preview image for you to test. We are also working on an update path from TUXEDO OS 3 to the new version.

Have fun reading

The TUXEDO OS Team

Updates TUXEDO OS

Preview for TUXEDO OS 4

We have put a preview of TUXEDO OS 4 based on Ubuntu 24.04 online for testing. The image brings

  • Kernel 6.8-tuxedo
  • Plasma 6
  • NVIDIA driver 560
  • Mesa 24.2.1

The only thing missing at this point is our configuration service Tomte, which is still being tested internally.

Please inform us of any issues with the image on GitLab. Notice: This image is not suitable for productive use. However, the stable release should not be long in coming.

Firefox 130

Firefox 130 introduces Firefox Labs, a new function for testing experimental functions. In addition, ten security vulnerabilities have been closed.

Security updates Ubuntu

The Ubuntu security updates listed here flow directly into TUXEDO OS

USN-6982–1: Dovecot vulnerabilities

Several security issues have been fixed in Dovecot.

CVE-2024–23184, CVE-2024–23185

Subject: Ubuntu 24.04 LTS

USN-6984–1: WebOb vulnerability

WebOb could be tricked into redirecting or redirecting to unwanted URLs.

CVE-2024–42353

Subject: Ubuntu 24.04 LTS | Ubuntu 22.04 LTS | Ubuntu 20.04 LTS

USN-6983–1: FFmpeg vulnerability

FFmpeg could crash or run programmes as your login if it opens a specially crafted file.

CVE-2024–32230

Subject: Ubuntu 24.04 LTS | Ubuntu 22.04 LTS | Ubuntu 20.04 LTS | Ubuntu 18.04 ESM | Ubuntu 16.04 ESM

USN-6986–1: OpenSSL vulnerability

OpenSSL could be crashed or reveal sensitive information if it receives a specially prepared certificate.

CVE-2024–6119

Subject: Ubuntu 24.04 LTS | Ubuntu 22.04 LTS

USN-6987–1: Django vulnerabilities

CVE-2024–45231, CVE-2024–45230

Subject: Ubuntu 24.04 LTS | Ubuntu 22.04 LTS | Ubuntu 20.04 LTS | Ubuntu 18.04 ESM

USN-6988–1: Twisted vulnerabilities

Several security issues have been fixed in Twisted.

CVE-2024–41810, CVE-2024–41671

Subject: Ubuntu 24.04 LTS | Ubuntu 22.04 LTS | Ubuntu 20.04 LTS | Ubuntu 18.04 ESM | Ubuntu 16.04 ESM | Ubuntu 14.04 ESM

USN-6985–1: ImageMagick vulnerabilities

Several security issues have been fixed in ImageMagick.

CVE-2019–12975, CVE-2019–11470, CVE-2019–11472

Subject: Ubuntu 24.04 LTS | Ubuntu 22.04 LTS

USN-6989–1: OpenStack vulnerability

OpenStack could be forced to disclose sensitive information.

CVE-2024–44082

Subject: Ubuntu 24.04 LTS | Ubuntu 22.04 LTS

USN-6990–1: znc vulnerability

ZNC could be made to execute arbitrary code on a user’s system when they connect to a compromised server.

CVE-2024–39844

Subject: Ubuntu 24.04 LTS | Ubuntu 22.04 LTS | Ubuntu 20.04 LTS | Ubuntu 18.04 ESM | Ubuntu 16.04 ESM | Ubuntu 14.04 ESM

USN-6993–1: Vim vulnerabilities

Several security issues have been fixed in Vim.

CVE-2024–41957, CVE-2024–43374

Subject: Ubuntu 24.04 LTS | Ubuntu 22.04 LTS | Ubuntu 20.04 LTS | Ubuntu 18.04 ESM | Ubuntu 16.04 ESM | Ubuntu 14.04 ESM

Problems solved

tuxedo-touchpad-switch 1.0.9

Fixes the deactivation of the touchpad after waking up from suspend.

Fix for the problem with empty pages in the system settings

Some pages in the system settings have recently displayed empty pages. The error in the kf6-kirigami package has now been fixed.

BIOS / EC Updates

There are new BIOS versions for:

Aura 15 Gen1

BIOS:1.07.11RTR4

Changelog: Minor bug fixes, performance and stability improvements