logo

Rocky Linux launches opt-in security repository for urgent fixes

ID: 106e40f4-9235-5a0a-8ca6-bf892504b95c

STIX ID: report--106e40f4-9235-5a0a-8ca6-bf892504b95c

Feed Name: Help Net Security

Threat Score
45/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Sinisa Markovic

...
...

Rocky Linux has introduced an opt-in Security Repository to provide accelerated security fixes in narrow cases where a significant vulnerability is public, exploit code exists, and upstream patches are unavailable. The repository is disabled by default to preserve upstream compatibility; administrators can enable it temporarily (e.g., via `sudo dnf --enablerepo=security update`) to receive urgent patches. The move was prompted by two local privilege-escalation flaws (CopyFail and Dirty Frag) that had public proof-of-concept exploits before upstream fixes were broadly available, and updates from this repo are designed to be superseded by the next upstream release.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.