Skip to content

Commit ecceb49

Browse files
author
Raito Bezarius
committed
content/blog: drop insufficient option A
Signed-off-by: Raito Bezarius <[email protected]>
1 parent 83c6a7f commit ecceb49

File tree

1 file changed

+3
-11
lines changed

1 file changed

+3
-11
lines changed

content/blog/2025-06-27-lix-critical-bug.md

Lines changed: 3 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -118,16 +118,7 @@ If you need assistance on how to apply remediation, feel free to inquire in our
118118

119119
We will not publish a fixed release on June 28th (today, at the time of writing) due to incomplete testing. We have three recommendations:
120120

121-
### Option A: Patch your current version
122-
123-
We have published patches per release line. You can apply them manually:
124-
125-
* 2.91: https://gerrit.lix.systems/c/lix/+/3515
126-
* 2.92: https://gerrit.lix.systems/c/lix/+/3513
127-
* 2.93: https://gerrit.lix.systems/c/lix/+/3510
128-
* HEAD: https://gerrit.lix.systems/c/lix/+/3501 (already merged, just update the HEAD pin)
129-
130-
### Option B: Revert only the CVE fix
121+
### Option A: Revert only the CVE fix
131122

132123
The vulnerability in CVE-2025-52992 has **no known exploit path**.
133124

@@ -138,7 +129,7 @@ Revert the CVE-2025-52992 patch using reverse diffs:
138129
* 2.93: https://gerrit.lix.systems/c/lix/+/3444 / `f85c84db371d91c4e651d96df6a06fc4ff95b231`
139130
* HEAD: https://gerrit.lix.systems/c/lix/+/3454 / `42e2bd045c9e51a59fdab038dc4e6f9e86c4922c`
140131

141-
### Option C: Roll back to the previous (vulnerable) version
132+
### Option B: Roll back to the previous (vulnerable) version
142133

143134
If you prefer stability, you can revert to your last working version.
144135

@@ -174,6 +165,7 @@ Note that our Gerrit instance returns patches encoded in base64.
174165
* **2025-06-28 17:45 CEST** : Added instructions on how to rebuild the system using the static Nix, co-written by boogiewoogie (thank you!).
175166
* **2025-06-28 21:40 CEST** : Clarified that rebuilding your system makes sense if you changed your configuration to move away from the dangerous version.
176167
* **2025-06-29 21:40 CEST** : Release engineering started to put an end to the incident.
168+
* **2025-06-29 21:48 CEST** : Remove the old option A with manual patching.
177169

178170
---
179171

0 commit comments

Comments
 (0)