This Week in TUXEDO OS #39-2024 - TUXEDO Computers

  ATTENTION: To use our store you have to activate JavaScript and deactivate script blockers!  
Thank you for your understanding!

This Week in TUXEDO OS #39-2024

Hello dear TUXEDO fans and Open-Source enthusiasts!

This week’s news is fresh out of the update oven! We’ve been hard at work on version 1.4 of WebFAI, mainly in preparation for the highly anticipated TUXEDO OS 4. But that’s not all—our little configuration hero Tomte has also treated itself to an upgrade and squashed a few pesky bugs. Who would have thought that a „no no no no bug“ could be so persistent? But no worries, Tomte has put it in its place!

Enjoy reading,
the TUXEDO OS Team!

Updates TUXEDO

Tomte 2.39.2

  • Hotfix: The ‚no no no no bug‘ was fixed by adding an entry to [/etc/default/grub] that prevents the faulty entry and removes all „no“ entries from GRUB.
  • Hotfix: The issue with [tomte list] or [tomte versions] not working has been resolved.

A simple reboot of the device should be enough to update Tomte and apply the fixes. If this doesn’t work, please follow these steps:

sudo apt update && sudo apt install tuxedo-tomte

WebFAI 1.4

  • Added: Code for TUXEDO OS 4
  • Converted: [sources.list.d] entries from .list to .sources extension starting with Ubuntu 24.04
  • Removed: Unnecessary classes
  • Fixed: OEM background for Kubuntu
  • Fixed: Added missing language package
  • Added: Separate menu for InfinityFlex

TUXEDO OS Updates

We are diligently working internally to finalize TUXEDO OS 4. The QA process is taking a bit longer this time, so it will likely be another two weeks before TUXEDO OS 4 is released as stable. In the meantime, feel free to continue testing the preview and report any issues on GitLab. Please do not use the preview for productive work.

TUXEDO News

TUXEDO not only offers Linux hardware but is also actively involved in Linux development. This week, a first patch for the integration of the tuxedo-driver was submitted to the kernel mailing list. This patch includes a driver for LED backlight control of individual keys on Sirius Gen1 and Gen2 devices.

What Else Happened?

The developers of KDE and the Plasma desktop held their annual developer conference, Akademy, from September 7 to 12. As in every year, there were many interesting talks this time as well. Among them, we found the talk titled An Operating System of Our Own particularly intriguing, where KDE developer Harald Sitter outlines a new KDE distribution he is working on.

BIOS / EC Updates

There are new BIOS versions for:

  • InfinityBook Pro 14 - Gen9 (Intel)
  • InfinityBook Pro 14 - Gen9 (AMD)
  • InfinityBook Pro 15 - Gen9 (Intel)
  • InfinityBook Pro 15 - Gen9 (AMD)

If a changelog is available, you can find it along with the files in your customer account.

Ubuntu security updates

The Ubuntu security updates listed here flow directly into TUXEDO OS.

  • USN-7003–4: Linux kernel vulnerabilities: Several security issues were fixed in the Linux kernel.
    IDs: CVE-2024–39509, CVE-2024–40958, CVE-2024–42084, and 82 others
    Concerns: Ubuntu 20.04 LTS
  • USN-7038–1: APR vulnerability: The system could be made to expose sensitive information.
    IDs: CVE-2023–49582
    Concerns: Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 ESM, Ubuntu 16.04 ESM
  • USN-7037–1: OpenJPEG vulnerability: OpenJPEG could be made to crash if it opened a specially crafted file.
    IDs: CVE-2023–39327
    Concerns: Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 ESM, Ubuntu 16.04 ESM
  • USN-7036–1: Rack vulnerabilities: Several security issues were fixed in Rack.
    IDs: CVE-2024–25126, CVE-2024–26146, CVE-2023–27539, and 7 others
    Concerns: Ubuntu 22.04 LTS
  • USN-7035–1: AppArmor vulnerability: AppArmor restrictions could be bypassed for rules allowing mount operations.
    IDs: CVE-2016–1585
    Concerns: Ubuntu 22.04 LTS, Ubuntu 20.04 LTS
  • USN-7034–1: ca-certificates update: The CA certificates in the ca-certificates package were updated.
    Concerns: Ubuntu 22.04 LTS, Ubuntu 20.04 LTS
  • USN-7009–2: Linux kernel vulnerabilities: Several security issues were fixed in the Linux kernel.
    IDs: CVE-2024–38615, CVE-2024–42082, CVE-2024–39490, and 216 others
    Concerns: Ubuntu 20.04 LTS
  • USN-7033–1: Intel Microcode vulnerabilities: Several security issues were fixed in Intel Microcode.
    IDs: CVE-2024–24968, CVE-2024–23984
    Concerns: Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 ESM, Ubuntu 16.04 ESM
  • USN-7032–1: Tomcat vulnerability: Tomcat could allow unintended access to network services.
    IDs: CVE-2023–46589
    Concerns: Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 ESM
  • USN-7031–2: Puma vulnerability: Puma could be made to overwrite headers if it received specially crafted network traffic.
    IDs: CVE-2024–45614
    Concerns: Ubuntu 22.04 LTS, Ubuntu 20.04 LTS
  • USN-7021–2: Linux kernel vulnerabilities: Several security issues were fixed in the Linux kernel.
    IDs: CVE-2024–39494, CVE-2024–27012, CVE-2024–42160, and 5 others
    Concerns: Ubuntu 22.04 LTS, Ubuntu 20.04 LTS
  • USN-7029–1: Linux kernel vulnerabilities: Several security issues were fixed in the Linux kernel.
    IDs: CVE-2024–32936, CVE-2024–39490, CVE-2024–39483, and 224 others
    Concerns: Ubuntu 22.04 LTS
  • USN-7007–3: Linux kernel vulnerabilities: Several security issues were fixed in the Linux kernel.
    IDs: CVE-2024–38615, CVE-2024–42082, CVE-2024–39490, and 216 others
    Concerns: Ubuntu 22.04 LTS, Ubuntu 20.04 LTS
  • USN-6999–2: Linux kernel vulnerabilities: Several security issues were fixed in the Linux kernel.
    IDs: CVE-2024–32936, CVE-2024–39490, CVE-2024–39483, and 217 others
    Concerns: Ubuntu 24.04 LTS
  • USN-7028–1: Linux kernel vulnerabilities: Several security issues were fixed in the Linux kernel.
    IDs: CVE-2024–26880, CVE-2024–27398, CVE-2024–38570, and 19 others
    Concerns: Ubuntu 18.04 ESM, Ubuntu 16.04 ESM
  • USN-7020–2: Linux kernel vulnerabilities: Several security issues were fixed in the Linux kernel.
    IDs: CVE-2024–42160, CVE-2024–42224, CVE-2024–42154, and 3 others
    Concerns: Ubuntu 24.04 LTS
  • USN-7007–2: Linux kernel vulnerabilities: Several security issues were fixed in the Linux kernel.
    IDs: CVE-2024–42229, CVE-2024–39509, CVE-2024–39471, and 216 others
    Concerns: Ubuntu 20.04 LTS
  • USN-6992–2: Firefox regressions: USN-6992–1 caused some minor regressions in Firefox.
    Concerns: Ubuntu 20.04 LTS\