Gnoppix Security Update: Critical Opam Flaw Enables Remote Code Execution
Gnoppix 23/25 and 25 users must urgently update the opam package manager. A critical vulnerability, tracked as GSA-6386-1, allows attackers to execute arbitrary code.
The Vulnerability
The flaw resides in how opam handles specially crafted repository metadata. An attacker can exploit this to run malicious code on a victim’s system.
Affected Systems
- Gnoppix 23/25 (stable)
- Gnoppix 25 (testing)
Immediate Action Required
Update your opam package immediately. This is a high-severity security issue.
How to Fix
Run the following command as root:
apt update && apt upgrade opam
Background
The vulnerability was discovered during a security audit. It does not require user interaction beyond normal package operations. No workaround is available. - Please update your systems.