This is an addendum to our release notes for Qlustar releases 14.1.5 and
13.4.5 which were published on Saturday. Since then a few local root
exploits and other critical bugs have been published, in particular
- GhostLock (CVE-2026-43499)
- Bad Epoll (CVE-2026-46242)
- Januscape (CVE-2026-53359)
Qlustar 14.1.5/Ubuntu has fixed all of these bugs and you are urged to
update your systems if you haven't done so.
Qlustar 14.1.5/Alma and Qlustar 13.4.5 are not vulnerable to Bad Epoll,
but are still vulnerable to Januscape and GhostLock.
In general we highly recommend to update to Qlustar 14 if you haven't
done so yet, as the Qlustar 13 kernel 5.15.x receives fixes by upstream
with a much larger delay as compared to the Qlustar 14 kernel 6.12.x.